1 comment

[ 8.9 ms ] story [ 39.9 ms ] thread
"We don't check that the user is authoritative for an email address, some thought needs to go into how we prove a user has access to an email address in a federated system."

Ideas?