How hard is it to implement email verification?

  • it_depends_man@lemmy.world
    link
    fedilink
    English
    arrow-up
    241
    arrow-down
    4
    ·
    1 day ago

    How hard is it to implement email verification?

    Harder, actually.

    That’s the point of OAuth, which is what you’re seeing there.

    The idea is that you’re you and you have a… google account. This shitty little website doesn’t want to be responsible for you login details, because those can get stolen. Maybe they contain an email address, which is a problem. Software needs to be updated, it’s all a big. They don’t want to touch anything in terms of security that identifies you as you.

    Maybe all the website does is save your favorite pepe memes. They don’t need anything else from you, but they still need to have something to get a user id and make sure nobody messes with your pepe meme collection. That’s where this system comes in, because the rest of website becomes significantly easier. They don’t need to store anything personally identifying, all they get is an ID and they can connect it with your pepes.

    The only downside to OAuth is, as you can also see, that it’s corpos you don’t want to trust that are offering it.

    • skisnow@lemmy.ca
      link
      fedilink
      English
      arrow-up
      1
      ·
      4 hours ago

      Most users outside of Lemmy dgaf about corpos if it saves them having to type in an email address on their phone and get it right and then go to their email and then hit refresh a few times before going back and hitting send again and then checking their spam folder

    • Wispy2891@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      9 hours ago

      But most oauth implementations use the user email as identifier so they get the email anyway

      • it_depends_man@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        2 hours ago

        All the smarter ones don’t because an email can change, your google account unique id will not, that’s the purpose of account IDs.

        I won’t deny that many people/websites probably do use email though. Which is bad. But I can’t deny that that probably is what is happening.

    • nieminen@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      ·
      12 hours ago

      Yeah, some of the same reason everyone uses stripe or PayPal for payment systems. If the site itself handles the cc info it holds all the liability, and has to pass rigorous POC testing and compliance.

    • criss_cross@lemmy.world
      link
      fedilink
      English
      arrow-up
      26
      ·
      23 hours ago

      Was just about to say getting Auth right is super hard. Getting someone else to do it for you is a godsend.

    • lenocolomo@lemmy.ml
      link
      fedilink
      English
      arrow-up
      33
      arrow-down
      1
      ·
      1 day ago

      While I get that, it is still unfortunate that no open-source, trusted variant can be part of the usual ways.

    • fraksken@infosec.pub
      link
      fedilink
      English
      arrow-up
      5
      arrow-down
      1
      ·
      24 hours ago

      I have no account with the above. I wouldn’t make one for being able to use another service.

      No idea what the product is here, but I guess I’m not their target audience. Which is fine.