This feels very not right… How can they refuse email change? Can only imagine how many people who eventually change their emails and want theirs changed too. What a shitty thing.

  • Nougat@kbin.social
    link
    fedilink
    arrow-up
    4
    ·
    9 months ago

    You’d be surprised by how many services use your email address as the key piece of information to identify your account with them. It is a horribly stupid practice.

        • entropicdrift@lemmy.sdf.org
          link
          fedilink
          English
          arrow-up
          3
          ·
          9 months ago

          Okay, as a software dev, allow me to change your mind:

          Bad code is no more malicious than bad writing, bad ideas.

          It’s like arguing that everyone who’s ever had a bad idea or a poorly structured sentence was a troll and not just some moron.

    • Jackinopolis@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      0
      arrow-down
      1
      ·
      9 months ago

      What else is reasonable to use to uniquely identify users? A username they’ll forget? A phone number maybe? But who wants to give their phone number to some company? We could use SSN like Korea, but that’s way too far for a typical user.

      • Nougat@kbin.social
        link
        fedilink
        arrow-up
        2
        ·
        9 months ago

        You want to use a value which will never change, so you don’t use anything the user provides at all. When a user creates an account, that account is assigned a unique identifying value by the application. This is how objects are identified in Active Directory, for example: each user, computer, group, etc. gets a Security Identifier (SID). That SID never changes, and the value is never repeated for any other object ever, even if the original object is deleted. Every other property of the object can be changed.

        Basically, the key value to say “this account is this account” should never ever have any other purpose.

      • Still@programming.dev
        link
        fedilink
        English
        arrow-up
        1
        ·
        9 months ago

        you would use some form of UUID or GUID and then have email as a secondary to look the ID up

  • bionicjoey@lemmy.ca
    link
    fedilink
    English
    arrow-up
    1
    ·
    9 months ago

    Lol, the fact that they try to give security advice for an account other than their own… They can’t possibly know what sort of email someone has or what they should do with it.

    • amio@kbin.social
      link
      fedilink
      arrow-up
      1
      ·
      9 months ago

      Well, they’ve got to say something. Whether it actually makes sense is probably not even a secondary concern.