cybersecurity
Cybersecurity News videodrome 9 months ago 88%

Email addresses are not good 'permanent' identifiers for accounts

Every so often someone needs to create a more or less permanent internal identifier in their system every person's account. Some of the time they look at how authentication systems like OIDC return email addresses among other data and decide that since pretty much everyone is giving them an email address, they'll use the email address as the account's permanent internal identification.

As the famous saying goes, now you have two problems.

7
0
Comments 0