Hacker News new | ask | show | jobs
by johnbrodie 2208 days ago
FWIW, this solution isn't as easy to implement as you'd think. I've seen unsubscribe pages harvested for email addresses when they show the full address and used urls/tokens that weren't sufficiently secure. In the case I'm thinking of, the home-rolled algo that generated the unique links was bugged enough that you could reverse it, and I was surprised that someone actually took the time to do so.