Hacker News new | ask | show | jobs
by wmf 5005 days ago
you will have to trust the user's email provider

Or another way to look at it is that you put the burden of choosing a responsible identity provider on the user. If the user chooses poorly they get owned, not you.