Hacker News new | ask | show | jobs
by steven777400 4420 days ago
Email has been compared to the "keys to the kingdom", since almost all other services passwords can be reset if you have access to someone's email. Some other posters have expressed doubt or concern about granting access to email for this service; I would express the concern in the opposite direction:

As developers, we should not be asking people for access to their email (or similar levels of access).

It sets a bad precedent, like banks sending out emails with clickable links; we're encouraging people to engage in very risky behavior and ultimately making it more likely they (the users) will fall for a scam in the future.

This should one of those "IT will never ask for your password" kind of things that gets hammered into people. "Legitimate services will never ask for access to your email/harddrive/etc". I'm not saying this service is not legitimate: I'm saying, as a presumably legitimate service, it should not set a bad example.