Get the latest tech news
Not OK Cupid – A story of poor email address validation
A story of poor email address validation.
Specifically, this list included trash@brong.net — an address that has never been used to send or receive email and appears in precisely one place — an article on our blog! Attackers can use unverified sign-ups to flood inboxes, making it easier to hide critical emails among the noise — something we’ve discussed our own experience of in our post on 2FA vulnerabilities. Masked emails are designed, particularly when integrated with a password manager, to make it very easy to create new addresses, and track where they are expected to be used.
Or read this on Hacker News