-
Notifications
You must be signed in to change notification settings - Fork 73
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Directed e-mail address concerns in case of making it mandatory #24
Comments
Yep, agreed that this is a massive problem. However, I think that the biggest challenges aren't on the IDP side (these are fairly well funded companies, at least in the consumer space. in enterprise and EDU, I think that's a whole different story.)
These are the biggest challenges I think: relying parties use cases where real email addresses are needed. Account recovery and customer support occurs often. Anything else comes to mind where RPs will face a challenge if given a directed email address? |
Speaking to most of those issues, yes this does put an onus on IDPs to make significant changes to how they work, including possibly requiring that non-email-providing IDPs set up forwarding services. The main way these concerns have shaped our approach is to ensure that IDPs are engaged as stakeholders early on, and also they set expectations for a longer timeline before this is might be commonly in use. |
Needs some thought - Two things that come to mind immediately:
The above would entail changes at RPs most probably / and or user education. Not sure how IDPs that implemented proxy features deal with that. |
Physical world interactions also greatly suffer here. Retail loyalty programs are a great example. In most cases, you walk into a store and they ask for a phone or email to look up your loyalty number. If phone number isn't capture and email is a directed email, the user experience greatly suffers overall. |
In addition to the many challenges faced by RPs mentioned here and elsewhere (like https://twitter.com/__b_c/status/1362471694082826246) I don't think the challenges to the IDP side can be written off so easily. Support for directed email addresses is a huge requirement that will further push towards centralization of a very small number of large IdPs. |
This is an old thread, and we never got to directed email addresses (e.g. in terms of making them mandatory), aren't actively working on anything remotely close to it, so I'm going to close this as obsolete. Feel free to re-open if you feel like there is something actionable here. |
Moving this into a separate issue from #12
The directed e-mail claim feature requires clarification (the privacy goal is clear) (https://github.com/WICG/WebID/blob/master/design.md#directed-basic-profile)
The text was updated successfully, but these errors were encountered: