Comment 4 for bug 457371

Revision history for this message
root (n-root-psiphon-ca) wrote :

Temporary solution gives the same feedback whether the email address is valid or not, although it's still possible that there's a timing attack as the success case sends an email (doesn't enqueue, sends -- but that may just enqueue in the SMTP server process).

                There's still no throttling or daily limit. Maybe this could piggy back on the throttling done for email verification in April/2.2.