Hello all,
I putting together a small system where the users put create their login and are asked to use their email for that purpose.
As it stands now - after sucsessul account creation the users can log in with their email address.
What I'm worried about is that they can login without confirming that they have access to the email given by them (that becomes their login) this is something I overlooked it in v1 of the design and I'm worried that this could breach some laws and create a potential for 'identity teft'.
What do you think I should do - redesign (a bit of a time pressure on that) or is it acceptable to leave it as is.
If anyone knows about systems like this could you give examples in your postings.
Cheers
Now my
I putting together a small system where the users put create their login and are asked to use their email for that purpose.
As it stands now - after sucsessul account creation the users can log in with their email address.
What I'm worried about is that they can login without confirming that they have access to the email given by them (that becomes their login) this is something I overlooked it in v1 of the design and I'm worried that this could breach some laws and create a potential for 'identity teft'.
What do you think I should do - redesign (a bit of a time pressure on that) or is it acceptable to leave it as is.
If anyone knows about systems like this could you give examples in your postings.
Cheers
Now my