Confirmed users
920
edits
LesOrchard (talk | contribs) |
LesOrchard (talk | contribs) |
||
| Line 15: | Line 15: | ||
==== Safe migration from legacy auth to BrowserID ==== | ==== Safe migration from legacy auth to BrowserID ==== | ||
* Never trust that the email address currently associated with a profile is valid or usable | * Never trust that the email address currently associated with a profile is valid or usable | ||
** | ** Stale data; user could have lost control in the time since first signed up and verified it | ||
* Require legacy username / password auth followed by subsequent BrowserID signin | * Require legacy username / password auth followed by subsequent BrowserID signin | ||
** Ensures verified hand-off from legacy auth to BrowserID | ** Ensures verified hand-off from legacy auth to BrowserID | ||