Re: [w3ctag/design-reviews] Incubation: Email Verification Protocol (Issue #1169)

samuelgoto left a comment (w3ctag/design-reviews#1169)

> To be clear, there are problems with disposable email addresses and we're working on solutions for that (see recent Anti-Fraud CG discussions), but I think they should be the default. In other words, privacy with respect to the RP is the main concern I have

I just wanted to re-enforce what @dickhardt said here:

> wrt. disposable emails -- a browser could coordinate with an email provider to provide a signed token containing a disposable email address -- simplifying providing a privacy preserving communication identifier.

That's correct: we designed this such that if a browser wanted to provide directed/disposable email addresses (that are also cryptographically verifiable) through this system they would be able to (without any modification to relying parties, meaning interoperable with the other parts of the system).

-- 
Reply to this email directly or view it on GitHub:
https://github.com/w3ctag/design-reviews/issues/1169#issuecomment-3647935203
You are receiving this because you are subscribed to this thread.

Message ID: <w3ctag/design-reviews/issues/1169/3647935203@github.com>

Received on Friday, 12 December 2025 19:55:22 UTC