[FEEDBACK] E-mail Security - Sharing An Idea
So I just noticed that to change the e-mail of my account, is pretty simple. But I don't think that's even a bit safe. It seems that stealing someone's password is easy and just with that, just with the password, you can change the course of the account by simply entering on the website, changing the password and then changing the e-mail (there is not even one e-mail sent to the original e-mail to confirm these changes!!!) If this is about convenience, forget about it! Such big company cannot afford this sort of stuffs! Security is a need!
I believe that it would be wiser, if not, safer to change this. Please hear me out RIOT.
So I thought of this:
. Instead of simply being the otpion "New E-mail Adress" (the other options are irelevant) and simply going to that E-Mail and confirm the change, why not placing an option before that one "Original E-Mail Adress" and then yes "New E-Mail Adress".
What I seek with this is quite simple. By doing this, whoever has the password, no matter what happens, he won't change the password, he won't change the e-mail IF there is a mail sent to the ORIGINAL mail FIRST, CONFIRMING the PASSWORD and/or E-MAIL change.
(NOTE: There is no specific place to put feedback like this anywhere!!! (help me if there is) Maybe it would be a good idea to add one?)
Much thanks for reading.