Dafacto

  • Home
  • About
  • Blog
  • My Book
  • Contact
  • Social
    • Twitter
    • Flickr
    • LinkedIn
    • Facebook
    • Instagram
Home » Blog » Design » Authenticating support requests

Authenticating support requests

February 29, 2016 Leave a Comment

I experienced something today that’s frustratingly becoming quite common. I emailed the support address of a financial institution I use, and they replied that they can only provide support if I contact them from the email address registered to my account.

The problem here is that as the owner of my own domain, I can receive email sent to [email protected], and I take advantage of that by using unique email addresses for most services I sign up for. (If for nothing else, this makes it easy to determine who’s passing on my email address to spammers.) But I can not easily send emails from all those different addresses, since that would require adding each one manually to Mail.app.

What I find irritating, is the company’s assumption that the “from” address serves as any kind of authentication, since it’s dead easy to spoof the from address on an email!

Any company that wants to provide authenticated support must provide a mechanism to initiate the conversation only from within a logged-in authenticated session at their website (or app). After that, it’s fine to continue the conversation outside the authenticated session—e.g. using ZenDesk, HelpScout or whatever support tool they use—because regardless of the email address I use from that point forward in the conversation, I wouldn’t be in a position to even respond if I hadn’t been the one who securely initiated the conversation in the first place.

Filed Under: Design Tagged With: Geek

Hi there! I’m Matt—a co-founder at Makalu and Brazilian Jiu-Jitsu black belt. I wrote a book you should read about investing and financial freedom, Money for Something.

I’m Matt Henderson—co-founder at Makalu, author and Brazilian Jiu-Jitsu black belt.

Get updates by email

Your email is safe, and you can unsubscribe at any time

Popular Posts

  • The Big Short—A brief summary of the 2008 financial collapse
  • How to setup a roaming wifi network over ethernet with an Airport Extreme and Airport Express
  • How to setup a Wordpress site on a Mac mini running OS X Server Yosemite
  • Fixed — Stopped the tccd process in Mac OS X Mavericks from consuming CPU and memory
  • A Two-Context Approach to GTD with OmniFocus
  • How to create a kill-switched VPN on Mac OS X with Little Snitch
  • My experience with the Paleo diet

Recent Posts

  • Email, please
  • The difference between developers and product designers
  • My interview about Bitcoin and blockchains on the Gruvi podcast
  • Why keeping it simple would be a better choice for TransferWise

Tags

Apple Bitcoin BJJ Books Business Businesses Chess Customer Service Cycling Design eBooks Economics Education Fail Finance Fitness Funny Geek GTD Health Ideas Investing iOS KeyboardMaestro Mac Makalu Money for Something Personal Politics Productivity Products RaceSplitter Rants Rego Religion Society Spain Spam Spammers Sports Technology Tips UI+UX User Experience WordPress

Categories

  • Books (2)
  • Brazilian Jiu Jitsu (14)
  • Business (41)
  • Chess (21)
  • Design (50)
  • Life (29)
  • Makalu (28)
  • Money (24)
  • Productivity (12)
  • Products (20)
  • Rants (98)
  • Society (29)
  • Sports (12)
  • Technology (205)
  • Tidbits (120)
  • Travel (26)

Copyright © 2016 · All rights reserved.