Open-Assistant
Open-Assistant copied to clipboard
Email spam potential
On Open Assistant if you type your email to the login page, it would send to you an email that contains the verification link. However, a bad actor can make a small script to harrass other users by spamming their inbox with unsolicited email. There should be a rate limit for sending the link to an email inbox in one session.
This is true for any email magic link service right? Is anyone actually doing this?
I don't think it's super urgent or dangerous atm, but it's the classical attack: If not rate limited, it could be "weaponized". Because of this, many services ensure rate limitation and similar.
We now have a captcha for email signin