Someone registered an extension using my email address, so now I can't. Could you validate email-style IDs so they can't be hijacked?

The title pretty much says it all.

I’m making an extension. I set its ID to an email address I own and created specifically for this extension. But before I could get it registered, a user did it by accident. Now I can’t use my own address as its ID.

There really should be some sort of verification in this process, when the ID looks like an email address, to confirm that the person actually owns the address they’re claiming.

I’d like to claim my ID (and address), but I see a bunch of other support requests saying that’s not possible. The ID (and address) is just permanently burned, forever. But I hope to at least prevent others from running into similar issues, and prevent potential attacks where people cause trouble for a target by claiming their target’s address-style IDs. It shouldn’t be possible to register an extension with an address-style ID without confirming that you own that address.

1 Like