On Sat, Nov 11, 2023 at 05:58:43PM +0100, Nicolas George wrote: > Michael Niedermayer (12023-11-11): > > Also iam not sure resending mails to different addressed when they bounce is safe > > Lets just consider i receive a mail at niedermayer.cc, i could construct a bounce and > > send it back while still voting with the token in it. If i now get a mail at gmx.at > > i could vote twice. > > I am confused: you would get the same token in the second mail, you > would not be able to use it twice. yes, i got 2 emails with the same url with teh same token in it so i can only vote once with that (each token can only vote once) id have to check the CIVS source on how this is achieved. i guess its either storing the emails or hashes of them. or the tokens are computed from the emails so the same email results in the same token thx [...] -- Michael GnuPG fingerprint: 9FF2128B147EF6730BADF133611EC787040B0FAB "Nothing to hide" only works if the folks in power share the values of you and everyone you know entirely and always will -- Tom Scott