▲ 1 r/discover
Poor security upon changing my email address
I've had bank accounts at discover.com for several years. I just updated my email address there, and they only sent a confirming email to my new address. They didn't email my old address to notify me that someone had changed my email address.
This ignores current best practices, where it's important to notify the person at the old address in case someone has hacked their login and then changed their email -- thereby permanently stopping all future emails to them.
This is rather disappointing, given that several sites, far less critical than banking, manage to do this properly.
u/LegDramatic9635 — 13 days ago