OK, so now I know that I need to hack your dns server or your registrar instead - then I'd just publish MX records for your domain and head off to all the "I forgot my password" links I can find.
It's turtles^h^h^h^h^h^h^hsecurity problems all the way down…
Yes. I am aware that there a further attacks, and I mention that in the blog post. There is still significant security value in doing what I'm doing though.
For sure - sorry if I gave the impression that I thought otherwise. There's a big win in making it impossible for me to trawl through all your old mail looking for "interesting" things. It's a very nice idea.
It's turtles^h^h^h^h^h^h^hsecurity problems all the way down…