如何验证网站的所有权?
例如,Google 网站管理员控制台通过要求网站所有者上传具有特定名称的文件来实现此目的。其他服务也使用相同的方法。
是否有任何理由不通过简单地要求人们通过单击发送到该特定域下的电子邮件的电子邮件来确认来验证所有权? (前提是该网站不泄露用户的电子邮件地址,例如 gmail 等)
e.g. Google Webmaster Console does it by asking website owners to upload a file with specific name. Other services use the same approach.
Is there any reason why not verify ownership by simply asking people to confirm by clicking the email that was sent to the email under that particular domain? (provided that website does not give out its users email addresses like gmail etc)
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。
绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论
评论(5)
因为这是查明该人是否拥有相关网站控制权的最直接且 100% 万无一失的方法。
域“下”的电子邮件地址可以属于管理员,而站点实际上由开发人员管理。
此外,许多人使用匿名注册,在这种情况下,电子邮件将发送到注册商地址(尽管它通常会转发到您的真实地址或至少通知您)。
Because it is the most direct and 100% bulletproof way to find out if the guy has the control over the site in question.
Email address "under" the domain can belong to the admin while the site is actually managed by the developer.
Also, many use anonymous registration, in which case email will be sent to the registrar address (though it will usually forward to your real address or at least notify you).
我拥有 GMail 帐户并不意味着我拥有 gmail.com 域。就像“开发者艺术”所说,上传文件表明您有权访问该域的网络托管部分。
I have a GMail account doesn't mean I own the gmail.com domain. Like 'Developer Art' said, uploading a file shows that you have access to web-hosting portion of the domain.
除非您以某种方式修改网站,否则他们怎么知道您是该域中负责该网站的人?我有一个公司电子邮件地址 - 这并不意味着我对公司网站负责。
How would they know that you are the person at that domain responsible for the website unless you modify it in some way? I have a company e-mail address - that doesn't mean I'm responsible for the company website.
我可以使用您提出的验证技术来证明我“拥有”Yahoo、Hotmail、Gmail 和许多其他公司。对于从事网络工作的人来说,将文件上传到服务器有什么困难呢?
I can prove that I "own" Yahoo, Hotmail, Gmail, and many others with your proposed verification technique. What's so hard about uploading a file to a server for someone doing web work?
我认为其意图是,“如果您拥有该网站,请将此验证文件放在您网站的根目录中。”一旦验证系统看到该文件,所有权就得到验证。至少,它确认了发布到站点根文件夹的能力。如果您的用户没有这种期望,您可能会因为您没有正确验证所有权而暴露在别人的网站上进行恶意活动的风险。在法律界,我们称之为“尽职调查”。
电子邮件……你知道,我不断收到来自我没有账户的银行、英国彩票的消息,甚至还有来自尼日利亚的一个人的消息。它们看起来是真实的。现在想来,也许我应该将他们所有的电子邮件转发给对方。彩票人和尼日利亚人可以将所有的钱存入假银行账户。垃圾邮件问题解决了!
I think the intent is, "If you own the site, please place this verification file in your site's root directory." Once the verification system sees the file there, ownership is verified. At the very least, it confirms the ability to post to a site's root folder. Not having this expectation of your users might open you up to folks doing malicious activities as someone else's site because you didn't properly verify ownership. In legal circles, we call that, "due diligence."
E-mail... you know, I keep receiving messages from banks I don't have accounts with, the British Lottery and even more from a guy in Nigeria. They look real. Now that I think about it, maybe I should forward all of their e-mails to each other. The lottery guys and the Nigerian guy can put all their money into the fake bank accounts. Spam problem solved!