My question is based on this tweet after I commented about forbidding +
symbols in email addresses. The tweet says, "This is a measure we've taken for security reasons."
This can be frustrating and inconvenient for people that have (or use) plus signs in their email address, and I'm sure web sites don't intend to do that. I'm unaware of the security vulnerabilities related to using the +
character; is this something I should change to improve my own security? What is the security reason for a web site to disallow that character on an email field?
Update: Meetup Support responded positively. Turns out it's more of a UX issue than a security one. They clarified in this tweet that they disallow +
to prevent spam (?) and they acknowledged a suggestion for improving the user experience. (My intent here was not to gripe about Meetup; let's be gentle! I wanted to make sure I was not missing something important in my own web sites that receive email addresses.)