Microsoft's Security Scanners Break Single-Use Links: A Shifting Cyber Norm
2025-01-23

Bert Hubert reveals that Microsoft and other email security scanners are visiting links in emails and executing JavaScript, including sending POST requests. This violates the long-standing norm that POST requests shouldn't have side effects, breaking single-use login links. The article discusses the impact on web development and calls for greater transparency from large tech companies when changing internet norms.
Development
Single-use links