I just signed up for tagged.com because I heard about something strange...

Apparently - they send email notifications with tokens in the URL that authenticate you automatically to their site after clicking...

I was wondering what kind of vulnerabilities would exist with this... For instance if my email account is ever used by anyone else again, they would receive these emails that let them into my account.

At the same time though, password reset emails would get them in all the same.

Does anyone else see this as a problem? It seems fishy...