- Microsoft's email security scanners now execute JavaScript in email links, including POST requests, breaking single-use sign-on links.
- Historically, GET requests were considered safe and idempotent, while POSTs had side effects and were avoided by scanners.
- Website operators must now design systems to handle repeated or fake confirmations from security scanners.
- Microsoft's actions represent a significant shift in cyber norms without transparency or warning to users.
- The author calls for better accountability from tech gatekeepers like Microsoft under regulations like the EU Digital Markets Act.