by loftar » Mon Mar 07, 2016 4:37 am
I generally don't consider the e-mail address to be a security attribute of an account -- if someone has your password, the account is compromised anyway. The reason a confirmation mail goes to the new account is simply to verify that you actually own the account (as is also done when creating an account in the first place).
Conversely, if changing the e-mail address requires verification from the previous e-mail account, then that thwarts the main purpose of being able to change e-mail address on the account, namely to update if you've switched actual e-mail accounts.
"Object-oriented design is the roman numerals of computing." -- Rob Pike