It seems like this should have been noticed earlier. If you are working on authentication code, you should think about how it could be used by a malicious actor.<p>Does anyone know why it took several years to realize the problem here? This kind of simple vulnerability makes me concerned about other security issues in Go.<p>Edit: I am referring to only the SMTP issue here.