Agree this needs some thought. Right now anyone can log in with fake email address and personal details – useless for marketing or security purposes. But how do you validate while keeping user behind a captive portal?