Recovery based on the creation e-mail *not* the changed e-mail address.
This isn't a competition of who's right or wrong, dude. Maybe if you didn't treat it as such (leading you to attempt to dominate others) you'd be able to actually follow what others are saying.
This moron with a nasty attitude can't seem to get it through his head that in the first scenario, the user which has received the 2VC did not do so via access to the owner's e-mail, but simply being transferred the information (2VC) from the owner himself who has sole means of access to an associated e-mail, therefore, putting a limit (i.e. e-mail verification) on changing privacy settings (e.g. e-mail change, password, 2SV) would be a rational safety mechanism.
Then he can't even imagine the second scenario where even if an "unauthorized" user gained e-mail through a compromised e-mail (which is associated with runemate), and changed the e-mail associated to runemate, that the original creator may recover the original [e-mail] creation account and request a password reset.
After all that, he proceeds to belittling, personal attacks, and parental-type accusations because he's too arrogant and retarded to accept and recognize the fact that he was incorrect, and goes forth projecting that onto others.
If you're not interested in helping others, or having a rational discussion with them on the matter in question, and just need to express an arrogant, judge-like character, because you are unable to control your own emotions, then FUCK OFF, and don't ever comunicate with me again.
Or this will be how it play out: