Live data from Hacker News

The dots do matter: how to scam a Gmail user

jameshfisher.com

21–30 of 518 posts

Re: The dots do matter: how to scam a Gmail user

#21
post #11

>Where is the security flaw here? Some would say it’s Netflix’s fault; that Netflix should verify the email address on sign up, or that Netflix should disallow the registration of james.hfisher@gmail.com when a Netflix account already existed for jameshfisher@gmail.com. But such policies would not add security, and would force Netflix and every other website to have insider knowledge of Gmail’s canonicalization algor…

I'm sorry, this sentence wasn't clear, and I agree with you. What I meant by this was:

- Some would say that Netflix should verify the email address on sign up, but there's no obvious attack that this mitigates. Using someone else's address on signup only cedes account control to them.

- Others would say that Netflix should disallow the registration of james.hfisher@gmail.com when a Netflix account already existed for jameshfisher@gmail.com. But this would force Netflix and every other website to have insider knowledge of Gmail’s canonicalization algorithm.

Re: The dots do matter: how to scam a Gmail user

#23
post #6

> But firstly, no one wants this infinite set of email addresses. Gmail already provides this in the better form of plus labelling. What is the difference between dots and pluses? They both have the same flaw: to Netflix they will both be distinct addresses.

Pluses are part of email standard, dots are some nonsense Google thought was a good idea.

As far as I know, plus wildcards are not part of the standard either.

Re: The dots do matter: how to scam a Gmail user

#24
post #6

> But firstly, no one wants this infinite set of email addresses. Gmail already provides this in the better form of plus labelling. What is the difference between dots and pluses? They both have the same flaw: to Netflix they will both be distinct addresses.

Maaaany email address validators will reject Gmail addresses with + in them as "not valid".

"Read the Friendly Standard", I know, but dots are much less likely to be rejected.

Half the time I think it's because the site wants it to be less obvious when their database is compromised.

Re: The dots do matter: how to scam a Gmail user

#27
A couple of things that I didn't quite follow.

1. In order to provide the payment details, they had to do a password reset to the dot-email address. I can only assume that locks out 'eve' in this case, but I suspect it doesn't force a re-login on all devices.

2. When 'eve' signed up to the dot-email address, surely Netflix would have sent a welcome email thanking them for starting a trial. So in that case, I can't see how it would have gone completely undetected up to this point.

I personally feel that Netflix should validate the email address on registration. Otherwise people who genuinely sign up with a typo in their address may lose access to it forever.

Re: The dots do matter: how to scam a Gmail user

#28
post #6

> But firstly, no one wants this infinite set of email addresses. Gmail already provides this in the better form of plus labelling. What is the difference between dots and pluses? They both have the same flaw: to Netflix they will both be distinct addresses.

Pluses are part of email standard, dots are some nonsense Google thought was a good idea.

Both + and . are allowable characters in the user part of an email address. AFAIK, the tagging functionality isn’t part of the email standard any more than ignoring dots is.

EDIT: huh, turns out RFC 5233 covers this. TIL. Thanks, ipsin

Re: The dots do matter: how to scam a Gmail user

#29
Why doesn't Netflix require users to be logged in before they can change their card details? That seems like the biggest security flaw, not the Gmail dot alias.

(I'm guessing they did A/B testing and found that having to log into your account lost them some percentage of people. If that's the case, Netflix are clearly putting their retention rate ahead of security)

There's probably a not insignificant number of people who are happily using a dotted variation of their gmail account. Putting a big warning above the email wouldn't make them very happy.

Re: The dots do matter: how to scam a Gmail user

#30

Earlier quoted context omitted.

Pluses are part of email standard, dots are some nonsense Google thought was a good idea.

As far as I know, plus wildcards are not part of the standard either.

This is an RFC 5233 subaddress.
Post reply on HN