While I, like many in the comments, agree that Netflix needs to validate the email account, my hunch is this trick would still be quite effective with that.
The dots do matter: how to scam a Gmail user
31–40 of 518 posts
Re: The dots do matter: how to scam a Gmail user
#32I really wish that I could tell google to bounce all the emails that don’t match my “dot pattern” I’m now in complete control of someone else’s commercial business hvac account because of precisely this problem. And the worse part is that I don’t know the correct email to get ahold of this person. They’ve set up library appointments, I received a receipt for a down payment on a lake house, basically most of this pers…
I also combat with the same problem from time to time.
Re: The dots do matter: how to scam a Gmail user
#33I wonder if others feel that it is ethical or unethical to log into other people's accounts in this situation.
I get lots of emails resulting from people typo'ing my email address instead of theirs—and the unsubscribe links are often hidden behind a login page. But I feel uncomfortable signing in using a "forgot password" link into an account that I know isn't mine. At the end of the day, I usually just create (yet another) email filter to automatically delete these emails (marking them as spam doesn't train the spam filters in my experience).
I'd be interested to know what others think of the ethics of this, or if there are other workarounds.
Re: The dots do matter: how to scam a Gmail user
#34Re: The dots do matter: how to scam a Gmail user
#35Re: The dots do matter: how to scam a Gmail user
#36> But firstly, no one wants this infinite set of email addresses. Gmail already provides this in the better form of plus labelling. What is the difference between dots and pluses? They both have the same flaw: to Netflix they will both be distinct addresses.
Pluses are part of email standard, dots are some nonsense Google thought was a good idea.
Re: The dots do matter: how to scam a Gmail user
#37Totally disagree with the conclusion. This is Netflix's issue for not validating the email account. Not sure if Uber has changed this since then, but back in the day I used to get the full ride details and receipts from someone else who mistyped their email. If you are sending private transactional emails you need to verify accounts first.
I think these are orthogonal issues. The dots do matter, but Netflix should also validate email addresses. However, I don't think it's as critical. Lack of email validation means I receive someone else's ride details (I agree, annoying), but dots-don't-matter means I might accidentally pay for that person's rides.
Re: The dots do matter: how to scam a Gmail user
#38This is exactly why you need to normalize email addresses. The people who wrote the email RFCs just plain got it wrong, so it’s up to every SaaS site to do this so that they aren’t putting their users at risk. If someone is using an email with that’s the same as someone else’s except for the capitalization, it should be on them to get a new email address.
Re: The dots do matter: how to scam a Gmail user
#39>Where is the security flaw here? Some would say it’s Netflix’s fault; that Netflix should verify the email address on sign up, or that Netflix should disallow the registration of james.hfisher@gmail.com when a Netflix account already existed for jameshfisher@gmail.com. But such policies would not add security, and would force Netflix and every other website to have insider knowledge of Gmail’s canonicalization algor…
I'm sorry, this sentence wasn't clear, and I agree with you. What I meant by this was: - Some would say that Netflix should verify the email address on sign up, but there's no obvious attack that this mitigates. Using someone else's address on signup only cedes account control to them. - Others would say that Netflix should disallow the registration of james.hfisher@gmail.com when a Netflix account already existed fo…
Re: The dots do matter: how to scam a Gmail user
#40This is exactly why you need to normalize email addresses. The people who wrote the email RFCs just plain got it wrong, so it’s up to every SaaS site to do this so that they aren’t putting their users at risk. If someone is using an email with that’s the same as someone else’s except for the capitalization, it should be on them to get a new email address.
However since Netflix is not managing email addresses in accordance with RFC-5322 They are clearly wrong.