Live data from Hacker News

The dots do matter: how to scam a Gmail user

jameshfisher.com

31–40 of 518 posts

Re: The dots do matter: how to scam a Gmail user

#31
IMO, the big takeaway here is that protecting yourself from phishing is not just about making sure the email is from who it says it is but also making sure it's actually serving the purpose you believe it is.

While I, like many in the comments, agree that Netflix needs to validate the email account, my hunch is this trick would still be quite effective with that.

Re: The dots do matter: how to scam a Gmail user

#32
post #4

I really wish that I could tell google to bounce all the emails that don’t match my “dot pattern” I’m now in complete control of someone else’s commercial business hvac account because of precisely this problem. And the worse part is that I don’t know the correct email to get ahold of this person. They’ve set up library appointments, I received a receipt for a down payment on a lake house, basically most of this pers…

Obligatory XKCD: https://xkcd.com/1279/

I also combat with the same problem from time to time.

Re: The dots do matter: how to scam a Gmail user

#33
> but I also have access to the account because I own james.hfisher@gmail.com, and so I can follow the password reset process for this account. I did so.

I wonder if others feel that it is ethical or unethical to log into other people's accounts in this situation.

I get lots of emails resulting from people typo'ing my email address instead of theirs—and the unsubscribe links are often hidden behind a login page. But I feel uncomfortable signing in using a "forgot password" link into an account that I know isn't mine. At the end of the day, I usually just create (yet another) email filter to automatically delete these emails (marking them as spam doesn't train the spam filters in my experience).

I'd be interested to know what others think of the ethics of this, or if there are other workarounds.

Re: The dots do matter: how to scam a Gmail user

#35
100% disagree. My standard gmail address is with dots but when I have to tell my (rather long because it is my full three part name) I either omit the dots or tell them they don't matter. Totally an important and useful feature. Netflix is at fault for letting someone else use your email without asking you for permission.

Re: The dots do matter: how to scam a Gmail user

#36
post #6

> But firstly, no one wants this infinite set of email addresses. Gmail already provides this in the better form of plus labelling. What is the difference between dots and pluses? They both have the same flaw: to Netflix they will both be distinct addresses.

Pluses are part of email standard, dots are some nonsense Google thought was a good idea.

Plusses are an optional part of a standard[1]. The main email standard does not require a+b@c.com to be treated the same as a@c.com [2].

[1] https://tools.ietf.org/html/rfc5233

[2] https://tools.ietf.org/html/rfc5322#section-3.2.3

Re: The dots do matter: how to scam a Gmail user

#37

Totally disagree with the conclusion. This is Netflix's issue for not validating the email account. Not sure if Uber has changed this since then, but back in the day I used to get the full ride details and receipts from someone else who mistyped their email. If you are sending private transactional emails you need to verify accounts first.

I think these are orthogonal issues. The dots do matter, but Netflix should also validate email addresses. However, I don't think it's as critical. Lack of email validation means I receive someone else's ride details (I agree, annoying), but dots-don't-matter means I might accidentally pay for that person's rides.

But if just the email validation problem were addressed - you wouldn't accidentally pay for someone's rides. Their account would never be created as they don't have access to the email they provided. Just dealing with email validation solves both problems.

Re: The dots do matter: how to scam a Gmail user

#38

This is exactly why you need to normalize email addresses. The people who wrote the email RFCs just plain got it wrong, so it’s up to every SaaS site to do this so that they aren’t putting their users at risk. If someone is using an email with that’s the same as someone else’s except for the capitalization, it should be on them to get a new email address.

In gsuite dot matters.

Re: The dots do matter: how to scam a Gmail user

#39
post #11

>Where is the security flaw here? Some would say it’s Netflix’s fault; that Netflix should verify the email address on sign up, or that Netflix should disallow the registration of james.hfisher@gmail.com when a Netflix account already existed for jameshfisher@gmail.com. But such policies would not add security, and would force Netflix and every other website to have insider knowledge of Gmail’s canonicalization algor…

I'm sorry, this sentence wasn't clear, and I agree with you. What I meant by this was: - Some would say that Netflix should verify the email address on sign up, but there's no obvious attack that this mitigates. Using someone else's address on signup only cedes account control to them. - Others would say that Netflix should disallow the registration of james.hfisher@gmail.com when a Netflix account already existed fo…

Does anyone else use dots in their email service? Wouldnt your second point be as simple as Netflix checking every gmail address against a dotless version of all of those addresses? Eg email-1 in the table is their address as input and email-2 is the dotless version, Netflix could then ensure that email-2 is unique. Seems pretty straight forward to accomodate an admittedly silly ‘feature’ of the largest email provider.

Re: The dots do matter: how to scam a Gmail user

#40

This is exactly why you need to normalize email addresses. The people who wrote the email RFCs just plain got it wrong, so it’s up to every SaaS site to do this so that they aren’t putting their users at risk. If someone is using an email with that’s the same as someone else’s except for the capitalization, it should be on them to get a new email address.

My understanding is that the RFCs define how the Internet work so by definition, they are not wrong. You're certainly free to assert that they made a bad decision and I'm not qualified to offer an opinion on whether you are right or wrong.

However since Netflix is not managing email addresses in accordance with RFC-5322 They are clearly wrong.

Post reply on HN