Live data from Hacker News

The dots do matter: how to scam a Gmail user

jameshfisher.com

61–70 of 518 posts

Re: The dots do matter: how to scam a Gmail user

#61
post #41

> but I also have access to the account because I own james.hfisher@gmail.com, and so I can follow the password reset process for this account. I did so. I wonder if others feel that it is ethical or unethical to log into other people's accounts in this situation. I get lots of emails resulting from people typo'ing my email address instead of theirs—and the unsubscribe links are often hidden behind a login page. But…

I'd log in an cancel the account. Why feel wierd? Someone is using your email address without your permission. Curious how often this happens.

I have firstname.lastname (although now it just forwards to my FastMail vanity domain) and I've shut down new eBay and Amazon accounts plus received doctors appointments and even school lunch duty emails. Sometimes I respond, and I even forwarded a couple after figuring out one mis-user's real email (firstnamelastname0) when a cable company csr chat log was emailed, but they never responded so now I delete them all.

Re: The dots do matter: how to scam a Gmail user

#62
post #11

>Where is the security flaw here? Some would say it’s Netflix’s fault; that Netflix should verify the email address on sign up, or that Netflix should disallow the registration of james.hfisher@gmail.com when a Netflix account already existed for jameshfisher@gmail.com. But such policies would not add security, and would force Netflix and every other website to have insider knowledge of Gmail’s canonicalization algor…

I'm sorry, this sentence wasn't clear, and I agree with you. What I meant by this was: - Some would say that Netflix should verify the email address on sign up, but there's no obvious attack that this mitigates. Using someone else's address on signup only cedes account control to them. - Others would say that Netflix should disallow the registration of james.hfisher@gmail.com when a Netflix account already existed fo…

Why are dots special? I have several email addresses that all find my inbox. Heck, I've done this annoying identity split to myself by accident, creating two accounts with a product I only wanted one account for.

Re: The dots do matter: how to scam a Gmail user

#63
Fascinating article, thanks for the info!

> The only clue in the screenshot above is that the interface says “to james.hfisher”, instead of “to me”.

I just tested it, and I'm not even getting that clue. It says "to me", and it's only when I click on the little arrow that it says "(Yes, this is you.) Learn more". But you'd have to be suspicious in the first place to click the arrow...

I find this to be a very poor idea indeed, and hiding the clue is poor design to boot.

Re: The dots do matter: how to scam a Gmail user

#64

Totally disagree with the conclusion. This is Netflix's issue for not validating the email account. Not sure if Uber has changed this since then, but back in the day I used to get the full ride details and receipts from someone else who mistyped their email. If you are sending private transactional emails you need to verify accounts first.

I think these are orthogonal issues. The dots do matter, but Netflix should also validate email addresses. However, I don't think it's as critical. Lack of email validation means I receive someone else's ride details (I agree, annoying), but dots-don't-matter means I might accidentally pay for that person's rides.

They're both issues, I agree there, but I think Netflix's screwup is larger here.

Lack of validation means that Netflix is emailing someone asking them to pay for something, who may be totally different than the person getting that thing.

Re: The dots do matter: how to scam a Gmail user

#65
post #4

I really wish that I could tell google to bounce all the emails that don’t match my “dot pattern” I’m now in complete control of someone else’s commercial business hvac account because of precisely this problem. And the worse part is that I don’t know the correct email to get ahold of this person. They’ve set up library appointments, I received a receipt for a down payment on a lake house, basically most of this pers…

I'm now in complete control of someone else’s commercial business hvac account because of precisely this problem.

But that has absolutely nothing to do with the dots. Indeed, almost every comment about this has nothing to do with the dots, including the submission.

Someone entered the wrong email address, and in the process got yours. It isn't like the dotted or undotted one is legitimately theirs -- it can't possibly be -- but that they forgot a middle initial or something of the sort.

I've written about this before-

https://dennisforbes.ca/index.php/2016/04/08/email-addresses...

-but the issue is with email itself, and the notion that once someone enters an email address it is authoritative. Like you I get a tonne of email for other people. I get travel tickets. I get room reward points. I get calendar events for car service in England. The dots aren't the reason.

Re: The dots do matter: how to scam a Gmail user

#66
post #29

Why doesn't Netflix require users to be logged in before they can change their card details? That seems like the biggest security flaw, not the Gmail dot alias. (I'm guessing they did A/B testing and found that having to log into your account lost them some percentage of people. If that's the case, Netflix are clearly putting their retention rate ahead of security) There's probably a not insignificant number of peopl…

[deleted]

Re: The dots do matter: how to scam a Gmail user

#67
post #29

Why doesn't Netflix require users to be logged in before they can change their card details? That seems like the biggest security flaw, not the Gmail dot alias. (I'm guessing they did A/B testing and found that having to log into your account lost them some percentage of people. If that's the case, Netflix are clearly putting their retention rate ahead of security) There's probably a not insignificant number of peopl…

They do. The author reset the password to gain access.

Re: The dots do matter: how to scam a Gmail user

#68
I agree with the conclusion because for years I’ve gotten bills for this guy who has a middle initial different from me. Sometimes people put in the wrong email. For him it still works but I get all of his billing etc. Turning off dots would make their emails go away and his account more secured.

Re: The dots do matter: how to scam a Gmail user

#69

Totally disagree with the conclusion. This is Netflix's issue for not validating the email account. Not sure if Uber has changed this since then, but back in the day I used to get the full ride details and receipts from someone else who mistyped their email. If you are sending private transactional emails you need to verify accounts first.

If you have a bug in a system, do you fix it at the source, or do you fix it at all the leaves? Netflix might be wrong here, but fixing it at Netflix doesn't make the problem go away. Fix the problem once (GMail) and never ever have to deal with it again.

Re: The dots do matter: how to scam a Gmail user

#70
post #11

>Where is the security flaw here? Some would say it’s Netflix’s fault; that Netflix should verify the email address on sign up, or that Netflix should disallow the registration of james.hfisher@gmail.com when a Netflix account already existed for jameshfisher@gmail.com. But such policies would not add security, and would force Netflix and every other website to have insider knowledge of Gmail’s canonicalization algor…

I'm sorry, this sentence wasn't clear, and I agree with you. What I meant by this was: - Some would say that Netflix should verify the email address on sign up, but there's no obvious attack that this mitigates. Using someone else's address on signup only cedes account control to them. - Others would say that Netflix should disallow the registration of james.hfisher@gmail.com when a Netflix account already existed fo…

At least three people have successfully created a Netflix account with my gmail address, written in exactly the same way I would normally write it: Jessica in 2012, John in 2013, and Jen in 2017. The first two somehow managed to recover and change the email address, the last one never did. (So maybe it's now finally blocked off from further registrations.)

If any of them had shared my name, the effect would have been just the same as in your case despite there being no canonicalization issues. Likewise would you really have been suspicious about seeing the notification come in for e.g. jamesfisher+netflix@gmail.com? Who can remember exactly what services they used a +something for?

No. This hole is totally on Netflix. It's a total shitshow, especially for a company that loves to brag so much about how they only hire the best technical people. No. Either they don't hire the best, or they let some kind of piece of growth hackers actually run the show.

Post reply on HN