Live data from Hacker News

The dots do matter: how to scam a Gmail user

jameshfisher.com

71–80 of 518 posts

Re: The dots do matter: how to scam a Gmail user

#71
As someone who commonly has other people mistakenly use my email when signing up for things, I 100% blame the service (Netflix) for this. This is only done as a way for them to increase signups/revenue and the fact that so few services require verification is why people don't realize they are using an email that isn't theirs for years.

Getting rid of dots only solves one tiny portion of this problem which would be completely solved if Netflix and others required verification. Gmail cannot stop people from using my email address to sign up for things, but Nextlix et al. can do that and protect their users privacy and personal info with one single email.

A better example is that a few years ago Turbo Tax emailed me personal details and gave me access to someone else's taxes because they didn't require verification. That is insane (and I believe/hope was since fixed)!

Re: The dots do matter: how to scam a Gmail user

#72
post #13
post #2

netflix security suck for not doing email confirmation and the ONLY email to be sent to the updated address being a billing one. and no, it should never "know about" the dot feature in gmail. that is working as intended all around. it's simply that netflix put user bounce rate metric in front of protecting users from scam. plain and simple.

IMO It's not Netflix fault, actually emails with dots in different positions should be different emails. Also, not sending a confirmation email is a common pattern now. Maybe an email about "you created an account :D" should be enough mitigation, but this is not their fault.

As somebody who has multiple people who aren't me registering accounts to variations of my email address:

Companies who do not send "you've created an account! Click here if you didn't!" emails can die in a fire.

Re: The dots do matter: how to scam a Gmail user

#73
post #8
post #4

I really wish that I could tell google to bounce all the emails that don’t match my “dot pattern” I’m now in complete control of someone else’s commercial business hvac account because of precisely this problem. And the worse part is that I don’t know the correct email to get ahold of this person. They’ve set up library appointments, I received a receipt for a down payment on a lake house, basically most of this pers…

Just create a filter to send everything that doesn’t match your dot pattern to the trash. I have a relatively common first name / last name gmail account and it gets out of control sometimes.

My issue with doing that is that the other person will never get help. They’ll just say “oh my emails keep getting lost”, but if google would bounce them, then hopefully one of these services would notify the person that that isn’t their email. Instead of them happily continuing to send it all to me.

Re: The dots do matter: how to scam a Gmail user

#74

I prefer creating a unique email alias from dots more than plus. Especially if I sign up for something I'm worried will leak my email address to a third party, I use the dots. A malicious sharer of emails could trivially strip all the "+site@gmail.com" before sharing, but they can't know ahead of time if they get my primary email by adding or removing dots. Also, a few times when I've signed up with "name+service@gma…

The malicious sharer could modify the rule to not only remove the "+site" part but remove all the dots. Then, your trick is useless.

They might realize the "+site" and not the dots, but your point was about ability not awareness. ;)

Re: The dots do matter: how to scam a Gmail user

#77
post #69

Totally disagree with the conclusion. This is Netflix's issue for not validating the email account. Not sure if Uber has changed this since then, but back in the day I used to get the full ride details and receipts from someone else who mistyped their email. If you are sending private transactional emails you need to verify accounts first.

If you have a bug in a system, do you fix it at the source, or do you fix it at all the leaves? Netflix might be wrong here, but fixing it at Netflix doesn't make the problem go away. Fix the problem once (GMail) and never ever have to deal with it again.

But you can’t put the cat back in the bag. People have used the system to sign up for multiple emails at multiple sites, expecting them to go to the same inbox.

I suppose you could solve the problem by grandfathering all existing aliases and whitelisting delivery of only those that received at least one email before the policy change. And also continuing to forbid registration of any aliases.

Re: The dots do matter: how to scam a Gmail user

#78

One interesting thing to note, for GSuite accounts, the dots do matter. first.last@company.com is not the same account as firstlast@company.com.

This is true of gmail accounts as well. If you signed up with first.last you always must login with first.last.

The real issue is that old account names are actually case sensitive too. Starting a few years ago Google normalized all account creation to lowercase, but existing case sensitive accounts remain. We implemented OAuth, normalizing accounts to lowercase in our db and everything was fine for years until we ran across a user who's account legit was FirstLast@ and would only auth that way.

Re: The dots do matter: how to scam a Gmail user

#79

Fascinating article, thanks for the info! > The only clue in the screenshot above is that the interface says “to james.hfisher”, instead of “to me”. I just tested it, and I'm not even getting that clue. It says "to me", and it's only when I click on the little arrow that it says "(Yes, this is you.) Learn more". But you'd have to be suspicious in the first place to click the arrow... I find this to be a very poor ide…

Oddly a friend has an email that’s first.middle initial.last. I just tried without dots and it got bounced.

Re: The dots do matter: how to scam a Gmail user

#80
post #13
post #2

netflix security suck for not doing email confirmation and the ONLY email to be sent to the updated address being a billing one. and no, it should never "know about" the dot feature in gmail. that is working as intended all around. it's simply that netflix put user bounce rate metric in front of protecting users from scam. plain and simple.

IMO It's not Netflix fault, actually emails with dots in different positions should be different emails. Also, not sending a confirmation email is a common pattern now. Maybe an email about "you created an account :D" should be enough mitigation, but this is not their fault.

There should be an account creation email and another for a payment method being added. A lot of sites nag you to verify email but never force it.
Post reply on HN