> Gmail already provides this in the better form of “plus labelling”
True, but lots of singups disable the +.
Netflix should do what everyone else does and do an email verification test.
91–100 of 518 posts
> Gmail already provides this in the better form of “plus labelling”
True, but lots of singups disable the +.
Netflix should do what everyone else does and do an email verification test.
netflix security suck for not doing email confirmation and the ONLY email to be sent to the updated address being a billing one. and no, it should never "know about" the dot feature in gmail. that is working as intended all around. it's simply that netflix put user bounce rate metric in front of protecting users from scam. plain and simple.
IMO It's not Netflix fault, actually emails with dots in different positions should be different emails. Also, not sending a confirmation email is a common pattern now. Maybe an email about "you created an account :D" should be enough mitigation, but this is not their fault.
Don’t know from where this is coming from but there’s no such _should be_ rule, there never was.
As a matter of fact an email server can have any aliasing setup it wants. FastMail for example does sub-domain aliasing, which is awesome because I can use an unique email address for any service I sign up to.
Any email server or service worth its salt allows aliases. Which aren’t hard to guess for a determined attacker either.
Netflix has no excuse ;-)
Earlier quoted context omitted.
I'd log in an cancel the account. Why feel wierd? Someone is using your email address without your permission. Curious how often this happens.
I have firstname.lastname (although now it just forwards to my FastMail vanity domain) and I've shut down new eBay and Amazon accounts plus received doctors appointments and even school lunch duty emails. Sometimes I respond, and I even forwarded a couple after figuring out one mis-user's real email (firstnamelastname0) when a cable company csr chat log was emailed, but they never responded so now I delete them all.
Do we have a word to describe frustrations caused as a byproduct of other people's use of technology? I wonder if the Japanese do.
Totally disagree with the conclusion. This is Netflix's issue for not validating the email account. Not sure if Uber has changed this since then, but back in the day I used to get the full ride details and receipts from someone else who mistyped their email. If you are sending private transactional emails you need to verify accounts first.
I think these are orthogonal issues. The dots do matter, but Netflix should also validate email addresses. However, I don't think it's as critical. Lack of email validation means I receive someone else's ride details (I agree, annoying), but dots-don't-matter means I might accidentally pay for that person's rides.
Google follows the standard, Netflix does not.
Totally disagree with the conclusion. This is Netflix's issue for not validating the email account. Not sure if Uber has changed this since then, but back in the day I used to get the full ride details and receipts from someone else who mistyped their email. If you are sending private transactional emails you need to verify accounts first.
PSN's emails don't have a "This is the wrong email" link like some services do, and the US support page link geo redirects to a UK 404 page. I had to go googling for an email address to complain to in order to remedy this.
Earlier quoted context omitted.
Pluses are part of email standard, dots are some nonsense Google thought was a good idea.
Plusses are an optional part of a standard[1]. The main email standard does not require a+b@c.com to be treated the same as a@c.com [2]. [1] https://tools.ietf.org/html/rfc5233 [2] https://tools.ietf.org/html/rfc5322#section-3.2.3
Had an acquaintance who was signed up to a popular email service with "a.b." (their initials) for years until they changed their underlying platform, after which they actually were very sorry to let him know that they could not support his strange email address any more and terminated the account.
Earlier quoted context omitted.
But you can’t put the cat back in the bag. People have used the system to sign up for multiple emails at multiple sites, expecting them to go to the same inbox. I suppose you could solve the problem by grandfathering all existing aliases and whitelisting delivery of only those that received at least one email before the policy change. And also continuing to forbid registration of any aliases.
I'm (naively?) hoping that Google doesn't know which aliases received at least one email.
Earlier quoted context omitted.
IMO It's not Netflix fault, actually emails with dots in different positions should be different emails. Also, not sending a confirmation email is a common pattern now. Maybe an email about "you created an account :D" should be enough mitigation, but this is not their fault.
There should be an account creation email and another for a payment method being added. A lot of sites nag you to verify email but never force it.
Earlier quoted context omitted.
I think these are orthogonal issues. The dots do matter, but Netflix should also validate email addresses. However, I don't think it's as critical. Lack of email validation means I receive someone else's ride details (I agree, annoying), but dots-don't-matter means I might accidentally pay for that person's rides.
Dot's don't matter if the relevant RFC says they don't matter and I think this is the case. Google follows the standard, Netflix does not.
Why doesn't Netflix require users to be logged in before they can change their card details? That seems like the biggest security flaw, not the Gmail dot alias. (I'm guessing they did A/B testing and found that having to log into your account lost them some percentage of people. If that's the case, Netflix are clearly putting their retention rate ahead of security) There's probably a not insignificant number of peopl…
They do. The author reset the password to gain access.