Live data from Hacker News

The dots do matter: how to scam a Gmail user

jameshfisher.com

91–100 of 518 posts

Re: The dots do matter: how to scam a Gmail user

#91
If they can get 6 months free access to Netflix with a dodgy CC, just keep going down that route. No reason to do the double scam when a single is working so well for you.

> Gmail already provides this in the better form of “plus labelling”

True, but lots of singups disable the +.

Netflix should do what everyone else does and do an email verification test.

Re: The dots do matter: how to scam a Gmail user

#92
post #13
post #2

netflix security suck for not doing email confirmation and the ONLY email to be sent to the updated address being a billing one. and no, it should never "know about" the dot feature in gmail. that is working as intended all around. it's simply that netflix put user bounce rate metric in front of protecting users from scam. plain and simple.

IMO It's not Netflix fault, actually emails with dots in different positions should be different emails. Also, not sending a confirmation email is a common pattern now. Maybe an email about "you created an account :D" should be enough mitigation, but this is not their fault.

> actually emails with dots in different positions should be different emails

Don’t know from where this is coming from but there’s no such _should be_ rule, there never was.

As a matter of fact an email server can have any aliasing setup it wants. FastMail for example does sub-domain aliasing, which is awesome because I can use an unique email address for any service I sign up to.

Any email server or service worth its salt allows aliases. Which aren’t hard to guess for a determined attacker either.

Netflix has no excuse ;-)

Re: The dots do matter: how to scam a Gmail user

#93
post #61
post #41

Earlier quoted context omitted.

I'd log in an cancel the account. Why feel wierd? Someone is using your email address without your permission. Curious how often this happens.

I have firstname.lastname (although now it just forwards to my FastMail vanity domain) and I've shut down new eBay and Amazon accounts plus received doctors appointments and even school lunch duty emails. Sometimes I respond, and I even forwarded a couple after figuring out one mis-user's real email (firstnamelastname0) when a cable company csr chat log was emailed, but they never responded so now I delete them all.

Wow, what a shitshow.

Do we have a word to describe frustrations caused as a byproduct of other people's use of technology? I wonder if the Japanese do.

Re: The dots do matter: how to scam a Gmail user

#94

Totally disagree with the conclusion. This is Netflix's issue for not validating the email account. Not sure if Uber has changed this since then, but back in the day I used to get the full ride details and receipts from someone else who mistyped their email. If you are sending private transactional emails you need to verify accounts first.

I think these are orthogonal issues. The dots do matter, but Netflix should also validate email addresses. However, I don't think it's as critical. Lack of email validation means I receive someone else's ride details (I agree, annoying), but dots-don't-matter means I might accidentally pay for that person's rides.

Dot's don't matter if the relevant RFC says they don't matter and I think this is the case.

Google follows the standard, Netflix does not.

Re: The dots do matter: how to scam a Gmail user

#95

Totally disagree with the conclusion. This is Netflix's issue for not validating the email account. Not sure if Uber has changed this since then, but back in the day I used to get the full ride details and receipts from someone else who mistyped their email. If you are sending private transactional emails you need to verify accounts first.

I had a similar issue with Sony/PSN recently. Someone had registered their account and even though I received a validation email I didn't click the link. I then got a welcome-to email a few days later.

PSN's emails don't have a "This is the wrong email" link like some services do, and the US support page link geo redirects to a UK 404 page. I had to go googling for an email address to complain to in order to remedy this.

Re: The dots do matter: how to scam a Gmail user

#96
post #36

Earlier quoted context omitted.

Pluses are part of email standard, dots are some nonsense Google thought was a good idea.

Plusses are an optional part of a standard[1]. The main email standard does not require a+b@c.com to be treated the same as a@c.com [2]. [1] https://tools.ietf.org/html/rfc5233 [2] https://tools.ietf.org/html/rfc5322#section-3.2.3

Another interesting part of dots in emails is that they apparently can't be at the end of the username, EXCEPT if you also "quote" the entire username. So, is probably invalid but (including the "quotes") is supposedly valid.

Had an acquaintance who was signed up to a popular email service with "a.b." (their initials) for years until they changed their underlying platform, after which they actually were very sorry to let him know that they could not support his strange email address any more and terminated the account.

Re: The dots do matter: how to scam a Gmail user

#97
post #89

Earlier quoted context omitted.

But you can’t put the cat back in the bag. People have used the system to sign up for multiple emails at multiple sites, expecting them to go to the same inbox. I suppose you could solve the problem by grandfathering all existing aliases and whitelisting delivery of only those that received at least one email before the policy change. And also continuing to forbid registration of any aliases.

I'm (naively?) hoping that Google doesn't know which aliases received at least one email.

Of course they know. They delivered the emails to the aliases, which are permanently in the To: field of the metadata. As long as you can see the email “to” address in the gmail web interface, so can Google.

Re: The dots do matter: how to scam a Gmail user

#98
post #13

Earlier quoted context omitted.

IMO It's not Netflix fault, actually emails with dots in different positions should be different emails. Also, not sending a confirmation email is a common pattern now. Maybe an email about "you created an account :D" should be enough mitigation, but this is not their fault.

There should be an account creation email and another for a payment method being added. A lot of sites nag you to verify email but never force it.

Yeah, another pattern I've seen is that confirmation is required just in case you need to provide a payment method.

Re: The dots do matter: how to scam a Gmail user

#99
post #94

Earlier quoted context omitted.

I think these are orthogonal issues. The dots do matter, but Netflix should also validate email addresses. However, I don't think it's as critical. Lack of email validation means I receive someone else's ride details (I agree, annoying), but dots-don't-matter means I might accidentally pay for that person's rides.

Dot's don't matter if the relevant RFC says they don't matter and I think this is the case. Google follows the standard, Netflix does not.

The other way around. It's Google who decided to do it that way.

Re: The dots do matter: how to scam a Gmail user

#100
post #67
post #29

Why doesn't Netflix require users to be logged in before they can change their card details? That seems like the biggest security flaw, not the Gmail dot alias. (I'm guessing they did A/B testing and found that having to log into your account lost them some percentage of people. If that's the case, Netflix are clearly putting their retention rate ahead of security) There's probably a not insignificant number of peopl…

They do. The author reset the password to gain access.

But then if the password is reset, the original scammer has no access to the account! And the scammer cannot reset the password because they do not have access to the email.
Post reply on HN