Live data from Hacker News

The dots do matter: how to scam a Gmail user

jameshfisher.com

121–130 of 518 posts

Re: The dots do matter: how to scam a Gmail user

#121
post #74

I prefer creating a unique email alias from dots more than plus. Especially if I sign up for something I'm worried will leak my email address to a third party, I use the dots. A malicious sharer of emails could trivially strip all the "+site@gmail.com" before sharing, but they can't know ahead of time if they get my primary email by adding or removing dots. Also, a few times when I've signed up with "name+service@gma…

The malicious sharer could modify the rule to not only remove the "+site" part but remove all the dots. Then, your trick is useless. They might realize the "+site" and not the dots, but your point was about ability not awareness. ;)

except my "real" address has dots, so I know that 0 dots are being cleaned. I just can't tell who did it.

Re: The dots do matter: how to scam a Gmail user

#122
post #57

Totally disagree with the conclusion. This is Netflix's issue for not validating the email account. Not sure if Uber has changed this since then, but back in the day I used to get the full ride details and receipts from someone else who mistyped their email. If you are sending private transactional emails you need to verify accounts first.

Why can't it be both sides' issue? I have a fairly uncommon first and last name, but I still get emails from the few folk who share my name combination, and I too have gotten sensitive information that I shouldn't have. I cannot imagine the strangeness that must occur for folks with more common name combinations, and the idea that e.mail@gmail.com is the same as email@gmail.com just seems wrong to me. As far as I kno…

Permitting separate "sarah.jones" and "sarahjones" accounts would be pretty bad, too. Too easy to impersonate people. "Dots matter but are not included in uniqueness checks" is probably the safest approach.

Re: The dots do matter: how to scam a Gmail user

#123

Earlier quoted context omitted.

I'm now in complete control of someone else’s commercial business hvac account because of precisely this problem. But that has absolutely nothing to do with the dots. Indeed, almost every comment about this has nothing to do with the dots, including the submission. Someone entered the wrong email address, and in the process got yours. It isn't like the dotted or undotted one is legitimately theirs -- it can't possibl…

In the initial submission, without the dots issue though, the wrong address entered wouldn't be able to match an existing user.

That's why you send an email to whatever the user typed in with a link they have to click before they can complete the signup process. This is really, really basic stuff.

Re: The dots do matter: how to scam a Gmail user

#124
post #86

Earlier quoted context omitted.

Yep. Bug is the ability for users to charge a credit card before verifying email. Or did the victim in this blogpost also verify their email at some point? Netflix could be forgiven for thinking that updating payment details via email = verifying email. But if the victim had to respond to two emails, the first of which is a “verify email for your new account,” the phishing would be less believable. Ultimately, the vi…

The standard email verification patterns rely on the user clicking a link. I am not sure how that would have helped here. Making users retype the email (instead of merely click on a link) might be better for exposing scams but requires more work on the user’s part.

[deleted]

Re: The dots do matter: how to scam a Gmail user

#125
post #89

Earlier quoted context omitted.

I'm (naively?) hoping that Google doesn't know which aliases received at least one email.

Of course they know. They delivered the emails to the aliases, which are permanently in the To: field of the metadata. As long as you can see the email “to” address in the gmail web interface, so can Google.

What about emails that were deleted?

Re: The dots do matter: how to scam a Gmail user

#126
post #104

I have multiple "e-mail doppelgangers" - confused people who don't know their own email address and so accidentally use my address when they register stuff. One's in Chile. I have almost no knowledge of Spanish. The other is in California. Having experienced this: Services need to email new email accounts they become aware of ASAP. They have literally zero UI available to me to notify them that this is an invalid ema…

I have this problem a lot as well. There was someone with my name with a Bank of America account that regularly bounced checks, and BoA provided no way to disassociate my email address from the account. These days I'll flag any email from a service as spam, no matter how well known, if there was no email verification step.

Yup. I had some guy's credit card bills appearing. It was actually super weird - somehow Google had metadata about the credit card bill that was not in the body of the email, so I'd get "reminders" on Google Now saying "pay $1200 to Notyourbank by the 1st of Octember", but I couldn't actually see that bill without logging in (which, obviously, I could not and did not try to).

Re: The dots do matter: how to scam a Gmail user

#127
post #17
post #4

I really wish that I could tell google to bounce all the emails that don’t match my “dot pattern” I’m now in complete control of someone else’s commercial business hvac account because of precisely this problem. And the worse part is that I don’t know the correct email to get ahold of this person. They’ve set up library appointments, I received a receipt for a down payment on a lake house, basically most of this pers…

That same problem can happen even without dots. People can simply mistype their email and have it be your email. That happens if even if neither of you have dots in your email.

So then send the verification email at signup and any time the user changes the stored email on their account. Am I missing something?

Re: The dots do matter: how to scam a Gmail user

#128

I don’t get the argument that the email dots stripping should be removed but the “+” tag feature should be kept. Both of them allow infinite email addresses. The tag feature is not always available because app developers frequently don’t allow the plus character. I would prefer that (1) a Netflix require email verification and (2) GMail describe in detail all of the email address features so app developers can explor…

> The tag feature is not always available because app developers frequently don’t allow the plus characte

Should we stop using a feature because some buggy apps don’t support it?

Re: The dots do matter: how to scam a Gmail user

#129
post #104

I have multiple "e-mail doppelgangers" - confused people who don't know their own email address and so accidentally use my address when they register stuff. One's in Chile. I have almost no knowledge of Spanish. The other is in California. Having experienced this: Services need to email new email accounts they become aware of ASAP. They have literally zero UI available to me to notify them that this is an invalid ema…

I actually have dots in my Netflix account email address because somebody who wasn't me had previously started to register for Netflix using my email address.

I have had to do this with some other services as well. Some services won't allow the + in gmail addresses, which is pretty annoying.

If a service starts recognising the dots don't matter and denying the plus symbol, there's a good chance I won't be able to register without obtaining a new email address.

I wouldn't mind but my name is really not that common -- my surname is uncommon enough for me not to have met another with that surname outside my family.

Re: The dots do matter: how to scam a Gmail user

#130

Totally disagree with the conclusion. This is Netflix's issue for not validating the email account. Not sure if Uber has changed this since then, but back in the day I used to get the full ride details and receipts from someone else who mistyped their email. If you are sending private transactional emails you need to verify accounts first.

What you say can be applicable for subscription billing. But there are hundreds of other sites and apps where you can "checkout" stuff without needing to register, which is also a welcome/better feature. And yes, they do notify when a transaction failed.

You cannot ask a whole ecosystem to change because of a feature/flaw on a central vendor. Where will you start? Force people to create accounts and verify emails when buying a one-off train ticket or ordering a pizza? What if people/market don't want this registration/activation crap for doing small utility stuff? For a payment, I have to authenticate with my payment provider, not to my email vendor. And payment providers do have delayed reconciliation issues that are sometimes notified back. And where would you stop? Validate each and every piece of info the user provides? Send a SMS verification code to the phone for same utility bill?

The conclusion is correct: Fix the vendor. I asked for a specific email address when I signed up. Similarly I should get emails only for "dots" that I have specifically opted in to. Deny receiving the email, show me a warning, don't allow it until I opt in. Anything else is just asking for trouble.

Post reply on HN