Live data from Hacker News

The dots do matter: how to scam a Gmail user

jameshfisher.com

241–250 of 518 posts

Re: The dots do matter: how to scam a Gmail user

#241
post #229
post #189

Earlier quoted context omitted.

It really bothers me the number of web services which reject email addresses containing '+' in the local part. If you're going to try to "validate" an email address, read the goddamn RFCs.

Try using an email address with .wedding or .solutions TLD. Loads of absolutely brain-dead sites refuse to allow them, sometimes they validate by TLD length (all TLDs are 2 or 3 characters, apparently) or other times rejection TLDs they haven't whitelisted.

"(all TLDs are 2 or 3 characters, apparently)"

Which is odd, since there are some very, very old TLDs that are "long" ... I am thinking of .bitnet, .uucp and even the old .ussr[1] ...

[1] "Initially, before two-letter ccTLDs became standard, the Soviet Union was to receive a .ussr domain." (https://en.wikipedia.org/wiki/.su)

Re: The dots do matter: how to scam a Gmail user

#242
post #204

Earlier quoted context omitted.

There is no bug in Gmail. This bug has nothing to do with Gmail, it is with Netflix not clearly communicating when verifying the address a user claims to own.

The bug is in humans. Heck, I regularly come across people who think the case in an email address matters! While there is no bug in Gmail, that is irrelevant because you have to deal with the reality of how people use your product. Its basic engineering. Standards are simply a means for interoperability. In this case, the dots don't matter much for that goal.

The case in an email address does matter. Look it up.

Re: The dots do matter: how to scam a Gmail user

#243
post #161
post #103

Earlier quoted context omitted.

They couldn't carry out the same attack without the dots, because the attack relies on the target mistaking the attacker's Netflix account for their own account. If you get a Netflix email when you've never signed up using that email account then it's obviously not for you.

I have ~1000 online accounts. I can't remember every site that I've signed up for or not, and whether or not they've been deleted. Many websites allow multiple accounts to have the same email address.

You probably know whether you're paying for Netflix though.

Re: The dots do matter: how to scam a Gmail user

#244

I think he missed one detail... Eve in this scenario wouldn't be able to get back into the account once James had reset the password.

IIRC Netflix accounts stay logged in over password changes, but there would be no way to change the email back.

I really don't see how this could be an effective scam.

Re: The dots do matter: how to scam a Gmail user

#245
post #100
post #67

Earlier quoted context omitted.

They do. The author reset the password to gain access.

But then if the password is reset, the original scammer has no access to the account! And the scammer cannot reset the password because they do not have access to the email.

Netflix offers SMS password resets.

Re: The dots do matter: how to scam a Gmail user

#246
post #30

Earlier quoted context omitted.

This is an RFC 5233 subaddress.

You're full of shit. The word "subaddress" doesn't occur anywhere in RFC 5233. The only thing RFC 5233 says about + in email addresses is that it's an allowable character.

What? It's literally in the title of RFC 5233. "Sieve Email Filtering: Subaddress Extension". The introduction starts with a sentence that defines subaddressing. It has half a dozen references to using + as the separator between the username and the "detail".

Re: The dots do matter: how to scam a Gmail user

#247

> but I also have access to the account because I own james.hfisher@gmail.com, and so I can follow the password reset process for this account. I did so. I wonder if others feel that it is ethical or unethical to log into other people's accounts in this situation. I get lots of emails resulting from people typo'ing my email address instead of theirs—and the unsubscribe links are often hidden behind a login page. But…

Ethically - you shouldn't log in to other people's accounts, but rather, you should delete the email (and possibly notify them if you can).

I'm pretty sure that legally it's problematic as well.

Re: The dots do matter: how to scam a Gmail user

#248

I don’t get the argument that the email dots stripping should be removed but the “+” tag feature should be kept. Both of them allow infinite email addresses. The tag feature is not always available because app developers frequently don’t allow the plus character. I would prefer that (1) a Netflix require email verification and (2) GMail describe in detail all of the email address features so app developers can explor…

I must be missing something but the + and . feature both have the same problem for this "scam", right?

Re: The dots do matter: how to scam a Gmail user

#249
post #189

Earlier quoted context omitted.

It really bothers me the number of web services which reject email addresses containing '+' in the local part. If you're going to try to "validate" an email address, read the goddamn RFCs.

I like the idea of adding +spam@gmail.com, but it would be really easy for this to be invalidated by just stripping this from your email before selling it in a mailing list.

Instead of blacklisting the +spam@gmail.com email, you could whitelist emails like +netflix@gmail.com. You can create a filter so that if it doesn't match the whitelist - including stripping the plus - then it will be automatically binned.

I describe this technique in my blog post[0]. I'll warn everyone now though, you'll probably want an email address for real people that you trust (like +friends@gmail.com). Also, you'll rarely have to email companies, but it is a pain if you need to do it from the +plus email.

[0]: http://iamqasimk.com/2016/10/16/absolutely-zero-email-spam/

Re: The dots do matter: how to scam a Gmail user

#250
post #73
post #8

Earlier quoted context omitted.

Just create a filter to send everything that doesn’t match your dot pattern to the trash. I have a relatively common first name / last name gmail account and it gets out of control sometimes.

My issue with doing that is that the other person will never get help. They’ll just say “oh my emails keep getting lost”, but if google would bounce them, then hopefully one of these services would notify the person that that isn’t their email. Instead of them happily continuing to send it all to me.

The amount of consideration I'm willing to extend to a person who either doesn't know their own email address or is trying to scam me isn't that great.

Sometimes I'll text the person and complement them on their choice of purchases- yesterday it was a stunningly large Domino's pizza order.

Post reply on HN