Live data from Hacker News

The dots do matter: how to scam a Gmail user

jameshfisher.com

301–310 of 518 posts

Re: The dots do matter: how to scam a Gmail user

#301
post #128

I don’t get the argument that the email dots stripping should be removed but the “+” tag feature should be kept. Both of them allow infinite email addresses. The tag feature is not always available because app developers frequently don’t allow the plus character. I would prefer that (1) a Netflix require email verification and (2) GMail describe in detail all of the email address features so app developers can explor…

> The tag feature is not always available because app developers frequently don’t allow the plus characte Should we stop using a feature because some buggy apps don’t support it?

This is why, on my semi-personal (<10 users) email server I process several different characters as tagging characters: dot, dash, underscore, and plus IIRC.

Re: The dots do matter: how to scam a Gmail user

#302

Earlier quoted context omitted.

> However since Netflix is not managing email addresses in accordance with RFC-5322 They are clearly wrong. Where are they not?

I was wrong. I cannot find any information that indicates that the RFC specifies that the period is not significant, only that it is allowed. In this case I suppose it is Google that is wrong.

How is Google wrong?

Re: The dots do matter: how to scam a Gmail user

#303

Totally disagree with the conclusion. This is Netflix's issue for not validating the email account. Not sure if Uber has changed this since then, but back in the day I used to get the full ride details and receipts from someone else who mistyped their email. If you are sending private transactional emails you need to verify accounts first.

Totally... different services provide different ways to have multiple addresseses. The article already mentions one (plus addressing), but there are also others (like FastMail's subdomain addressing)[1]. And many people have catchall or misspelling addresses on their own domain.

That said, I dislike Gmail's "the dots don't matter" since it really screws up calendar invitation handling, because calendars don't handle aliases well.

[1] https://www.fastmail.com/help/receive/addressing.html

Re: The dots do matter: how to scam a Gmail user

#304
post #253

Earlier quoted context omitted.

Yup. Even spaces are allowed if you put double quotes around the local part: “Kevin Spacey”@example.com. It’s really surprising, there’s very little that can be verified if you strictly follow the RFC.

This is a common issue with text based formats and ietf/RFCs. HTTP allows comments in some headers. And allows line breaks: H: hi Mom Is the same as H: hi Mom Bets on how many http clients and servers get this right? Without losing speed? My guess is when you're not responsible for ensuring compatibility or having to deal with writing robust, fast, code, the temptation to be cute with your format overtakes things.

I expect all commonly used HTTP clients (Chrome, Firefox, IE, even libcurl) and servers (Apache, Nginx, does IIS still exist?) get this right.

Re: The dots do matter: how to scam a Gmail user

#305
post #189

Earlier quoted context omitted.

Absolutely. I don’t blame people who don’t interact with email for not reading the relevant RFCs, but not verifying control and expecting local part uniqueness to mean uniqueness of users is obviously busted to anyone who has worked with email. This is Netflix failing to understand part of their product surface. Both the dot behavior and the even more common ‘+’ feature are perfectly spec compliant.

It really bothers me the number of web services which reject email addresses containing '+' in the local part. If you're going to try to "validate" an email address, read the goddamn RFCs.

One of the two reasons i changed my recipient_delimiter parameter to '.'

The other would be that spammers know that anything after a + is usually optional and strip it. Can't do that when the delimiter is a '.'

Re: The dots do matter: how to scam a Gmail user

#306
post #104

I have multiple "e-mail doppelgangers" - confused people who don't know their own email address and so accidentally use my address when they register stuff. One's in Chile. I have almost no knowledge of Spanish. The other is in California. Having experienced this: Services need to email new email accounts they become aware of ASAP. They have literally zero UI available to me to notify them that this is an invalid ema…

I have a few.

On in New York used by to confirm a doctors appointment (with some information on their condition). They also gave my address to their broker who sent an account summary. Bond portfolio in the millions.

Some lunch delivery server in Mumbai sends sends out emails to the address provided with no option for me to remove my address.

Another one or two in the UK who put me down for random stuff.

I just got one for a hotel booking. Google usefully added it to my calendar.

"My" X-Box live account seems to have gone.

I did enjoy repeatedly rejecting "parental" permission for some kid to join Club Penguin though.

Re: The dots do matter: how to scam a Gmail user

#307
post #128

Earlier quoted context omitted.

> The tag feature is not always available because app developers frequently don’t allow the plus characte Should we stop using a feature because some buggy apps don’t support it?

This is why, on my semi-personal (<10 users) email server I process several different characters as tagging characters: dot, dash, underscore, and plus IIRC.

I use a subdomain as catch-all; *@something.example.com all goes to one folder. That way it's impossible for the spammers to know that this is a "sorted" e-mail address since lots of people have e-mail addresses under a subdomain and it's not trivial to filter out like myrealidentity+youareaspammer@example.com turning into myrealidentity@example.com.

Other users on my setup can use it, they just have to pick a different "something" if they want to use the same example.com as me.

Re: The dots do matter: how to scam a Gmail user

#308
post #290

Earlier quoted context omitted.

Not only that, but apparently he was able to change Eve's account details without having to enter a password. If instead Netflix had prompted him before allowing him to change the credit card, it would not have worked, because he wouldn't have known Eve's password and Eve wouldn't have known his. All around very bad security design on Netflix's part.

He said in the post that he was able to reset the password because the account was linked to "his" email.

But if you have to reset the password to update the credit card details, then surely the scam won't work because the scammer would no longer be able to use the account.

For this scam to work the "Update your credit card" mail must contain a credential that allows you to update the scammer's card without changing or being challenged for their password. That doesn't seem great.

Re: The dots do matter: how to scam a Gmail user

#309

It's a Gmail issue. I sometime gets wrong mail coz of this FEATURE. Not talking about any specific site. Gmail to Gmail only. Just to clarify with an example: My email is: abcd.wxyz@gmail.com Other guy: abcdwxyz@gmail.com I wonder how many of my emails the other is receiving. All my stuff is linked with Gmail. Any suggestions to resolve this?

There is no "other guy" getting your emails.

There are just idiots who genuinely don't remember their own email address. So they'll type in your address, or the dotless variant of it, and as described for Netflix this "works" except you get all the stuff sent to you.

Re: The dots do matter: how to scam a Gmail user

#310
ebay in india also has no email based verification and can use phone only based verification because users are actually more likely to have a phone # and only use sms than any email or chat app. A person from india used my mom's email address (a us resident/citizen) to sign up and purchase men's underwear from ebay.in (with no email verification). She had never signed up for an ebay account. I took over the ebay account and after speaking with an ebay rep it seems there was no way to even convert the ebay indian account to an ebay US account. Customer support in the US didn't even think it was possible to sign up for an account without a valid email and thought her email was hacked (which it wasn't!). Unfortunately all they could do is offer to disable the account forever. So now if she ever actually does want to use ebay she'll have to use an address like foo+ebay@gmail.com or intersperse her addr with dots assuming ebay allows it. I did email ebay's security disclosure team and I only got a reply saying that they would look into it.

For some added fun and since I was pissed for all this wasted time (figuring out what exactly happened, if my mom's email was hacked or not because I was very confused initially about not seeing an email verification email from ebay), I call the guy in india and asked if he had ordered some chaddi's, he said yes, freaked out and hung up the phone.

So yes the moral of the story is companies, PLEASE VERIFY YOUR USERS' email, or if you don't then don't associate that email address with the account and only do business with that user through SMS.

Post reply on HN