Live data from Hacker News

The dots do matter: how to scam a Gmail user

jameshfisher.com

321–330 of 518 posts

Re: The dots do matter: how to scam a Gmail user

#321

Totally disagree with the conclusion. This is Netflix's issue for not validating the email account. Not sure if Uber has changed this since then, but back in the day I used to get the full ride details and receipts from someone else who mistyped their email. If you are sending private transactional emails you need to verify accounts first.

Absolutely - his proposed solution - disabling the dots-dont-matter feature and retiring them does nothing to stop this exact same attack vector instead employing the '+' feature that he admires and wishes to retain.

The attack goes like this:

* Hammer the Netflix signup form until you find a gmail.com address which is “already registered”. Let’s say you find the victim jameshfisher.

* Eve creates a Netflix account with address jameshfisher+netflix

* Sign up for free trial with a throwaway card number.

* After Netflix applies the “active card check”, Eve cancels the card.

* Wait for Netflix to bill the cancelled card. Then Netflix emails jameshfisher+netflix, going to jameshfisher's inbox, asking for a valid card.

* Hope Jim reads the email to jameshfisher+netflix, assumes it’s for his Netflix account backed by jameshfisher, then (follows a link in the email and) enters his card 1234.

* Eve changes the email for the Netflix account to eve@gmail.com, kicking Jim’s access to this account.

* Use Netflix free forever with Jim’s card 1234!

Either they're both security liabilities, and they should both be removed, or the problem lies elsewhere.

Re: The dots do matter: how to scam a Gmail user

#323
post #189

Earlier quoted context omitted.

It really bothers me the number of web services which reject email addresses containing '+' in the local part. If you're going to try to "validate" an email address, read the goddamn RFCs.

One of the two reasons i changed my recipient_delimiter parameter to '.' The other would be that spammers know that anything after a + is usually optional and strip it. Can't do that when the delimiter is a '.'

I do the same thing, for the same reason. I haven't A/B tested both options or anything, but I know I've gotten spam where they stripped the "+" parameter.

Re: The dots do matter: how to scam a Gmail user

#324
post #216

Earlier quoted context omitted.

Multiple accounts with the same email haven't been available for many, many years. I'm not sure exactly when registration for these was disabled, but it was 10+ years ago. Possibly 15-20 years ago. I think it was a valid design decision at the time, before accounts on websites were widespread and a family might only have a single email address from their ISP. The rise of free webmail accounts from Hotmail etc changed…

Naw, I left about 10 years ago and out was still there, and still had co-workers at a different job asking me about it a couple years later, because they got bit by it. The justification I heard was that someone would have a personal and business (or library) account to the same email, but it definitely persisted longer than you think.

Well, they were enabled but you couldn't create new ones when I joined 7 years ago. I was under the impression they'd long since been retired at that point. Given the turnover there, ancient lore could have only been a year or two before that.

I had to jump through some hoops to get one of the accounts to test something I worked on with them.

Re: The dots do matter: how to scam a Gmail user

#325
post #322

The opinion of the author is ridiculous. What about someone use your email, without dots, to register as a netfix user?

You won't pay for it then since you know you don't have a Netflix account. In this case you have one and you mistakenly pay for theirs too.

Re: The dots do matter: how to scam a Gmail user

#326
post #322

The opinion of the author is ridiculous. What about someone use your email, without dots, to register as a netfix user?

You won't pay for it then since you know you don't have a Netflix account. In this case you have one and you mistakenly pay for theirs too.

What about you have ever used another of your emails, without any dots, to register as a netfix user?

Re: The dots do matter: how to scam a Gmail user

#328

Totally disagree with the conclusion. This is Netflix's issue for not validating the email account. Not sure if Uber has changed this since then, but back in the day I used to get the full ride details and receipts from someone else who mistyped their email. If you are sending private transactional emails you need to verify accounts first.

Yep, but it's still a misfeature.

I set up a firstname.lastname account for someone. On other services (e.g. iTunes) they've used that combo with and without dots.

It's a nightmare trying to help them with password resets. They're not an internet-savvy individual.

Re: The dots do matter: how to scam a Gmail user

#329
post #299

I'm sorry but this is ridiculous. The author 1) mentions the dots DO matter, and calls for they're removal as a feature, but makes no mention of the ability to add '+{whatever}' to an email providing the exact same attack vector 2) states this is a gmail issue, when any email provider could do the exact same thing and have it be a problem 3) states the Netflix not verifying the email before payment is somehow not a f…

Author does mention the “+” feature.

Re: The dots do matter: how to scam a Gmail user

#330
The real kicker here though is that it IS possible to have registered a separate email address in gmail with a dot. My wife has been dealing with this in the opposite, she has a valid first.last@gmail and another person has a separate firstlast@gmail. She has the dot but frequently gets emails for the non dot address. We’ve gotten to know the person over like 10 years. If we’re victims of some sort of con game, then they’re certainly in it for the long haul...
Post reply on HN