Live data from Hacker News

The dots do matter: how to scam a Gmail user

jameshfisher.com

431–440 of 518 posts

Re: The dots do matter: how to scam a Gmail user

#431

Totally disagree with the conclusion. This is Netflix's issue for not validating the email account. Not sure if Uber has changed this since then, but back in the day I used to get the full ride details and receipts from someone else who mistyped their email. If you are sending private transactional emails you need to verify accounts first.

And if they do require a verify, they should make it obvious that it was user initiated just then. Otherwise it could be the same scam: Eve creates an account. James gets the email. "Hmm that's funny. Okay I'll verify again".

Re: The dots do matter: how to scam a Gmail user

#432

Totally disagree with the conclusion. This is Netflix's issue for not validating the email account. Not sure if Uber has changed this since then, but back in the day I used to get the full ride details and receipts from someone else who mistyped their email. If you are sending private transactional emails you need to verify accounts first.

EmIl address is an identity. The core philosophical issue here is that an identity provider assigns you bucket of identities without your knowledge. Now others who do have knowledge of your assigned identities can take advantage to impersonate you. The idea that it can be resolved by email verification does not hold well because in several circumstances it might not be possible (for example, you need to create your account at the PoS). It’s a bug indeed if you think of email address as identity. It’s unrealistic expectation that all non-technical users should be aware about this feature as well as that all login system must use email verification.

The solution is simple: email provider should let user create additional identities with their knowledge. That is by default dot feature is not enabled but user should be able to go in and create alternative identities that they want explicitly.

Re: The dots do matter: how to scam a Gmail user

#433

Earlier quoted context omitted.

> the web form shouldn't indicate anything out of the ordinary How will the user know that the registration failed and what to do about it?

Upon entering a valid email (whether it is already registered or not) the form will show the following notification "an email was sent to user@email.com with the sign up instructions, please follow the link in the email to continue the registration" (rewrite for more concise message) If the user already exists the email will be a warning + a link to the password reset form If the user does not exist, the email will b…

And conversion drops right away. On every of my projects as soon as "auto sign in" was dropped -- conversion dropped as well. (assuming that the "conversion" is to make a user to register and do something afterwards)

I know that there should be some kind of compromise since any security measure added to secure accounts will lead to some inconvenience for users.

If your goal to make sign in process as smooth for users as possible you may want introduce as little steps as possible between their landing on a page and "purchase".

But verification of email address should be kind of mandatory and happen before something important will be sent to this email.

Re: The dots do matter: how to scam a Gmail user

#434
post #429
post #104

I have multiple "e-mail doppelgangers" - confused people who don't know their own email address and so accidentally use my address when they register stuff. One's in Chile. I have almost no knowledge of Spanish. The other is in California. Having experienced this: Services need to email new email accounts they become aware of ASAP. They have literally zero UI available to me to notify them that this is an invalid ema…

One of my emails is a "one name" gmail address so I get a few of these fairly often. I've tried doing the good thing where possible and trying to get it changed by contacting the provider but I just gave up. If I get more than a couple of emails from any account, I just hijack it permanently; I've found that deleting the account will only lead to the offender recreating it.

I have the same issue, but Uber has 2FA on the account through SMS. This way I can't login to cancel the account, and there is no 'unsubscribe here' link in the emails.

Also had someone use my email to sign up to an airline. After messing with the seat assignment and meal selection a few times it became old and customer service didnt know what to do, so I changed the associated email to 'helpdesk@airline.com'

Even funnier was how a gameshop website that I did have an account with actually changed my password and account details to be assigned to someone in another country. No notifications etc... So now there are a bunch of trade-in credits on my account, after changing it back to my own details.

Re: The dots do matter: how to scam a Gmail user

#435
post #321

Earlier quoted context omitted.

Absolutely - his proposed solution - disabling the dots-dont-matter feature and retiring them does nothing to stop this exact same attack vector instead employing the '+' feature that he admires and wishes to retain. The attack goes like this: * Hammer the Netflix signup form until you find a gmail.com address which is “already registered”. Let’s say you find the victim jameshfisher. * Eve creates a Netflix account w…

> Hammer the Netflix signup form until you find a gmail.com address which is “already registered”. Let’s say you find the victim jameshfisher. The bug is right here - you shouldn't be able to determine if a user account already exists. If an account already exists: - Logon shouldn't tell you that you have an account and the password was wrong - Registration should send a "looks like you already have an account" email…

> Registration should send a "looks like you already have an account" email to the recipient with "maybe this wasn't you" warning, and the web form shouldn't indicate anything out of the ordinary.

Well that wont work. If you can't register with an email it's obviously because an account has already taken it.

Re: The dots do matter: how to scam a Gmail user

#437
post #355

Earlier quoted context omitted.

But how do you know that the other person registered a gmail account, as opposed to, say, them registering the wrong email address with the email senders?

Send an email and see if that email shows up in your inbox?

If gmail ignores dots in the email address, of course that email is going to show up in your inbox.

Re: The dots do matter: how to scam a Gmail user

#438
post #104

I have multiple "e-mail doppelgangers" - confused people who don't know their own email address and so accidentally use my address when they register stuff. One's in Chile. I have almost no knowledge of Spanish. The other is in California. Having experienced this: Services need to email new email accounts they become aware of ASAP. They have literally zero UI available to me to notify them that this is an invalid ema…

I have one of those too. Who has signed up to the world's most persistent architecture and industrial construction email lists.

Re: The dots do matter: how to scam a Gmail user

#439
Wait.. he logged in to the N2 account by going through the password reset procedure, right? So now, the scamster loses access to the account, because the password that she set is no longer valid.. So how does she get back access to the account once he's changed the password and put in his credit card details?

Re: The dots do matter: how to scam a Gmail user

#440
post #416

Earlier quoted context omitted.

Further, it is trivial to picture an attack where through some other channel, the attacker already knows the email address of their target, and has the knowledge that this victim has a netflix account. If I only need these two pieces of information, neither of which is intended to be 'secret', then I might easily already have enough information to attempt this attack on (for example) my ex, or their new partner, or s…

I really don't see why Netflix needs insider knowledge or whatever to be able to detect john.doe as being the same as johndoe.

I believe it’s because this feature is largely unique to Gmail? So Netflix would need to know and maintain a database of rules based on domains.

* Gmail: Dots are cool.

* Hotmail: No capes! I mean dots. No dots!

* Multiplied by 8 hundred gazillion domains...

Post reply on HN