Totally disagree with the conclusion. This is Netflix's issue for not validating the email account. Not sure if Uber has changed this since then, but back in the day I used to get the full ride details and receipts from someone else who mistyped their email. If you are sending private transactional emails you need to verify accounts first.
The dots do matter: how to scam a Gmail user
431–440 of 518 posts
Re: The dots do matter: how to scam a Gmail user
#432Totally disagree with the conclusion. This is Netflix's issue for not validating the email account. Not sure if Uber has changed this since then, but back in the day I used to get the full ride details and receipts from someone else who mistyped their email. If you are sending private transactional emails you need to verify accounts first.
The solution is simple: email provider should let user create additional identities with their knowledge. That is by default dot feature is not enabled but user should be able to go in and create alternative identities that they want explicitly.
Re: The dots do matter: how to scam a Gmail user
#433Earlier quoted context omitted.
> the web form shouldn't indicate anything out of the ordinary How will the user know that the registration failed and what to do about it?
Upon entering a valid email (whether it is already registered or not) the form will show the following notification "an email was sent to user@email.com with the sign up instructions, please follow the link in the email to continue the registration" (rewrite for more concise message) If the user already exists the email will be a warning + a link to the password reset form If the user does not exist, the email will b…
I know that there should be some kind of compromise since any security measure added to secure accounts will lead to some inconvenience for users.
If your goal to make sign in process as smooth for users as possible you may want introduce as little steps as possible between their landing on a page and "purchase".
But verification of email address should be kind of mandatory and happen before something important will be sent to this email.
Re: The dots do matter: how to scam a Gmail user
#434I have multiple "e-mail doppelgangers" - confused people who don't know their own email address and so accidentally use my address when they register stuff. One's in Chile. I have almost no knowledge of Spanish. The other is in California. Having experienced this: Services need to email new email accounts they become aware of ASAP. They have literally zero UI available to me to notify them that this is an invalid ema…
One of my emails is a "one name" gmail address so I get a few of these fairly often. I've tried doing the good thing where possible and trying to get it changed by contacting the provider but I just gave up. If I get more than a couple of emails from any account, I just hijack it permanently; I've found that deleting the account will only lead to the offender recreating it.
Also had someone use my email to sign up to an airline. After messing with the seat assignment and meal selection a few times it became old and customer service didnt know what to do, so I changed the associated email to 'helpdesk@airline.com'
Even funnier was how a gameshop website that I did have an account with actually changed my password and account details to be assigned to someone in another country. No notifications etc... So now there are a bunch of trade-in credits on my account, after changing it back to my own details.
Re: The dots do matter: how to scam a Gmail user
#435Earlier quoted context omitted.
Absolutely - his proposed solution - disabling the dots-dont-matter feature and retiring them does nothing to stop this exact same attack vector instead employing the '+' feature that he admires and wishes to retain. The attack goes like this: * Hammer the Netflix signup form until you find a gmail.com address which is “already registered”. Let’s say you find the victim jameshfisher. * Eve creates a Netflix account w…
> Hammer the Netflix signup form until you find a gmail.com address which is “already registered”. Let’s say you find the victim jameshfisher. The bug is right here - you shouldn't be able to determine if a user account already exists. If an account already exists: - Logon shouldn't tell you that you have an account and the password was wrong - Registration should send a "looks like you already have an account" email…
Well that wont work. If you can't register with an email it's obviously because an account has already taken it.
Re: The dots do matter: how to scam a Gmail user
#436That's not the internet is supposed to work.
Re: The dots do matter: how to scam a Gmail user
#437Earlier quoted context omitted.
But how do you know that the other person registered a gmail account, as opposed to, say, them registering the wrong email address with the email senders?
Send an email and see if that email shows up in your inbox?
Re: The dots do matter: how to scam a Gmail user
#438I have multiple "e-mail doppelgangers" - confused people who don't know their own email address and so accidentally use my address when they register stuff. One's in Chile. I have almost no knowledge of Spanish. The other is in California. Having experienced this: Services need to email new email accounts they become aware of ASAP. They have literally zero UI available to me to notify them that this is an invalid ema…
Re: The dots do matter: how to scam a Gmail user
#439Re: The dots do matter: how to scam a Gmail user
#440Earlier quoted context omitted.
Further, it is trivial to picture an attack where through some other channel, the attacker already knows the email address of their target, and has the knowledge that this victim has a netflix account. If I only need these two pieces of information, neither of which is intended to be 'secret', then I might easily already have enough information to attempt this attack on (for example) my ex, or their new partner, or s…
I really don't see why Netflix needs insider knowledge or whatever to be able to detect john.doe as being the same as johndoe.
* Gmail: Dots are cool.
* Hotmail: No capes! I mean dots. No dots!
* Multiplied by 8 hundred gazillion domains...