Live data from Hacker News

The dots do matter: how to scam a Gmail user

jameshfisher.com

451–460 of 518 posts

Re: The dots do matter: how to scam a Gmail user

#451
post #401

> The dots do matter: how to scam a Gmail user The dots do not matter, this does not enable a scam, and 99% of people replying to this seem to have utterly missed the point. First off, let's be clear: The story is about someone who entered the wrong email. They should have entered "eve@foo.com" but actually entered (or later changed it to) "james@foo.com", which means that James got some emails from Netflix about Eve…

> the issue which is about people giving out your address instead of their own when creating an account, which is the actual issue here. If the other person had tried to use the author's email address written exactly the same as his existing Netflix account, Netflix wouldn't have let the other person create a new account, but would instead have made them log into the existing account. The fact that Netflix and Gmail…

> Well, Eve knows the account's password at the time she changes the account email, the article explicitly mentions this

Right, but read the rest of the sentence:

> I also have access to the account because I own james.hfisher@gmail.com, and so I can follow the password reset process for this account. I did so.

So at a minimum, Eve did not know the password at the time they would have (hypothetically) tried to change the email, as James says he had reset the password. And at least based on my interpretation of the linked article, this is unavoidable; you can't manipulate payment details without being logged into an account, and the only way to log into his bogus second account would be via a password reset.

If that's true, your proposal is in fact the situation: You do have to reset the password, and there's no benefit to the "scammer"; at most you can trick someone into paying for two different Netflix accounts. And this does seem to be true; he provides the link as https://www.netflix.com/simplemember/editcredit?locale=en-GB which doesn't contain an account identifier and does (of course) require authentication.

> The fact that Netflix and Gmail don't have the same notion of "existing account" IS the key issue here.

Well, first it's worth noting that Gmail is following the relevant RFC here (as per RFC 5321 2.3.11 Mailbox and Address, "...the local-part MUST be interpreted and assigned semantics only by the host specified in the domain of the address."), so if Netflix is relying on the semantics of the local-part then they're simply in error. And second even without this there's a lot of ways of getting a plausible looking phishing email into someone's inbox. If Netflix security relies on targets not seeing a malicious email, then they've done something terrible.

Re: The dots do matter: how to scam a Gmail user

#452
Frankly feels like these comments are being astroturfed by Google.

Sure, Netflix should have done things differently, and technically what Google is doing is not wrong, but if we look back at reality for a second here, it is simply the case that many services (and users) make the assumption that only one e-mail address leads to a user's inbox.

This breaks this paradigm and as a result does cause realistic security issues, whether it requires a Netflix to make a mistake, too, or not.

Re: The dots do matter: how to scam a Gmail user

#453
post #449

Earlier quoted context omitted.

Are we reading the same article? The author is writing about getting a Netflix account funded by causing Netflix to send an email to a Gmail account holder. For all intents and purposes this is a legitimate email originating from Netflix. It is not about someone surreptitiously transferring control of another person's Netflix account to himself.

> It is not about someone surreptitiously transferring control of another person's Netflix account to himself. That's exactly what we're talking about. Keep in mind that by the end of the proposed "scam", there are two accounts, both registered to James' email address, and with passwords that only James knows. He has control over both accounts. Any attempt to profit from the scam would require surreptitiously transfe…

Not really. There are two Netflix accounts, and both recovery emails are directed to James’s Gmail account.

The scam is operating on the chance that James does not realize that it is someone else's Netflix account and goes ahead to add funds to it. The other person then logs in before James realizes his mistake and changes the recovery email to something else.

Re: The dots do matter: how to scam a Gmail user

#454

Totally disagree with the conclusion. This is Netflix's issue for not validating the email account. Not sure if Uber has changed this since then, but back in the day I used to get the full ride details and receipts from someone else who mistyped their email. If you are sending private transactional emails you need to verify accounts first.

Agree, this said the "dot don't matter" is also an awful thing. I'd rather have gmail create a real alias system instead of this hack. That's the thing that is good with Yahoo.mail, it has real alias system.

Re: The dots do matter: how to scam a Gmail user

#456

Earlier quoted context omitted.

I really don't see why Netflix needs insider knowledge or whatever to be able to detect john.doe as being the same as johndoe.

I believe it’s because this feature is largely unique to Gmail? So Netflix would need to know and maintain a database of rules based on domains. * Gmail: Dots are cool. * Hotmail: No capes! I mean dots. No dots! * Multiplied by 8 hundred gazillion domains...

You’re thinking too much like a programmer. It’s a single rule for a single domain that accounts for the majority of users.

The right thing to do is ask for a password, but absent that, accounting for gmail addresses seems worthwhile. It would save them getting a thread like this on hn.

Re: The dots do matter: how to scam a Gmail user

#457
post #449

Earlier quoted context omitted.

> It is not about someone surreptitiously transferring control of another person's Netflix account to himself. That's exactly what we're talking about. Keep in mind that by the end of the proposed "scam", there are two accounts, both registered to James' email address, and with passwords that only James knows. He has control over both accounts. Any attempt to profit from the scam would require surreptitiously transfe…

Not really. There are two Netflix accounts, and both recovery emails are directed to James’s Gmail account. The scam is operating on the chance that James does not realize that it is someone else's Netflix account and goes ahead to add funds to it. The other person then logs in before James realizes his mistake and changes the recovery email to something else.

> The scam is operating on the chance that James does not realize that it is someone else's Netflix account and goes ahead to add funds to it.

Right, but keep in mind that he's already changed the password.

> The other person then logs in

How? They don't know the new password.

The timing doesn't seem to work; James can't add funds without resetting the password, and Eve can't hijack it without knowing the new password. There's a potential loophole if Netflix 1) doesn't invalidate the old session when the password changes and 2) doesn't require a user to provide the current password for changing the email but as far as I'm aware, that isn't the case. (It certainly shouldn't be! And if it is, then that's the real issue here...)

Re: The dots do matter: how to scam a Gmail user

#459
post #449

Earlier quoted context omitted.

> It is not about someone surreptitiously transferring control of another person's Netflix account to himself. That's exactly what we're talking about. Keep in mind that by the end of the proposed "scam", there are two accounts, both registered to James' email address, and with passwords that only James knows. He has control over both accounts. Any attempt to profit from the scam would require surreptitiously transfe…

Not really. There are two Netflix accounts, and both recovery emails are directed to James’s Gmail account. The scam is operating on the chance that James does not realize that it is someone else's Netflix account and goes ahead to add funds to it. The other person then logs in before James realizes his mistake and changes the recovery email to something else.

But he can't add funds to it without logging in to it, which requires him to reset the password. Once the password is reset, the scam can't benefit the scammer.

In order for the scam to work, either he has to be able to change the credit card details without knowing or changing the password, or the scammer has to be able to access the account without access to the password or e-mail address. Both of these are serious security issues, but not what the article was about.

Re: The dots do matter: how to scam a Gmail user

#460
post #206

Earlier quoted context omitted.

This is true if changing the password s you to re-enter the password on every device (even those that were logged in at the time)

Changing a password should always invalidate all existing sessions. If you aren't doing that, then you are doing it wrong. Edit: Or at least invalidate all sessions initiated using the old password if you have that tracked.

> Changing a password should always invalidate all existing sessions

Doesn't with Google. They display a prompt and let you select which sessions to expire.

Post reply on HN