Earlier quoted context omitted.
You don't click because you're educated in these matters. Most people are not.
Not clicking on the credit card update e-mail requires being educated in these matters. Not clicking on the account verification e-mail just requires reading the e-mail before clicking. I think that's an important distinction.
The dots do matter: how to scam a Gmail user
481–490 of 518 posts
Re: The dots do matter: how to scam a Gmail user
#482Earlier quoted context omitted.
Not true, domain part is case insensitive by the standard. Server can decide for non-standard behavior, but that would be foolish.
The domain being in any case for the purpose of delivery is part of the standard, but there's nothing I know if which would prohibit you from implementing local delivery and routing in any way you want once the mail is accepted.
Re: The dots do matter: how to scam a Gmail user
#483Earlier quoted context omitted.
Send an email and see if that email shows up in your inbox?
If gmail ignores dots in the email address, of course that email is going to show up in your inbox.
Re: The dots do matter: how to scam a Gmail user
#484Totally disagree with the conclusion. This is Netflix's issue for not validating the email account. Not sure if Uber has changed this since then, but back in the day I used to get the full ride details and receipts from someone else who mistyped their email. If you are sending private transactional emails you need to verify accounts first.
Re: The dots do matter: how to scam a Gmail user
#485Earlier quoted context omitted.
I just took a screenshot of being logged into both accounts. https://imgur.com/a/jxmhI
How did you get the 2nd account in the first place? I'd like to reproduce this.
Pretty sure that is all it takes.
Re: The dots do matter: how to scam a Gmail user
#486Or you could make sure vendors follow RFC2822. Now admittedly its dense to read, but the two sections that are relevant are; https://tools.ietf.org/html/rfc2822#section-3.2.4 & https://tools.ietf.org/html/rfc2822#section-3.4.1 3.2.4 explains what a dot-atom can be made up of 3.4.1 explains what can be accepted in the make up of an address. I'll always prefer vendors operating within spec even if the spec is a dense a…
Re: The dots do matter: how to scam a Gmail user
#487I can understand wanting to minimize user-friction, but if you're asking someone to enter their payment information, it's very reasonable to have them log in first.
Email aliasing (dots/plus) in gmail is very useful to many people, and it seems overkill to blame Google for having introduced it. Besides, getting rid of it at this point would break backwards compatibility for a huge number of users, so the author's idea is completely infeasible.
Re: The dots do matter: how to scam a Gmail user
#488This makes no sense. Only 1 person can receive the email with or without dots. How can this be taken advantage of when you have to login on netflix to update your card details?
Re: The dots do matter: how to scam a Gmail user
#489It's a user's problem. If user is willing to click through some unsolicited email and pay , he will probably click on the verification link too if the service would send those. It's still a statistics game. Not everyone would pay without verification and not everyone would click the big green button in the verification mail, but some people will without realizing what's up, just like people fall for Nigerian scams ma…