Live data from Hacker News

The dots do matter: how to scam a Gmail user

jameshfisher.com

511–518 of 518 posts

Re: The dots do matter: how to scam a Gmail user

#511

Earlier quoted context omitted.

Which the RFCs for email do allow. The local part is the local part, under local control, and should not be assumed about by remote systems.

Regular people, upon looking at an email address, might think that - alert@example.com - A.Lert@example.com - Al.Ert@example.com etc. were different. Requiring them to know or check what's the "local control" policy at each site may be a stretch. Principle of least surprise, etc.

These are all different e-mail addresses; that part should not be surprising, and Netflix is absolutely doing the right thing by considering them different. (The same goes for "+labels": a "+" is a perfectly valid character in the local part of an e-mail address and the meaning of the "+" is entirely up to the mail host, so e.g. rejecting e-mails with a "+" or stripping out the "+" and following characters would violate the RFCs.)

No, Netflix's errors lie in (a) sending e-mail for any purpose other than account validation to an unvalidated e-mail address, and (b) including a pre-authenticated link in the e-mail that bypasses the normal account access controls. Pre-authenticated links are poor security practice in general; e-mail is notoriously insecure, and simply being able to read an e-mail sent to the address on file does not imply that the reader should have access to the account.

As for "dots don't matter", it can be argued that Google made some scams a bit easier by routing e-mails to non-canonical e-mail addresses to users who don't realize they even have such addresses; my own recommendation would have been to block registration of e-mails differing only in the number or placement of dots, but bounce any incoming mail where the "To:" field doesn't match the canonical form chosen at account creation time. However, since doing away with the "dots don't matter" policy would not significantly impact the more general issue of e-mail address aliasing, I do not believe that Google's policies are to blame for this particular security gap.

Re: The dots do matter: how to scam a Gmail user

#512
post #83

Totally disagree with the conclusion. This is Netflix's issue for not validating the email account. Not sure if Uber has changed this since then, but back in the day I used to get the full ride details and receipts from someone else who mistyped their email. If you are sending private transactional emails you need to verify accounts first.

The verification email too is a phishing attempt, as it gets delivered to wrong person. All it takes is just a click.

The verification e-mail is going to say something like "Please verify this e-mail address for your new Netflix account", which is going to look very suspicious to anyone who didn't just sign up for an account. As phishing attempts go, this is not likely to be very effective. It's not nearly as bad as skipping right to the part where they ask for updated payment information (with a pre-authenticated link!)—someone who has a Netflix account, and perhaps a credit card which recently expired, has no reason to suspect such a request, and most likely would not notice that the e-mail address the notice was sent to does not match the one they used when setting up their own account.

Re: The dots do matter: how to scam a Gmail user

#513
post #271

Earlier quoted context omitted.

There is no bug in Gmail. This bug has nothing to do with Gmail, it is with Netflix not clearly communicating when verifying the address a user claims to own.

While I agree with you from a technical perspective, Netflix isn't going to be the only one with this particular issue. If you addressed the issue at gmail, you can be sure you've fixed it for all the little leaves.

The problem with this reasoning is that doing away with the "dots don't matter" policy would not fix the more general issue of e-mail aliasing. Besides variations in dots, there are also "+labels" (which Netflix must also consider a valid and necessary part of the e-mail address, per the RFCs) and the fact that for every "xyz@gmail.com" address there is an equivalent "xyz@googlemail.com" address. Unlike "dots don't matter", labels are a useful and well-liked feature, supported by many mail servers (though not always using "+" as the delimiter). Removing them would be an extremely unpopular move on Google's part.

No account-related emails (other than e-mail validation) should be sent to the e-mail address on file until it has been validated. Period.

Re: The dots do matter: how to scam a Gmail user

#514
post #401

> The dots do matter: how to scam a Gmail user The dots do not matter, this does not enable a scam, and 99% of people replying to this seem to have utterly missed the point. First off, let's be clear: The story is about someone who entered the wrong email. They should have entered "eve@foo.com" but actually entered (or later changed it to) "james@foo.com", which means that James got some emails from Netflix about Eve…

> All of which is fine; this is how email works, and how modern services (correctly) use email: By identifying an account with an email address, and assuming that if you have control of the email address you should have control of the associated accounts.

That is not the correct way to use e-mail. Unless you're encrypting all your customer messages with S/MIME or PGP, a number of people have access to the content other than the account holder. This includes the e-mail provider, the operators of any servers the message happened to pass through, and of course anyone who happened to hack them, plus anyone who can listen in on the links between the mail servers in the event that those aren't encrypted. None of these people should have control over the associated accounts just because they have the technical ability to read e-mails send to the address on file.

> If gmail bounces all emails with "incorrect" periods, it might have stopped this particular incident, but it doesn't solve the issue which is about people giving out your address instead of their own when creating an account, which is the actual issue here.

The actual issue is more nuanced than that. This isn't just about signing up for a service with someone else's address, it's about signing up for a service the target already subscribes to using an alternate e-mail address routed to the same account. Now, it is absolutely true that getting rid of the "dots don't matter" policy would not prevent this from happening, since there are other ways of aliasing e-mail accounts such as "+labels". However, in the absence of aliasing this issue wouldn't exist, since someone who doesn't subscribe to Netflix would (probably) not fall for a request to update their payment information, and the scammer couldn't create a new account with exactly the same e-mail address as an existing subscriber.

> Further, the proposed scam, if it works, only works because (allegedly) Netflix lets you change an account email without verifying that you know the current password.

The scam does not require the ability to change the e-mail address. That just makes it harder for the target to regain control, but ultimately the scheme depends on the target remaining blissfully unaware that they're paying for someone else's account. If the target becomes aware of what is going on then they can just dispute the charges with their card issuer; they don't need access to the Netflix account for that.

No, this scam only works because Netflix does not require validation of the e-mail address on file before sending account-related e-mails to that address. This is the core issue. The first e-mail you get related to an account should always be the notice that a new account is being created, with active effort required on the recipient's part before the address is considered valid.

Re: The dots do matter: how to scam a Gmail user

#515

Earlier quoted context omitted.

Which the RFCs for email do allow. The local part is the local part, under local control, and should not be assumed about by remote systems.

Regular people, upon looking at an email address, might think that - alert@example.com - A.Lert@example.com - Al.Ert@example.com etc. were different. Requiring them to know or check what's the "local control" policy at each site may be a stretch. Principle of least surprise, etc.

Those are three different addresses. On some systems they may be three different accounts. On others they may be one account.

On some systems, anything ending in '@example.com' may be a single account.

It may be that defined address to account mappings exist on a domain and all other addresses map to a default account. It's common enough the hosting industry supports it and it has a name - a catchall email account.

Nobody sending mail to any of those addresses needs to know how many addresses map to the account associated with the address to which they are sending. It's an address, not an identifier. I would argue you don't have a reason nor a right to know the address to account mappings in my systems.

What a sender should reasonably expect is that someone who can receive mail delivered to a particular address is in charge of the email account to which that address maps. Sending a verification email to someone expecting to receive it is the way to validate the recipient is the intended recipient. That's it.

If I give you my phone number, do you need to know what other phone numbers will ring that phone or how many phones I answer in order to call me? Do I need to disclose all the possible places I might receive a package if I want one delivered to a single place? No.

Email addresses are addresses. That's all they are. Stop pretending they are something else, and this will become much clearer for you.

Re: The dots do matter: how to scam a Gmail user

#516
* The below is copied verbatim from a deeper branch of the thread, but may clarify some things for others as well. *

Those are three different addresses. On some systems they may be three different accounts. On others they may be one account. On some systems, anything ending in '@example.com' may be a single account.

It may be that defined address to account mappings exist on a domain and all other addresses map to a default account. It's common enough the hosting industry supports it and it has a name - a catchall email account.

Nobody sending mail to any of those addresses needs to know how many addresses map to the account associated with the address to which they are sending. It's an address, not an identifier. I would argue you don't have a reason nor a right to know the address to account mappings in my systems.

What a sender should reasonably expect is that someone who can receive mail delivered to a particular address is in charge of the email account to which that address maps. Sending a verification email to someone expecting to receive it is the way to validate the recipient is the intended recipient. That's it.

If I give you my phone number, do you need to know what other phone numbers will ring that phone or how many phones I answer in order to call me? Do I need to disclose all the possible places I might receive a package if I want one delivered to a single place? No.

Email addresses are addresses. That's all they are. Stop pretending they are something else, and this will become much clearer for you.

Re: The dots do matter: how to scam a Gmail user

#517
post #74

Earlier quoted context omitted.

The malicious sharer could modify the rule to not only remove the "+site" part but remove all the dots. Then, your trick is useless. They might realize the "+site" and not the dots, but your point was about ability not awareness. ;)

except my "real" address has dots, so I know that 0 dots are being cleaned. I just can't tell who did it.

Which doesn't provide extra information for you, as you probably don't go around subscribing to spam mailing lists.

But all right, '+site' is more well known, so it does definitely work better.

Re: The dots do matter: how to scam a Gmail user

#518

Earlier quoted context omitted.

Moreover some broken email validators reject plus addresses. It's nice to be able to fall back on special dot combos when you want to keep track of sites selling your email to spammers.

I used to use + for that purpose and was always pretty annoyed when a website wouldn’t accept it. I’ve since dropped gmail for fastmail though so now I use sitename@sites.mydomain for all website registrations. No site ever rejects it and it works great for knowing where spam comes from, although I’ve had some funny phone calls where people were baffled that my email address starts with their website name.

> No site ever rejects it

Have you ever tried it on Yahoo? They wouldn't let me set my email address to yahoo@mydomain a few years ago, claiming that the "email owner" had blocked this: https://www.dropbox.com/s/t213wkajdz5753k/yahoolies.png?dl=0

Post reply on HN