Live data from Hacker News

The joys of owning an ‘OG’ email account

krebsonsecurity.com

211–220 of 285 posts

Re: The joys of owning an ‘OG’ email account

#211
I was a very early Gmail user due to being a Google Answers researcher so I got an 'OG' name (which I still own but don't use as my main inbox) and it gets lots of mind boggling stuff as covered in the article. Even a Facebook account (which I could log into) and tickets for major shows (which I could cancel/change seat at, if I had wanted to).. Since I don't use the account myself other than for YouTube anymore, I just let it fly by and look at it in amazement every now and then.

Re: The joys of owning an ‘OG’ email account

#212

Earlier quoted context omitted.

Most 'FluffyBunny...' style addresses and usernames I see tend to end in a 2 digit number which is obviously the user's birth year, which they added when told that plain old 'FluffyBunny' wasn't available. Not a very sensible idea, given how many sites have "What year where you born?" as one of their security questions.

>"What year where you born?" Anecdata from me: I've never seen this as a security question, I'm willing to concede that I didn't notice it because I just pick a security question at random and record it in my password database with a made up answer so that I can satisfy their test later on without using a real, guessable answer.

This is exactly what I do too.

I've mentioned before on here; it did come back to bite me once when I had to ring my insurance company and confirm that my mother's maiden name was... er... "Hitler"!

Re: The joys of owning an ‘OG’ email account

#213
An amusing anecdote from someone on the other side of this story...

A friend of mine has first@fullname.co.uk, and he's forever getting email intended for first@fullname.com (who is someone entirely different, also in the UK, and works in the military).

One day my friend books a flight and accidentally uses first@fullname.com. He doesn't realise anything is wrong as the flight still shows up in the app. However, the owner of first@fullname.com also sees the flight confirmation and thinks there's some identity fraud going on, so phones it in to the police. So my friend gets to the airport and scans his passport at the boarding gate, but is met with a big red exclamation mark. Next thing he knows, he's flanked by two armed officers who take him away for questioning for an hour!

After working out the mix-up, my friend sent a note to first@fullname.com thanking them for the welcome committee.

Re: The joys of owning an ‘OG’ email account

#214
post #210

My wife owns an email address in Gmail and you wouldn't think it was a very popular email address. Until of course someone's account information at numerous shopping sites began showing up. My wife contacted this person by phone and it turned out to be an elderly woman. The elderly woman was not having it and began arguing with my wife about whose email address it was. The elderly woman ranted on and on about HOW DAR…

That couldn't have worked out better, and was a nice thing for you and your wife to have done.

Re: The joys of owning an ‘OG’ email account

#215

Ugh, this is my life. Yes, including accusations of “hacking” when someone signed up for Facebook with my email. On the plus side, this personal experience made me very adamant about protecting mistakenly-registered users at my employer. When we were planning to add logged in accounts to our service, the sales team (understandably!) wanted the signup process to be as frictionless as possible, and thought that new use…

[deleted]

Re: The joys of owning an ‘OG’ email account

#216
post #117

Earlier quoted context omitted.

Yup, I feel your pain. One of my emails is @ .com. This fails verification on so many websites it's just comical. I then figured on making a @ .com. Turns out folks mostly validate .com in my experience, which I assume is because of good old mail.com. It's frustrating.

I have something similar when I used contact@ . .name There were various ways in which that failed. 1. ".name" was pretty new by then, so some frontends did not accept it 2. some frontends objected to the third level of my domain part, accepting third levels only in such cases as the well know. ".co.uk" for example 3. some frontends let me sign up, but something in the backend failed, I can only suspect if it was the…

> 2. some frontends objected to the third level of my domain part, accepting third levels only in such cases as the well know. ".co.uk" for example

This is actually not such a rare edge case. My university, for example, uses @students..de . So there's really not much excuse for not handling this.

Re: The joys of owning an ‘OG’ email account

#217

Ugh, this is my life. Yes, including accusations of “hacking” when someone signed up for Facebook with my email. On the plus side, this personal experience made me very adamant about protecting mistakenly-registered users at my employer. When we were planning to add logged in accounts to our service, the sales team (understandably!) wanted the signup process to be as frictionless as possible, and thought that new use…

My email account got 'hacked' by the Chinese (not really hacked, just reused the same password). From there they broke into multiple other accounts by password recovery. I got control of the account back. But few years later, someone used my email to register at some Singaporean university. Since then I keep receiving emails from multiple departments telling me about exams and my lack of attendance.

Re: The joys of owning an ‘OG’ email account

#219
post #207
post #117

Earlier quoted context omitted.

Yup, I feel your pain. One of my emails is @ .com. This fails verification on so many websites it's just comical. I then figured on making a @ .com. Turns out folks mostly validate .com in my experience, which I assume is because of good old mail.com. It's frustrating.

Similar experience with IDN domains. Most places altogether reject them, but those which accept them, only a subset accept IDN recipient in the mail address.

The SMTPUTF8 RFC to support non-ASCII local parts is from February 2012 and thus fairly new [1]. Postfix supports it since July 2014 [2] and to the best of my knowledge Dovecot still does not yet support SMTPUTF8 for LMTP.

Personally I did not enable SMTPUTF8 support in my Postfix due to the lack of Dovecot support.

[1] https://tools.ietf.org/html/rfc6531 [2] http://www.postfix.org/SMTPUTF8_README.html

Post reply on HN