Live data from Hacker News

Don't verify email addresses by sending spam to them

milek7.pl

41–50 of 67 posts

Re: Don't verify email addresses by sending spam to them

#41
post #38
post #23

Earlier quoted context omitted.

That'd be nice, but I'd even settle for the plain pdf attached to the email.

Unencrypted sensitive data in an email is a really bad idea. I hope they never do that. Although what I would really like, and think is long overdue, is an extension to email that normalises encryption and sender verification. It's ridiculous that email can be spoofed like that. (The same is even more true for phone numbers.)

Is it really? Who can read it today? Your email provider and theirs? Gmail won't deliver messages without TLS any more, so everyone supports it or they're effectively kicked out of email.

Re: Don't verify email addresses by sending spam to them

#42

I would make even stronger advice. If you want to verify an email, send me a one-time code with several hours expiry that I have to resubmit through my logged in web identity at your site. It drives me batty that a financial provider (retirement vendor from previous employer) won't seem to let my "paperless" setting remain active. Only because I don't ping their abusive email tracking pixels etc. To me, paperless mea…

To me, paperless means they ATTACH MY STATEMENT TO THE EMAIL. Not signing up to any paperless until they do, none yet have met this bar. The statement is supposed to be a snapshot of the status of the account at a given moment, if you have to open their website to view it they could regenerate it from whatever crap data they have lying around at the given moment. If it can change every time you look at it, it's a qua…

Many places don't attach the statement because it has sensitive information. Add that with "email is not secure" which we've been yelling for years (well, me since 1996). Sending it via email is risk exposure for them.

Re: Don't verify email addresses by sending spam to them

#43
Hey! Founder of Pangram here. We use Zerobounce and CustomerIO for email validation. I had no idea this was happening. Not entirely sure which one this is coming from, but this is not intentional on our part. Will dig deeper and eliminate the part of the stack that is sending spam — definitely not good that this is happening.

Re: Don't verify email addresses by sending spam to them

#45
post #31

I have a Gmail address in the format of x.surname@gmail.com, which is obviously potentially applicable to tens of thousands of people. The amount of misdirected mail I get is astounding. I literally just got a delivery updaye for hair removal cream, with the option to sign the unknowing recipient up to a paid for tracking subscription service. The problem isn't just making sure the address is valid. You need to ensur…

You seem to be getting unsolicited commercial email, a.k.a. spam, and could possibly initiate legal action against the sender. If you did so, it would cause the entire industry to stop using email verification, and probably switch to phone number until they get sued for the exact same thing with phone numbers.

Re: Don't verify email addresses by sending spam to them

#46
post #38

Earlier quoted context omitted.

Unencrypted sensitive data in an email is a really bad idea. I hope they never do that. Although what I would really like, and think is long overdue, is an extension to email that normalises encryption and sender verification. It's ridiculous that email can be spoofed like that. (The same is even more true for phone numbers.)

Is it really? Who can read it today? Your email provider and theirs? Gmail won't deliver messages without TLS any more, so everyone supports it or they're effectively kicked out of email.

TLS just encrypts the IMAP / SMTP sessions, no guarantee it’s stored encrypted, let alone end to end

Re: Don't verify email addresses by sending spam to them

#48
post #31

I have a Gmail address in the format of x.surname@gmail.com, which is obviously potentially applicable to tens of thousands of people. The amount of misdirected mail I get is astounding. I literally just got a delivery updaye for hair removal cream, with the option to sign the unknowing recipient up to a paid for tracking subscription service. The problem isn't just making sure the address is valid. You need to ensur…

https://xkcd.com/1279/

Re: Don't verify email addresses by sending spam to them

#49

I just did a signup on a brand new email address and was not able to recreate. No random spam emails reported. Just a normal verification email. It's likely that the email the author received is pure coincidence. Especially if they are using a client that downloads emails in batches. FWIW it looks like their validation email is sent by Customer.IO via Mailgun. Both have squeaky clean service agreements so it's unlike…

> getting a random empty email

Is it really empty? From a sibling comment by tom1337 https://news.ycombinator.com/item?id=48651560 it looks like they are using some CSS tricks to hide the text in a html email.

Re: Don't verify email addresses by sending spam to them

#50

Earlier quoted context omitted.

To me, paperless means they ATTACH MY STATEMENT TO THE EMAIL. Not signing up to any paperless until they do, none yet have met this bar. The statement is supposed to be a snapshot of the status of the account at a given moment, if you have to open their website to view it they could regenerate it from whatever crap data they have lying around at the given moment. If it can change every time you look at it, it's a qua…

they send important (financial?) documents over email???? who tf does that what vendor is this

All of them.

My personal tax agent only accepts forms and sends them back via email. I had a conversation with him about using password protected zips and he just told me he won't accept them.

My hospital sent me a PDF that I was to fill in and email back with cleartext credit card information filled in to pay bills. Screenshot:

https://infosec.exchange/@jsmall/116745959468132388

I recently deal with an inheritance and the Super Fund would only accept legal documents by email. I could go on, this is normal.

Post reply on HN