Sean B.: Hi there, We’ve been looking into these spam reports and take them seriously. Back in July we reported that certain user email addresses had leaked and some users had received spam as a result. At this time, we have not seen anything to suggest this is a new issue, but remain vigilant given the recent wave of security incidents at other tech companies. If you’ve received spam to an email account you only use…
Coincidence that it came (relatively) right on the heels of "and you're on HN"...?
Why was my email leaked?
121–130 of 265 posts
Re: Why was my email leaked?
#122Earlier quoted context omitted.
When I try subaddressing as I try to sign up for new online services, more often than not that address format is rejected as invalid. Most online services don't have very good email validation.
I changed my mail server to accept . instead of +'s so now the emails I generate work through pretty much any validation.
Re: Why was my email leaked?
#123Earlier quoted context omitted.
It's pointless in practice in theory; in practice in practice spammers (in my experience) don't target + aliases. And if you think about the set of people who are likely to give money to spammers, the set of people using + aliases, and the fraction of + alias space that is occupied versus the fraction of non-+'aliased space that is occupied, the reason why becomes clear.
I've tried to use this system in the past, but found it to be a PITA. A lot of email systems won't let you use a +. The other gotcha I get is that they use the email address as a login token (Dropbox, for example). So you have to remember a) that you used a token and b) what it was. Any suggestions on approaching these?
Even though a service might desperately want to know my personal and/or business email address, and disguise that desire with the usual "Hey, just use your email address as your login username!", doesn't mean I have to comply. Unless they're prepared to accept responsibility to disclosure of my address, I feel perfectly happy taking the required measures to minimise those risks myself - no matter what they attempt to enforce with crappy email validation or ToS requirements.
(And, although Dropbox have finally arrived in their forum-thread ~24hrs late apologising for their "community moderators" calling their customers idiots, the responses from Nathan and especially Chris only strengthen my resolve to ignore any attempt by companies/services to gain access to my personal email addresses as part of their user databases.)
Re: Why was my email leaked?
#124Earlier quoted context omitted.
Yeah, Chris seems a bit of prick: "Just the fact that you listed your emails says it all."
Especially considering the context. It seemed pretty clear that the user was posting the email address publicly for the first time. That is just awful, and is an awkward example of why you may not want unpaid, mostly un-vetted volunteers as the public face of a company.
I was wary of this thread showing up on HN because I felt I was a bit unkind when posting in that thread, but Chris' comment towards me seemed completely unjustified. And he deleted a prior post along the same lines, hence why I quoted him on my next post.
Re: Why was my email leaked?
#125On the other hand, too often as a user I feel I have to walk on egg shells to avoid upsetting some over sensitive petal of a forum mod. One misunderstood word and you are banned for life, with no appeal what so ever.
All of which leads me to think there should be some third party arbitration for this sort of thing.
Re: Why was my email leaked?
#126Earlier quoted context omitted.
It's pointless in practice in theory; in practice in practice spammers (in my experience) don't target + aliases. And if you think about the set of people who are likely to give money to spammers, the set of people using + aliases, and the fraction of + alias space that is occupied versus the fraction of non-+'aliased space that is occupied, the reason why becomes clear.
I've tried to use this system in the past, but found it to be a PITA. A lot of email systems won't let you use a +. The other gotcha I get is that they use the email address as a login token (Dropbox, for example). So you have to remember a) that you used a token and b) what it was. Any suggestions on approaching these?
Re: Why was my email leaked?
#127I have to say, accusing Dropbox of leaking in the title of the thread, with out any actual basis, since it is possible that the user cocked up somewhere, is not the best way to get polite support. Yes the mods could have been a lot more professional, but I can see why their backs were up and why they would be defensive. On the other hand, too often as a user I feel I have to walk on egg shells to avoid upsetting some…
Re: Why was my email leaked?
#128I have to say, accusing Dropbox of leaking in the title of the thread, with out any actual basis, since it is possible that the user cocked up somewhere, is not the best way to get polite support. Yes the mods could have been a lot more professional, but I can see why their backs were up and why they would be defensive. On the other hand, too often as a user I feel I have to walk on egg shells to avoid upsetting some…
Re: Why was my email leaked?
#129Holy crap Dropbox's moderators make me want to terminate my account with them.
Reading that thread was painful. I always use custom one-off email addresses for services I sign-up for and. When I've attempted to report disclosure of my email address I'm almost always met with major skepticism. It's maddening. I used to enjoy the reactions I'd get from store clerks and telephone reps when I give them my email address. "Oh, how you have an email address with our company name in it?" In recent year…
If I'm at Toys R Us or something, I'll just be like uh... "tru25@.com" so they don't question me. (Also, I chose Toys R Us as an example because when I went to sign up for a loyalty program, and they typed in "toysrus@.com" their cash register black screened and rebooted... !)
Re: Why was my email leaked?
#130Sean B.: Hi there, We’ve been looking into these spam reports and take them seriously. Back in July we reported that certain user email addresses had leaked and some users had received spam as a result. At this time, we have not seen anything to suggest this is a new issue, but remain vigilant given the recent wave of security incidents at other tech companies. If you’ve received spam to an email account you only use…
I'm just relieved that they realized the moderator[s] were being dismissive. I'm not sure that it's a new breach, but it does look like something is going on...
I'm surprised (bordering on disappointed) that the initial response by the moderator Chris didn't trigger a Dropbox employee response almost immediately. Even given worst-case timing I'd expect a first thing next working day response in 16 hours - but for a potentially serious security related problem like this I really expected to see an immediate "Hey, thanks for the report - we're looking into this right now, can I contact you off-forum to get more details." from a Dropbox employee - preferably with an obviously security related job title.
I fully understand why Dropbox can't afford/justify providing high priority customer support to their free-tier customer base, but ignoring possible security breaches reported from the free-tier seems foolish, and allowing your crowd-sourced forum-based-customer-support to mishandle it like this is really sad.