Live data from Hacker News

Why was my email leaked?

forums.dropbox.com

191–200 of 265 posts

Re: Why was my email leaked?

#191
post #49

Earlier quoted context omitted.

Check out Tonido Cloud ( http://www.tonido.com/cloud/ ) and host your own dropbox.

Are you affiliated with Tonido, or just really into Dropbox alternatives? Your submission history seems a little too focused.

He claims to be with Tonido in a prior post, as he talks about the back end infrastructure and uses the term "we".

http://news.ycombinator.com/item?id=4703166

Re: Why was my email leaked?

#192

Earlier quoted context omitted.

I've also done that and I've just recently added _ to the mix, which I think is particularly devious and wholeheartedly recommend.

These (the dot and underscore separators) are a great solution, because when the spam-happy-marketroids try to get the webdevs to intentionally implement broken email address validation, they can point out all the corporate email addresses which are by-policy of the form "firstname.lastname@domain.tld"…

Yeah, so much for RFC2822. Oh well, apparently, some spammers are clever enough to grep the emails with "+" and throw away the obvious additional portion.

Re: Why was my email leaked?

#193

I have a unique email address for dropbox that has not received any spam. I created it a couple years ago but only used it once briefly.

I didn’t get any spam either, but then a short grep through my mail.log showed this: 2013-02-28T18:05:18.865406+01:00 nfc postfix/smtpd[14995]: NOQUEUE: reject: RCPT from bl14-172-78.dsl.telepac.pt[85.247.172.78]: 504 5.5.2 : Helo command rejected: need fully-qualified hostname; from= to= proto=ESMTP helo=

It is as if spammers don't even try anymore! Bogus helo is soon 1990s..

Re: Why was my email leaked?

#194
post #167

Earlier quoted context omitted.

Nice investigative work, he definitely seems affiliated...

I am offering an alternative suggestion to a person who is not happy with dropbox's customer service. He/she has the smarts to decide whether a new service is worth a try. My affiliation is irrelevant. Can u guarantee the readers who downvoted me are not affiliated with dropbox or positively biased towards dropbox. You are no different from the dropbox forum moderators.

Yes, your affiliation is quite relevant. When you are talking about something when you have a clear conflict of interest, you need to disclose it. Then at least the reader has the right context in which to make a decision.

When you post w/o disclosing, you make it seem like someone from this community has found your product interesting and is suggesting others try it. Instead of working for a company and trying to drum up business while disparaging a competitor.

Seriously, things like this reduces the likelihood that I'll ever try Tonido to nil. All you had to do was add "disclosure: I work for Tonido" to your post, if that is the case.

Re: Why was my email leaked?

#196

Earlier quoted context omitted.

The victim-blaming was shocking to me here. The bit where Andy Y. says, "Oh, some spammer just guessed it" was funny. As if spammers needed to do dictionary attacks against the sort of tagged addresses that 0.1% of people use. But it became hilarious when he said the same thing to the guy who uses 10-random-character tags. As if they would hit upon two different Dropbox addresses like that before the sun cooled to a…

To defend Dropbox here, those people are forum moderators and not employees of Dropbox. The first Dropbox employee to respond specifically apologized for those responses. Jumping on Dropbox for this is just going to harm other companies responding to customer support requests in a timely fashion before lawyers get a chance to review...

And yet, those users are still wearing moderator tags...

Re: Why was my email leaked?

#197

Earlier quoted context omitted.

The victim-blaming was shocking to me here. The bit where Andy Y. says, "Oh, some spammer just guessed it" was funny. As if spammers needed to do dictionary attacks against the sort of tagged addresses that 0.1% of people use. But it became hilarious when he said the same thing to the guy who uses 10-random-character tags. As if they would hit upon two different Dropbox addresses like that before the sun cooled to a…

To defend Dropbox here, those people are forum moderators and not employees of Dropbox. The first Dropbox employee to respond specifically apologized for those responses. Jumping on Dropbox for this is just going to harm other companies responding to customer support requests in a timely fashion before lawyers get a chance to review...

> "those people are forum moderators and not employees of Dropbox"

They're official representatives of Dropbox, even if they are unpaid. Their behavior is entirely on Dropbox, and the fact that Dropbox has farmed out its customer support to unpaid amateurs is possibly a worse realization than the fact that the clueless person was not an employee.

Re: Why was my email leaked?

#198
The FAA's E-mail database for pilots has also been hacked or sold.

So has the Atlanta Journal-Constitution's.

Those are the only two I've caught with similar tracking in quite a few years. Oh, and Oakley. They acknowledged that one though.

Re: Why was my email leaked?

#199
post #60

What about the possibility that end-users' computers are breached? - User/pass is saved in the 'Remembered password' area of browser (this is decodable by malware) - Email is screen-scraped by malware - Email is sniffed during login at a wifi hotspot (Password is encrypted, user/email may not be) - 3rd party apps that are linked to your dropbox account I'm not saying that this wasn't caused by the database breach, bu…

Yeah, but if that happened to a person who habitually used sub-addressing it would be pretty obvious. They would likely have received the same spam many times from many of their sub-addressed emails. People who take the trouble to set this up, don't use it in only one place.

Re: Why was my email leaked?

#200

Earlier quoted context omitted.

From this forum "experience", it seems they have copied the Google model of service. They offer the support forum as a major source of support and promote heavy users to moderators or give them some other special flair. Mind you, normal users, without any inside access, information or capabilities. These users then spend their time flagging down support requests and blaming the posters.

The victim-blaming was shocking to me here. The bit where Andy Y. says, "Oh, some spammer just guessed it" was funny. As if spammers needed to do dictionary attacks against the sort of tagged addresses that 0.1% of people use. But it became hilarious when he said the same thing to the guy who uses 10-random-character tags. As if they would hit upon two different Dropbox addresses like that before the sun cooled to a…

"The original complainant is much more patient than I am. If that's what I'd gotten as "support" on a paid service when reporting a security breach, I would have closed my account and told them to get fucked."

I agree with the end part of your response, but it's unknown if Forrest is a paid customer.

Post reply on HN