Live data from Hacker News

Why was my email leaked?

forums.dropbox.com

241–250 of 265 posts

Re: Why was my email leaked?

#241
post #4

The way the moderators handled this was pretty damn bad. Two different users tell the moderator they use UNIQUE e-mail addresses for dropbox only, and they received spam roughly at the same time and yet the moderator answers by assuming the users are idiots.

The initial responses by moderators were fine and correct. They met the complaint with skepticism.

The fact that the guys email was blah.dropbox@blah.com meant it was a possibility that another site had been compromised and the email matched a keyword filter which allowed it to be easily guessed.

Its like passwords. MyPASSW0rDdropbox. If this is leaked it is fairly likely someone may try.. MyPASSW0rDfacebook.

They failed a bit further on. One obviously misread the thread and made a comment which isn't really acceptable.

Generally though it is the typical user forum thread. User repeatedly hammers the moderator with the same question. The user cannot elaborate. The moderator can only speculate due to lack of information. User doesn't find moderator answer acceptable, provides no further information and asks the same question.. both sides get annoyed.

It seems like the spam is to do with the data that Dropbox previously lost. An answer which a moderator actually provided.

Re: Why was my email leaked?

#242
post #52

Earlier quoted context omitted.

Nope, nope and nope.

See, the problem with that email address (dropbox@example.com) is that it tells me that I can try amazon@example.com, paypal@example.com. So, if I get access to an email for somerandomsite@example.com, trying these others is fairly trivial. It takes no time to suddenly generate an effective list of emails to try. The point being, using a pattern is easy to discover. Even if that pattern is a random set of characters.…

Nope. I didn't use dropbox@mydomain but another string that was not guessable.

And how is a random pattern easy to discover? Quite coincidental that of the hundreds of addresses, just the three that are used for Dropbox are receiving spam in the past few days.

The spam I'm receiving is the kind of spam that you attempt to send to a non-tech audience (obvious phishing is obvious). The addresses were harvested, not carefully picked by looking at other addresses I used with my domain. The word "dropbox" is not even in the spammed addresses; they were school addresses. I never publicly mentioned I even went to that school. It are also three variants on the school's name, incredible that they picked just these three to spam.

Re: Why was my email leaked?

#243

Earlier quoted context omitted.

When I try subaddressing as I try to sign up for new online services, more often than not that address format is rejected as invalid. Most online services don't have very good email validation.

I have anything sent to any address at my vanity domain forwarded to gmail. I use the name of the website and add e.g. ".shop@mydomain.tld" or ".bank@mydomain.tld" so I can apply different labels to them in gmail. It works great except I chose a .info domain which some sites don't recognise as valid.

I should also have said that this system means that for forums I feel safe enough using the same password on all sites as it will never be linked with the same address. (I still use a different (predictable for me) password for banking/ecommerce websites)

Re: Why was my email leaked?

#244

Earlier quoted context omitted.

> "those people are forum moderators and not employees of Dropbox" They're official representatives of Dropbox, even if they are unpaid. Their behavior is entirely on Dropbox, and the fact that Dropbox has farmed out its customer support to unpaid amateurs is possibly a worse realization than the fact that the clueless person was not an employee.

Eh not really. They are community volunteers. The best part is that they can give free support in the forums without pay, and then when something esclates and they've done something wrong an actual employee can wash their hands of the situation (as they've done here) by stating they aren't actually employed by the company. So it's a win win for Dropbox. Free forum support for low level day to day forum chatter and ea…

Whether it's a win or loss for Dropbox depends on the public's reaction to it. I'm totally with potatolicious here: It's a dropbox site, and these people have a special status (moderator) which I automatically assume is conferred upon them by Dropbox. So their behavior is "on" dropbox- whether dropbox wants it to be or not. Even if my assumption is wrong, it's still on Dropbox.

The only question is, are people going to hold them accountable or not (by finding other solutions). I don't use them (I do my own syncing) and this display warns me off of starting to use them any time in the near future.

Re: Why was my email leaked?

#245

I have to say, accusing Dropbox of leaking in the title of the thread, with out any actual basis, since it is possible that the user cocked up somewhere, is not the best way to get polite support. Yes the mods could have been a lot more professional, but I can see why their backs were up and why they would be defensive. On the other hand, too often as a user I feel I have to walk on egg shells to avoid upsetting some…

All of which leads me to think there should be some third party arbitration for this sort of thing.

There are companies that do this - in the US, we have the Better Business Bureau (BBB) and they handle this sort of thing for offline companies. The problem with this approach is one of cost - if I want my company to appear "In Good Standing" with the BBB, I have to pay $800 per year regardless of whether anyone files a complaint or praise with my company. Ouch. Good luck getting that to work on the web.

Re: Why was my email leaked?

#246

Earlier quoted context omitted.

The victim-blaming was shocking to me here. The bit where Andy Y. says, "Oh, some spammer just guessed it" was funny. As if spammers needed to do dictionary attacks against the sort of tagged addresses that 0.1% of people use. But it became hilarious when he said the same thing to the guy who uses 10-random-character tags. As if they would hit upon two different Dropbox addresses like that before the sun cooled to a…

"The original complainant is much more patient than I am. If that's what I'd gotten as "support" on a paid service when reporting a security breach, I would have closed my account and told them to get fucked." I agree with the end part of your response, but it's unknown if Forrest is a paid customer.

Even a non-paying customer does not deserve to get treated like that when a security issue is involved.

Re: Why was my email leaked?

#247

Earlier quoted context omitted.

Yes, your affiliation is quite relevant. When you are talking about something when you have a clear conflict of interest, you need to disclose it. Then at least the reader has the right context in which to make a decision. When you post w/o disclosing, you make it seem like someone from this community has found your product interesting and is suggesting others try it. Instead of working for a company and trying to dr…

tl;dr: read http://hastebin.com/raw/gefuxumubu "your affiliation is quite relevant. When you are talking about something when you have a clear conflict of interest, you need to disclose it. Then at least the reader has the right context in which to make a decision." I used to think the way you do. Then I entered the financial world. At this point, I've seen so many people talk up their positions without disclosing th…

I've never seen someone use tldr; to send someone to a different link :)

My response is that it is all about context and community norms. Here, on HN, the norm is that if you're going to bash someone, and you work for a competitor, you disclose that. If you can't pass that small ethical hurdle, there are other companies I can send my money to. (Not to mention, That I consider it uncouth to bash a competitor like that)

In the financial world, things are probably different and you just assume some level of conflict from the beginning. And that's fine, so long as everyone knows the ground rules.

I've actually looked into Tonido a couple of times, so I already knew what the service was. I have a friend who was all ready to buy one of their plugs for their lab when their university got hooked up with Box.net (I think).I probably wouldn't have thought to question them had a) I not already known what Tonido was and b) they had already been downvoted, so I wasn't the only o e to put it together. For some reason, I always had reservations about it, and so this just cemented an already held feeling.

But, you are quite right that different communities have different norms.

Re: Why was my email leaked?

#248
post #229

Earlier quoted context omitted.

Yep. I know for a fact they do. Yahoo! Plus has a much better system where you use a different base email address plus the sub-address rather than your regular address. For example, if my account is "somebody@gmail.com" then you use somebody+dropbox@gmail.com. But with yahoo, you pick an alternate, e.g. "huggybear", and use that instead (huggybear-dropbox@yahoo.com). That way if a spammer seems the sub-addressed acco…

That's perfect, I wish you could do something like this in gmail without specifically creating a new account for every alias.

I should clarify: with Yahoo plus you only create one base for all your sub-addresses, not a new base for every sub-address.

So in my earlier example, if you wanted to sub-address ebay, amazon and hackernews you'd have huggybear-ebay@, huggybear-amazon@ and huggybear-hn@.

The big deal is that huggybear@ != someone@ and sending to huggybear@ won't reach someone@ and likely earns you a place on their blacklist (or some points towards ending up there).

Re: Why was my email leaked?

#249
post #86
post #24

Earlier quoted context omitted.

Because the point number 1 on their Privacy and Security Policy is "Your Privacy is not for sale" : https://www.mint.com/how-it-works/security/policy/ The way it is worded, it seems like your e-mail may be used by Intuit for promotion or by third-parties bound by the same privacy policies, but certainly not sold for spam.

> [...] it seems like your e-mail may be used by Intuit for promotion or by third-parties bound by the same privacy policies, but certainly not sold for spam Same difference in my book. If you are not the original entity that I supplied my address to, and I get email from some 3rd party, that's SPAM. Sure, you could argue that it's in the T&C and that I "agreed" to it, but it's still SPAM the way I see it. And since…

For me there is a clear different between "Hey! You use Mint, we thought you'd like [finance product X] Try it free!" and "Your paypal account has been compromised, log here to reset your password : www.paypalscam.com/reset"

Re: Why was my email leaked?

#250
This post in the forum thread may be on to something:

"I also have a unique dropbox email address, it was compromised on 2/6, but I tracked it down to a friends system that was hacked. I had shared a dropbox folder with them, they got the email from my dropbox address. Virus on their system collected my dropbox email from their system."

Post reply on HN