Live data from Hacker News

Typing In an E-Mail Address, and Giving Up Your Friends’ as Well

nytimes.com

11–20 of 22 posts

Re: Typing In an E-Mail Address, and Giving Up Your Friends’ as Well

#11

I had to read this like 3 times to understand that users were voluntarily typing their email password into a site. It's so ingrained in my behavior not to do that, I was trying to figure out, "how do they get the password?"

Wait -- are they just using the password you type for their site to log in and go through your gmail account (guessing that they're the same pw)? That's fraud. I don't care if it's in the fine print. I use multiple passwords, but not enough. If websites just start using my passwords to break into my private data on other sites, that's seriously fucked up.

[deleted]

Re: Typing In an E-Mail Address, and Giving Up Your Friends’ as Well

#13

I'm confused, does it ask you to type in your email address and password for your email provider? I can't believe anybody would be stupid enough to fall for that. If it doesn't, where did it get all of his contact info? Did he enter it in himself. If this is the case, what does the website say that prompts you to enter in your contact lists?

Yeah, that was my question too. I think what happens is, when you enter your email address and password to login to the site, the site assumes its the same password you use to login to your mail provider. Of course, that assumption could be wrong but apparently, it works often enough. And of course, this only works with the big web mail providers like Google and Yahoo. I got a similar spate of emails from friends ask…

Not really, they aren't assuming you use the same password as your mail provider. These sorts of sites just ASK you outright for your login/password.. and a lot of users actually give this up voluntarily to a third party site.

Lots of information here on this sort of anti-pattern:

http://microformats.org/wiki/social-network-anti-patterns

Re: Typing In an E-Mail Address, and Giving Up Your Friends’ as Well

#14
post #5

Earlier quoted context omitted.

I work for a web dev firm, and one of the features a client wants is a facebook-style "invite your friends by giving us your e-mail and password" feature. I'm trying to think of a nice way of convincing the client that the feature they want is really a psychological bug that's going to cause long-term problems for, well, everyone on the internet.

Why not use bbauth? I know Yahoo and Google support it. That way you can grab their email contacts without requiring them to give you their email/password. It just sends them to the email provider to login, then back to your site with the api token to access their address book.

Still spams a buncha folks tho'.

Re: Typing In an E-Mail Address, and Giving Up Your Friends’ as Well

#15

I had to read this like 3 times to understand that users were voluntarily typing their email password into a site. It's so ingrained in my behavior not to do that, I was trying to figure out, "how do they get the password?"

Wait -- are they just using the password you type for their site to log in and go through your gmail account (guessing that they're the same pw)? That's fraud. I don't care if it's in the fine print. I use multiple passwords, but not enough. If websites just start using my passwords to break into my private data on other sites, that's seriously fucked up.

No, users explicitly enter their email password.

I blame this on user stupidity.

Re: Typing In an E-Mail Address, and Giving Up Your Friends’ as Well

#16

I'm confused, does it ask you to type in your email address and password for your email provider? I can't believe anybody would be stupid enough to fall for that. If it doesn't, where did it get all of his contact info? Did he enter it in himself. If this is the case, what does the website say that prompts you to enter in your contact lists?

yep, it asks for your email login and pw - pretty common; facebook and twitter also do this (or did). people would rather allow them unfettered access than manually set up friends/followers.

Re: Typing In an E-Mail Address, and Giving Up Your Friends’ as Well

#17
post #15

Earlier quoted context omitted.

Wait -- are they just using the password you type for their site to log in and go through your gmail account (guessing that they're the same pw)? That's fraud. I don't care if it's in the fine print. I use multiple passwords, but not enough. If websites just start using my passwords to break into my private data on other sites, that's seriously fucked up.

No, users explicitly enter their email password. I blame this on user stupidity.

I blame this on developer negligence.

Re: Typing In an E-Mail Address, and Giving Up Your Friends’ as Well

#19

I'm confused, does it ask you to type in your email address and password for your email provider? I can't believe anybody would be stupid enough to fall for that. If it doesn't, where did it get all of his contact info? Did he enter it in himself. If this is the case, what does the website say that prompts you to enter in your contact lists?

[quote] I can't believe anybody would be stupid enough to fall for that. [/quote]

It's not a question of belief; you've already got the proof.

Re: Typing In an E-Mail Address, and Giving Up Your Friends’ as Well

#20
First time I saw this happen was when my daughter signed up for doostang. All of us on her gmail address list got an invite, including some ex-boyfriends. She later sent an apology to the whole list. It was certainly a wake up call.

Software glitch, nah. Who are we kidding.

Post reply on HN