Live data from Hacker News

Not OK Cupid – A story of poor email address validation

fastmail.com

101–110 of 123 posts

Re: Not OK Cupid – A story of poor email address validation

#101
post #15

Problem is, if you implement strict email verification, you lose users. Because that step of "please open your email and verify" is actually a big drop-off point in the funnel. No amount of "shaming" people over lax email validation is going to convince them to implement a change that loses them money . Don't get me wrong, I hate it too. Every single day I have to block about a dozen new sender addresses for services…

Problem with email in general is that very people people are incentivized to think of the long-term impact of spam.

Re: Not OK Cupid – A story of poor email address validation

#102
post #51

Earlier quoted context omitted.

Related stupidity: "Security Questions" that enable someone to take over your account just by collecting not-so-secret information that is often shared because the site insists you pick from their own set of questions which other sites have already used.

The problem becomes when a CS rep needs you to answer those questions on the phone. How do you handle that?

Not parent poster, but generating a sequence of randomized dictionary words will work provided the answer-field isn't too small and none of them are too hard to spell.

Re: Not OK Cupid – A story of poor email address validation

#103
post #27

Earlier quoted context omitted.

It probably started when they sold to The Match Group a while back. I used it a little back in 2014, and again in 2021. The second time around, it was very different. I don't know of any dating companies that focus on matching people versus optimizing for revenue.

Unfortunately most consumers are unwilling to pay what something is worth to them. Businesses are often the same so it isn't just consumer behaviour. Meeting the right person should be worth a lot, and we should be happy to pay thousands for that. Of course the profit depends on the user statistics too: I'm not sure what the economic term for profit thresholds for power law masses versus targeting - where say lots of…

It's because we loosely understand that value based pricing is a scam.

An insulin shot at the right moment can be of unlimited value to the consumer. SaaS salesmen try to capture the entire value add a tool gives a user, but this seems to kill companies as the price a competitor can undercut by is huge (so much that the original price seems exploitative).

Basically any marketing based on the "value to me" I'm sceptical of.

An approach with transparency, that shows "this is what delivering an actually good product costs", might be possible...

Re: Not OK Cupid – A story of poor email address validation

#104
post #83
post #78

Earlier quoted context omitted.

What gives you the confidence to say that it was a single individual and not just a common email name which lots of people accidentally used?

> What gives you the confidence to say that it was a single individual Because you can see their first name and last name on the emails you receive.

And addresses, I even knew when he was sending his mistress nicer flowers than his wife.

I get other people’s email too, just this guy has been more prolific than others.

Re: Not OK Cupid – A story of poor email address validation

#105
post #64

Earlier quoted context omitted.

If you're in the US, I've had success by contacting customer service and threatening action under CAN-SPAM. The FTC has never really provided an easy way to file complaints or request enforcement by the public, but it seems to get their attention all the same. Now is a good time to try to exercise your legal rights against corporations before they are all executive order'ed away.

The FTC has had a place for the public to report CAN-SPAM violations for some time at https://reportfraud.ftc.gov The FAQ confirms this is the correct place to report email spam https://reportfraud.ftc.gov/faq

I missed that FAQ item, thanks. I've seen (and used) the "report fraud" page before, and I had seen something to suggest that it was the right place to report illegal spam, but it wasn't clear how "spam" and "fraud" were related.

Re: Not OK Cupid – A story of poor email address validation

#106

Earlier quoted context omitted.

If you're in the US, I've had success by contacting customer service and threatening action under CAN-SPAM. The FTC has never really provided an easy way to file complaints or request enforcement by the public, but it seems to get their attention all the same. Now is a good time to try to exercise your legal rights against corporations before they are all executive order'ed away.

What action were you threatening? When I looked into it, it seemed like only state Attorneys General could sue violators.

I just said something like "If you don't remove me from the list within 24 hours I will report this to the FTC as a violation of US federal law." That's the easy part, the hard part is actually getting through to someone.

Re: Not OK Cupid – A story of poor email address validation

#107
post #96

Ugh. Then there's the general stupidity of forcing people to use E-mail addresses as user IDs. It's not just annoying, but also a security blunder. The general public can't be counted on to understand that when they're forced to use their E-mail address as an ID, they don't have to use their E-mail account's password for it. That makes every one of these sites a gatekeeper to the user's E-mail account. All it takes i…

Another problem with email address as user ID is that much of the public (most I'd guess) does not have a permanent email address. Many use an email address provided by their ISP. What happens when they move out of that ISP's territory? Or, if they are someplace served by multiple decent ISPs decide to switch providers? Many use addresses from gmail, outlook, yahoo, and similar. Those at least keep working if they mo…

"Another problem with email address as user ID is that much of the public (most I'd guess) does not have a permanent email address."

Exactly, which gave rise to the on-going multiple-Apple-IDs fiasco.

Re: Not OK Cupid – A story of poor email address validation

#108
post #51

Earlier quoted context omitted.

Related stupidity: "Security Questions" that enable someone to take over your account just by collecting not-so-secret information that is often shared because the site insists you pick from their own set of questions which other sites have already used.

The problem becomes when a CS rep needs you to answer those questions on the phone. How do you handle that?

This question reminds me of another brain-dead and rather incredible password policy I encountered. I was trying to set a password for United Healthcare. Their password requirements were shown, and I was complying with all of them. Yet it was failing over and over.

I finally called them to report the problem, and the first question out of the rep's mouth was, "Does your password contain swear words?"

I shit you not, UHC secretly audits your passwords for "swear words." Doing so is bad enough, but not mentioning it in the rules is doubly offensive for deliberately stealing users' time.

Re: Not OK Cupid – A story of poor email address validation

#109
post #21

Fastmail's masked emails are great! I honestly very rarely give out my "real" email. Usually when I sign up for something I create a masked email, or if I need an email on the spot I use a wildcard alias (xxxxxx@myalias.fastmail.com). Since most of my emails are random, it serves as an authentication additional factor.

I've been using simple vendor-specific aliases e.g. $VENDOR.$MyInitials@fastmail.com, or a shared spam bucket alias.

Can you remind us how fastmail's subdomains, and "masked emails" are an improvement?

Re: Not OK Cupid – A story of poor email address validation

#110
post #47

Earlier quoted context omitted.

I thought about doing something mildly nefarious with someone's PayPal account that they added my address to, but didn't want to chance legal problems. Instead I just logged into their account and removed my email address and logged out.

PayPal is certainly trickier. I felt more comfortable testing with buying Amazon Prime through an Amazon account, because it would be easy for them to refund. I assume I thought of trying to remove the email address! :) I sometimes forget they’re not necessarily the only identifiers, and some accounts let you use a mobile number instead. Probably there wasn’t a mobile on the profile. It would be nice if all accounts…

Email is probably important as a spam-prevention measure. Without the necessity of validating an email or a phone number, one can create am unlimited number of accounts.

One can of course create any number of emails from server/domain they own, but that requires more skill.

Post reply on HN