Live data from Hacker News

Not OK Cupid – A story of poor email address validation

fastmail.com

111–120 of 123 posts

Re: Not OK Cupid – A story of poor email address validation

#111
post #56
post #51

Earlier quoted context omitted.

Related stupidity: "Security Questions" that enable someone to take over your account just by collecting not-so-secret information that is often shared because the site insists you pick from their own set of questions which other sites have already used.

The best way to tackle "Security Questions" is to generate a passphrase, store in your password manager, and use that for the answer. In the unlikely event you ever need to recover your account with the Security Answer, it's much easier to read out a few words than a 16+ character random password.

1Password actually has built-in support for that very flow: https://support.1password.com/generate-security-questions/#c...

The only thing is you sometimes have to warn the customer service agent that you have an unusual answer to "childhood best friend" but otherwise I've never had a problem with it

Re: Not OK Cupid – A story of poor email address validation

#112
post #21

Fastmail's masked emails are great! I honestly very rarely give out my "real" email. Usually when I sign up for something I create a masked email, or if I need an email on the spot I use a wildcard alias (xxxxxx@myalias.fastmail.com). Since most of my emails are random, it serves as an authentication additional factor.

I've been using simple vendor-specific aliases e.g. $VENDOR.$MyInitials@fastmail.com, or a shared spam bucket alias. Can you remind us how fastmail's subdomains, and "masked emails" are an improvement?

1. it allows associating a description with the address, which could contain any annotation information you'd like

2. it has a handy delete option, for severing the relationship

3. when they do arrive in the inbox, it shows the annotation instead of the address because no sane person could remember what battery.horse.staple@fastmail corresponds to

Re: Not OK Cupid – A story of poor email address validation

#114
post #56

Earlier quoted context omitted.

The best way to tackle "Security Questions" is to generate a passphrase, store in your password manager, and use that for the answer. In the unlikely event you ever need to recover your account with the Security Answer, it's much easier to read out a few words than a 16+ character random password.

1Password actually has built-in support for that very flow: https://support.1password.com/generate-security-questions/#c... The only thing is you sometimes have to warn the customer service agent that you have an unusual answer to "childhood best friend" but otherwise I've never had a problem with it

"Can you tell me the name of your favourite teacher... hmm..."

"Oh, it's a load of random letters and numbers, starts with X"

"Yes, let's proceed"

Happened to me once, I can't remember the company as it was many years ago.

Re: Not OK Cupid – A story of poor email address validation

#115
Someone with my identical full name has for the past few years kept providing my old and unused gmail email address to various entities.

This has included banks, shops, and a company which apparently offers training to help you acquire a gun license in Poland.

I now know where this person lives (from order confirmation emails). I know this person's date of birth. I also know this person's PESEL (Polish national identification number) because one of the banks "protected" a document intended for this person by using part of the PESEL as a password (I just brute-forced that part). The other part is just an encoding of the birth date.

So I now have enough information to impersonate someone just because a number of organisations screwed up by not verifying ownership of an email address.

Re: Not OK Cupid – A story of poor email address validation

#116

Earlier quoted context omitted.

1Password actually has built-in support for that very flow: https://support.1password.com/generate-security-questions/#c... The only thing is you sometimes have to warn the customer service agent that you have an unusual answer to "childhood best friend" but otherwise I've never had a problem with it

"Can you tell me the name of your favourite teacher... hmm..." "Oh, it's a load of random letters and numbers, starts with X" "Yes, let's proceed" Happened to me once, I can't remember the company as it was many years ago.

I don't mean to discount your experience, and I'm guessing the social engineering opportunities are unlimited no matter the protections, but the screenshot I provided shows that by default it uses words, not password-style, generation so your childhood best friend would be "couch tulip wheel" and not cafe8675309$

Re: Not OK Cupid – A story of poor email address validation

#117

Someone with my identical full name has for the past few years kept providing my old and unused gmail email address to various entities. This has included banks, shops, and a company which apparently offers training to help you acquire a gun license in Poland. I now know where this person lives (from order confirmation emails). I know this person's date of birth. I also know this person's PESEL (Polish national ident…

PESEL generally shouldn't be considered secret.

Re: Not OK Cupid – A story of poor email address validation

#118
post #56
post #51

Earlier quoted context omitted.

Related stupidity: "Security Questions" that enable someone to take over your account just by collecting not-so-secret information that is often shared because the site insists you pick from their own set of questions which other sites have already used.

The best way to tackle "Security Questions" is to generate a passphrase, store in your password manager, and use that for the answer. In the unlikely event you ever need to recover your account with the Security Answer, it's much easier to read out a few words than a 16+ character random password.

There's other good reasons not to use a random string! Try calling up customer service, they'll ask you the question, and you can say "oh it's just a bunch of random letters and numbers".

Unlike a code or password, these security questions are fuzzy matches generally based on the judgment of human on the other end.

Re: Not OK Cupid – A story of poor email address validation

#119

This was interesting until the end when it became an advert for fastmail.

On their corporate blog?! How could they sell out like that?

Despite your sarcasm, I don't disagree. Except for the fact I didn't click on this because it was their corporate blog. I clicked on it because it was on Hacker News.

And then once I realized it was their corporate blog, I became a bit more apprehensive.

Re: Not OK Cupid – A story of poor email address validation

#120
post #68

For those who are considering aliases to reduce spam in this. DO THIS TODAY. One of my aliases at the vendor Thermpro got compromised by them. I got list bombed pretty badly. Because it was an alias, I was able to turn it off. I got over 2k messages (Most of it "sign up for our mailinglist") within the first 12 hours. Reaching out to the vendor got nowhere. (Pretty sure they don't care that they were compromised)

Problem is most email provider web interface and mail agents don’t handle dealing with aliases correctly. For me I’ve found only Fastmail & mutt to be able to handle my 500 email aliases.
Post reply on HN