Live data from Hacker News

The dots do matter: how to scam a Gmail user

jameshfisher.com

161–170 of 518 posts

Re: The dots do matter: how to scam a Gmail user

#161
post #103
post #43

Earlier quoted context omitted.

> Some would say that Netflix should verify the email address on sign up, but there's no obvious attack that this mitigates. Someone could carry out this exact attack but without dots. The attacker creates an account, associates it with your email, and hopes you put your credit card info into the account. How come the attacker didn't "[cede] account control to [you]" when the attacker put your email into the attacker…

They couldn't carry out the same attack without the dots, because the attack relies on the target mistaking the attacker's Netflix account for their own account. If you get a Netflix email when you've never signed up using that email account then it's obviously not for you.

I have ~1000 online accounts. I can't remember every site that I've signed up for or not, and whether or not they've been deleted.

Many websites allow multiple accounts to have the same email address.

Re: The dots do matter: how to scam a Gmail user

#162
I get emails to my gmail account for some elderly person who lives in NYC about him not seeing his doctor all of the time. He has my same email address with a dot between his first and last name. I used to reply to the emails saying they had the wrong person, but now I just auto delete them.

Re: The dots do matter: how to scam a Gmail user

#163
post #100
post #67

Earlier quoted context omitted.

They do. The author reset the password to gain access.

But then if the password is reset, the original scammer has no access to the account! And the scammer cannot reset the password because they do not have access to the email.

This is true if changing the password s you to re-enter the password on every device (even those that were logged in at the time)

Re: The dots do matter: how to scam a Gmail user

#164
post #114

Earlier quoted context omitted.

A similar problem exists for weird services like Amazon that allow multiple accounts for the same email address (unless they finally fixed that stupid idea?).

Multiple accounts with the same email haven't been available for many, many years. I'm not sure exactly when registration for these was disabled, but it was 10+ years ago. Possibly 15-20 years ago. I think it was a valid design decision at the time, before accounts on websites were widespread and a family might only have a single email address from their ISP. The rise of free webmail accounts from Hotmail etc changed…

Good to know. I had accidentally created multiple accounts for myself around '05 or so and was really surprised by it. Iirc back then they also required separate accounts per-country, but I could be wrong about that.

Re: The dots do matter: how to scam a Gmail user

#165
It's a Netflix issue. They let people register email addresses which they haven't proved to be in possession of.

Takeaway for developers: no email should be sent to unverified addresses, except the verification emails. An "I didn't register for this" link is also a must have in these letters.

Re: The dots do matter: how to scam a Gmail user

#166
post #57

Totally disagree with the conclusion. This is Netflix's issue for not validating the email account. Not sure if Uber has changed this since then, but back in the day I used to get the full ride details and receipts from someone else who mistyped their email. If you are sending private transactional emails you need to verify accounts first.

Why can't it be both sides' issue? I have a fairly uncommon first and last name, but I still get emails from the few folk who share my name combination, and I too have gotten sensitive information that I shouldn't have. I cannot imagine the strangeness that must occur for folks with more common name combinations, and the idea that e.mail@gmail.com is the same as email@gmail.com just seems wrong to me. As far as I kno…

> Why can't it be both sides' issue?

Even if Google didn't provide this feature to their users (and it is a feature that I regularly use to track who leaks my email address and then auto block emails to that address), Netflix's approach of sending sensitive emails without verifying the email address is still prone to security problems. Many people have multiple email accounts, or aren't really aware which email account they used to sign up. Sending a "please update your billing info" without verifying the email account first is purely on Netflix.

Re: The dots do matter: how to scam a Gmail user

#167
post #126

Earlier quoted context omitted.

I have this problem a lot as well. There was someone with my name with a Bank of America account that regularly bounced checks, and BoA provided no way to disassociate my email address from the account. These days I'll flag any email from a service as spam, no matter how well known, if there was no email verification step.

Yup. I had some guy's credit card bills appearing. It was actually super weird - somehow Google had metadata about the credit card bill that was not in the body of the email, so I'd get "reminders" on Google Now saying "pay $1200 to Notyourbank by the 1st of Octember", but I couldn't actually see that bill without logging in (which, obviously, I could not and did not try to).

Btw that meta data I believe it's in the body of the email. Hidden with some html tags that Google tells companies to use so they can do those things. Inspect the source of the html of the body and see if you can find it there.

Re: The dots do matter: how to scam a Gmail user

#168

Earlier quoted context omitted.

I think these are orthogonal issues. The dots do matter, but Netflix should also validate email addresses. However, I don't think it's as critical. Lack of email validation means I receive someone else's ride details (I agree, annoying), but dots-don't-matter means I might accidentally pay for that person's rides.

Thinking about this a bit more, I believe that there is another problem with how account creation is done. In general we do it in two steps: 1. User detail and password 2. E-mail confirmation Instead, if we did 1. User details but NOT password 2. E-mail confirmation and subsequently entering the password on the page that was sent via e-mail. Actually, I think the most optimal would be 1. Enter e-mail address only 2.…

Second solution seems pretty optimal for security but not sure if users up for that.

Re: The dots do matter: how to scam a Gmail user

#169
I don't see the scam here. If you have to go through password reset to get into the account and update the CC number, then the would be scammer does not have access to that account anymore (assuming Netflix logs you out of other devices when you change your password).

Sure, you end up paying for an account you don't use, but nobody gains from that (other than netflix). It certainly is an issue that can easily be fixed by netflix validating email addresses, but I don't see any incentive for scammers abusing it.

Re: The dots do matter: how to scam a Gmail user

#170

100% disagree. My standard gmail address is with dots but when I have to tell my (rather long because it is my full three part name) I either omit the dots or tell them they don't matter. Totally an important and useful feature. Netflix is at fault for letting someone else use your email without asking you for permission.

Why should netflix be required to adhere to the different ways that every email provider doesn't adhere to the spec?

Because it's Netflix not adhering to the spec, which states that local addresses are to be interpreted by the host only. Netflix has no business caring about how Gmail interprets its local parts.
Post reply on HN