I had my email stolen in such an attack, i still get random "you abandoned your cart!" Emails now and then, but luckily (?) they got my credit card at the same time and i cancelled it within minutes. So it's a little annoyance, but it doesn't really make sense to me that the flood works. At least not with American credit cards that are routinely flagging my own trips to microcenter lol Editing to add: almost 100% of…
was it ccsend.com?
Subscription bombing and how to mitigate it
191–199 of 199 posts
Re: Subscription bombing and how to mitigate it
#192Earlier quoted context omitted.
Ouch. Just one credit card change per account? This is one of those levels of monitoring that only gets put in place after such an event. Eg whole subsystem analysis - the change card feature being used 1000s of times (well, proportional to scale) in 7 hours is a massive red flag
> This is one of those levels of monitoring that only gets put in place after such an event. For a website, yes. But honestly the credit card people and their infrastructure should probably _also_ watch out for this. They'd be in a much better place to detect these.
Re: Subscription bombing and how to mitigate it
#193> If a bot creates an account with someone else’s email, the victim gets one email, if they ignore it that’s the end of it. The welcome email and everything after it only fires once the user verifies. As a user, I would prefer no welcome email at all.
What I find annoying is services that only send the welcome email once, and don't let you resend it if you never receive it.
Re: Subscription bombing and how to mitigate it
#194Re: Subscription bombing and how to mitigate it
#195Earlier quoted context omitted.
Nothing with email can ever be an easy fix, although the idea is amusing. It is inherently the problem.
'Inherent' has an absoluteness, which I disproved. Relying on email, is inherently troublesome, I agree. But as I said, it's not about what's technically, or ethically mandated, but what's ensuring users won't get annoyed (getting bombed with mails is bad PR). Companies collect all these IDs for their (future) shareholders first and foremost. Asking for email doesn't alert people. Phone number would be more alarming,…
Re: Subscription bombing and how to mitigate it
#196Earlier quoted context omitted.
'Inherent' has an absoluteness, which I disproved. Relying on email, is inherently troublesome, I agree. But as I said, it's not about what's technically, or ethically mandated, but what's ensuring users won't get annoyed (getting bombed with mails is bad PR). Companies collect all these IDs for their (future) shareholders first and foremost. Asking for email doesn't alert people. Phone number would be more alarming,…
Cloudflare has a stranglehold on the internet, but its marketshare is much lower than the incumbant email giants. Aprroximately 70-90% of all email goes through Google & Microsoft. You're trading one benevolant toll keeper for another... except those two give you no recourse should you end up on a sh*tlist or don't meet their unspecified and forever changing criteria for being a recognised mail provider.
Re: Subscription bombing and how to mitigate it
#197Re: Subscription bombing and how to mitigate it
#198Recently we suffered a different kind of subscription bombing: a hacker using our 'change credit card' form to 'clean' a list of thousands credit cards to see which ones would go through and approve transactions. He ran the attack from midnight to 7AM, so there were no humans watching. IPs were rotated on every single request, so no rate limiter caught it. We had Cloudflare Turnstile installed in both the sign up for…
Well, what you can do is notify the card issuer about those cards that went through, so they can mark them as stolen. That surely will make the hacker really happy, and discourage them of doing it again :)
Re: Subscription bombing and how to mitigate it
#199Earlier quoted context omitted.
was it ccsend.com?
I actually have no idea. I looked up one of the emails in my trash and it doesn't have any "built with" kind of thing or anything. So I can't actually tell what platform they're using, but they're definitely all the same. Here's one of the retailers in question https://utopiagoods.com/