Live data from Hacker News

Subscription bombing and how to mitigate it

bytemash.net

191–199 of 199 posts

Re: Subscription bombing and how to mitigate it

#191

I had my email stolen in such an attack, i still get random "you abandoned your cart!" Emails now and then, but luckily (?) they got my credit card at the same time and i cancelled it within minutes. So it's a little annoyance, but it doesn't really make sense to me that the flood works. At least not with American credit cards that are routinely flagging my own trips to microcenter lol Editing to add: almost 100% of…

was it ccsend.com?

I actually have no idea. I looked up one of the emails in my trash and it doesn't have any "built with" kind of thing or anything. So I can't actually tell what platform they're using, but they're definitely all the same. Here's one of the retailers in question

https://utopiagoods.com/

Re: Subscription bombing and how to mitigate it

#192
post #77
post #46

Earlier quoted context omitted.

Ouch. Just one credit card change per account? This is one of those levels of monitoring that only gets put in place after such an event. Eg whole subsystem analysis - the change card feature being used 1000s of times (well, proportional to scale) in 7 hours is a massive red flag

> This is one of those levels of monitoring that only gets put in place after such an event. For a website, yes. But honestly the credit card people and their infrastructure should probably _also_ watch out for this. They'd be in a much better place to detect these.

They do, but they’re also just as aware that you could be the fraudster. So they put the punishment where it’s optimal for them. You are not inside their trust space.

Re: Subscription bombing and how to mitigate it

#193
post #3

> If a bot creates an account with someone else’s email, the victim gets one email, if they ignore it that’s the end of it. The welcome email and everything after it only fires once the user verifies. As a user, I would prefer no welcome email at all.

I don't mind getting a welcome email. It also tells me when somebody has attempted to sign up for a service using my email address.

What I find annoying is services that only send the welcome email once, and don't let you resend it if you never receive it.

Re: Subscription bombing and how to mitigate it

#195

Earlier quoted context omitted.

Nothing with email can ever be an easy fix, although the idea is amusing. It is inherently the problem.

'Inherent' has an absoluteness, which I disproved. Relying on email, is inherently troublesome, I agree. But as I said, it's not about what's technically, or ethically mandated, but what's ensuring users won't get annoyed (getting bombed with mails is bad PR). Companies collect all these IDs for their (future) shareholders first and foremost. Asking for email doesn't alert people. Phone number would be more alarming,…

Cloudflare has a stranglehold on the internet, but its marketshare is much lower than the incumbant email giants. Aprroximately 70-90% of all email goes through Google & Microsoft. You're trading one benevolant toll keeper for another... except those two give you no recourse should you end up on a sh*tlist or don't meet their unspecified and forever changing criteria for being a recognised mail provider.

Re: Subscription bombing and how to mitigate it

#196

Earlier quoted context omitted.

'Inherent' has an absoluteness, which I disproved. Relying on email, is inherently troublesome, I agree. But as I said, it's not about what's technically, or ethically mandated, but what's ensuring users won't get annoyed (getting bombed with mails is bad PR). Companies collect all these IDs for their (future) shareholders first and foremost. Asking for email doesn't alert people. Phone number would be more alarming,…

Cloudflare has a stranglehold on the internet, but its marketshare is much lower than the incumbant email giants. Aprroximately 70-90% of all email goes through Google & Microsoft. You're trading one benevolant toll keeper for another... except those two give you no recourse should you end up on a sh*tlist or don't meet their unspecified and forever changing criteria for being a recognised mail provider.

There is no trade tho.

Re: Subscription bombing and how to mitigate it

#198
post #27

Recently we suffered a different kind of subscription bombing: a hacker using our 'change credit card' form to 'clean' a list of thousands credit cards to see which ones would go through and approve transactions. He ran the attack from midnight to 7AM, so there were no humans watching. IPs were rotated on every single request, so no rate limiter caught it. We had Cloudflare Turnstile installed in both the sign up for…

Well, what you can do is notify the card issuer about those cards that went through, so they can mark them as stolen. That surely will make the hacker really happy, and discourage them of doing it again :)

Pretty sure this goes against PCI DDS requirements to not store CC numbers.

Re: Subscription bombing and how to mitigate it

#199

Earlier quoted context omitted.

was it ccsend.com?

I actually have no idea. I looked up one of the emails in my trash and it doesn't have any "built with" kind of thing or anything. So I can't actually tell what platform they're using, but they're definitely all the same. Here's one of the retailers in question https://utopiagoods.com/

For me the sender email addresses contain ccsend.com
Post reply on HN