Live data from Hacker News

The dots do matter: how to scam a Gmail user

jameshfisher.com

261–270 of 518 posts

Re: The dots do matter: how to scam a Gmail user

#261
post #140
post #110

Earlier quoted context omitted.

I see a lot of claims that email addresses should be verified prior to a transactional email being delivered - that that’s the “norm” or stupidly obvious way. But when there is a real consequence on a conversion funnel for requiring email address verification (say ecommerce), I imagine the obvious business decision is to do the exact opposite.

What's the point of a conversion funnel that creates exactly one conversion and then a huge amount of customer grief when they can never use the account again? If the email address matters then validate it, if it doesn't need to be validated then don't ask for it.

I don’t understand what you mean by a “CF that creates exactly one conversion”.

Anyways, your response isn’t relevant in that I’m not suggesting an email address should (not) be verified. Rather, we’re discussing whether verifying identity needs to come before or after (or alongside) the transactional email - e.g. a receipt of purchase.

At the same time, validation and verification are not the same thing - and sometimes it’s not necessary to perform address/identity verification.

Re: The dots do matter: how to scam a Gmail user

#262
post #12

Interestingly Gmail will let you filter in a dot sensitive way. Anyone missing my dot gets sent to a folder called “wrongguy”. Whenever I drop by to look at it it’s full of spam.

That works for the usual, accidental missing-dot case. Won't work for phishing that injects a '.' in some other position.

Re: The dots do matter: how to scam a Gmail user

#263

> but I also have access to the account because I own james.hfisher@gmail.com, and so I can follow the password reset process for this account. I did so. I wonder if others feel that it is ethical or unethical to log into other people's accounts in this situation. I get lots of emails resulting from people typo'ing my email address instead of theirs—and the unsubscribe links are often hidden behind a login page. But…

(I get a ton of misdirected email because I have a six character gmail address with a common name.)

My rule is that I'm willing to "steal" the account and cancel it or change the email for "unimportant" services, like dating sites. For financial institutions, I contact the institution instead. (My email has gotten associated with at least two bank accounts that aren't mine.)

Re: The dots do matter: how to scam a Gmail user

#265

Totally disagree with the conclusion. This is Netflix's issue for not validating the email account. Not sure if Uber has changed this since then, but back in the day I used to get the full ride details and receipts from someone else who mistyped their email. If you are sending private transactional emails you need to verify accounts first.

I have the same problem with Netflix, Uber and other sites. They simply do not check the email. It's an absurd. And the biggest problem is that the person who mistakenly uses my email asks a hundred times to reset MY password. Gmail and these sites need to take this issue more seriously.

Re: The dots do matter: how to scam a Gmail user

#266

Earlier quoted context omitted.

I think these are orthogonal issues. The dots do matter, but Netflix should also validate email addresses. However, I don't think it's as critical. Lack of email validation means I receive someone else's ride details (I agree, annoying), but dots-don't-matter means I might accidentally pay for that person's rides.

Thinking about this a bit more, I believe that there is another problem with how account creation is done. In general we do it in two steps: 1. User detail and password 2. E-mail confirmation Instead, if we did 1. User details but NOT password 2. E-mail confirmation and subsequently entering the password on the page that was sent via e-mail. Actually, I think the most optimal would be 1. Enter e-mail address only 2.…

Typically when I implement user self-registration for my portal-website clients, I use a variation of your third option:

1. Enter email address and some out-of-band information that only an existing-account-holder should know. Eg: a web portal for a utility company could ask for the account number and amount due from a recent bill.

2. Send confirmation email with a code/link.

3. After user enters a valid code, continue registration by gathering additional user details, password, and (usually) recovery Q&A.

The user account is not created until step 3; if they provide a fake email, it's as if the registration attempt never occurred. Absolutely no access is granted until after the final step.

The extra details in step #1 only works for website registration of a user that has a pre-existing relationship with the company, of course. For a new account, email address is all you should request at that point.

Re: The dots do matter: how to scam a Gmail user

#267

> but I also have access to the account because I own james.hfisher@gmail.com, and so I can follow the password reset process for this account. I did so. I wonder if others feel that it is ethical or unethical to log into other people's accounts in this situation. I get lots of emails resulting from people typo'ing my email address instead of theirs—and the unsubscribe links are often hidden behind a login page. But…

The law isn't on your side if you log into a litigious person's account without their permission.

Re: The dots do matter: how to scam a Gmail user

#268

Totally disagree with the conclusion. This is Netflix's issue for not validating the email account. Not sure if Uber has changed this since then, but back in the day I used to get the full ride details and receipts from someone else who mistyped their email. If you are sending private transactional emails you need to verify accounts first.

Absolutely. Netflix is using ID created by some other service as their ID without verifying with the other service if the ID in question belongs to the user who is claiming it's theirs. There needs to be a 2nd factor to confirm whether an ID belongs to someone - password/confirmation/code/pin which Netflix doesn't use here at all.

Re: The dots do matter: how to scam a Gmail user

#269
post #104

I have multiple "e-mail doppelgangers" - confused people who don't know their own email address and so accidentally use my address when they register stuff. One's in Chile. I have almost no knowledge of Spanish. The other is in California. Having experienced this: Services need to email new email accounts they become aware of ASAP. They have literally zero UI available to me to notify them that this is an invalid ema…

Same with me, I have someone who is in the US (I'm in the UK) who has registered for a university and attempted to buy a car using my email address.

They must be fairly disorganised as I keep getting emails about overdue library fees. No matter how many times I email these places, they never remove the email from their system. I'm hoping GDPR might give me a hand with that, though I'm doubtful if they're places like a US University.

Email validation is a must for all services, people make mistakes and clearly some people don't even know their own email address. This is a problem with both Google and Netflix. Netflix are being negligent and Google should retire this feature.

Post reply on HN