Live data from Hacker News

The dots do matter: how to scam a Gmail user

jameshfisher.com

401–410 of 518 posts

Re: The dots do matter: how to scam a Gmail user

#401
> The dots do matter: how to scam a Gmail user

The dots do not matter, this does not enable a scam, and 99% of people replying to this seem to have utterly missed the point.

First off, let's be clear: The story is about someone who entered the wrong email. They should have entered "eve@foo.com" but actually entered (or later changed it to) "james@foo.com", which means that James got some emails from Netflix about Eve's account, incorrectly assumed they were about his account, reset the password on Eve's account, and came close to entering payment information into it.

All of which is fine; this is how email works, and how modern services (correctly) use email: By identifying an account with an email address, and assuming that if you have control of the email address you should have control of the associated accounts.

The author is weirdly focused on the fact that gmail allows some flexibility in how the local part of the address is interpreted, but this is a feature of most email providers (yahoo, outlook.com, protonmail, and fastmail all do it), and is a feature offered by qmail, courier, and postix as well. It's also explicitly required by the relevant RFCs. And...

...it's utterly unrelated to the issue at hand. This isn't about how the local part is interpreted; it's about someone typing the wrong address that they don't control when they sign up for an account. Sub-addressing and the details of how some random mail server normalises the local part is not what this is about. If gmail bounces all emails with "incorrect" periods, it might have stopped this particular incident, but it doesn't solve the issue which is about people giving out your address instead of their own when creating an account, which is the actual issue here.

Further, the proposed scam, if it works, only works because (allegedly) Netflix lets you change an account email without verifying that you know the current password. This violates every tenant of account security; because email is used to prove you control an account (allowing, eg, password resets), changing the email obviously requires you to prove you control the account. You have to ask for the password! I rather suspect Netflix does, but if not, this is the core issue.

Re: The dots do matter: how to scam a Gmail user

#402
post #345

Earlier quoted context omitted.

Not true, domain part is case insensitive by the standard. Server can decide for non-standard behavior, but that would be foolish.

The name part, per the standard, is case sensitive. However, some organizations I get email from canonicalize it to all caps - and one even removes the dots(!) and all-cap it, which for my gmail I have a filter that sends all non-dotted email to spam, since 90% of my spam is non-dotted. Since that particular email was important and I'd just happened to notice it in spam, I checked the capitalization change and called…

Changing case could be a co's lazy way of checking for existing accounts. In a perfect world they would store the input as-is and also use a lower or upper func on the indexed col. I suppose if they are verifying emails with their users and not seeing a big drop-off in verified accounts, they probably don't care to be too exact. Removing dots from the user portion is pretty shitty though.

Re: The dots do matter: how to scam a Gmail user

#403
post #290

Earlier quoted context omitted.

Not only that, but apparently he was able to change Eve's account details without having to enter a password. If instead Netflix had prompted him before allowing him to change the credit card, it would not have worked, because he wouldn't have known Eve's password and Eve wouldn't have known his. All around very bad security design on Netflix's part.

I think this is the bingo. The scam doesn't work if you don't treat "access to email" as the sole authentication mechanism.

This gives the excuse for companies to request phone numbers. What if I don't have a phone (I am frequently without mobile phone access due to some personal circumstances recently, and it's a massive butt pain).

Re: The dots do matter: how to scam a Gmail user

#404

Totally disagree with the conclusion. This is Netflix's issue for not validating the email account. Not sure if Uber has changed this since then, but back in the day I used to get the full ride details and receipts from someone else who mistyped their email. If you are sending private transactional emails you need to verify accounts first.

Still... I get so many other people's email because of this dot's don't matter feature it's very frustrating!

For example I'm regularly cc'd on a list of a South African film production company.

I often get invites to parties from a group of students in Georgia.

And, someone seems to use a dot alternative of my name to buy sex toys! And that is just a few!

I used to send back the emails saying "Hey you go the wrong person" until I realized it has no effect on these types of group emails.

Re: The dots do matter: how to scam a Gmail user

#405

Earlier quoted context omitted.

> the web form shouldn't indicate anything out of the ordinary How will the user know that the registration failed and what to do about it?

Upon entering a valid email (whether it is already registered or not) the form will show the following notification "an email was sent to user@email.com with the sign up instructions, please follow the link in the email to continue the registration" (rewrite for more concise message) If the user already exists the email will be a warning + a link to the password reset form If the user does not exist, the email will b…

Why is it bad to know if an email is already registered?

Re: The dots do matter: how to scam a Gmail user

#406
post #321

Totally disagree with the conclusion. This is Netflix's issue for not validating the email account. Not sure if Uber has changed this since then, but back in the day I used to get the full ride details and receipts from someone else who mistyped their email. If you are sending private transactional emails you need to verify accounts first.

Absolutely - his proposed solution - disabling the dots-dont-matter feature and retiring them does nothing to stop this exact same attack vector instead employing the '+' feature that he admires and wishes to retain. The attack goes like this: * Hammer the Netflix signup form until you find a gmail.com address which is “already registered”. Let’s say you find the victim jameshfisher. * Eve creates a Netflix account w…

The difference is that the dot behavior is non-standard, the plus behavior is standard.

Re: The dots do matter: how to scam a Gmail user

#407

Earlier quoted context omitted.

And, it's still finite, right? Just a large, finite number :P

No? You can put whatever string you want there, of which there are an infinite number…

The poster already explained that no, you can only write up to 64 characters which is not "infinite"

Re: The dots do matter: how to scam a Gmail user

#408

Earlier quoted context omitted.

No? You can put whatever string you want there, of which there are an infinite number…

The poster already explained that no, you can only write up to 64 characters which is not "infinite"

Ah, I didn't catch that.

Re: The dots do matter: how to scam a Gmail user

#409
post #86

Earlier quoted context omitted.

The standard email verification patterns rely on the user clicking a link. I am not sure how that would have helped here. Making users retype the email (instead of merely click on a link) might be better for exposing scams but requires more work on the user’s part.

Ultimately the bug relies on how believable the emails from Netflix are. If I got an email from Netflix asking me to update card details, I wouldn’t be surprised because maybe my card expired. But if I got an email asking to verify my new account, I would be very surprised. I didn’t sign up for a new Netflix account. If after that, I got an email to update my card details, I would be alarmed because of the recent une…

Maybe some middle road:

+ Netflix can send an email about optionally(!) confirming a user's address.

+ Now, rather than disabling all features and slowing down on-boarding it is possible to update the communication towards unregistered users.

+ If an email has to be sent to an unconfirmed address, preceed it with a warning. If pietjepuk@gmail.com has been confirmed, but pietje.puk@gmail.com not, emails for the latter will have this warning automatically.

+ Remaining option: do you want to send regular safety requests to unconfirmed addresses as provider? Policy might differ. However, it is possible to use this email to tell the user about safety/security w.r.t. your system. I'd say yes.

Re: The dots do matter: how to scam a Gmail user

#410
Can't understand people who are trying to place blame on a single service. IMO Gmail has to make those addresses disabled by default. I doubt that most mistypes come from dots, so it is useless to handle mistypes. So it is only useful to have those multiple email address to use them in different places. Then why enable them by default? You can still own them but they can be disabled until you need them. As for Netflix it is obvious that emails have to be verified before any usage begins.
Post reply on HN