Live data from Hacker News

The dots do matter: how to scam a Gmail user

jameshfisher.com

491–500 of 518 posts

Re: The dots do matter: how to scam a Gmail user

#491
post #395
post #320

Earlier quoted context omitted.

If I send an email to John@company.com instead of john@company.com and the server of company.com is configured to be case sensitive, then john will never see my email.

I see, so not relevant in the real world. Thanks!

Please don't be rude on HN.

https://news.ycombinator.com/newsguidelines.html

Re: The dots do matter: how to scam a Gmail user

#492
post #387
post #320

Earlier quoted context omitted.

If I send an email to John@company.com instead of john@company.com and the server of company.com is configured to be case sensitive, then john will never see my email.

It is allowed to matter per the rfc. However I believe 99% of all mail servers in the world are configured to make it non case sensitive.

>It is allowed to matter

And we don't know when it will matter and when it won't matter, therefore we have to assume that it does matter unless we are sure it doesn't for our specific case.

Re: The dots do matter: how to scam a Gmail user

#493

It's a user's problem. If user is willing to click through some unsolicited email and pay , he will probably click on the verification link too if the service would send those. It's still a statistics game. Not everyone would pay without verification and not everyone would click the big green button in the verification mail, but some people will without realizing what's up, just like people fall for Nigerian scams ma…

I believe there is a technical solution. The verification link should ask you for a password or a passcode of some sort which is provided to you out-of-band --- ie, not via email. For example the webpage where you sign up can give you a short 6 digit passcode for the purposes of validating your email. Then the link that you are sent via your email directs you to a form that asks you for the passcode. That way another…

That's pretty good. It would require some serious gullibility to defeat. If it's active attack, attacker may send the second mail with the passcode and instruct the user to enter it.

Though people are forwarding their second factor SMS confirmation codes for their banking accounts to attackers upon request, so it's not too far fetched someone would find a way to trick some users to enter it.

Here's one study about the phenomenon (the N is basically zero, but this happens and banks are warning people against doing this):

https://engineering.nyu.edu/files/VCFA_PasswordsCon15.pdf

Re: The dots do matter: how to scam a Gmail user

#494
post #491
post #395

Earlier quoted context omitted.

I see, so not relevant in the real world. Thanks!

Please don't be rude on HN. https://news.ycombinator.com/newsguidelines.html

I wasn't trying to be. I was mildly annoyed that this person was being needlessly pendantic about an irrelevant point that doesn't matter in any way whatsoever in the real world. They failed to give an example that matters.

Re: The dots do matter: how to scam a Gmail user

#495

Totally disagree with the conclusion. This is Netflix's issue for not validating the email account. Not sure if Uber has changed this since then, but back in the day I used to get the full ride details and receipts from someone else who mistyped their email. If you are sending private transactional emails you need to verify accounts first.

Still... I get so many other people's email because of this dot's don't matter feature it's very frustrating! For example I'm regularly cc'd on a list of a South African film production company. I often get invites to parties from a group of students in Georgia. And, someone seems to use a dot alternative of my name to buy sex toys! And that is just a few! I used to send back the emails saying "Hey you go the wrong p…

Not because dots don't matter. That's unrelated. It's because people don't know or lie about their own email address.

Re: The dots do matter: how to scam a Gmail user

#496

Totally disagree with the conclusion. This is Netflix's issue for not validating the email account. Not sure if Uber has changed this since then, but back in the day I used to get the full ride details and receipts from someone else who mistyped their email. If you are sending private transactional emails you need to verify accounts first.

Yep, but it's still a misfeature. I set up a firstname.lastname account for someone. On other services (e.g. iTunes) they've used that combo with and without dots. It's a nightmare trying to help them with password resets. They're not an internet-savvy individual.

Gmail can't cure stupid.

Re: The dots do matter: how to scam a Gmail user

#497

Totally disagree with the conclusion. This is Netflix's issue for not validating the email account. Not sure if Uber has changed this since then, but back in the day I used to get the full ride details and receipts from someone else who mistyped their email. If you are sending private transactional emails you need to verify accounts first.

Agree, this said the "dot don't matter" is also an awful thing. I'd rather have gmail create a real alias system instead of this hack. That's the thing that is good with Yahoo.mail, it has real alias system.

Why is it awful?

Re: The dots do matter: how to scam a Gmail user

#498
post #457

Earlier quoted context omitted.

Not really. There are two Netflix accounts, and both recovery emails are directed to James’s Gmail account. The scam is operating on the chance that James does not realize that it is someone else's Netflix account and goes ahead to add funds to it. The other person then logs in before James realizes his mistake and changes the recovery email to something else.

> The scam is operating on the chance that James does not realize that it is someone else's Netflix account and goes ahead to add funds to it. Right, but keep in mind that he's already changed the password. > The other person then logs in How? They don't know the new password. The timing doesn't seem to work; James can't add funds without resetting the password, and Eve can't hijack it without knowing the new passwor…

The perp can regain access to the account by using alternative forms of account recovery in the account management settings, which the user would unlikely notice if he doesn't suspect anything amiss. e.g. an SMS password reset link sent to a phone number the perpetrator controls, or a secondary email address.

Re: The dots do matter: how to scam a Gmail user

#499

Totally disagree with the conclusion. This is Netflix's issue for not validating the email account. Not sure if Uber has changed this since then, but back in the day I used to get the full ride details and receipts from someone else who mistyped their email. If you are sending private transactional emails you need to verify accounts first.

That was exactly my reaction after reading the first few paragraphs. “How did Eve circumvent the email verification step?”

Netflix should totally fix this, even my local public library asks for email verification after signing up.

Post reply on HN