Live data from Hacker News

Not OK Cupid – A story of poor email address validation

fastmail.com

51–60 of 123 posts

Re: Not OK Cupid – A story of poor email address validation

#51

Ugh. Then there's the general stupidity of forcing people to use E-mail addresses as user IDs. It's not just annoying, but also a security blunder. The general public can't be counted on to understand that when they're forced to use their E-mail address as an ID, they don't have to use their E-mail account's password for it. That makes every one of these sites a gatekeeper to the user's E-mail account. All it takes i…

Related stupidity: "Security Questions" that enable someone to take over your account just by collecting not-so-secret information that is often shared because the site insists you pick from their own set of questions which other sites have already used.

Re: Not OK Cupid – A story of poor email address validation

#52
post #29

Companies that allowed others to create accounts with my email addresses: PayPal, Apple, Credit Karma, Walmart (I just forwarded the email to legal@ and they took care of that instance very quickly, kudos to that at least). Edit: Forgot to add TD Bank - I actually opened a case with the Office of the Comptroller of the Currency that regulates this bank. Companies that spammed me in the last 24 hours because they don'…

Someone signed up to Amazon with an email address of mine, and saved their credit card details. I couldn’t get any attention from Amazon, and just got generic responses telling me I could reset my password, etc. In the end, I signed up to Amazon prime, I think to test some reassurance they had given me - I wasn’t expecting it to work. The email saying I had just accidentally made a purchase with someone else’s credit…

You are probably technically violating the CFAA when you do this. Having your email address accidentally associated with the account isn't authorization.

Re: Not OK Cupid – A story of poor email address validation

#53

Companies that allowed others to create accounts with my email addresses: PayPal, Apple, Credit Karma, Walmart (I just forwarded the email to legal@ and they took care of that instance very quickly, kudos to that at least). Edit: Forgot to add TD Bank - I actually opened a case with the Office of the Comptroller of the Currency that regulates this bank. Companies that spammed me in the last 24 hours because they don'…

Ashley Madison is another, then they tried to change for delete.

Twitter is another back in the day, but that doesn't impact employment like Ashley Madison does due to the leaks.

Re: Not OK Cupid – A story of poor email address validation

#55

Companies that allowed others to create accounts with my email addresses: PayPal, Apple, Credit Karma, Walmart (I just forwarded the email to legal@ and they took care of that instance very quickly, kudos to that at least). Edit: Forgot to add TD Bank - I actually opened a case with the Office of the Comptroller of the Currency that regulates this bank. Companies that spammed me in the last 24 hours because they don'…

What email are you using that's so popular that dozens of people are (inadvertently?) entering it in all these businesses? Are you "john.smith@gmail.com" or something like that? I'm firstname@firstnamelastname.com, and I have had maybe a half dozen instances in the past decade.

I have lastname first initial @ gmail, and I wish I didn't. I have started using it for school related stuff for my kid, and other places where I want to present as normal, but mostly I get garbage from a set of about 4 people who share my last name and first initial, but don't know their email address (I don't know it either!).

Lots of car dealers and travel reservations. Ugh. I've got a couple job application responses, and usually get a nice email from the sender when I respond and let them know the email was misdirected.

I used to get a lot of mail directed to people whose organization's domain has an extra letter compared to mine, but I think they must have figured it out, or closed down, I used to add their mistaken addresses to be rejected if sent to and have to update when they got a new employee (their IT person sent me the new user stuff once sigh), but that stopped happening. I got some invoices for them that looked kind of shady, but they're in Brazil, and I can't navigate the system down there to have forwarded it to someone who would find it interesting.

Re: Not OK Cupid – A story of poor email address validation

#56
post #51

Ugh. Then there's the general stupidity of forcing people to use E-mail addresses as user IDs. It's not just annoying, but also a security blunder. The general public can't be counted on to understand that when they're forced to use their E-mail address as an ID, they don't have to use their E-mail account's password for it. That makes every one of these sites a gatekeeper to the user's E-mail account. All it takes i…

Related stupidity: "Security Questions" that enable someone to take over your account just by collecting not-so-secret information that is often shared because the site insists you pick from their own set of questions which other sites have already used.

The best way to tackle "Security Questions" is to generate a passphrase, store in your password manager, and use that for the answer.

In the unlikely event you ever need to recover your account with the Security Answer, it's much easier to read out a few words than a 16+ character random password.

Re: Not OK Cupid – A story of poor email address validation

#57
post #27

Earlier quoted context omitted.

Unfortunately most consumers are unwilling to pay what something is worth to them. Businesses are often the same so it isn't just consumer behaviour. Meeting the right person should be worth a lot, and we should be happy to pay thousands for that. Of course the profit depends on the user statistics too: I'm not sure what the economic term for profit thresholds for power law masses versus targeting - where say lots of…

> Meeting the right person should be worth a lot, and we should be happy to pay thousands for that. We're happy to pay much more than thousands to marry the right person. Meeting the right person doesn't do anything for you; why would you pay thousands for it?

"A Jewish man goes into the synagogue and prays. "O Lord, you know the mess I'm in, please let me win the lottery."

The next week, he's back again, and this time he's complaining. "O Lord, didn't you hear my prayer last week? I'll lose everything I hold dear unless I win the lottery."

The third week, he comes back to the synagogue, and this time he's desperate. "O Lord, this is the third time I've prayed to you to let me win the lottery! I ask and I plead and still you don't help me!"

Suddenly a booming voice sounds from heaven. "Benny, Benny, be reasonable. Meet me half way. Buy a lottery ticket!""

Re: Not OK Cupid – A story of poor email address validation

#58
post #29

Earlier quoted context omitted.

Someone signed up to Amazon with an email address of mine, and saved their credit card details. I couldn’t get any attention from Amazon, and just got generic responses telling me I could reset my password, etc. In the end, I signed up to Amazon prime, I think to test some reassurance they had given me - I wasn’t expecting it to work. The email saying I had just accidentally made a purchase with someone else’s credit…

You are probably technically violating the CFAA when you do this. Having your email address accidentally associated with the account isn't authorization.

Aren't they the ones violating CFAA? They made an account for GP then accessed it without authorization.

Re: Not OK Cupid – A story of poor email address validation

#59
post #27

Earlier quoted context omitted.

It probably started when they sold to The Match Group a while back. I used it a little back in 2014, and again in 2021. The second time around, it was very different. I don't know of any dating companies that focus on matching people versus optimizing for revenue.

Unfortunately most consumers are unwilling to pay what something is worth to them. Businesses are often the same so it isn't just consumer behaviour. Meeting the right person should be worth a lot, and we should be happy to pay thousands for that. Of course the profit depends on the user statistics too: I'm not sure what the economic term for profit thresholds for power law masses versus targeting - where say lots of…

The problem is most people won't send in a check to the matchmaker when they get married (or whatever the success criteria is). You've got to pay before the introduction, and you can't know if the introduction will be good before you have it.

E-Harmony seemed like it was going for the pay a bit more, one time, and you'll take who you get and be done. But I don't know if that worked for them.

Re: Not OK Cupid – A story of poor email address validation

#60

> When I tried to unsubscribe using the one-click unsubscribe button in one of the emails, I was met with an error: “Something went wrong, please try again later.” I want to start a blog which is just shaming every company whose most basic functions don't work and there's no recourse. It happens at least twice a day to me. Like a financial services management company whose website can't load my financial information.…

On this topic, I signed up for a new bank account online. They did not approve instantly, so I wasn't able to set up an account during the application. No big deal. A while later, they approved the application and invited me to sign up for an online account and do some setup with the account.

Of course, I can't do any of that without an account number which they haven't given me. I assume it'll arrive in the mail eventually.

Post reply on HN