Live data from Hacker News

Not OK Cupid – A story of poor email address validation

fastmail.com

61–70 of 123 posts

Re: Not OK Cupid – A story of poor email address validation

#61

Companies that allowed others to create accounts with my email addresses: PayPal, Apple, Credit Karma, Walmart (I just forwarded the email to legal@ and they took care of that instance very quickly, kudos to that at least). Edit: Forgot to add TD Bank - I actually opened a case with the Office of the Comptroller of the Currency that regulates this bank. Companies that spammed me in the last 24 hours because they don'…

What email are you using that's so popular that dozens of people are (inadvertently?) entering it in all these businesses? Are you "john.smith@gmail.com" or something like that? I'm firstname@firstnamelastname.com, and I have had maybe a half dozen instances in the past decade.

See also:

https://xkcd.com/1279/ - Reverse identity theft

Having an email address that resembles a real name is a blessing and a curse.

Re: Not OK Cupid – A story of poor email address validation

#62
post #20

Earlier quoted context omitted.

> The best you can hope for really is that they put a link in the email to disavow the account with one click. I've only seen a few companies do that but I really appreciate it! That's a great middle-ground, and I think I've only seen that once.

That’s not a middle ground at all that offloads the cost of your growth to unrelated parties who are potentially being defrauded. Typical tech ploy.

Look, when option A is actually make sure your user gives you contact info that works, option B is include a link that stops sending garbage for a user that doesn't know their email address, and option C is signing up with an email address results in an unending stream of garbage...

I would prefer option A, but I'll accept option B, because it's better than option C.

Re: Not OK Cupid – A story of poor email address validation

#63

Earlier quoted context omitted.

> Meeting the right person should be worth a lot, and we should be happy to pay thousands for that. We're happy to pay much more than thousands to marry the right person. Meeting the right person doesn't do anything for you; why would you pay thousands for it?

It made the news a while back when someone was offering $10k USD to anyone who introduced them to someone he would marry. I would do the same, but I don't know how to make it feasible without sounding terrible. I do often let people know I'm open to matchmaking if they know any women my age.

It seems like these dating services could hold the bulk of the money in escrow pending the marriage. Maybe you pay a few hundred up front, but a few thousand in escrow, and when you get married, it gets paid out.

Re: Not OK Cupid – A story of poor email address validation

#64
post #19

Earlier quoted context omitted.

Had the same problem with Peacock despite constantly attempting to unsubscribe and mark spam. In the end I just created a filter rule to throw it in spam.

If you're in the US, I've had success by contacting customer service and threatening action under CAN-SPAM. The FTC has never really provided an easy way to file complaints or request enforcement by the public, but it seems to get their attention all the same. Now is a good time to try to exercise your legal rights against corporations before they are all executive order'ed away.

The FTC has had a place for the public to report CAN-SPAM violations for some time at https://reportfraud.ftc.gov

The FAQ confirms this is the correct place to report email spam https://reportfraud.ftc.gov/faq

Re: Not OK Cupid – A story of poor email address validation

#65
post #57

Earlier quoted context omitted.

> Meeting the right person should be worth a lot, and we should be happy to pay thousands for that. We're happy to pay much more than thousands to marry the right person. Meeting the right person doesn't do anything for you; why would you pay thousands for it?

"A Jewish man goes into the synagogue and prays. "O Lord, you know the mess I'm in, please let me win the lottery." The next week, he's back again, and this time he's complaining. "O Lord, didn't you hear my prayer last week? I'll lose everything I hold dear unless I win the lottery." The third week, he comes back to the synagogue, and this time he's desperate. "O Lord, this is the third time I've prayed to you to le…

I think you'll find that the market price for speculative lottery tickets is very far below the value of winning the lottery. Do you not agree?

Re: Not OK Cupid – A story of poor email address validation

#66
post #58

Earlier quoted context omitted.

You are probably technically violating the CFAA when you do this. Having your email address accidentally associated with the account isn't authorization.

Aren't they the ones violating CFAA? They made an account for GP then accessed it without authorization.

People make mistakes.Just because someone made a mistake isn't permission to commit a crime against them.

Re: Not OK Cupid – A story of poor email address validation

#67
post #21

Fastmail's masked emails are great! I honestly very rarely give out my "real" email. Usually when I sign up for something I create a masked email, or if I need an email on the spot I use a wildcard alias (xxxxxx@myalias.fastmail.com). Since most of my emails are random, it serves as an authentication additional factor.

Don’t de email domains get blacklisted or are they valid?

Most of the generalized aliasing domains get blacklsited. If you are going to do aliasing set it against your custom domains.

From what I can tell: Atlasian and Stackoverflow try to reject you based on your mx records on the domain (which makes that a problem)

There are a few other companies that try to restrict you to gmail or hotmail domains. (Which is even more frustrating)

Re: Not OK Cupid – A story of poor email address validation

#68
For those who are considering aliases to reduce spam in this.

DO THIS TODAY. One of my aliases at the vendor Thermpro got compromised by them. I got list bombed pretty badly. Because it was an alias, I was able to turn it off. I got over 2k messages (Most of it "sign up for our mailinglist") within the first 12 hours. Reaching out to the vendor got nowhere. (Pretty sure they don't care that they were compromised)

Re: Not OK Cupid – A story of poor email address validation

#69
post #56
post #51

Earlier quoted context omitted.

Related stupidity: "Security Questions" that enable someone to take over your account just by collecting not-so-secret information that is often shared because the site insists you pick from their own set of questions which other sites have already used.

The best way to tackle "Security Questions" is to generate a passphrase, store in your password manager, and use that for the answer. In the unlikely event you ever need to recover your account with the Security Answer, it's much easier to read out a few words than a 16+ character random password.

That is an unattainable standard for the average joe though. Savvy people have their ways to keep things secure, even if it's inconvenient. It's the masses that fall prey to these avoidable traps.

Re: Not OK Cupid – A story of poor email address validation

#70
post #21

Fastmail's masked emails are great! I honestly very rarely give out my "real" email. Usually when I sign up for something I create a masked email, or if I need an email on the spot I use a wildcard alias (xxxxxx@myalias.fastmail.com). Since most of my emails are random, it serves as an authentication additional factor.

Don’t de email domains get blacklisted or are they valid?

iCloud’s HideMyEmail service generates @icloud.com addresses. Very easy, single click.

Nevertheless, I still use my personal name at lastname dot com for everything for decades and amount of spam is quite tolerable. Rarely it leaks into inbox. It’s even published on my personal web site in plain text.

Post reply on HN