Earlier quoted context omitted.
That's a good idea. Maybe a subject line like your password p *rd has been compromised.
Password is already compromised, so this is a worthless step. And only seeing part of the password may cause them to think it's largely still secure or something. (Some people don't understand wildcards.)
“I Emailed 97,931 Users Their Passwords”
61–70 of 72 posts
Re: “I Emailed 97,931 Users Their Passwords”
#62Earlier quoted context omitted.
Really? Do people seriously have this notion? Yes, sending actual spam is rude. But an unsolicited automated email can easily be deleted, especially if it's one time. I would never associate "rude" with that, maybe "annoying" at worst.
But this is actual spam! It's bulk, and unsolicited. The content doesn't matter.
Re: “I Emailed 97,931 Users Their Passwords”
#63Earlier quoted context omitted.
But this is actual spam! It's bulk, and unsolicited. The content doesn't matter.
Well, it really depends on one's definition of spam. I personally consider emails that are bulk and unsolicited, but provide some sort of actual information or help to not be "spam" but instead just call it what it is, a bulk, unsolicited email. To move it over to the spam category, I also would require it not be at all useful to me. Of course, that's just me, which is why I asked the question.
Re: “I Emailed 97,931 Users Their Passwords”
#64This is a cute experiment, but unfortunately the integrity of the service is is easily corrupted. The biggest problem is being prone to misinformation. There's nothing to prevent people from posting arbitrary e-mail lists to pastebin, with purported matching passwords, as an effort to provoke your service to cry wolf. A few suggestions to harden the service: - provide integrity when sending the message by including a…
These are very good points. 1. Good idea 2. Good point, however, these credentials are usually already posted in public forums. My thoughts were that the risk was already present-- and the person who potentially didn't know was the user. 3. I am patiently waiting on let's encrypt. As a side project with no income, I cannot justify the cost of a certificate. 4. I found based on some responses that some of the credenti…
Re: “I Emailed 97,931 Users Their Passwords”
#65Earlier quoted context omitted.
Well, it really depends on one's definition of spam. I personally consider emails that are bulk and unsolicited, but provide some sort of actual information or help to not be "spam" but instead just call it what it is, a bulk, unsolicited email. To move it over to the spam category, I also would require it not be at all useful to me. Of course, that's just me, which is why I asked the question.
Sure, that's one definition. Your definition would get you kicked off many service providers and is illegal in some jurisdictions.
Re: “I Emailed 97,931 Users Their Passwords”
#66This is a cute experiment, but unfortunately the integrity of the service is is easily corrupted. The biggest problem is being prone to misinformation. There's nothing to prevent people from posting arbitrary e-mail lists to pastebin, with purported matching passwords, as an effort to provoke your service to cry wolf. A few suggestions to harden the service: - provide integrity when sending the message by including a…
These are very good points. 1. Good idea 2. Good point, however, these credentials are usually already posted in public forums. My thoughts were that the risk was already present-- and the person who potentially didn't know was the user. 3. I am patiently waiting on let's encrypt. As a side project with no income, I cannot justify the cost of a certificate. 4. I found based on some responses that some of the credenti…
Re: “I Emailed 97,931 Users Their Passwords”
#67Earlier quoted context omitted.
I believe the trick is to put a hidden, 1px image in the email. Then you can track how many times it was requested.
Assuming people read their email in HTML and has their email client set/defaulting to automatically requesting external content. Sure, for a large sample from non-technical audience such as here it's probably a good assumption, but it may not be for e.g. a small sample from a tech-savvy audience.
This'll only work on very very old desktop clients, or users that actually click the "show images" button.
Re: “I Emailed 97,931 Users Their Passwords”
#68Earlier quoted context omitted.
These are very good points. 1. Good idea 2. Good point, however, these credentials are usually already posted in public forums. My thoughts were that the risk was already present-- and the person who potentially didn't know was the user. 3. I am patiently waiting on let's encrypt. As a side project with no income, I cannot justify the cost of a certificate. 4. I found based on some responses that some of the credenti…
While we wait for Let's Encrypt, you can use a free certificate from StartSSL.
Re: “I Emailed 97,931 Users Their Passwords”
#69If you're going to continue doing this, you might want to take a look at the message you're sending (or have someone else do that for you). Remember that a large segment of your recipients are probably not the most tech-savvy (or brightest). Do not overestimate random users reading comprehension. Without clear explanation where these passwords came from the natural assumption is that you did it, and you're warning them as a threat. No that doesn't make sense but remember who you're talking to.
One more thing:
> the person indicated that they use the same password for everything and wanted to know which account had been compromised.
If you answered that, you may just have got social engineered.
Re: “I Emailed 97,931 Users Their Passwords”
#70> Including one request to F k off. If someone had just sent me an email letting me know that my email and password are out there in the wild, "fuck off" would not be my first reaction. That's just rude.
Really? This guy emailed 97,000 people and you're just going to assume they're all just like you? :)
In this list, with near certainty there will be all of the following: children, teenagers, people having a really really shitty day, dogs, criminals, mentally ill, and possibly indeed also a few who are "just rude" ...
Frankly it surprises me he only got one "fuck off" reply.