Live data from Hacker News

Not OK Cupid – A story of poor email address validation

fastmail.com

71–80 of 123 posts

Re: Not OK Cupid – A story of poor email address validation

#72

Ugh. Then there's the general stupidity of forcing people to use E-mail addresses as user IDs. It's not just annoying, but also a security blunder. The general public can't be counted on to understand that when they're forced to use their E-mail address as an ID, they don't have to use their E-mail account's password for it. That makes every one of these sites a gatekeeper to the user's E-mail account. All it takes i…

Unfortunately you're right. Your email is an identity that follows you everywhere. In the world we live in, we need to make an email per service.

Re: Not OK Cupid – A story of poor email address validation

#73
post #56
post #51

Earlier quoted context omitted.

Related stupidity: "Security Questions" that enable someone to take over your account just by collecting not-so-secret information that is often shared because the site insists you pick from their own set of questions which other sites have already used.

The best way to tackle "Security Questions" is to generate a passphrase, store in your password manager, and use that for the answer. In the unlikely event you ever need to recover your account with the Security Answer, it's much easier to read out a few words than a 16+ character random password.

Definitely, but it's very hard to convince your whole family to adopt this practice...

Re: Not OK Cupid – A story of poor email address validation

#74

Companies that allowed others to create accounts with my email addresses: PayPal, Apple, Credit Karma, Walmart (I just forwarded the email to legal@ and they took care of that instance very quickly, kudos to that at least). Edit: Forgot to add TD Bank - I actually opened a case with the Office of the Comptroller of the Currency that regulates this bank. Companies that spammed me in the last 24 hours because they don'…

What email are you using that's so popular that dozens of people are (inadvertently?) entering it in all these businesses? Are you "john.smith@gmail.com" or something like that? I'm firstname@firstnamelastname.com, and I have had maybe a half dozen instances in the past decade.

I have a common lastnameinitial @ email provider. It's the same username from my mainframe days. Some people with similar surname use that, probably because they either don't want to receive emails or because they are just... I don't know, clueless?

Usually I takeover an account and change the password. Then add a 2FA if possible and update the details to my name and address. This way people can't say it's their account anymore.

A couple of times there were credit card numbers. I just delete those if possible.

I have cancelled hair appointments and car services. I have received flight information multiple times. I have locked out an account on a French dating site, which had some interesting exchanges (the guy's missing out!).

I did not cancel a vet appointment. Pets need to see a vet and their owners being dumb is not an excuse. I won't interfere with that. But I did book a full grooming for a week after.

When I takeover I just use a random password from Bitwarden and don't even bother saving the account, as I don't plan to ever use these again.

Re: Not OK Cupid – A story of poor email address validation

#75
post #66
post #58

Earlier quoted context omitted.

Aren't they the ones violating CFAA? They made an account for GP then accessed it without authorization.

People make mistakes.Just because someone made a mistake isn't permission to commit a crime against them.

Accidentally signing up once is a mistake. One person signing up for products, credit cards, unemployment, medical bills, television services, payday loans, mortgages, jobs with my email address over a 6 year period isn’t a mistake. This is some middle age dude in middle America.

Re: Not OK Cupid – A story of poor email address validation

#76
I sympathize, I have dealt with this a couple of times, most recently with Coinbase (resolved).

I agree that we would live in a better world if everyone on the internet followed standards and best practices, but we will never live in that world. We can expect the enshittification to get worse.

When this happens to me I make a filter to trash the emails. No amount of complaining or well-meaning (and in this case a bit self-promoting) articles will make the rest of the world change.

Re: Not OK Cupid – A story of poor email address validation

#77

Earlier quoted context omitted.

What email are you using that's so popular that dozens of people are (inadvertently?) entering it in all these businesses? Are you "john.smith@gmail.com" or something like that? I'm firstname@firstnamelastname.com, and I have had maybe a half dozen instances in the past decade.

I have a common lastnameinitial @ email provider. It's the same username from my mainframe days. Some people with similar surname use that, probably because they either don't want to receive emails or because they are just... I don't know, clueless? Usually I takeover an account and change the password. Then add a 2FA if possible and update the details to my name and address. This way people can't say it's their acco…

Have done all that without suffering any sense of guilt ?

Re: Not OK Cupid – A story of poor email address validation

#78
post #66

Earlier quoted context omitted.

People make mistakes.Just because someone made a mistake isn't permission to commit a crime against them.

Accidentally signing up once is a mistake. One person signing up for products, credit cards, unemployment, medical bills, television services, payday loans, mortgages, jobs with my email address over a 6 year period isn’t a mistake. This is some middle age dude in middle America.

What gives you the confidence to say that it was a single individual and not just a common email name which lots of people accidentally used?

Re: Not OK Cupid – A story of poor email address validation

#79

Companies that allowed others to create accounts with my email addresses: PayPal, Apple, Credit Karma, Walmart (I just forwarded the email to legal@ and they took care of that instance very quickly, kudos to that at least). Edit: Forgot to add TD Bank - I actually opened a case with the Office of the Comptroller of the Currency that regulates this bank. Companies that spammed me in the last 24 hours because they don'…

What email are you using that's so popular that dozens of people are (inadvertently?) entering it in all these businesses? Are you "john.smith@gmail.com" or something like that? I'm firstname@firstnamelastname.com, and I have had maybe a half dozen instances in the past decade.

Generally speaking, it seems people gets it wrong when things are created over phone etc. My firstname lastname is not common, but if one use firstname.middlenameinitial.lastname you can be sure that several people when noting their email will skip the initial, same if you have a suffix. I had banks, credit cards, social securities related stuff being registered to my email, generally it last a few weeks to be fixed.

Re: Not OK Cupid – A story of poor email address validation

#80
post #78

Earlier quoted context omitted.

Accidentally signing up once is a mistake. One person signing up for products, credit cards, unemployment, medical bills, television services, payday loans, mortgages, jobs with my email address over a 6 year period isn’t a mistake. This is some middle age dude in middle America.

What gives you the confidence to say that it was a single individual and not just a common email name which lots of people accidentally used?

I get regular emails intended for my doppelgänger, and have for many, many years. I know her entire family by proxy—we’ve effectively moved through the same stages of life together, in parallel, across the globe. For a while I used to respond to the more important-seeming messages, but it’s more mailing lists now. She and I are very far away physically—and it’s hard to say whether she knows about me at all, as I don’t mess up the email address in our collective name…

Oddly enough I’m still not sure of her correct address, only those of her correspondents. And in some cases family members.

Post reply on HN