Live data from Hacker News

Not OK Cupid – A story of poor email address validation

fastmail.com

91–100 of 123 posts

Re: Not OK Cupid – A story of poor email address validation

#91

> When I tried to unsubscribe using the one-click unsubscribe button in one of the emails, I was met with an error: “Something went wrong, please try again later.” I want to start a blog which is just shaming every company whose most basic functions don't work and there's no recourse. It happens at least twice a day to me. Like a financial services management company whose website can't load my financial information.…

Nobody cares because the world has been taken over by organized crime, and to them you're just someone to be exploited.

And why doesn't an independent company just create a better product? Because they don't like competition. It's a racket.

You'll find that your suppliers give you outrageous prices (but discounted rates for their friends), that potential customers refuse to buy from you (you're blacklisted), and so on.

Re: Not OK Cupid – A story of poor email address validation

#92
Ugh, I've got exactly the same thing with match.com at the moment. Some other Evan, presumably with the same last name, used my gmail address. Unsubscription link seems to have had no effect, I ended up just putting a filter in to send them straight to deleted.

Over the years I've been signed up for various porno sites, had wedding invitations, college applications, airplane tickets and an ongoing rental dispute all because either another Evan doesn't want to use their own email address for something dubious, or someone has assumed my gmail address must be the Evan they are after.

Re: Not OK Cupid – A story of poor email address validation

#93
post #58

Earlier quoted context omitted.

You are probably technically violating the CFAA when you do this. Having your email address accidentally associated with the account isn't authorization.

Aren't they the ones violating CFAA? They made an account for GP then accessed it without authorization.

It's not particularly likely to be tested for most types of online accounts, but if you told a judge that you thought the person had created an account for you to use, the judge would tell you to stop lying, they would not congratulate you on your clever argument.

Re: Not OK Cupid – A story of poor email address validation

#94

Companies that allowed others to create accounts with my email addresses: PayPal, Apple, Credit Karma, Walmart (I just forwarded the email to legal@ and they took care of that instance very quickly, kudos to that at least). Edit: Forgot to add TD Bank - I actually opened a case with the Office of the Comptroller of the Currency that regulates this bank. Companies that spammed me in the last 24 hours because they don'…

Ah, Apple -- I had that happen to me with them too. Had to contact their support to get the account closed. Infuriatingly, they were adamant that I must have approved the sign up email. Obviously I never received such an email.

To this day I wonder what path the mystery usurper followed to sign up my email address without validation.

Re: Not OK Cupid – A story of poor email address validation

#95

> When I tried to unsubscribe using the one-click unsubscribe button in one of the emails, I was met with an error: “Something went wrong, please try again later.” I want to start a blog which is just shaming every company whose most basic functions don't work and there's no recourse. It happens at least twice a day to me. Like a financial services management company whose website can't load my financial information.…

>Why is it that, on my Samsung Android phone, when I pull up Google Search in the browser

Define "the browser".

Re: Not OK Cupid – A story of poor email address validation

#96

Ugh. Then there's the general stupidity of forcing people to use E-mail addresses as user IDs. It's not just annoying, but also a security blunder. The general public can't be counted on to understand that when they're forced to use their E-mail address as an ID, they don't have to use their E-mail account's password for it. That makes every one of these sites a gatekeeper to the user's E-mail account. All it takes i…

Another problem with email address as user ID is that much of the public (most I'd guess) does not have a permanent email address.

Many use an email address provided by their ISP. What happens when they move out of that ISP's territory? Or, if they are someplace served by multiple decent ISPs decide to switch providers?

Many use addresses from gmail, outlook, yahoo, and similar. Those at least keep working if they move, but still have some risk. If you use multiple services from the companies that own those and do something to get banned from one of those company's services that might also get you banned from their email service.

Best if a site insists you use email as user ID is to use an email at a domain of your own. That won't be free because you'll have to rent the domain, and pay someone to handle your email (most people will not be up to running their own email server), but if the domain is at one of the long established TLDs and you don't do anything too illegal and it isn't close enough to the name of an established company that you could lose it over trademarks you can probably keep it for the rest of your life.

Whoever you use to actually handle you mail might go away or kick you off, but as long as you still have the domain you can switch to some other mail handler and point the domain's mail records in DNS to that new handler.

If you want to be sure that there is no risk of being accused of being a domain squatter or losing the domain in a trademark dispute pick a name that will not be at all similar to any business name or famous person name. I've got my ham radio callsign as a domain under the US TLD for example.

If you aren't using your own domain, at least check with any important site that you use that requires email as user ID to make sure they have a way to change the email so that if you do end up losing your current email you can update the site. That might not work if you lose the email without warning, but at least it can help in cases where you know you are going to lose the email such as switching to a new ISP.

It might also be a good idea to keep a list of all sites you are using where you will need to change the email as user ID if you are going to move, so fixing it can be part of your moving checklist.

In the US both of the login servers that more and more government agencies require you to use for online access, ID.me and Login.gov, use email as user ID. Both allow you to change that email (add the new email as a secondary email on the account, then change the new email to be the default email). It would be really annoying to not remember to do so until after you have lost the old email, and so find yourself unable to login to your IRS account or your Social Security account.

Re: Not OK Cupid – A story of poor email address validation

#97

Companies that allowed others to create accounts with my email addresses: PayPal, Apple, Credit Karma, Walmart (I just forwarded the email to legal@ and they took care of that instance very quickly, kudos to that at least). Edit: Forgot to add TD Bank - I actually opened a case with the Office of the Comptroller of the Currency that regulates this bank. Companies that spammed me in the last 24 hours because they don'…

venmo does it too

Re: Not OK Cupid – A story of poor email address validation

#99
post #51

Ugh. Then there's the general stupidity of forcing people to use E-mail addresses as user IDs. It's not just annoying, but also a security blunder. The general public can't be counted on to understand that when they're forced to use their E-mail address as an ID, they don't have to use their E-mail account's password for it. That makes every one of these sites a gatekeeper to the user's E-mail account. All it takes i…

Related stupidity: "Security Questions" that enable someone to take over your account just by collecting not-so-secret information that is often shared because the site insists you pick from their own set of questions which other sites have already used.

The problem becomes when a CS rep needs you to answer those questions on the phone.

How do you handle that?

Re: Not OK Cupid – A story of poor email address validation

#100

Earlier quoted context omitted.

Are you implying there are companies that don't focus on optimizing for revenue?

I mean, if I had the time, I would create a non-profit to do so. And yes, there are probably small mom-and-pop types of businesses that just want to keep their status quo. I believe I've heard a few years ago, that at least one country operates a dating service for their citizens. I can't find it now, but apparently the Tokyo Metropolitan Government just launched their own dating app, "TOKYO Enmusubi"

Are you saying non-profits aren't concerned with trying to generate earned income to stay afloat and grow their impact?

Different words, same problem.

Post reply on HN