The joys of owning an ‘OG’ email account
krebsonsecurity.com
krebsonsecurity.com
She just didn't get it and more and more new accounts began showing up.
When that didn't work, I tracked down one of her relatives on Facebook, who happened to be younger so she got the whole Internet thing, and explained that her elderly grandmother (it turns out) was using an address that didn't belong to her. Her granddaughter told me she would talk to her grandma and tell her how silly she was being and promised to explain how her grandma could keep herself safe while shopping online.
No new accounts in the grandma's name have shown up since...
A woman texted me via iMessage that she was calling out sick to her job at a local public school. I replied that I hoped she felt better, but clearly had a wrong number.
She insisted that I was Joanna, an Occupational Therapist at this school. (Emma gave me this number!). Clearly I was not, and did not know Emma, or any of the other things that were going on. Then she accused me of stealing Joanna's phone number.
Turns out -- if you send an iMessage to someone in your Contacts, it does the first lookup by email, NOT by phone number. By assuming Joanna had my email address -- something lots of people seem to think is theirs -- I ended up also getting their iMessages.
I tried emailing the gent to explain, but received no reply. So I've just been forwarding those emails to the fellow's real address when they arrive. Perhaps he never checks email, hence his lack of reply to my earlier note, but I forward just in case.
On the plus side, this personal experience made me very adamant about protecting mistakenly-registered users at my employer. When we were planning to add logged in accounts to our service, the sales team (understandably!) wanted the signup process to be as frictionless as possible, and thought that new users should be able to start putting data into their account as soon as they registered. I insisted that we require email verification before allowing users to enter personal data. When I got resistance to my plan, I logged into my webmail and showed the team all the crazy email I got from people who’d mis-entered my address, and suddenly they understood. I wasn’t just inventing some bizarre, unlikely edge case: these things really happen, and often.
Edit: And as you might guess if you squint at my username, my name isn’t super common. It’s not unique on the planet, but it’s certainly not “Smith”. If I have to deal with all this, I bet the Smiths of the world find it nightmarish.
Back then, I never considered this address an "OG" address, but then around 2012 I noticed something funny. I volunteered to do some charity work and everyone was asked to sign in to a log book and write down their email address with a pen. Several people who worked for this charity said to me "How did you get that email address?" and seemed to think it was unusual that I had a Gmail address that was simply my last name. When I asked them what their email address was, they'd say something like "fluffybunny32428@hotmail.com" or something like that. Hard to believe people use those kinds of addresses for official business and applying for jobs, but they do.
My name is also very English. So when I get missent email, almost everybody using my address is from the UK, Canada, Australia, or NZ.
firstname.lastname (at) gmail and firstnamelastname (at) gmail
are the same address.
People also get very confused about + in addresses.
Literally the only time I've gotten something that was for another person is when someone else with my exact name purchased something medical and they emailed the receipt to "firstnamelastname@gmail.com". It turns out that if gmail receives an email in that format and all they find is "firstname.lastname@gmail.com", they'll go ahead and stuff it into that inbox.
I was able to track the person down, call them, explain what happened, forward the email to them, and delete it.
My name isn't super uncommon, but for whatever reason I don't get those sorts of emails.
One of my Gmail addresses is <my first name>@gmail.com and I never get interesting titbits intended for other people.
Mind you, it probably helps that my first name and surname are pretty unusual. I've also got <my first name>@yandex.com, <my surname>@yandex.com, plus the <my first name>.net and <my surname>.net domain names. So I've pretty much cornered the market in being uniquely identifiable online, for anyone who knows me.
Hmmm... maybe I should se if <my surname>@gmail.com is available, just to really tie up the loose ends!
UPDATE: Hmmm... <my surname>@gmail.com has already been taken, so I can't complete the set. Chances are I actually set it up myself a long while back and then never bothered to use it, but I'm buggered if I can remember the password.
To get a good email address these days you either have to be very early at jumping on a new email service or you have to be skilled enough to use your own domain.
Not a very sensible idea, given how many sites have "What year where you born?" as one of their security questions.
Anecdata from me: I've never seen this as a security question,
I'm willing to concede that I didn't notice it because I just pick a security question at random and record it in my password database with a made up answer so that I can satisfy their test later on without using a real, guessable answer.
I've mentioned before on here; it did come back to bite me once when I had to ring my insurance company and confirm that my mother's maiden name was... er... "Hitler"!
A couple of years back, a friend was doing some recruiting. One of the applicants had the email address givesdamngreathead@hotmail.com.
(Translated, it was in another language.)
On the other hand, it appears my name is unique in the world. The only things I've ever found under my name that weren't written by me appear to be people scraping for content and trashing the format--I've found plenty of examples of words attributed to me that were really quotes.
I occasionally try to remedy the issues, but I have yet to convince my mother to fix the email on her bank account.
One large financial services provider even told me that their "policy" was to allow 3, 4, or 5 characters as the last part of the domain. So .ninja is A-OK. I pointed out how ludicrous this was, and they told me it was their "policy" again, and that's why Australian Super doesn't have any of my money.
Wow, no country codes? I could understand a restriction dating from before the great expansion of TLDs, but expect it to have a 2 in it.
Actually I wonder then if it was 2, 3, or 4. I think it was, because I remember thinking that .wiki would have been okay.
Either way. Arbitrary and stupid.
But don't activate an account without e-mail verification. I got a random account on Deezer because someone signed up with my e-mail address; they probably got it off a spam list. But it kind of implies that Deezer didn't do e-mail verification before letting people use their platform.
There were various ways in which that failed.
1. ".name" was pretty new by then, so some frontends did not accept it
2. some frontends objected to the third level of my domain part, accepting third levels only in such cases as the well know. ".co.uk" for example
3. some frontends let me sign up, but something in the backend failed, I can only suspect if it was the ".name" tld or my third level, but I never got any mails after signing up
This is actually not such a rare edge case. My university, for example, uses <name>@students.<university>.de . So there's really not much excuse for not handling this.
var domain = addr.split(['@','.']).take_last(2)
var tld = domain[1]
// check TLD against wacky rules...
See, boss, it's easy. What's next?I wonder what happens with .co.uk, and other two-letter second-level domains.
This has the side effect of knowing who has been selling out your email to spammers.
[0] https://www.cs.rutgers.edu/~watrous/plus-signs-in-email-addr...
Fails a lot of validations because ‘example’ can’t possible by right eh?!
Personally I did not enable SMTPUTF8 support in my Postfix due to the lack of Dovecot support.
[1] https://tools.ietf.org/html/rfc6531 [2] http://www.postfix.org/SMTPUTF8_README.html
I wonder what happened when I didn't show up (I did let them know that I wouldn't be there), and I wonder if it was ever finished and released.
Yes, I also get the bills (mostly from electricians in Australia for some reason) the porn/game signups, the notes from Grampa, etc.
I still get updates in my email from this family and even had bank statement updates sent to me. and birthday wishes mean for the other sstave...
I have told them multiple times - but I am still on their family tree - for a DECADE
I have Firstname.Lastname@gmail but I never get any mistaken mail there.
Now text messages on the other hand... I get all sorts, at one point I was getting some for a Black Gun group. Now I am getting them from the DNC but they are address to the wrong name.
The scarier thing is two factor authorization text messages, I remember getting some for Facebook and Instagram. I never did anything with them but if not set up right I suppose I could get into someone else's account.
One time I got a wrong number and over the next few days coached a lady who was calling her friend for advice on her upcoming job interview, as she wasnt sure she wanted to make that career change.
I did the best I could to advise on the matter (sincerely) - but I never got a reply on the matter.
I always delete the message immediately after so the thread isnt there so I have no way of initiating a connection.
I was once the (proud) owner of `ozzy@ibm.net` at some point in the mid-late nighties.
I was living in Istanbul for awhile and IBM had just entered the market to bring us all Internet, and decided to use their `ibm.net` domain to give all their customers free email.
Still miss that one xD
Really like your approach at work though, I am apparently signed up to so many various services that I have never heard of, and could probably access lots of PII if I wanted to.
I unsubscribe and/or report spam where I can, but on a typical day, I still get around 3 emails intended for someone else.
Google's "targeted-journalist-level" Advanced Protection Program means I don't have to worry about password resets or account recovery stuff on the account.
Though I have lost track of the number of services I didn't have immediate access to since someone signed up using my email address, and reclaiming it can be a battle sometimes. The Apple ID was interesting - but luckily everyone's "first pet's name" was "Fido"... (Seriously... Please validate your emails everyone!!!)
Often, whenever a real mailing address is included I print out the email and send it in a real letter with a friendly (if just a tad passive-aggressive) note inside. But overall I try to do the right thing for important documents and correspondence.
I do shudder to think how many random accounts are just an email-password-reset away from having access though...
Thanks, I never heard of that before. https://landing.google.com/advancedprotection/
I did get a subscription for a Diners credit card, and I am torn about contacting the guy; I don't look at the emails but I probably could find the owner relatively easily. I contacted Diners and they didn't believe me. (Who the heck is using Diners these days?)
The worst was when my wife began receiving outage alerts from a Fortune 100 company's NOC. Not just simple Nagios alerts, but detailed technical information accompanying the alert. When we attempted to notify their security team they threatened us for having "hacked" their system. Turns out they realized a former employee added their personal address to the distro when they left so they could help with the transition.
Then there was the mother who signed me up to get email when her kids didn't show up at school ....
Then again I used to have a fax phone number one off from a pharmacy, other people's prescriptions every week
Its crazy.
Linkedin is criminal in this department.
I don't really like email alerts for social media as a concept anyway, if I want to hear what LinkedIn has to say I'll look at LinkedIn itself, it has no business injecting itself into the rest of my life via out-of-band methods like email.
I get emails from middle schools, online shopping of course, but also emails for at least a couple Trump supporters (not trying to profile; simply getting Trump campaign's constant barrage of emails demanding more money; nothing from Joe's side yet)
What I find particularly annoying is when parents use this account to register for a kid's school alerts. All sort of important stuff like "Do not send your kid to school this week!" or "Where did your kid go?" and because the school itself is also not super savvy, there is nowhere for me to send a reply saying "You need to fix this!"
I couldn't send mail from that address, but I sure did receive it. An endless torrent of weird junk, and a surprising amount of personal data, business secrets, and passwords. If I was maliciously minded I could have done a lot of damage.
I spent those months trying to find any way to get a message into Google to fix it, and only eventually succeeded when I learned a friend-of-a-friend actually worked there, and they helped un-scramble my account.
I don't know how many there are, but are you saying that 3 would be a lot? There's probably hundreds of internal libraries for other languages like Java, C++, Go, etc. 3 really doesn't seem excessive.
At some point both his wife has asked me what I thought about a forwarded message from their mortgage broker and his brother in-law asked me my input on buying a 30ft yacht and what to name it.
I always ignore the serious ones for obvious ethical reasons but can't help myself with the more innocent cases. I've found I quite enjoy giving non-commital responses to these emails that won't give up the gig but also don't help them either, things like: "that seems pricey" or "cool! What are you going to name her?", and "she's a beaut!".
I suspect it will go on for a while.
* Several people from (I think) Mexico City have sent me requests in Spanish asking for medical prescriptions, including photos of their current medication.
* I started receiving receipts for an Italian parking fee app. After I contacted their support about the problem, I received an email addressed to their user asking them to confirm the email address.
* Someone signed up for Comcast DSL and there was no way to opt out of those emails, support didn't react and logging into the account would have required additional information not in the emails. I finally made a complaint to the FTC under the CAN SPAM act - that got their attention and they managed to fix the issue.
* Someone signed up for some rewards program and proceeded to collect points by signing up for about 10 different newsletters.
I have answered some helpfully if I had the time, but mostly ignored them and put them in a folder as "mail for others".
One in particular, some kid in Arizona who shares my last name has signed up for everything from golf to Epic Games. I found him on facebook and friended (since we shared our last name) and politely asked him if he could try to not use my email for things. He told me it was his, called me a creep and blocked me.
It's kind of hilarious how many people insist the email I (or Google I suppose) own is also theirs, despite the technical impossibility of that scenario. The same has happened with my phone number.
There's also no feature to verify or disavow email addresses.
I wonder if they change this policy now that more people know about it.
It really is mind boggling.
The tld is a little rarer but plenty of people still use it as garbage input to web forms!
1.x decades later, I regret it. I get people's medical information, legal documentation, all of it. It is stunning to me the quantity of PII that flows into my inbox daily. Back when it was a trickle, I used to try and contact the people involved to let them know of the issue. It almost never worked out, and I got tired of getting yelled at.
At this point, I keep my account simply because if I were to close it, I don't trust whomever might have it next. It is what it is.
https://www.zdnet.com/article/rupert-goodwins-diary-30391728...
This whole thread is the reason I started requiring extra email verification when members signed up at our hackerspace/makerspace. A surprising number of otherwise-bright people don't know their own email address.
I have a similar .mac/.me/.icloud email.
Unfortunately the innumerable 1,2,3 ended users of the same email get wearying to deal with for both of us. We both have persistent UK versions of ourselves, lots of offers for free tickets to football games in the UK that I have to regretfully pass up; as well as a variety of other people that we've managed to classify by geography.
The PII stuff is really the hard part- real estate documents, job offers, legal communications, x-rays, etc. You want to help but often it just generates a lot of heat without helping.
I also get fun things like family photos from people I've never met before
They also told me about an MS website hack, where you could enter spaces into your name by changing the client-side javascript and entering about 500 spaces between each character and then filling the field with spaces until maxchar.
I contacted Amazon about it the first time and they wouldn't cancel it or issue a refund because I was the recipient, not the purchaser. I worry that someone has been written out of their Dad's will because he thinks they have forgotten father's day 3 years running.
Most recently I’ve been getting a cell phone bill for a South African person. It had their address so I looked it up on gMaps and it was a small home in a shantytown. I just received an email telling me the service was being cut off for non-payment. No email for me to reply to.
Fortunately his phone number was in the emails, so I called him and had a great chat, he got his Nan on the phone and we spent ages walking through our family tree finding connections.
Tangentially related -- catch-all email accounts also get a ton of mail when the domain name they're tied to is close to something that many people send messages to. If you own a domain one keystroke away from a high volume domain - you'll get access to all sorts of things you shouldn't be seeing.
It's annoying but I'm still striving for inbox zero. :)
100+ emails a week in my primary inbox that are from people signing up to random stuff in my name, basically any/every service you can imagine where I don't already have my own account (large social networks and sites in countries other than me own, online shopping sites, etc).
The other interesting thing is I seem to get a LOT of email for addresses that "almost" match mine, as though Gmail is doing fuzzy-search for addresses? Eg lets say my email is "david@gmail.com", I get dozens of emails a week for "david.17@gmail.com" and "davidab@gmail.com" and stuff like that. I can't explain this one, and everyone I bring it up with says it shouldn't be possible.
It's gotten to the point where I've created a more normal fullname@gmail.com and then do some filters/forwarding on the old one for the more important emails, then just check the old one every couple weeks to see if I missed anything, because it's just not usable anymore with notifications on.
15 years later: https://i.imgur.com/FlCi3xT.png
Almost none of that is actually spam. Mostly list/membership subscriptions, reminders that my $(VEHICLE) is due for service at $(DEALERSHIP), and misdirected personal emails ranging from amusing to upsetting.
I've seen many people locked out of their hosting accounts because they have their primary account email address as one of the hosted email addresses on their accounts, and suddenly they've lost access to their web hosting control panel because their domain expired or their email was otherwise taken offline.
I think what all of this boils down to is that people don't receive any actual training about how these things work. They pick up a phone and start using it and figure it out along the way, or they buy a computer and set it up the way Microsoft says and never think twice about anything else. The amount of training that people receive is dismal at best and most the time it's not even that.
There's also a contingent of the public that doesn't want any training and their main argument is "well this is how I've always done it!"
This is a surprisingly difficult risk to effectively mitigate.
If you have a domain and tie your domain registration and hosting accounts to an email address hosted by the domain, you could get locked out if something goes wrong with the domain registration.
If you tie your registration and hosting accounts to a third-party email account, you could get locked out if the third-party decides to nuke your account for any arbitrary reason (cough, cough, Gmail).
If you tie your registration and hosting accounts to a cell phone number, you could get locked out if someone attacks your phone account (unauthorized porting, SIM swap, etc) or if the cell phone network goes down (think California fire protection blackouts, or hurricanes).
If you tie your registration and hosting accounts to TOTP or Webauthn 2FA, you could get locked out if you lose or damage your 2FA device.
There's no good way to authenticate domain registration and hosting accounts unless your registrar and host have the foresight to allow multiple authentication paths.
This is interesting. I usually point all my WHOIS info to <something>@<other-domain>, but <other-domain>'s WHOIS goes to one of my personal Gmail accounts.
I'm going to switch it to a domain where I control the DNS, so I can change the MX record if a provider decides to nuke my account.
Now I'm wondering how this works with any registrar's domain privacy feature — technically, they're the "owner" of the domain in the WHOIS record.
I'm surprised there aren't more in person or by mail verification options available. I guess partly due to the "who pays for it" aspect (and people moving, etc., plus no verificaion method is completely accurate), but the current state of authenticating online accounts is rather worrying in general and allows anyone anywhere in the world to try to take over your accounts.
That doesn't leave many options.
[0] https://medium.com/@N/how-i-lost-my-50-000-twitter-username-...
That part was really shocking. I can see why you might be stuck with a low-level support tech that can't and won't help you, but not being helped despite having this level of attention is horrible.
I also got signed up for some kind of dating service I cannot remember the name of (before Tinder etc), and after being getting some weird messages in my inbox I felt I had to delete his profile. Sorry about the matches you lost.
Given the nickname he's been using on some sites when signing up, I managed to track down his real email some time ago. Basically mine + a number. Asked him to stop using my mail, and what services he wanted we should try to move to him before me closing them. All I got in reply was something along "why are you in my inbox".
I suspect you never see this with people whose number-after-name was 4 or 7, because they won't be entering a valid email address.
A friend of mine has first@fullname.co.uk, and he's forever getting email intended for first@fullname.com (who is someone entirely different, also in the UK, and works in the military).
One day my friend books a flight and accidentally uses first@fullname.com. He doesn't realise anything is wrong as the flight still shows up in the app. However, the owner of first@fullname.com also sees the flight confirmation and thinks there's some identity fraud going on, so phones it in to the police. So my friend gets to the airport and scans his passport at the boarding gate, but is met with a big red exclamation mark. Next thing he knows, he's flanked by two armed officers who take him away for questioning for an hour!
After working out the mix-up, my friend sent a note to first@fullname.com thanking them for the welcome committee.
I tried reaching out, but my email was probably ignored because they thought it was a scam.
I'm sure that sending that info insecurely at least... violates mastercard agreements? I dunno. I just hope people checked and double-checked what emails they send.
My catch-all mailbox has received an insane amount of highly sensitive medical records over the years. Most of these mails were coming from employees of the company itself, not external correspondents.
I have since modified the catch-all mailbox to reject mails from the medical company, so they get a bounce message. This has not reduced the number of messages, but at least they will know something went wrong...
People are not very careful, even with highly sensitive data...
The most interesting ones were about a trial where the defendants sold substandard steel to the military. I got added to the thread with their lawyers discussing strategy and sending attachments. I deleted it all after notifying them, their case made it into some national news stories.
This may have been rectified since, and I'm still not sure how so many of these people haven't noticed that their "new" email address is not working - but I guess they put it down to spam filtering or similar.
And there are also companies like Epic Games that got my email via a (failed) Playstation registration something. When I wanted to register to buy a game it did not allow me to create my account. I had to use another temporary email while I entered the account with my correct email and deleted it.
We should make a support group for the endless frustrations.
I should also point out that I connected with one of the similarly-named-email guy. When I recognize that it was directed to him, I'll just forward the email now.
Nowadays there's a lot of different people who try to use my address, but for a long time, most issues originated from a single person. At one point I received a Christmas wishlist from his nephew, to which I responded that I was not planning on giving any gifts this year, and would instead donate to charity. I didn't receive any response, but from what I remember, he didn't use my address after that.
Worst though is that PayPal created an account for another person with my email address. Apparently they don't send out the initial prove-your-ownership email. Still unresolved because PayPal refuses to believe me that I own the address, even though they don't even want to send a test email.
I've been talking to their support people on-and-off for months now and they seem utterly incapable of resolving an issue like this.
Well it seems that Paypal decided recently that why bother confirming email addresses. Just let anyone use any email address. They send a confirmation email, yes. But then accept the address no matter if they receive the answer or not.
So I start getting notices of some not very bright namesake that is making tens of cents with some online store. The spanish paypal office is totally useless, they just suggested to contact Google.
I sent a mail message to the European Paypal delegate for data protection, but no answer and I still get more notifications later. It's quieter now, after another confirmation email (that I obviously didn't answer) but no idea if they did something or it's just that the account owner is not selling so much later.
Edit: years ago I got a "nico" account in a very popular local provider, so I had experienced the og problem before. Some other namesake is gay (maybe he's the pornstar that I see in Google) and received some explicit pictures.
Hah, I don't remember receiving a confirmation email. Unfortunately, there's no way to disavow an email address from someone's account either, which means I can't use that particular email for PayPal.
Interestingly enough that email forwarding she set up still occurs and she has all of the received email for her attacker(s) including all the security notices. I figured it would be a bunch of people emailing angry that they received spam from the account. Instead it’s a bunch of disjointed English talking about the weather - back and forth messages such as “in Tuesday we will have windy”. There are several iOS devices now logged into it. I am baffled yet insanely curious.
Unfortunately even though this email forwarding has been set up for more than a decade, googles automated account recovery does not recognize her request and we can’t get the original flast@gmail.com address back.
Anyone at google have thoughts? I can drop my personal contact info if so.
We're actually moving in the opposite direction now. A lot of services nowadays became less strict in what they require to open an account (for the sake of growth and engagement) compared to a decade ago.
There should be a standardised protocol and flow which makes the experience much better for both users and developers.
Perhaps the author collected those accounts 12 years ago when it hasn't been the case? Or does he click on the verification links?
Of course I got rate limited in this, as you can probably imagine given the factorial complexity of checking every name.
I suspect it's only exponential. Or does more of unicode open up as you increase the length?
Until about 3-4 years ago, I basically didn't get any spam or these kinds of accidental "put the wrong email in the signup box". Then one-by-one, I started getting them. Facebook account request, bank signups, tinder account verification emails, twitch, the works.
Sometimes I'll get half a dozen emails clearly initiated by somebody trying to get access to some account somewhere and my email address was provided as a backup. Occasionally, I'll get notifications that somebody is trying to rest my password.
I wonder sometimes, with email and the internet being so ubiquitous and for so long, how is it that people don't honestly know their own addresses? And then I'll get peaks into the lives of these people every once in a while. Pictures from their facebook account, emails from real estate brokers, from "hookups" and so on.
Every once in a while, if there's an obvious way to contact somebody, and the emails seem like they're from legitimate people, I'll respond and say something like "wrong email address." or something. About 1 out of 20 times the person on the other end will fight back informing me that I, in fact, "am wrong about my email address and yes I can't avoid making my childcare payment this lamely."
It's gotten frustrating, the Eternal September has now impacted one of the oldest continuous ways I've used the internet, a way I've jealously guarded and preserved from spammers, scammers, and all other form of miscreant, only for that judicious and careful defense to be washed effortlessly away by people who aren't even aware what their own on-line identity is.
So I do get fairly regular emails addressed to people who share my last name and forgot that their domain may be the same as mine but is a different TLD and not the .com. I don't have a wildcard catchall email set up but I do have the common ones like info@mylastname.com.
The most recent was someone who ordered business cards from Vistaprint and used my info@ address. I figured out who it was and emailed them at their own info@ address. (No, I didn't sign into their Vistaprint account, though I could have easily done a password reset.) Haven't heard back yet. I just hope they didn't put my domain on the cards. They probably did - time to reorder!
People on the other end of the counter just type in what’s easy because they make minimum wage and don’t care, people on the other end of the phone that didn’t hear something and just type in what’s easy because they truly don’t care, people that truly don’t understand the internet and really think that their family members first name or last name, or any combination there of will magically get to them via email because no else has the same name.
Life is truly random and the truth is rather boring once you find out what really happened.
Probably his most famous domain was corp.com, which was recently bought by Microsoft because it turns out that older versions of Windows and other Microsoft products actually invited people to use corp.com for their internal Active Directory names. Problem is, when those machines are outside the internal network, they're constantly trying to share passwords and other sensitive data with corp.com.
More here:
https://krebsonsecurity.com/2020/02/dangerous-domain-corp-co...
https://krebsonsecurity.com/2020/04/microsoft-buys-corp-com-...
Turns out it’s the same number as a major medical insurance support number. Just a different area code. I get calls in waves, it seems. This week I get 3 or 4 a day. I ignore them. Occasionally I get voicemail “I have a question about a patient” or whatever.
If I answer and try to explain it, it confuses people and they usually get frustrated. Not worth my time anymore. Basically I ignore all calls that aren’t from people I have saved.
Just scrolling through the catchall for the last couple of days I see AT&T and Verizon bills, several doctor's office reminders, some medical patient portal emails (including "new test results available"), a Navy Credit Union account notice, a surprising number of reminders and test results from veterinary offices...
The only one I ever bothered trying to get sorted out was when I discovered that I seemed to be getting any HP corporate purchase order without an email address on file.
I haven't had it happen for quite a while, but for a fairly long period when email was relatively new to a lot of people I received a fairly regular stream of mail intended for other (presumably alumni) with the same first name, including some fairly sensitive emails with board meeting minutes and the like.
- People have bought iPhones, XBoxes, Playstations, ... and created the respective accounts using my email address. - Holiday bookings, flights, accommodation bookings. - A PayPal account that was created using my address five years ago that I'm still trying to get PayPal to resolve. - I've been sent death certificates, wills, lawsuits, confidential legal docs. - Someone bought a car. I received all the transaction details and was signed up to a variety of free services that appear to have been bundled with the car.
One of the most frustrating things about this is that it's generally impossible to contact the person who make the mistake directly, so resolving it often involves jumping through lots of hoops and explanations to third party websites or other individuals. The other huge frustration is the sheer number of sites that don't validate email addresses. Or perhaps worse (and I'm looking at you PayPal), send a validation email but then create the account and assume everything's fine regardless, with no way to opt out or reject the verification.
He received one while we were working on a project together and opened it up to show me. I thought it's kinda hilarious that some dev is just chucking that in their sign up page but he actually gets a real email because of it.
Seriously, people need to learn how to deal with the internet, and I'm utterly tired of the let's dumb it down movement - it doesn't work.
My guess is it's bob@gmail.com
It’s amazing how many services will not confirm email addresses and just send sensitive info (and make it hard to unsub).
Many years ago I had a CEO who made us keep one of those “retype your password to confirm” that I thought was stupid, but we did it. I think of how right he was every time some Uber driver signs up with my email.
It’s very hung up on making sure the user types the right email address on account registration, having them type it twice, making them provide some sort of security question (before their account is created, mind you!), making sure the question is answered correctly by the person clicking the link, etc etc.
None of that is necessary. Your signup form can literally be a single email field. You validate that it looks enough like an email, and send a unique link to it to continue signup. Then you ask whoever clicked that link questions like “please create a password”, “select a username”, whatever personal information you require.
What happens if they type the wrong email? Well, you send a signup link to the wrong person. Big whoop. Worst case, someone else will get a link to create an account on your system. (Not to create the original person’s account! Because you didn’t ask for anything but an email yet! They would be creating an account, with their own email, even.)
The email validation link only tells you that the person who followed the link owns the email address that was typed. Just don’t do anything permanent (like actually creating an account) until the link is followed, and you don’t need to worry about whether the email was correct.
Now, this still has issues where people can type all sorts of emails into the signup form without friction to make your service spam them with signup links, but I’d argue that the advice in the article has the same problem, just with a trivial amount of additional steps (like having to type the email twice and set up some security question.)
No, it's saying you can do this, this, _or_ this. It's giving you options, not telling you to do everything on it.
> You: "I will NEVER..."
>
> Me: "...send the user a simple clickable link in an email and assume that the clicking of the link establishes validity."
> You: "...send the user a simple clickable link in an email and assume that the clicking of the link establishes validity."
It doesn’t seem like it’s giving an option here at all.
I certainly want to send the user a simple clickable link in an email and assume that the clicking of the link establishes validity. It’s how I know they actually own the email address they typed! (And that they are capable of receiving email I send them.)
I just wouldn’t use that validity to assume anything other than: “The person who clicked this link is allowed to create an account with the email address I sent the link to”. In other words, it must happen prior to account creation, not after. But the section of the guide is entitled “validating email addresses during new account creation”, so it’s pretty obvious that is this before the new account is created.
Irritating. I just copy and paste it if I see that. Just send out a validation email.
Definitely not worth telling people that they messed up because chances are they don't care, won't know what to do, or will get angry. The only time I'll correct someone is if the email was entered incorrectly by a sender.
Just signed into it for the first time in a while, and it looks like it's gotten some better than it was-- now it's mostly mailing list stuff and actual spam (of the "your paypal account is locked" variety); seems that most legitimate services are doing better about email verification these days. At one point a few years back, someone had managed to actually create working Apple ID, Facebook, and Paypal accounts against it without access to the email (was still receiving "verify your email"-type messages at the same time as transactional emails indicating real activity).
On this topic, I do get some mails intended for others, including bank statements with passwords that are trivial to crack, account signups for social media platforms, delivery services, etc. I’ve also seen that there’s no way to rectify this in many cases — the entity sending the email (or the appropriate group within the company) isn’t available to contact and resolve the situation. In other cases they just don’t care even after they receive the emails about the information leaks form their systems.
I never realised how many friends I had on the internet, and at first I gently replied to a few that I wasn't the `<firstname>` they were looking for. This was a more utopian era where email spam was in a more infant stage, and most of these friends were real people trying to connect rather than bots and scammers. However, there were a lot of new users joining Y!Mail and apparently quite a few were looking for me.
Some of my new friends were pretty insistent (and oversharing), so it didn't take long for me to abandon the OG forwarding address and associated nostalgia. So many friends, so little time for real conversation.
The really sad thing about it is that it exposes major flaws about the way we think about users and techonology.
* Lots of highly profitable and seemingly reputable sites give zero fucks about unsubscribe requests, don't require email verification and have no reasonable way of getting in touch with support staff.
* Considering the amount of errors stemming from failure to understand the concept of unique email addresses, lots of people who shouldn't use the net still insist on doing so. No clever app design or UX patterns can withstand the failure to grasp the most common uniquely identifying online token we have.
* A lot of the people mentioned above probably insist on using the net because they don't have a choice: Everything comes with an app or a web site and requires online registration just to harvest whatever is the desired user data du jour. Depending on where you live, even using official government services might require going online.
A lot of them are people releasing some political steam and we can usually tell if a company has been in the news based on the type of messages that come in.
I still don’t really understand how people make the mistake given the nature of our site, but it is what it is.
Favourite ones are:
Getting a copy of a AirBNB booking that just happened to be 5mins down the road from me. I resisted the urge to check-in as the person with the same name (emailed their friends on the booking to alert them).
I was also included in a neighbourhood spat somewhere in the states at one point. It took considerable effort to get across I was not their neighbour (they thought I was ignoring the issue). Eventually the person's wife engaged and it's been quiet since.
My wife has a fairly uncommon irish name but gets accounts created on platforms all the time by someone with the same name. Doesn't beat showing up to work and finding your boss has the same name. My wife was not happy when she decided to go on a sabatical. Payroll added the salary sacrifice to my wife's payroll account (they never checked employee IDs because surely two people in the same organisation wouldn't have the same name!!). :0
On another note - I've got several <firstname>.<lastname>@<providername>.tld mail addresses, and also a <firstname><lastname> domain. They get mixed up quite often:
There is someone with almost the same name as mine, except that my last letter is "t", and his is "g". Because these keys are so close to each other on a keyboard, I receive a lot of stuff which was meant for him. I always forward it.
Then there is someone with the exact same name in my country, who has <firstname>-<lastname>@<provider>.de, whereas I have <firstname>.<lastname>@<provider>.de
Needless to say I got to know a lot about him in the last 10 years.
Since people are routinely misspell my coworkers email, I decided early on I would be the catch-all of the company domain.
Excluding the droves of email from various services from former coworker, there has been a very interesting one: someone that never worked for the company decided to use [firstname].[lastname]@company. That guy was in my country military, serving on a military boat. For some time (before I found how to block any email addressed to that particular email at the domain level), I received what seemed to be very sensitive military information.
I can't be too sure, as I did exactly what was outlined at the end of the emails: destroy them as soon as I received them, since I was not the intended recipient. Luckily, nothing ever came out of it.
I'd forgotten about this until last week I started receiving messages from a cluster of contacts as if I were the member of an online continuing education course. None of the addresses had the domain of an educational institution, but the content mostly tracked. I managed to communicate to the group that they had the wrong after, but it took a few repetitions, because they were not all members of the same thread.
I also had in the early days of facebook the username 'qetuo' which was very convenient. Though has since been picked up years later by some chancer, after my having deleted my initial account. Though I did introduce the idea to some friends, who then created usernames such as 'tyghv' or 'rtfgv' which are sort of OG qwerty convenient usernames.
The crazy thing is that we don’t really have any way to contact these people. None of the invoices include identifying information other than what state the businesses are located in.
For a while, any time I got signed up for something where they provided a cell phone, I’d use my Google Talk number to text the cell phone and inform them. I don’t really bother any more, as generally people are just confused and it ends up being a lot of back and forth.
A sampling of the other emails I’ve received over the years:
- Nude photos from a woman who, when I informed her that I wasn’t the person she meant to send them to, got quite offended that I didn’t want her pictures. After a little back and forth she realized her mistake (and I deleted the email and the pictures).
- Pictures and video of a baby, along with emails criticizing me for not wanting to see my baby, and not supporting her.
- There’s a man in Texas and a man in Florida who have both used my email address to sign up for what could only charitably be described as dating sites. These sites all seem to use the same base software, and have no way to remove your account. With these I’ve taken to resetting the password and deleting the account. Sometimes I’ll have a little fun and change the bio to something like “I hope you like STDs, because that’s all I’m bringing to the table”.
- Receipts for web purchases. Mostly these are boring, clothes, home goods and the like. However one person used my email address when purchasing several hundred dollars in sex toys. The email included his name (same as mine) and his address, along with a detailed accounting of his purchase. I was tempted to print that and mail it to the address with a nice note advising him to use his own email address next time.
- Job search emails. Sometimes it’s scheduling interviews, sometimes it’s notification of a start date and some paperwork. I’ve also gotten an email with the results of a background check that wasn’t favorable.
- The absolute craziest one was an email exchange that lasted over a year. This man in California would send texts from his phone to a bunch of different email addresses complaining to his wife, who had left him (and was included on the emails). He would rant about her new boyfriend, complain that she had stolen money from him and wouldn’t visit with his kid. It was a bit sad but I tried repeatedly to convince him that I wasn’t the person he thought I was, even going so far as to send him a selfie and asking him if I looked anything like the person he thought he was emailing (his response: yes, but you’ve gained a few pounds! Jackass.). I never did convince him, and he refused to stop sending emails. He told me I should just block him. I suspect he was having some mental health issues and perhaps wasn’t all there. The emails finally stopped. I kind of wonder if he passed away or ended up in a facility without access to his phone.
Thankfully nothing seemed super secretive, but I got a lot of PowerPoint presentations and other things that I definitely should not have been seeing.
Not to mention the countless password reset requests, 1₽ added to accounts from kiosks, etc.
Edit: Apparently some guy found it funny to sign up using that GMail address on a Brazilian dating website. And no, the address itself isn't a Portuguese term or anything.
Luckily, I didn't have any issues. I just wrong a short, blunt email saying this is the wrong email address, I have no relationship with this company, and they realized the mistake and left me alone. That said, this was a European rental car company (and a European collector, I assume). The American ones might have been more aggressive.
https://scheduler.hope.net/hope2020/talk/79JKLA/
Video:
https://archive.org/details/hopeconf2020/20200726_1800_Anato... (you may have to go through the video selector at Archive.org)
On the joys of owning gandrews <at> gmail <dot> com.
On one occasion though, a user from Tumblr had set their account name to my email. I think I forgot about it for a year, until the system emailed me about account inactivity. Upon talking to their support team about the issue, they told me just to reset the password and deactivate the account. Feels weird closing an account that I don't own and the owner has no access to.
Usually I just send a polite response or flag it as spam; but the time I got a Covid-19 test order I called the doctor.
Same here. In the last few years, I've had a Toyota dealer send me quotes for new cars ("as per our meeting yesterday"), I've been looped into ongoing business conversations about negotiating bulk rates for importing doodads from China, and have even received a job offer as a junior dealer at a brokerage. This last one had a CV for the job applicant attached so I could see the applicant's actual address and forwarded the mail to them.
I've only done "polite" replies if there's clear innocence. One was to a teenager trying to guess email addresses for people involved in a college program they wanted to attend. Another was a Canadian regional employment authority trying to collect back wages from a deadbeat employer.
But someone uses my email address at a repair shop, salon, ect? Ignore. Someone puts my email address into a group discussion? Spam.
I also own my own domain. (legal name)@gmail.com sat idle for years until I found that it's easier to say "(legal name)@gmail.com" instead of ??????@(legal name).com Then I switched.
Apparently, one of them is a doctor with a caribbean bank account. I was getting monthly balance updates for years.
I get confirmations of automobile service appointments and a bunch of other things.
Once, I even got an email from someone saying "This is MY name."
Occasionally, I get alerts on my phone that someone tried a password recovery. I gleefully decline and go about my day.
My name is neither common nor uncommon but I'm glad I got here first.
The most surprising thing I had was someone who signed up to an Amazon account using the address (my own amazon account has always used a different email address). Whoever did that literally gave a complete stranger access to their credit card. (I contacted Amazon and got them to remove my email from the account).
The worst thing is that people continue to accidentally sending these mails for me, even if i ask them to stop.
I did exploit this exactly once, someone signed me up for Spotify (free tier) which wasn't available in my area then.
I used to get an insane amount of mistweets around the start of every year.
We get lots of interesting stuff. Ironically, most of it is because Apple routes icloud.com and me.com to mac.com, and there's no way (short of a mail rule) to reject that.
It still seems to get daily private communications, including private information between lawyers and their partners and cients, and doctors and clients. It's kind of amazing.
She was in a retirement community and in her 80s was Chair of the Computer Club and used to do orientation for new people. She quickly realised that she needed a yahoo account as when she showed them her one they all asked - "how do I get one of those!"
I have never understood the cache or appeal of having a particular address at Gmail or Yahoo or Outlook or whatever. By the time Gmail happened, I was already many years into using my own domain for email. Why would I want an address at an advertising company?
Still, amusing tales.
I used to receive 1000s of email per day for the wrong person, including chat requests from MSN messenger.
I eventually traded for 10 invites in a forum when gmail.com was invite only.
Best trade ever.
I mean, sure, it is spam to you, but I doubt you could train a decent spam filter for this situation. Maybe a whitelist, but that's about it.
That is the only time I have done that.
Add I Get a forgotten password once a week for some random account that isn't mine.
They ended up being completely overtaken by spam, but I wish I still had "alex@aol.com" if just for the novelty.
Until I blocked them, I was receiving password resets about 7 times a day, every day.
But I like to sit on it, just in case :)
C=UK CN="NAME"
My Boss had the set up BTW
I get a bit of that stuff.
Occasionally, I also get a bit of skepticism when people ask for my email.