Stupid Patterns
darshit.dev
darshit.dev
I was able to track down his actual phone number and on Facebook. Messaged him and explained to him. He wouldn't act. He said he intentionally gave a random number since he didn't want to be bothered by their phone calls and asked me to "deal with it".
Finding no other option, I used Tata sky IVRS service calling from my mobile number(linked to his account) to subscribe to a bunch of expensive channels, totalling the monthly subscription fee to 10x of what his usual fee was.
He reached out to me requesting that he be allowed to take control of his account, as he is unable to change the phone number linked to the account, without an OTP (one time password) received on the existing number (which was my number).
Did take some sweet revenge by not responding to his request for a while, but eventually gave him the OTP after a week.
So now I get multiple password-protected monthly statements every month, and there is no way to unsubscribe since it's a bank statement. And the email subject doesn't have the full account number, and the email is from a no-reply address. Contacting the bank has been useless even when I found a way to do so. The most annoying one is from a bank where I have an account of my own (they used a capitalized version of my email address, which the bank thinks is a separate email), and so I can't block them all emails from this bank either.
The one fun time was when someone (in Asia) would frequently place food delivery orders using my email, and this service would send multiple emails for each order. Frustrated, I canceled their order once directly from the email, after which this particular problem stopped.
These are handled differently than message user agent filtering. Incoming messages are immediately rejected and the sending server is notified.
It's much easier than trying to contact some company that doesn't bother validating email addresses. You already know they are technically deficient so just bounce everything. Problem's at their end, let them work it out.
Fastmail do this, as do a few other hosted email providers. Highly recommended. I also use Sieve filters to reject attachment types beyond the default set, such as Microsoft Office files (.docx, .doc, etc.).
Here's some documentation to get started. No affiliation, just a happy customer. https://www.fastmail.help/hc/en-us/articles/1500000280481-Si...
This is, presumably, a crime.
I have a very common name and a very common surname and people have used my email (name.surname at gmail.com plus the infamous GMail variants such as namesurname or NameSurname) for purposes like accounts on dating sites, Spotify, Instagram etc.; invoices; banks and insurances; resumes and job applications; medical test results; newsletters and all kinds of personal communications.
"I" am a local politician, a Swiss or Italian banker, a boyfriend deserting some girl in Argentina, a rugby player, a professor or two; "I" buy screws, magic tricks, diving suits; I know several of "my" birth dates and addresses and I have easily identified a couple of correspondents.
In most cases there is no practical way to verify email addresses, particularly if the person is really convinced that their email is the wrong one or that some approximation is allowed, and without actual payment collections coming your way little harm is done.
I sometimes complain to web sites with inexcusable confirmation-less registrations or reclaim accounts on services I might want to use, but for the most part I just let incorrect emails accumulate to play the passive game of collating them and consolidating identities (e.g. is the person who follows cooking courses in a certain big city the same who received from a friend bus timetables for that city?).
It's interesting to think about how the very basis of our internet identities, that is the email, can be so easily abused by someone who has bad intent.
What's wrong with "Click the link in the email we just sent to x@x.com to verify your email"?
But it could be mitigated by "click the link and enter the one time code we gave you at sign-up time". Too much friction? How about "click the link on the same browser you used to sign up, and we'll verify that using a cookie we just set" - functionally equivalent and probably works for 90% of users while the rest can fall back to the one time code.
I've seen a handful of sites do something like this in practice. No idea why it's not more common: presumably most people don't roll their own verification process so if some major web frameworks adopt it we'll eventually see it more widely.
Oh boy. Auth is that thing that looks so easy because you just need to store an md5 password to feel like hackerman. If people actually used existing solutions, web logins wouldn’t be in such dire conditions.
Not all careless stupidity should be attributed to the website admin, however: assholes using random email addresses and phone numbers deserve to be punished, and knowing one's own email addresses is a basic literacy requirement.
My most recent one was Apple telling me my id was reset by my request. This definitely came from Apple, was verifiable... But it turned out some person entered my email on their support case and it almost gave me access to their entire Apple account, the support people were willing to go through everything with me as I had the email.
It was only when I asked for the transcript of what I'd apparently said to them that alarm bells rang on their end and they finally investigated enough and escalated enough and determined my email was not the one that had anything to do with the account in question.
Mostly I ignore the email I receive, but once in a while it has enough details that I can find the person involved and give them their train tickets, or car insurance docs, etc.
> You may need to create an account.
> We received a request to reset your password on BestBuy.com.
> However, we don't have an account associated with this email address. You can try to sign in with a different email address.
> You can also create a new account using any email you choose.
> Happy Shopping!
My guess is that it's a bad actor doing something like password stuffing to try see if my email address has an account there that they can try compromise. It's also possible someone thinks my email address is their email address, I doubt it though because in the 16 years I've had the Gmail address I've never received an email intended for someone else.
Regardless, I've never lived in a country in which Best Buy operates, but some "genius" at Best Buy thought it would be a brilliant idea to email people who they know don't have an account with them, because there is no way anyone would ever try reset a password for an account on an email address which they don't actually have access to.
After getting these annoying emails a few times I landed up making a Gmail rule to always report them as spam, then delete them.
I think you overestimate your less computer savvy fellow humans :) Also it could be phishing?
BestBuy is considering two different scenarios and trying to handle both:
BestBuy is avoiding leaking account status on their password reset page. This is done precisely so that people who don't have access to the email account can't figure out where you have accounts registered. This is a pretty standard approach.
BestBuy is providing visibility to people who can't remember if they have accounts or which email they signed up with. Simply trying to reset your password and never getting an email leaves you in a situation where you are unsure if you waited long enough, missed the email, the business is having deliverability issues, or if you have an account. Having worked with businesses around reports of password reset email deliverability issues, it makes complete sense to me.
This all seems like a perfectly reasonable approach.
Instead they opted for the option where every time a "hacker" is trying to use the form to compromise an account, it spams the victim with this email. As most of the world is not North America, it is statistically most likely that the email recipient is someone who's most assuredly never going to be a Best Buy customer.
What course of action could be taken when you get an email like this indicating a "hacker" is trying their luck to see if your email address has an account on BestBuy.com even though you don't have an account there (and probably never will)?
I've had my email address for 16 years, lots of "hackers" are aware of it due to account list leaks from various services I have used over that time and there is an entire industry which tries to compromise accounts from these lists.
If I got notified of every automated script's failed attempt to do something malicious involving my email address, I would probably get several notifications a week, possibly per day, all of which are probably unactionable.
So to answer your question, no, I most definitely wouldn't want to know about someone trying see if my email address was used for an account on some random website I'll never use.
On the the other hand, if a password of mine was being used by a "hacker", that I would want to know about.
> This wasn’t even a spam email!
I disagree, if it's not intended for you, then it's spam. Marking these emails as spam might affect the company's delivery rates and get them to actually fix the broken process that allowed this to happen.
Often these e-mails are not actual phishing attempts, they are just things made by absolutely phenomenally clueless hacks.
So there is this company that does e-mail list services called mailchimp. Apparently, by default all e-mail from their customers comes with links to a site something like "mandrill.com".
If mailchimp is that clueless about security, do you really want to let them manage your password login setups?
There is a stock-market accounts company, Carta, that uses mailchimp.
Do you really want your stock market holdings managed by a company clueless enough to let someone as clueless as mailchimp to manage their password login setup?
These companies aren't verifying that the email was entered correctly.
So I continue to get notices about what this person is doing even though I've reached out to the companies and this person to try to notify them of the error.
and then ask me to prove my identity to them?
Say, my bank calls me and ask to call back with an extension#. I look up their phone # on their website, call that number, and provide the extension.
They know who I am via The extension # I gave back to them, I know who they are via their phone # confirmed by their website SSL certificate.
Alternatively, I call them back on the phone number at the back of the credit card.
The most surprising offenders I've gotten were discord and spotify! Both of which were easy enough to resolve (I just requested the accounts be deleted, and then re-created for my own use).
I get misdirected emails like this at least multiple times a week.
Sounds like a really nice startup idea.
By any chance does the numeric component of your e-mail alias form a shape on the 10-key pad?
https://shkspr.mobi/blog/2021/10/ebcdic-is-incompatible-with...
Not a lawyer but I imagine this is a similar sort of situation and the same reasoning would apply.