By chance I looked into the Prime membership page. An obscure page listed the recent Prime charges. Yep, it's the Prime membership charge. The amount looked odd because tax was added to it, where the old charges were like $119 or $139. Amazon employs a dark pattern of not sending to the users any notification on the Prime renewal, no billing statement, no invoice, no email, just a silent charge on the credit card.
I promptly canceled my Prime membership, not for the money but for not rewarding dark pattern behaviors.
Saw the other day a charge get refused on a credit card I cancelled. 3DSecure is mandatory on it, so I kinda panicked thinking I got phished somewhere, but no, it was just Amazon reusing their authorization to charge a year later. I would have actually updated my info if I had a heads up, but now that my membership has been canceled following the charge refusal, it's kind of an occasion to let it go.
Lucky you who was able to get through the dark patterns in the unsubscribe page. I got one extra charge because the first time I tried, I fell for one of their dark patterns and believed it was canceled while it wasn't.
I gave up and blocked it through my bank and the customer service rep said she had to do the same thing. She also said Amazon will blacklist my credit card ... ummm i dont care I dont and will never subscribe again. Just use a friend or family's account and pick it up from them.
Amazon is stupid for pulling these anti-consumer tricks .. all about bottom line now vs. the future. Stupid!!
Before each subscription payment there after, The Bank reminds us with SMS about the payment and we can cancel it through that. For amount > INR 5000 (~ 60$) each subscription payment has to be approved by the consumer.
Amazon still does employ dark patterns, Like having 'Prime membership cancellation' behind several pages and the final confirmation located in a non-prominent location; But Indians can cancel Prime membership without even visiting Amazon's website.
I don’t think Amazon would be viable today if they dropped their dark patterns and held vendors accountable.
I am at a point where I’d rather go shop at a physical Walmart or Target than buy something from Amazon.com. Driving to a physical store causes me less frustration in 2022.
So a spammer created a project, they put their spam message in the project's name, and started to go through their victim list, inviting each into their project. I suppose that's one way to send an email :-)
It's easy to make money when you can send out thousands of spam emails, each with hundreds of recipients, for under a cent.
What does Google do about them? Making it harder to log in to dormant accounts from new devices and locations. What's the result? Periodic HN complaints on someone unable to access their decade-old dormant account, or an active account with a truly forgotten password, etc.
Anti-abuse is hard. Damned if you do something, damned if you don't.
For dormant account reactivation, they can ask the user for lots of details that are in the account. For example, "please type in email addresses of as many people as possible that you have sent emails to from this account". Which cities have you previously logged into this account from?
All info would be optional, but the more the user provides the quicker they're going to get in.
When the user has provided enough information to be fairly sure that it's a real user attempting to login, then start a 7 day countdown. During the 7 days, contact the users top contacted email addresses and ask them to reply confirming the user is trying to reactivate the account.
Hire attackers to try and break into old accounts, and use their input to find the likelihood of each type of information being correctly given by the real account owner and an attacker.
Also, gmail should never ever by emailing your contacts! It has no idea what your relationship with them is or what information about your actions you want to keep secret from them.
Oh. no. I'd rather they just up an deleted the account, instead.
Google is already painful enough to get into old accounts that you haven't used for a while.
For a dormant account, what's the chances that you're going to remember the email address that someone used years ago? People have address books for that, and the address book is locked on the other side of that password prompt.
> During the 7 days, contact the users top contacted email addresses and ask them to reply confirming the user is trying to reactivate the account.
Yeah, nah. That's awful for several reasons.
It's another phishing-like prompt - "Hey joe bloggs is trying to log into their email. Do you think it's really them? Click here to let them into their account".
If you invert it, then you're at risk of someone with a grudge against you clicking the "No, it's an attacker" link. Even a friend clicking it because they think it's funny.
There's no way I'd want most of the people I email to have any involvement in accessing my account, without me being able to nominate specifically whom the system emailed.
There is no justification in making it difficult to log in to accounts that have never sent spam, that's the user-hostile part of gmail. They have it in their logs which accounts are sending spam.
Sending spam is the last step... The steps beforehand are much more damaging to the user involved. And, sure, you could blame them for reusing their login password, but not being well versed on computer security isn't widespread, nor a reason to punish them.
Locking people out of their account (which sometimes means a large chunk of their real life) with no recourse is very punishing and inexcusable.
The only real solution is not allowing contact form emails to be customized with free text input.
I guess you could have a manual approval loop for "weird" names (more than 30 characters, has a dot in it, etc) or other signs of spam. It would still leave some space for spamming though (I can't imaging a rule that stops "Buy More ETH" but doesn't stop any unusual real name).
I don't know I haven't really probed random contact forms to see if they block this kind of thing.
There's a lot more to do to block this kind of proxy spam entirely for sure I was just talking about the particular problem of using the contact for to send to an mailing list.
I'm sure enough organizations have a mailing list called "customers@company" or "clients@company" to make it worth a shot. Colleges probably have "students@school" or "faculty@school" list.
Might be enough names you can profitably do it by hand.
In a previous life, I worked at a semi-well-known auto publisher site where scammers literally stood up a copy of almost _the entire site_ (ads, functionality, and all) in order to execute an auto escrow scam. We know of at least one instance where a user in the UK was scammed out of ~$10,000-ish using this method.
Democratization of technology at its best (worst?) I guess...
Edit: this was already pointed out downthread. Missed it before I posted.
e.g. this (and many others) AMA on Reddit [0]
[0]: https://www.reddit.com/r/IAmA/comments/9dw73/i_am_a_spammer_...