You can deactivate anyone's WhatsApp account by simply sending an email
twitter.com
twitter.com
- The inconvenience to the deactivated account is minor: one SMS verification code and the account is back, queued messages get received, etc.
- Persons who lost their phones probably don't have a good fast way of proving their identity, as their identity is tied to their phone number in WhatsApp's model.
- Needing to quickly lock out spammers, thiefs or hackers is probably far more frequent than abuse of this feature.
- If abuse of this feature becomes a recurring problem, I'd expect WhatsApp to react and adjust the flow to place more burden on its user.
The auto-delete part is slightly more worrying, but if you don't use WhatsApp during 30 days, your account and group membership probably isn't very precious. Backups are automated and separate. You can still easily re-create an account with the same number then.
The story might be "Apps should stop using SMS and phones numbers as the source of identity", and while I generally agree, most comments don't seem to be about this and WhatsApp is maybe _the_ one app whose success was based on this very idea.
Imagine an automated form of this where you can just mass deactivate antagonistic accounts
This is just an atrocious flow. A better approach would be a "temporary emergency block", and then give the user a week to sort it out, otherwise the account is automatically reinstated.
I agree with you in principle, but I still don’t understand how else to mitigate this: WhatsApp must get a lot of cases of stolen unprotected phones. The victim can ask their operator to lock the SIM card, but their WhatsApp account would still be out in the open.
With the continuous improvements in mobile OS security defaults, I’d expect this scenario to become less and less of a problem, but it must still be accounted for.
The process still goes through support ticketing, so I’d expect a spike to be noticed and stopped.
Can't the legitimate owner recover the account once they get a replacement SIM?
My point to that is that it is true, but the lockout would prevent a thief from using it until the new SIM is received. Versus a thief having access until the new SIM is received.
I use telegram instead of Whatsapp, but I would hate for anyone to have any time at all on my account. I'd prefer to immediately lock the whole thing down and figure it out once I have everything sorted.
Then imagine it. What would be the ramifications?
I wish I had this power for other social media sites, such as Twitter and Nextdoor. I'd just mass-deactivate ALL accounts. The world would be better off.
Give us your number, we’ll all take turns deactivating it every day. Then see how fun it is
Unless I spin up simple automation to deactivate your account every hour.
On top of that, if a specific account is targeted at the rate-limit, a flag could be put in place to let support disable the automation for that account.
If we're talking about deactivating someone's account via email, we are already talking about a targeted attack.
When traveling and using another SIM, it's not always that easy.
I've had plenty of times where I'm offline for a few weeks. Would cut it very close to having my entire account deleted.
I'd like a period where I'm offline for months.
1. Identify to your carrier and get a new SIM, deactivate the old one. 2. Put the SIM in another phone and take back your WhatsApp account.
Isn't this the standard recovery method for apps that rely on your phone number?
Getting a new SIM takes longer than sending an email, but at least you don't have this easy abuse potential.
With your suggested approach, the attacker is free to use the account to impersonate the victim until they get a new SIM card, which could easily take days or weeks.
This seems like a degredation compared to the current abuse potential which is mostly limited to logging you out.
I think it depends on who you ask. IIRC there was a stat that showed a substantial % of people only use WhatsApp rarely and they might not notice the deactivation and/or miss the 30 days deadline, getting their accounts deleted.
Another time I was talking to a credit union CTO who was dealing with someone blocking other people's account access by picking a random account number and making 3 bogus guesses to lock them out. At the time the credit union had a policy that required calling them to unblock... which was a PITA on weekends when people need money.
AT&T dutifully asked 'me' to confirm my email address. I did not.
Aaaand... now I still get all of his account email. So what's the point.
Years. I've closed netflix accounts, I've sent them sms from their telco's webtext portal asking them to stop, and still there's a koneill out there who is very, very confused about why his email doesn't work. I know where he lives, I know what pizza he ordered, I know his name, his phone number, I just don't know his email address. And apparently, neither does he.
The number of services that fail at email validation (or keep sending you reminders, forever, that you haven't validated), blows my mind. For such a simple process, that seems to exist on every single service I (and koneill) sign up for, it has a surprisingly low rate of successful implementations.
I used to get email for a guy in California when he would buy something from Harbor Freight, rent a movie from Redbox, or order a pizza. Those started tapering off about a year ago, so he must have figured it out.
The strangest one was I was receiving email for a colonel in the US Army! For a few years I kept getting these group emails to all these army officers about upcoming training exercises. I thought about replying to let them know they shouldn’t be sending them to me, but was worried about getting in trouble, so never did. They continued for years, but finally stopped. I always wondered if the guy had a .mil address and accidentally used gmail.com.
In retrospect I should have chosen g6adfs789zg2@gmail.com or something.
Not a lawyer, but feels like you could be sued for a) reaching out and clearly mentioning you have some very private information.
How does it work for a paper mail - from what I understand it could be illegal to open any letter originated to some other person's name.
Unless he was trying to extort her he’s done nothing wrong.
Her healthcare provider, on the other hand, could be in some hot shit.
As dysfunctional as the legal system seems to be at times, I'd be pretty surprised if she could find a lawyer willing to try that. At the very least, she'd half to pay a fair amount out of pocket just to initiate the suit, and this is someone who already hasn't shown much persistence in just getting the email address corrected with her provider.
A lawyer would presumably tell her that a case against me would certainly fail, and the healthcare provider has much deeper pockets. Go after them.
> How does it work for a paper mail - from what I understand it could be illegal to open any letter originated to some other person's name.
This is a federal law called "Obstruction of Correspondence" and it is fairly specific to USPS mail. It applies to letters & packages that are either in a postal facility (including the mailbox) or have transited through it. It does not apply to email.
I also started getting a ton of spam from some cell phone retailer in Jakarta - someone used an email address of mine to sign up for a SIM, it seems, and unsubscribing from their crapflood is behind a password, assuming they'd even honor it. I blackholed their mail server at mine, but that doesn't scale.
And I get an endless stream of "a lot has happened since you last logged in" any time I un-blackhole Zuckerbook, and I've never used them.
At this point, every commercial entity I do business with gets a unique email address so I can turn them off. But that doesn't stop the confused/stupid/malicious from using them.
If I can find the time, I've been wanting to write a new milter-type tool to make it much easier to control which mail servers I'll talk. Yes, this is how SMTP dies. But at least it will be usable for me in the mean time.
Sounds like a feature to me!
I'm the recipient of bank statements, cell phone statements, medical information, invitations to parties, and answers to HOA complaints. But more than anything, I'm the world's most prolific subscriber to dating websites, and my taste covers the whole spectrum and back.
I keep using the email address to use for low importance stuff. It's also a good way to see that clicking "Unsubscribe" actually works. Or better, the Spanish equivalent: "Darse de baja". I know the words very well.
After years of trying to make them stop, he just started replying. “I’m not coming in tomorrow”, that sort of thing.
He never lied. He was not going to be at work at Heathrow tomorrow.
I think that finally made it stop.
He argued that I was lying about getting his phone number from his phone bills because he doesn't get his phone bill emailed out to him. I said yes, that is correct. Your phone bill is emailed to me. Eventually I got frustrated with him and told him I was trying do him a favour and he accused me of hacking his email account.
Then over the next few hours he called me back multiple times to tell me he had called the police, how much trouble I was in, and to tell me to stop calling him and harassing him or he would press charges. I pointed out he was the one that kept calling me, and somehow that registered and he never called back.
He did fix his phone account so I don't get those, but I get plenty of other email for him.
I get email invoice every time Orkin goes out to spray a house in North Carolina. No option to say "this isn't me", and I've given up calling to tell them after multiple cycles.
The elderly German couple that would email their train itinerary so that their cousin could pick them up at the station. I would politely reply that I am not their cousin, and consequently their cousin would not be at the station. And six months later we start again.
Someone in Canada with first initial + last name that results in my last name kept getting wired money, and I would get in email with instructions. Of course no "not me" option. I haven't seen one of those in a while, hopefully he figured it out.
And so many more stories of people with my last name or close to it happily sending me their email... But I've had the address for practically forever, and really don't want to let it go.
I got service emails for the same year, model, and color Honda Civic that I own from a dealer in the UK. I am in the US. That alone was spooky.
The car was owned by somebody who matched my first initial, last name email address. (Edwin, I believe…)
I tried to unsubscribe. I tried to contact customer service. Nothing worked.
Each email would come with a little video walk around of the car. Eventually I started responding saying that their paint looked better than my car, etc.
I don’t get them anymore. I presume the owner sold the car.
I've received Amazon gift cards, customs approval for a yacht arrival in Vanuatu, spreadsheets from Iraqi oilfields, children's book reports, pictures of dogs meant to be sent to veterinarians, etc etc.
I know periods don't count, supposedly, but I still get emails for someone with the same name as mine. My email is first.last, theirs is firstlast. I wonder how much of my stuff they get erroneously?
Theirs is probably 'firstlaast' or something - i.e. some typo unrelated to their decision not to separate by '.'.
Interestingly, I can't change the password on one account to the password of the other account. The attempt fails. Which is... somewhat concerning.
On the website go to the Your Account page ("Account & Lists" dropdown -> "Your Account" section -> "Account" link, which goes to https://www.amazon.com/gp/css/homepage.html ) and click "Login & security" to get to it. Same place you'd update your password/etc.
me+folder@example.com
Maps to the account me and will (if configured correctly) put the mail in a folder called folder if such exists.
The reason you might want many accounts with the same email seem many to me if you don't realise that you can create arbitrary distinct emails this easily.
It seems to me like all benefits of the "exact same email, multiple accounts" feature are vastly outweighed by the inconvenience for users simply forgetting that they already have an account, and creating a second one by accident that way.
I mean, even I end up almost creating an account by accident every now and then (mostly on sites using the horrible "signup is the default, login needs one additional click" pattern), and I do so using autofill from a password manager!
Sometimes you can't even contact Customer Services because "your account doesn't exist" (because you cannot feed the correct email address to their customer service site).
Thankfully it's rare, but when it happens it's extremely infuriating.
Gmail supports it. Microsoft does not. Neither does Yahoo/AOL. It likely was not widely supported in the 90s either. It’s a nice hack but it doesn’t solve every problem.
Are you sure it's two accounts? I am using the same login on two different Amazon sites as well, but I'd call that SSO more so than "two accounts on one email address", since all data is separated by country, but the email and password are the same.
Source: I also had Amazon accounts in two separate countries and witnessed the different phases of global logins being implemented.
It was indeed called "Multiple Accounts, Same Email", though I only heard that term applied to it much later (after the phenomenon of these accounts was identified as a problem that the company needed to resolve). I don't think it was exactly what I'd call a feature, in the sense that I don't think anyone expected users to do it intentionally, so much as it was "We don't want to lose a purchase to someone getting stuck at the login screen".
The Web and its users have evolved significantly since those early days, and resetting a password by email is no longer the barrier it once was. Among other reasons: web users are savvy to the idea of having accounts, which was not true in Amazon's early days; and email is a lot faster and more reliable now.
Allowing multiple accounts to share an email address proved to be a problematic decision later on for a number of reasons. Amazon doesn't allow this any more, at least not from the primary sign-in screen; it gives an "Email address already in use" error.
It was really annoying as I would login on my browser to one account normally, but when I ordered an Amazon stick, it came with a different account from a different region preinstalled and would complain I didn't signed up for Prime.
I ultimately fixed the issues by manually changing the email on each account to a different address, but it was very confusing until I figured out what was happening.
Saying he “took it from them” is outright dishonest.
In either of those cases it's just lip service.
https://www.flyertalk.com/forum/travel-technology/952359-tho...
An appalling requirement
Go figure, you can't get a SIM card sent to you from the US to Europe, meaning that you potentially lose:
* Access to messenger apps and chat history
* Access to your bank account (with a special nod to Citi)
* Access to your email account if it uses "2FA" with a phone (looking at you, Google)
* etc
Given that my bank cards and laptop were stolen along with the phone, I've had a Very Fun Time™ dealing with all these systems.
And something tells me short-code SMS receipt (which is what banks use for 2FA) is not going to work well anyway.
a) Porting your number takes about as much effort as moving between mobile phone providers
b) Setting up a sip app on your phone is trivial (server, username, password) - I'm generally a fan of Acrobits Softphone
c) My voip provider has an sms <> email gateway, so my bank (and other sms based) mfa lands in my gmail inbox
But the funnel is brutal. Try signing up from anything but a phone, or try not giving it full permissions, etc etc - and you'll have a miserable time. It's a vicious vicious sweet and alluring Black Mirror episode.
No, you are not the only one. I don't understand how sharing contacts with any app is legal under GDPR without getting consent from all contacts
I don't use $SERVICE. I never want to use $SERVICE. I certainly don't consent to $SERVICE having my contact info because some acquaintance/friend/family member who doesn't know any better tapped "allow" on a button. But because it's allowed, any number of immoral companies like Facebook have my info, even though I've made a conscious decision never to use them due to their privacy violations.
What happened? I logged into an Apple service from the browser on my work computer. I should have known better, I get captchas everywhere when coming from our corporate network, so it's clearly on someone's shitlist. Well, even though my authentication was successful, including the verify-pin-on-device-you-already-own part, Apple said "this is a suspicious connection" and immediately logged out every last device, invalidated all sessions, invalidated the password so I had to change it. I was still feeling the pain from that for a week or more afterwards.
And now I have a simpler Apple password than the XKCD-style one I had been using, because I got tired of typing it in over-and-over-and-over-and-over.
Yeah, should have used, um, who?
Is there no solution to this pain that is actually suggested (designed) by Apple? I would expect there is /something/ that they can do for you for a small, recurring fee.
Apple are the worst UI company in the world bar none.
Sum up the total amount of utterly needless pain and wanton destruction of the time of their customers and nothing comes close in the wide field of "computing". Yet they have the "Good ui" reputation, which is insane.
When people got shocked by this 15 years ago I used to ask them: "Do you know /anyone/ who owns an iPod? Think of them, three names. Now of those three do you know anyone who has not had their music collection deleted by apple software against their wishes? Among those three? No? Anyone at all?"
Nowadays there isn't one example that sabotaged literally every user, instead there a many and it has become which subset of the Apple customer smashes got you? Ask your friends. Note the solution to pay apple more.
Apple are the shiny, vicious trap. Google are less shiny so it is impossible to sustain the illusion that they do "good ui." Microsoft haha. And from there Apple have consistently led the way in the race to the bottom of customer abuse - you've got nowhere else to go! You can't survive the modern world without this stuff! But sure, Facebook, Microsoft, Google are really quick to match and desperate to find niches in which they can lead and Apple copy.
I would wish it on my worst enemies. And I can...
Completely preventable by having WhatsApp 2FA enabled.
So you see, your honor, as a service provider, we did no wrong.
https://www.nytimes.com/2010/09/05/magazine/05hacking-t.html
Meta is such a big company I'd be surprised if the cost of the options premiums were less than the value that could be harvested... but maybe..?
is it illegal? also
— A Man for All Seasons, Robert Bolt, 1960
k thx bye
But not too easy...