Gmail might partially be to blame for receiving emails from other Sean Conners
boston.conman.org
boston.conman.org
I registered the `fname.lname` version very early on (before GMail was freely available), and while I do sometimes get emails sent to the `fnamelname` variant, which is consistent with someone having signed up with that variant, but is also consistent with someone just forgetting what their email address is (eg, they meant to type `fnamelname@hotmail.com`, or `fnamejlname`, or whatever). Especially since the mixups are very, veyr rare.
I can't rule out some weird collection of google bugs, but Occam's Razor suggests it's just an occasional typo. Especially until someone pulls up two screenshots of Google accounts showing colliding addresses.
There is an older man, late 60s I think, with that name. I receive his email at least once a month. I have received sensitive emails, and I could no doubt perform some sort of computer fraud with those. He is not forgetting his email and putting a period in between the first letter of his name and the rest of it.
The Google ecosystem is vast. Somewhere within that ecosystem is one or more components that strips and/or ignores the dots, and for that split second his email and mine are identical.
In Google's account system, there's ~nothing you can do with just the username. You need a user id. The only way you can get a user id from a username is to call an RPC service to do the lookup. Doesn't matter whether it's for logging in, finding the account to deliver email to, creating an account, or whatever. Everything goes through that chokepoint. And that RPC server will always normalize the username at lookup time.
(I probably read that normalization code more often than anyone when working at Google on account security stuff, since that was the single place that had any reason to deal with usernames rather than user ids. That code was effectively immutable.)
I registered my Gmail account very shortly after the invite-only public beta began, so my Gmail username is simply my first name (in this example, it would be john@gmail.com). Believe me, I know a thing or two about confused people giving out email addresses that don't belong to them.
Importantly, the dot-normalization rule was there from the very beginning. You learned about it alongside all the other kooky ways Google had decided to reimagine email, including 1 GB of storage, conversation threading, and an interface with a prominent "Archive" button but no visible "Delete" button.
The type of messages I receive are typically one of things like hotel, reservations, e-commerce shopping receipts. Likely someone misunderstands the address or misses a letter in between. Maybe alerting everone from myfirstnameAmylastname… to myfirstnameZmzlastname@gmail.com helps them take better care.
I've seen some fairly convincing evidence to suggest that different people have been able to register fnamelname@googlemail.com and fname.lname@gmail.com and, for them, the usual rule that you can add a '.' anywhere before the @ doesn't hold true.
I would like to see some of the evidence that two different people are logging in to accounts that are only different by periods.
From the various reports, including by people aware of gmail's stance, gmail may have had a bug allowing it at some point.
I think these are simply people who cannot believe that someone might give out an email address they do not actually own, either because they are confused or because they make one up on the spot just to fill in a required form field. So when they receive messages intended for someone else but addressed to another variant of their own address, they treat that as proof that the intended recipient owns that variant. In reality, people giving out email addresses they do not own is extremely common.
I see a lot of people swearing up and down that they have seen proof that such a Gmail bug exists. But whenever you dig into the details, it turns out that all they have actually seen is emails intended for someone else arriving in their inbox. There is never any direct evidence that two people were able to register two Gmail addresses that normalize to the same canonical address.
I paid 1.4€ or something on ebay back then for an invite and got a very common first.last@gmail.com, I’ve gotten everything, invoices, investment information, medical data, private photos, etc., though it has been getting better in the last few years, besides boring transactional mails and account recovery etc, I now only get such mails once or twice a year, used to be a monthly occurrence. Probably helped that I always wrote back and corrected those people ;)
I’m pretty sure the ignore the dot rule has always been there.
They've always had the "ignore the dot" semantics and it's sometimes even useful for testing, same as the plus-for-tagging.
On the plus side I did manage to save a name-cousin's immigration application one time when it went to spam on my account, I though that was a pretty interesting experience.
I also don't think google will let you actually register a new account without the dot, so the privacy leakage is much smaller than you might imagine.
People will forget their middle initial in their email (or others won’t notice it), or they’ll add firstlast as a recovery email or something.
Receiving other people’s email never stops being funny to me. Some of them are grumpy about it (especially the one who paid for and distributed “thousands” of poorly designed business cards.)
More have a sense of humor, and I’ve enjoyed getting to know a few of the other guys with the name over the years.
I have a canned reply to these to try to get them fixed, so there’ve been many opportunities for someone to communicate back.
There shall be none but mine on mine. I have received since day one, 2005 emails at my address meant for others. Their pay stubs, their tax forms, the prospectus for the apartments they want. If I feel like it, I warn them. If I don’t, it goes to the ether. That’s life.
Sucks that you won’t get your loan. Or notice that your bank needs you to fill in a form.
could it be that something changed after the beta? but something also changed much more recently I'm sure of it because it's become a huge problem for me recently!
people are using my email as their recovery email which I have no option to 'unsubscribe' from. someone signed up with chime (a US money sending service) which unless your in the US there is absolutely no way to contact them about removing your email. I ended up going through the bug bounty programme as a last resort because I was receiving all their transactions and even had their address! I've had graduation photos, blood test results, shipping confirmations, beautician appointments, wedding planning (I had to email the vicar in the end and let him know I wasn't the bride being rude!) I get emails from a primary school and I'm invested in the receipts from a garden centre every few weeks though, they have quite a few rewards points now, they're working on their lawn at the moment and the other month they bought two jellycats!
At first I thought it might be someone whose email was at ymail.com but I'm not sure anymore it seems it's not linked to any one country or person either.
You _could_ blame the users for not setting up 2FA. But two wrongs don't make a right, and these websites should always ask for another means of authentication, even if it's just a password. Url parameters in links don't count.
According to Google themselves dots never mattered, not even in 2004.
1. https://webapps.stackexchange.com/questions/14668/why-does-g...
But no evidence has been presented, and it feels very unlikely to me.
I never once considered that a gmail bug or intentional design decision could be at work there. TIL that they decided to cut down on the confusion by normalizing addresses.
However, in practice, there exist many services which have GMail's logic baked-in. Or worse, they get overzealous/underzealous with validating the email.
For example, you decide to sign up for e.g. Netflix as alice@gmail.com, which is the address for a Google account which you own completely.
There exists a small edge case where you want a second Netflix account, so you could do that by also registering alice+netflix@gmail.com. Or a.l.i.c.e@gmail.com. In that case, all the emails to these 2 addresses will be directed to the 'main' alice@gmail.com, as you might be aware of. So you'll get messages for more than one, separate Netflix accounts on the same inbox.
I'm not sure if they had this "plus aliasing" from the beginning, same as their logic with the dots.
When I say that there exist many services which have GMail's logic baked-in, I mean that certain apps will forbid you from registering again as alice+asdf@gmail.com or even a.l.i.c.e@gmail.com, because they want to stop on person from 'exploiting' multiple accounts (though Netflix is not one of them).
It is indeed important to go back to the RFC and understand what you are pointing out:
i.e. That, even though GMail redirects messages from both alice+asdf@gmail.com and a.l.i.c.e@gmail.com to plain old alice@gmail.com, it doesn't make it standard behavior, and this is likely not the case for your home-brewed mail server or your enterprise exchange server, which may treat those as separate inboxes, and this can lead and has led to unintended consequences.
I've been involved in the QA of a system which handles payments for a telecommunications provider. It's very common for the customer to land on a payment page, where he essentially clicks on a link, his telecom's account information is pre-filled, like his email address, phone number, and payment amount, and the customer just has to fill in payment information. So even though the telecoms provider can (and in some instances already has) saved a customer's email with a plus sign, the external payment processor's portal mangles it during parsing, converts the plus signs to a space, and then complains about a malformed URL.
As always, this gets filed as out of scope.
I used to cop a lot of emails intended for first.last@ca.ibm.com to first.last@au.ibm.com.
Senders got lazy, selecting the top most user alphabetically from the list, and then I popped up and just... never changed their behavior or habits.
Would have been less concerned if the canuck version of me wasn't embedded in like a bank or something, and I was embedded with a completely different customer account.
Took it to management when I got "Hey are we good for the firewall to come down ahead of the pentest to <bank> next week" and they did nothing about it lmao.