"Just the fact that you listed your emails says it all."That is just awful, and is an awkward example of why you may not want unpaid, mostly un-vetted volunteers as the public face of a company.
I was wary of this thread showing up on HN because I felt I was a bit unkind when posting in that thread, but Chris' comment towards me seemed completely unjustified. And he deleted a prior post along the same lines, hence why I quoted him on my next post.
You mean that tim-somespecificsite@mydomain.com was randomly compromised, but NO OTHER random email was mailed to me? No, that's not how spammers work. If they'd decided to spam tim-*, I would have gotten hundreds of emails...sigh...
Tangentially related: It drives me nuts to deal with people whose default answers are "no," "you must be doing it wrong" and so on. Particularly the moderators who insisted someone must have guessed a ten digit random email address -- because Dropbox and its vendors couldn't POSSIBLY have ever done anything wrong, and it's MUCH more likely that a spammer magically brute-forced a 10 billion combination address! Grrr. I'm not sure what the right word is to describe that sort of personality, but such people should never have contact with customers. Or with me.
On a side note, why the heck does dropbox have volunteers running their support forum? At this stage, cost savings isn't worth the reputation hit.
If I had to guess - I'd suspect three or four "nines" of their customer support workload comes from their "free tier" non-customers. (Having said that, there's evidence upthread in these HN discussions saying they're also dropping the support ball for paying, even team-account-sized paying customers - that's not OK...)
The guy who says that he had a truly random bunch of letters as his dropbox account is probably a better indicator, but it's hard to know if the guy ever leaked it himself.
Doesn't excuse the moderators being jerks, though.
When an address is "compromised" and starts to receive spam, I move the line to a "banned_recipients" file with an SMTP reject header listing the new email. That way, a human using an old address would get a bounce back with the new email.
[1] so that the argument about bruteforcing "common-service@domainname" can be avoided
I'm running with this rule in the access map:
/^from-.*@foobar.com$/ OK
That accepts all mail to an address prefixed with "from-" and (by default) rejects everything else. This way you can just make up the dummy-addresses on the fly.I remember being slightly worried about using such a simple prefix when setting it up initially. However I have never received mail to a from-* address that I didn't "create". Not once in over 6 years.
And disabling an address that has turned spammy is as easy as:
/^from-stuffit-expander@foobar.com$/ 554 No thanks.Even though a service might desperately want to know my personal and/or business email address, and disguise that desire with the usual "Hey, just use your email address as your login username!", doesn't mean I have to comply. Unless they're prepared to accept responsibility to disclosure of my address, I feel perfectly happy taking the required measures to minimise those risks myself - no matter what they attempt to enforce with crappy email validation or ToS requirements.
(And, although Dropbox have finally arrived in their forum-thread ~24hrs late apologising for their "community moderators" calling their customers idiots, the responses from Nathan and especially Chris only strengthen my resolve to ignore any attempt by companies/services to gain access to my personal email addresses as part of their user databases.)
Do they in fact do this?
Yahoo! Plus has a much better system where you use a different base email address plus the sub-address rather than your regular address.
For example, if my account is "somebody@gmail.com" then you use somebody+dropbox@gmail.com. But with yahoo, you pick an alternate, e.g. "huggybear", and use that instead (huggybear-dropbox@yahoo.com). That way if a spammer seems the sub-addressed account, they can't send email to huggybear@yahoo.com unless they want to end up on Yahoo's blacklist.
I've had a great deal more success with Yahoo's sub-addressing than Google's.
So in my earlier example, if you wanted to sub-address ebay, amazon and hackernews you'd have huggybear-ebay@, huggybear-amazon@ and huggybear-hn@.
The big deal is that huggybear@ != someone@ and sending to huggybear@ won't reach someone@ and likely earns you a place on their blacklist (or some points towards ending up there).
The fact that the guys email was blah.dropbox@blah.com meant it was a possibility that another site had been compromised and the email matched a keyword filter which allowed it to be easily guessed.
Its like passwords. MyPASSW0rDdropbox. If this is leaked it is fairly likely someone may try.. MyPASSW0rDfacebook.
They failed a bit further on. One obviously misread the thread and made a comment which isn't really acceptable.
Generally though it is the typical user forum thread. User repeatedly hammers the moderator with the same question. The user cannot elaborate. The moderator can only speculate due to lack of information. User doesn't find moderator answer acceptable, provides no further information and asks the same question.. both sides get annoyed.
It seems like the spam is to do with the data that Dropbox previously lost. An answer which a moderator actually provided.