4 ms·
> Hammer the Netflix signup form until you find a gmail.com address which is “already registered”. Let’s say you find the victim jameshfisher. The bug is right
by Splines 8y ago
> Hammer the Netflix signup form until you find a gmail.com address which is “already registered”. Let’s say you find the victim jameshfisher.
The bug is right here - you shouldn't be able to determine if a user account already exists.
If an account already exists:
- Logon shouldn't tell you that you have an account and the password was wrong
- Registration should send a "looks like you already have an account" email to the recipient with "maybe this wasn't you" warning, and the web form shouldn't indicate anything out of the ordinary.
- Password reset should say "if an account exists, we just sent it an email"
- sankalp_sans 8y agoFair warning. That does add a certain level (quite significant) of inconvenience to existing users though. But probably a happy trade-off for most people entrusted with protecting accounts.
- slx26 8y agoAgree that many steps can be improved. In real live, though, it's not so difficult to guess/find someone who has Netflix, and also find their email. That's a really weak security requirement, security shouldn't depend at all on that part (it seems more relevant for privacy to me)
- pryce 8y agoFurther, it is trivial to picture an attack where through some other channel, the attacker already knows the email address of their target, and has the knowledge that this victim has a netflix account. If I only need these two pieces of information, neither of which is intended to be 'secret', then I might easily already have enough information to attempt this attack on (for example) my ex, or their new partner, or someone at either work or university that I dislike, even if I didn't have enough information to target a random person in another country. It is good practice not to expose user's email addresses to attackers. It is breathtakingly bad practice to depend on those email addresses being secret.
- pttrpttrwttr 8y agoI really don't see why Netflix needs insider knowledge or whatever to be able to detect john.doe as being the same as johndoe.
- SlowBro 8y agoI believe it’s because this feature is largely unique to Gmail? So Netflix would need to know and maintain a database of rules based on domains. * Gmail: Dots are cool. * Hotmail: No capes! I mean dots. No dots! * Multiplied by 8 hundred gazillion domains...
- DataWorker 8y agoYou’re thinking too much like a programmer. It’s a single rule for a single domain that accounts for the majority of users. The right thing to do is ask for a password, but absent that, accounting for gmail addresses seems worthwhile. It would save them getting a thread like this on hn.
- patcheudor 8y agoNo database needed, just ask for e-mail validation by sending an account validation link to the e-mail. Problem mostly solved.
- hanspeter 8y ago> the web form shouldn't indicate anything out of the ordinary How will the user know that the registration failed and what to do about it?
- spinsser 8y agoUpon entering a valid email (whether it is already registered or not) the form will show the following notification "an email was sent to user@email.com with the sign up instructions, please follow the link in the email to continue the registration" (rewrite for more concise message) If the user already exists the email will be a warning + a link to the password reset form If the user does not exist, the email will be a link that confirms the ownership of the email address and the rest of the registration process. An attacker trying to guess if an email is registered would not know, because the form does not give away that info.
- hanspeter 8y agoGot it.
- EGreg 8y agoWhy is it bad to know if an email is already registered?
- barking 8y agobecause if you know someone's email address you have now also discovered that they have an account with a particular service which you should not be able to do.
- bostik 8y agoFurthermore, people reuse passwords. So of course there are a number of known-good login/password combination lists in the wild. As soon as you find a valid login, you can test all known passwords (plus variations) associated with it.
- factsaresacred 8y ago> Registration should send a "looks like you already have an account" email to the recipient with "maybe this wasn't you" warning, and the web form shouldn't indicate anything out of the ordinary. Well that wont work. If you can't register with an email it's obviously because an account has already taken it.