5 ms·
This happened to a friend. His life was destroyed. The only person he could talk to was the FBI. They told him they get dozens of calls about this a week. On to
by fswd 5y ago
This happened to a friend. His life was destroyed. The only person he could talk to was the FBI. They told him they get dozens of calls about this a week. On top of that, there's a exploit that allows anyone with a dot in their email to receieve any other person email it's been active for 19 years. Google doesn't care what so ever. Google has the worst infrastructure support. There probably needs to be regulation that if your a company making over 1B a year in revenue, you need to have a basic escalation procedure and human decency... or you can't make any tax deductions, and it claws back 10 years, and it applies to all share holders who own more than $1M in stock. Suddenly, they might answer the phone!
- Jerrrry 5y agoNot an exploit, it is intentional, and ironically, is a countermeasure against phishing. We all dread the day our Gmail password stops working, but this is what we signed up for. I know my gmail is safe, because I know that without the password, not even I can get into it. This is by design.
- tweenagedream 5y agoIndeed, it's a publicly documented feature: https://support.google.com/mail/answer/7436150?hl=en#:~:text=Your%20Gmail%20address%20is%20unique,for%20j.o.h.n.s.m.i.t.h%40gmail.com https://support.google.com/mail/answer/7436150?hl=en#:~:text....
- hda111 5y ago> is a countermeasure against phishing How can it prevent phishing?
- paddez 5y agoTaking a guess - If your Gmail address is larrypage@gmail.com - it prevents someone creating a completely different Gmail address like - larry.page@gmail.com - and using it to impersonate that other account. I think it's complete conjecture that it's meant to be some kind of anti-phishing method - the solution there is just removing the ability to create addresses with periods - but I guess this way has some kind of utility for users?
- paxys 5y ago> there's a exploit that allows anyone with a dot in their email to receieve any other person email it's been active for 19 years I'm not sure I follow? This isn't an exploit, but a feature of Gmail. It doesn't allow you to receive anyone else's email.
- logosmonkey 5y agoyeah, it just allows you to receive email from people who don't know their email address. I have my full name @gmail and constantly get folks who send stuff to first.last@gmail
- fswd 5y agoSomehow there's a Google service (I am guessing mobile) that allow you to register firstl.ast@gmail or f.irstlast@gmail, and then they will both get each other's email. Fundamentally if you allow any account to be created with a dot and without a dot (two accounts), but filter out the dot in the email received, it will cause a problem. The dot is one to one with the account, but filtered out becomes one to many with the email. Nobody seems to notice this logical issue.
- uxcolumbo 5y agoMy understanding is… John.Doe@gmail.com, JohnDoe@gmail.com and J.ohnDoe@gmail.com are not 3 different gmail accounts. It’s one account with multiple dynamic aliases using the dot.
- jaredsohn 5y ago>Adding dots doesn't change your address, so dots aren't why you got someone else's mail. Instead, the sender probably mistyped or forgot the correct address. From the link in the other comment in this thread
- Throwthrowbob 5y agoI received a few e-mails from Playstation/Sony recently that were intended to go to <firstnamelastname>@gmail.com but I received them at <firstname.lastname>@gmail.com. I tried doing a password recovery of the account (to see what I could do to change the address, or contact Playstation) and found that on their end, firstnamelastname@gmail.com and firstname.lastname@gmail.com are treated differently: Both gave the message that a reset e-mail had been sent. Only firstnamelastname@gmail.com caused me to receive an e-mail. So Google (and other e-mail providers, like ProtonMail) ignore the dots, but it's possible that other companies don't ignore this. Resolving the Playstation account required calling their support line for about 30 min, talking with an agent, and then replying to an e-mail generated specifying some information to confirm that I hold the e-mail account. They seem to already have the option for reporting misuse of an e-mail address.