4 ms·
Likewise I have no fewer than three people trying to use a gmail address I've had since 2003 as their own. It's extremely frustrating - one even sent me $45,00
by maxk42 4y ago
Likewise I have no fewer than three people trying to use a gmail address I've had since 2003 as their own. It's extremely frustrating - one even sent me $45,000 in a mistaken paypal transfer and then when I reversed the charges I was hit with an overdraft since I had made a Paypal purchase (which would ordinarily come from my direct bank funds) not knowing the money had been sent to me in error.
It shouldn't be this easy to use someone else's email address.
- metadat 4y agoThat was nice of you, you probably could've kept the money and there isn't much they could've done. Ask me how I know :( PP money was not recoverable that one time my ex sent it to the wrong email address.
- maxk42 4y ago(Meanwhile, Google flags every log-in from my daily Linux driver as a potential security issue. Madness.)
- xoa 4y agoI have an old 7 letter gmail address, not an English word even but it must mean something in India and someone must have used it because for years I got eye-opening stuff, full color scans of national IDs, job applications, business proposals, invoices etc. At first I tried to send messages back explaining but in the end I just had to block it all, didn't have the time. >It shouldn't be this easy to use someone else's email address. This though, seems hard. I don't think this is a "security" thing per se (though I dearly wish there was a modernized "email" system built with modern crypto from the ground up). But for any sort of communications at all it seems like there is an inherent tension between how low friction one wants for the world to communicate vs protection. Like, there is nothing stopping anyone from doing a pure whitelist system for email right now. I even do in fact do that for a few accounts like specific ones for client contacts, only active client addresses will be accepted everything else is blackholed. Those obviously receive zero spam or misuse of any kind [0]. But obviously the tradeoff for that is no new potential clients could ever "cold call" it either. One could imagine technical solutions like "only accept stranger email from accounts with a signed ID" or "vouched for by known address" (ie, WoT) or "only address with a signed time token >N from providers X, Y or Z", or some kind of challenge/response, but all would have privacy tradeoffs, complexity, and still wouldn't inherently do anything about honest mistakes. We could have more powerful options for this, but it'd still involve subjective tradeoffs between how open to new communications one wants to be vs cutting down on noise. No one right answer there. ---- 0: Forged from fields are of course possible but in practice someone would at the least have to know which handful of the total planetary email addresses were whitelisted, never mind flags that show up in the headers from that
- fragmede 4y agoWhen using Gmail to compose an email, sending to another gmail user, it shows me their profile icon. This has stopped me from sending to the wrong firstname.lastname@gmail.com variant several times. I don’t know if other providers do this but it’s something.