6 ms·
Maybe unrelated, but I think some people do this to check (at least partially) what email is tied to an account. E.g. if you suspect an anonymous instagram user
by jackbrookes 3y ago
Maybe unrelated, but I think some people do this to check (at least partially) what email is tied to an account. E.g. if you suspect an anonymous instagram user to be your friend Bob, you can invoke the reset email procedure to see
We sent an email to bo****@gm***.com
Which gives you a hint
- dist-epoch 3y agoInteresting hack, but it wouldn't explain the case where you receive multiple such resets emails.
- sammy2255 3y agoCould be multiple different actors doing it
- amelius 3y agoOr some runaway script.
- batch12 3y agoWell.. I have a theory. Maybe the threat actors are sending the recovery email with the hopes that the target does not engage. Then, the threat actor can indicate that they "no longer have access to this email address" to force recovery to an alternate address. Then, perhaps they have gained access to some people's old alternate email addresses either through credential stuffing or recreating deleted email accounts. If so, the TA can finish the reset and take over the account.
- larschdk 3y agoBest practice would be to display this message no matter whether the email address is correct or not, to avoid leaking information. Many sites do this.
- bananapub 3y ago? the comment you're replying to is talking about resetting by *account name*, not email address.
- larschdk 3y agoAh, sorry, I see now, but the underlying point is the same. You should not reveal any information. A "We have sent an email to the address associated with the account" would be sufficient.
- pc86 3y agoNot if you have multiple email accounts. Many times these codes reset in just a few minutes, you should try to avoid forcing users to spend time logging into every single email they can remember just to wait for an email to pop into one of them. You can show a few characters of an email or the first character of the domain to give a lot of info out in relative safety. Everything is about tradeoffs, and the only objectively wrong answer is this dogmatic "never do $X" nonsense.
- Brian_K_White 3y agoIt is not sufficient. The amount of disclosed information, and it's utility, is non-zero, but simply weighs less than the amount of damage from not hinting which account to check. Accounts can grow to be 20 years old and even a "normal" person who is not actively using lots of addresses for security, will still end up having used several in the fullness of time and completely forgotten about some, yet, may still have or can regain access to them if only they knew to go look. You don't see how that can happen or really be a problem? Oh well, consider yourself informed that it does happen and is a problem.
- hathchip 3y agoThe GP is talking about a situation where you are not asked for an email address. You ask for a password reset for the username @coolanonguy. The website tells you that the reset email was sent to an obscured email address. The obscured email allows you to confirm (with high likelihood) or deny (with certainty) that @coolanonguy is your friend whose email address you know.
- luma 3y agoFolks in the thread noted that the recovery code sent was the same each time, which leads me to think it might have been a phishing attack. Send email that looks like FB recovery, but have the links go to some domain you own and snarf up creds, including MFA etc.
- tomhoward 3y agoNot in my case; I've had two password reset emails in the past 3 days (having had none since February) and both have gone simultaneously to the different email addresses I have on the account, with different codes on all the emails (even the ones sent at the same time), and the click-through URL is certainly on the legit Facebook domain.
- jcpham2 3y agoI got one yesterday I ignored
- tonyedgecombe 3y agoI've been getting a lot of those lately. They were easy to spot as I don't have a Facebook account.
- Kiro 3y agoIs that how it actually works on Instagram or was it just an example?
- glenstein 3y agoI actually lost my Instagram account because, I believe, it filled in my email field with a dummy one, user@example.com and then when I had to do verification, I could never recover the account. I believe it was in the very early days of Instagram although it's possible there was user error on my part in this case. It is too bad because for symmetry I used the same use name in a number of places (not the one I have here).
- bluGill 3y agoI lost a yahoo account because I put in incorrect information (I claimed to be 99 year old female or some such thing) and then forgot the password. I never really did anything with my yahoo account though, so it doesn't matter other than I couldn't unsubscribe to some mailing list.
- iforgotpassword 3y agoLost my Yahoo account because it forwarded mail to another account and so I never logged in to it. Then Yahoo deleted it for inactivity ... No warning issued, just gone one day. So now I'm locked out of my YouTube account because it wants to send a verification code to the Yahoo address. Fuck this bullshit.
- matthiaswh 3y agoYou're in luck. Email forwarding with Yahoo is now a paid only feature.
- Cthulhu_ 3y agoA variant I've seen was "We've sent you a recovery code to your email at gmail.com". I think it's useful for login name based authentication, since people will have multiple email addresses and may forget which one they used for that account. (we have a 15 year old who's made at least four, probably more different gmail addresses for different purposes. Ironically, the one he used to sign up for porn includes his real first/lastname)
- aaron695 3y ago[dead]