4 ms·
Given it is your email that is being used, that should allow for you to take over the account(s)? I'd submit a password reset, change the password, then just al
by barkerja 3y ago
Given it is your email that is being used, that should allow for you to take over the account(s)? I'd submit a password reset, change the password, then just allow the account to live a dormant life.
That of course doesn't make it any less annoying, but it would at least stop an actor from using an account that is associated to your email.
- callalex 3y agoBe careful, in the USA that is still a violation of the CFAA and US courts have proven themselves to be technically incompetent time and time again. People have been sent to prison under CFAA for using the “view source” button that’s available in every web browser.
- l33t7332273 3y agoWhich case did someone go to prison for viewing the page’s source?
- jetbalsa 3y agoI think they are talking about this case, it was thrown out. https://www.theregister.com/2022/02/15/missouri_html_hacking/ https://www.theregister.com/2022/02/15/missouri_html_hacking...
- fragmede 3y ago> Governor Parson's office maintained that Renaud had unlawfully hacked the school website: "The hacking of Missouri teachers' personally identifiable information was a clear violation of Section 569.095, RSMo, which the state takes seriously. The state did its part by investigating and presenting its findings to the Cole County Prosecutor, who has elected not to press charges, as is his prerogative." It wasn't thrown out by a judge. The governor still maintains that the reporter "hacked" and violated state law but the prosecutor's office declined to pursue the case.
- l33t7332273 3y agoMy understanding of the law is that a judge would throw out the case as well
- deleted 3y ago[deleted]
- Izkata 3y agoDoesn't exactly work when they use your email to create an Apple iCloud account. It needed the actual iPhone it was connected to to complete the reset, I think I ended up getting it into a weird unusable state where neither of us could log in.
- elif 3y agoFor Experian accounts, doing a password reset requires an SMS or phone call code. The only mechanism you have to alert the person usurping your email identity that there is an issue is to trigger the phone call verification 3 times per day, preferably around 4am. If you call the phone support, it will give you robots until playing a pre-recorded message telling you to physically mail a legal request including copies of your ID etc.
- toomuchtodo 3y agoFile an FTC and CFPB compliant. Only regulators will light a fire. Experian isn't going to do anything due to consumer complaints, as the consumer's credit file is the product. Let someone from Compliance have to email the product owner about it, and the complaint starts the clock ticking. https://reportfraud.ftc.gov/ https://reportfraud.ftc.gov/ https://www.consumerfinance.gov/complaint/ https://www.consumerfinance.gov/complaint/ https://www.youtube.com/watch?v=9CWbc6pekd8&t=1310s https://www.youtube.com/watch?v=9CWbc6pekd8&t=1310s ("We have a complaint database, we collect information, and are always eager for information" -- FTC Chair Lina Khan at Y Combinator)
- NikolaNovak 3y agoI've been tempted. But 1. That exposes me to MORE involvement with this service, not less, and potentially legal culpability. Risk may be small but impact is large and benefit is neglible, so math doesn't work out for me. 2. It requires MORE effort on my part. For a poor design and error made by not me. If it were once every 5 years, maybe. When it's weekly, it's just an annoyance. Sometimes when I'm really angry, I just write to their gdpr or compliance officer with a stern better and links to various sections of the law and their obligations. Doesn't accomplish much but makes me feel better :-) But overall, it's a systemic issue, and given we are on hacker news, I'd say it's OUR systemic issue caused by us :-/