7 ms·
Not OK Cupid – A story of poor email address validation
- 0xbadcafebee 2y ago> When I tried to unsubscribe using the one-click unsubscribe button in one of the emails, I was met with an error: “Something went wrong, please try again later.” I want to start a blog which is just shaming every company whose most basic functions don't work and there's no recourse. It happens at least twice a day to me. Like a financial services management company whose website can't load my financial information. Or a jobs site that offers me premium subscription but its payments page is broken and I can't even notify them because there's no contact method. Or half the unsubscribes on the internet that never work, or require me to login to unsubscribe but it won't let me log in. Does anyone work at Google? Why is it that, on my Samsung Android phone, when I pull up Google Search in the browser and click the search bar, if I don't wait at least 30 seconds, anything I type into the text bar not only is severely lagged, but then the letters appear in random jumbled order like the cursor is jumping? But if I wait it works fine?? Don't they make billions of dollars? Isn't this their whole product? What the hell is going on over there?! The enshittification of technology is so extreme it feels like the whole web is constantly broken and literally nobody cares. If physical stores didn't exist and it was all online, I think riots would break out.
- toast0 2y agoOn this topic, I signed up for a new bank account online. They did not approve instantly, so I wasn't able to set up an account during the application. No big deal. A while later, they approved the application and invited me to sign up for an online account and do some setup with the account. Of course, I can't do any of that without an account number which they haven't given me. I assume it'll arrive in the mail eventually.
- concerndc1tizen 2y agoNobody cares because the world has been taken over by organized crime, and to them you're just someone to be exploited. And why doesn't an independent company just create a better product? Because they don't like competition. It's a racket. You'll find that your suppliers give you outrageous prices (but discounted rates for their friends), that potential customers refuse to buy from you (you're blacklisted), and so on.
- ThePowerOfFuet 2y ago>Why is it that, on my Samsung Android phone, when I pull up Google Search in the browser Define "the browser".
- ahstilde 2y agoWhat's OKCupid's incentive?
- bolognafairy 2y agoReputation of their addresses, IPs, etc.
- inetknght 2y agoOkCupid is a terrible service. It disassociates real people who don't pay, and encourages fraudulent scams such as pig butchering. Bots are ridiculously easy to spot. You can end up in an endless loop of the same rejects unless you start blocking them.
- dmd 2y agoOn the other hand, I met my wife there and my two children wouldn’t exist if not for it. That said, the OkCupid of today and that of 2011 when I used it are probably quite different.
- ChickeNES 2y agoYeah from what I've heard it's nothing like it was in 2010-2014
- xeromal 2y agoOKCupid in those days had some really cool technical blogs about their processes that's worth reading. https://web.archive.org/web/20101016050944/http://blog.okcupid.com/ https://web.archive.org/web/20101016050944/http://blog.okcup...
- bigstrat2003 2y agoSame, although for us it was 2015. But that is 10 years ago (noooo I hate getting old), and to your point I can imagine it changing a ton in that time.
- RandomBacon 2y agoIt probably started when they sold to The Match Group a while back. I used it a little back in 2014, and again in 2021. The second time around, it was very different. I don't know of any dating companies that focus on matching people versus optimizing for revenue.
- Gualdrapo 2y ago
- commandersaki 2y agoSpamazon did the same thing to me, someone signed up with my email and didn't verify and I couldn't recover the account because of the phone number associated with the account. Amazon was completely uncooperative. Again, similar story with Commonwealth Bank of Australia which is even scarier since its a bank.
- ChickeNES 2y agoSame story for me and one of the major credit reporting companies.
- comrade1234 2y agoJust mark the emails spam and forget about them. If everyone blogged about every spam email they got we’d get articles every day about spam emails everyone got.
- RandomBacon 2y agoI do in Gmail, but half of them will never go in the spam folder such as from Credit Karma.
- kxrm 2y agoHad the same problem with Peacock despite constantly attempting to unsubscribe and mark spam. In the end I just created a filter rule to throw it in spam.
- saaspirant 2y agoI can't find an opinion in Gmail to create a filter to "Always send it to spam". There's only "Never send it to Spam"
- HappMacDonald 2y agoThat might be out of concern of bad faith users abusing such a feature, such as folk who actually opt into a newsletter and then feed the results into such a filter. You can at least "delete" via filter, though.
- nerdponx 2y agoIf you're in the US, I've had success by contacting customer service and threatening action under CAN-SPAM. The FTC has never really provided an easy way to file complaints or request enforcement by the public, but it seems to get their attention all the same. Now is a good time to try to exercise your legal rights against corporations before they are all executive order'ed away.
- 2y ago
- RandomBacon 2y agoCompanies that allowed others to create accounts with my email addresses: PayPal, Apple, Credit Karma, Walmart (I just forwarded the email to legal@ and they took care of that instance very quickly, kudos to that at least). Edit: Forgot to add TD Bank - I actually opened a case with the Office of the Comptroller of the Currency that regulates this bank. Companies that spammed me in the last 24 hours because they don't validate emails addresses they add to their mailing lists (maybe there are accounts too, IDK): NerdWallet, Ace Hardware, Take 5 Oil Change, Boot Barn, Tommy Hilfiger, The University of Scanton, Tractor Supply Company, Kutztown University, and a few small businesses.
- flutas 2y agoAdd AT&T to your first list.
- foresterre 2y agoAlso Uber, I keep receiving mails from users who used my domain, on my catch all mail
- LeifCarrotson 2y agoWhat email are you using that's so popular that dozens of people are (inadvertently?) entering it in all these businesses? Are you "john.smith@gmail.com" or something like that? I'm firstname@firstnamelastname.com, and I have had maybe a half dozen instances in the past decade.
- RandomBacon 2y agofirst.last@gmail. Common-ish English names, uncommon combination, but apparently common enough (did a quick search and there are at least 20 in the U.S.) The Apple one was a catchall @lastname.com (a different first name than mine, but same last name)
- Spooky23 2y agoI have first initial / last name at gmail for a common Irish name. My wife has first name last name. There’s about a dozen people who routinely use my email address. The Washington post let someone subscribe for a year without any validation. One dude lost a job offer because they couldn’t contact him. One woman was the general manager of a factory and emailed “herself” with a VPN client and excel spreadsheet with passwords to access the factory’s IT and SCADA systems. A detective sent crime scene videos. The most recent is a guy in Scotland who isn’t paying his electric bill. My wife had someone who has stolen her accounts via retail employee resets at CVS, Sephora and others. She’s an executive at a big wall st bank, and spends a lot on makeup - my wife got lots of points when she reset the Sephora account back.
- kentonv 2y agoProblem is, if you implement strict email verification, you lose users. Because that step of "please open your email and verify" is actually a big drop-off point in the funnel. No amount of "shaming" people over lax email validation is going to convince them to implement a change that loses them money. Don't get me wrong, I hate it too. Every single day I have to block about a dozen new sender addresses for services that someone has signed up for under my email. Because my email address just so happens to be temporal at gmail.com (it was my teenage gamer tag), and it just happens that "temporal" means "temporary" in Spanish, so about half a billion humans think it's a great throw-away address. Luckily I can very easily identify the emails that aren't meant for me, because they are in Spanish, which I do not speak. Still, I thought that after years of blocking a dozen senders a day, I'd have blocked just about everything... but no, they just keep coming. I've given up on clicking "unsubscribe" or trying to hijack accounts to shut them down, I just go straight to "block" now... But yeah. I've been demanding that people validate email addresses for decades, and can assure you than nobody cares and they're not going to start. The best you can hope for really is that they put a link in the email to disavow the account with one click. I've only seen a few companies do that but I really appreciate it!
- RandomBacon 2y ago> The best you can hope for really is that they put a link in the email to disavow the account with one click. I've only seen a few companies do that but I really appreciate it! That's a great middle-ground, and I think I've only seen that once.
- gmerc 2y agoThat’s not a middle ground at all that offloads the cost of your growth to unrelated parties who are potentially being defrauded. Typical tech ploy.
- toast0 2y agoLook, when option A is actually make sure your user gives you contact info that works, option B is include a link that stops sending garbage for a user that doesn't know their email address, and option C is signing up with an email address results in an unending stream of garbage... I would prefer option A, but I'll accept option B, because it's better than option C.
- yx827ha 2y agoFastmail's masked emails are great! I honestly very rarely give out my "real" email. Usually when I sign up for something I create a masked email, or if I need an email on the spot I use a wildcard alias (xxxxxx@myalias.fastmail.com). Since most of my emails are random, it serves as an authentication additional factor.
- Moosdijk 2y agoDon’t de email domains get blacklisted or are they valid?
- nerdponx 2y agoIt's just fastmail.com, that would be insane to blacklist. Also you don't really use these for sending, it's more for signing up for things and online shopping.
- shakna 2y agoIt certainly still happens though. [0] [0] https://www.fastmail.com/blog/the-internet-blacklist/ https://www.fastmail.com/blog/the-internet-blacklist/
- monksy 2y agoMost of the generalized aliasing domains get blacklsited. If you are going to do aliasing set it against your custom domains. From what I can tell: Atlasian and Stackoverflow try to reject you based on your mx records on the domain (which makes that a problem) There are a few other companies that try to restrict you to gmail or hotmail domains. (Which is even more frustrating)
- ostensible 2y agoiCloud’s HideMyEmail service generates @icloud.com addresses. Very easy, single click. Nevertheless, I still use my personal name at lastname dot com for everything for decades and amount of spam is quite tolerable. Rarely it leaks into inbox. It’s even published on my personal web site in plain text.
- BrenBarn 2y agoOKCupid went steeply downhill over several years and as far as I can tell is now worthless and untrustworthy in every way.
- RandomBacon 2y agoI wonder if they still (illegally?) discriminate based on sex. They used to give different payment plans to men versus women. You used to be able to edit the plan number in the URL to get a better rate, then they "fixed" that, but then all you had to do was edit the plan number in the form action.
- DidYaWipe 2y agoUgh. Then there's the general stupidity of forcing people to use E-mail addresses as user IDs. It's not just annoying, but also a security blunder. The general public can't be counted on to understand that when they're forced to use their E-mail address as an ID, they don't have to use their E-mail account's password for it. That makes every one of these sites a gatekeeper to the user's E-mail account. All it takes is one shitty security regime or one disgruntled employee to expose these credentials. Then there's the fact that everyone's E-mail addresses are on thousands of spammers' lists. When you combine those lists with lists of common passwords and start probing accounts, you have... once again... boatloads of compromised ones. It's sad to see a company like Apple fall into this dumb behavior and then try to patch it up after some high-profile "hacks." Originally, Apple IDs did not have to be E-mail addresses; when they implemented this dumb policy, they wound up with scads of customers with multiple Apple IDs and purchases scattered across them willy-nilly. And when people rightfully complained, Apple huffily declared that it would NOT consolidate them for anyone. Nice attitude: Create a problem and then refuse to provide a solution. But back to the perpetrator here: OKCupid took this to a new level when they started insisting that you provide a phone number. I got into some loop where I couldn't log in and I couldn't log out, because they kept hounding me about the phone number that I couldn't access my account settings to provide. Or something stupid like that. And you know what, OKC? You don't need my phone number, so piss off. It's too bad. OKCupid was the best of the dating sites during its heyday.
- Terr_ 2y agoRelated stupidity: "Security Questions" that enable someone to take over your account just by collecting not-so-secret information that is often shared because the site insists you pick from their own set of questions which other sites have already used.
- torton 2y agoThe best way to tackle "Security Questions" is to generate a passphrase, store in your password manager, and use that for the answer. In the unlikely event you ever need to recover your account with the Security Answer, it's much easier to read out a few words than a 16+ character random password.
- Teever 2y agoOKCupid has another security issue related to email. If you get your hands on a link that they send out to a person's email regarding a match then that link auto logs you into their account and you can do whatever you want with it. I discovered that when a friend of mine forwarded me a match that they had made and I suddenly found myself able to read their messages. I contacted OKC about it and they did reply saying that it was a WONTFIX.
- WaitWaitWha 2y agoI know that in the US has CAN-SPAM Act, GDPR in the EU, and CASL in Canada. I do not believe this would be part of it. Are there any other legal recourse that could be done in small claims court/ESCP?
- monksy 2y agoFor those who are considering aliases to reduce spam in this. DO THIS TODAY. One of my aliases at the vendor Thermpro got compromised by them. I got list bombed pretty badly. Because it was an alias, I was able to turn it off. I got over 2k messages (Most of it "sign up for our mailinglist") within the first 12 hours. Reaching out to the vendor got nowhere. (Pretty sure they don't care that they were compromised)
- commandersaki 2y agoProblem is most email provider web interface and mail agents don’t handle dealing with aliases correctly. For me I’ve found only Fastmail & mutt to be able to handle my 500 email aliases.
- curtisszmania 2y ago[dead]
- gregjor 2y agoI sympathize, I have dealt with this a couple of times, most recently with Coinbase (resolved). I agree that we would live in a better world if everyone on the internet followed standards and best practices, but we will never live in that world. We can expect the enshittification to get worse. When this happens to me I make a filter to trash the emails. No amount of complaining or well-meaning (and in this case a bit self-promoting) articles will make the rest of the world change.
- mecher69Udan 2y ago[dead]
- anotherevan 2y agoUgh, I've got exactly the same thing with match.com at the moment. Some other Evan, presumably with the same last name, used my gmail address. Unsubscription link seems to have had no effect, I ended up just putting a filter in to send them straight to deleted. Over the years I've been signed up for various porno sites, had wedding invitations, college applications, airplane tickets and an ongoing rental dispute all because either another Evan doesn't want to use their own email address for something dubious, or someone has assumed my gmail address must be the Evan they are after.
- AbstractH24 2y agoThis was interesting until the end when it became an advert for fastmail.
- mdaniel 2y agoOn their corporate blog?! How could they sell out like that?
- AbstractH24 2y agoDespite your sarcasm, I don't disagree. Except for the fact I didn't click on this because it was their corporate blog. I clicked on it because it was on Hacker News. And then once I realized it was their corporate blog, I became a bit more apprehensive.
- Arch-TK 2y agoSomeone with my identical full name has for the past few years kept providing my old and unused gmail email address to various entities. This has included banks, shops, and a company which apparently offers training to help you acquire a gun license in Poland. I now know where this person lives (from order confirmation emails). I know this person's date of birth. I also know this person's PESEL (Polish national identification number) because one of the banks "protected" a document intended for this person by using part of the PESEL as a password (I just brute-forced that part). The other part is just an encoding of the birth date. So I now have enough information to impersonate someone just because a number of organisations screwed up by not verifying ownership of an email address.
- garaetjjte 2y agoPESEL generally shouldn't be considered secret.