4 ms·
Well thats messed up... At least now I know how spammers get my email :D
by andenq 13y ago
Well thats messed up...
At least now I know how spammers get my email :D
- dlss 13y agoAs jpalomaki points out it's better than that... We are entering a brave new world of spam that's "from" people you know.
- ars 13y agoNo, we've been there for a long long time now. I use different email address for different people, and virtually every single one of them has been harvested and used to send spam from that person. At this point I don't expect email to be secure at all. You basically have to expect that unless you are dealing with someone with IT skills their email will inevitably get hacked. The implication is that email is NOT a good way of doing password resets. The problem is what's the alternative (that doesn't require specialized hardware, like a 2nd auth token generator)?
- mcintyre1994 13y agoYou don't need to hack someone's account to send mail as them, you just need a server that will get into the popular services. That's the reason social graphs are sensitive, match up people who trust each other and send them messages as each other. Interesting point about password resets though, if you can read (have hacked) the email you're into pretty much any account. BTW in case you're unaware any Android/iOS device can run Google authenticator and generate 2FA tokens. Email behind 2FA is probably the best security/friction tradeoff for that sort of message, but not many people use it.
- ars 13y ago> You don't need to hack someone's account to send mail as them, you just need a server that will get into the popular services. They emailed me on an address only used by them in their email, and not in any other service. That only way I could get spam on that address is if their email was hacked. (Either remote, or locally via their desktop.)
- fordh 13y agoWhat about spoofing? http://en.wikipedia.org/wiki/Email_spoofing http://en.wikipedia.org/wiki/Email_spoofing
- jessaustin 13y agoI think 'ars is saying that these are "personalized" email addresses: there is a separate one for each person from whom 'ars wants to receive email. Assuming these addresses aren't easily guessable/enumerable, and aren't on any lists stolen from or sold by service providers, the spammer must have have gotten them somewhere else.
- vidarh 13y agoThe problem is that pretty much every one of them have probably given one or more services access to download their contact data to connect them to their friends, so any number of services other than their e-mail likely contains these personalized e-mail addresses. Someone has likely been hacked or sold/leaked data, but he should assume that those addresses have been spread quite a bit voluntarily by his friends/associates.
- deleted 13y ago[deleted]
- jessaustin 13y agoOK, that makes sense.
- makomk 13y agoI've been seeing spam that's "from" my Facebook friends for about a year or so now, so we're already living in that world.
- newaccountfool 13y agoGlad to see people still see spam as a problem, a few days ago when there was an article about Twitter Spam people where making it out like Email Spam has gone away and that Twitter should implement the same rules.