1/1/2023 0 Comments Gmail dot trick![]() ![]() I wish for any mail sent to to bounce instead of reaching my inbox. “Finally, Gmail users should be able to opt out of dots-don’t-matter. If an email is sent to a non-standard address, it should be shown with a warning. “Each Google account should have one variant configured as its standard address I would set as standard, and maybe John would set as standard. They should officially acknowledge that dots-don’t-matter is a misfeature,” Fisher continued. “The Gmail team should combat this kind of phishing. Unless they were really alert, they’d then unwittingly add their payment information to the scammer’s Netflix account. In response, Netflix would email the real Gmail account user, asking for their payment details. To exploit the confusion around it, all they’d need to do is find a Gmail address that’s already registered on Netflix, create a Netflix account using that email address, only with dots added in, sign up for a free trial using a “throwaway” card number, then cancel the card. Since you don’t need to verify the email address associated with a Netflix account when you first sign up, you can start watching shows straight away.įisher, who has branded dots-don’t-matter a “misfeature”, says it leaves users vulnerable to scammers. ![]() The Netflix account had been created in September 2017, whereas Fisher’s actual Netflix account has been up and running since 2013. ![]() You might think this email should have bounced, but instead it reached my inbox, because ‘dots don’t matter in Gmail addresses,’” he wrote. “I finally realized that this email is to I normally use with no dots. However, when he followed through and took a closer look, he noticed that the card number associated with the account was not his. He received a legitimate email from Netflix earlier this year, telling him his account was on hold and advising him to update his payment details. That’s a potential problem.Īs reported by the Register, this discrepancy almost tricked a developer, called James Fisher, into adding his card details to someone else’s Netflix account. This means that, if someone was to email or even the message would still be sent to other sites and services, such as Netflix, do recognise dots in email addresses, and would consider an account registered to and an account registered to to be completely separate. For example, if your email is you own all dotted versions of your address.” ![]() As the company explains, “If someone accidentally adds dots to your address when emailing you, you’ll still get that email. Google’s email service famously doesn’t recognise dots in email addresses. A Gmail quirk could open up users who have a dot in their email address to phishing attacks. ![]()
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. Archives
May 2023
Categories |