As part of a large-scale privacy investigation, I have bought more than 100 domain names previously belonging to social welfare and justice institutions in Belgium. What I observed was unsettling.

Some emails that came in looked as if they came from vulnerable people themselves, asking for help. It may be that they haven’t received or understood the message to update their address book.

I did not interfere with any of the e-mails, as this would go beyond the objectives of this investigation, but it is concerning, to say the least, that these individuals will never receive a reply. They would not have received a response anyway, but it makes me wonder how many cries for help get lost in abandoned e-mail inboxes.

This honestly depressed me, I know firsthand many people who need help from someone who has more or less knowledge to understand something as simple as the migration of a service or an email, it is really depressing not only to know that this happens, but also that There are people who are such bastards that take advantage of this.

Could someone explain to me how the author gained access to “I forgot my password” accounts that were not his but were in his domain? I mean, I understand that it’s on his domain, but just because I have the domain mydomain@domain.com does that mean I can redirect all emails to the main domain? Excuse the dumb question.

Edit: Thanks for the clarification! Now I understand!

@WolfLink@lemmy.ml
link
fedilink
7
edit-2
7M

What you’d buy is “domain.com” and can then redirect any emails of the form “<anything>@domain.com” or even things like “<anything>@<anything>.domain.com”.

In fact, any email ending in “.domain.com” or “@domain.com”. And you could set up a wildcard to catch all emails without having to setup that specific email first.

I think you are a bit confused about the E-mail structure.

Everything behind the @ is the domain, on your case “domain.com” Before the @ is just a name that can be used as you, the domain owner, wants.

If you want to redirect all mail to yourname@domain.com, that’s very easy to do AND you can still see the original e-mail address these nails were sent to.

So I assume for example Dropbox sent some commercial mail about current offers. Using that, he knew the old account and that it was signed up to Dropbox

If you want to redirect all mail to yourname@domain.com, that’s very easy to do AND you can still see the original e-mail address these nails were sent to.

And it’s a great way to see who’s leaking your email to spammers…

Yes, if you have a domain you can catch all emails being sent there even if you don’t know the name - having the domain means controlling the bit after the @, so every email address with that ending.

the domain is fifi.com,the dropbox account is office@fifi.com, the fifi.com expires and after 2 years you buy it you go to dropbox and you click forgot password, then you input the email address. if the email address had and account then you receive input such as link has been sent to you. there. done.

snrkl
link
fedilink
20
edit-2
7M

This needs a government / IEEE / domain registrar policy of some sort. Maybe it should simply be that all expired domains are put into stasis for 10 years.

If you want to buy it and have access to it sooner, then you need to run (and pay for) a program of works to catch and proactively kill all linked accounts, and build a register of embargoed existing email addresses that must be set to bounce.

I knew this was a problem, but wow, had no idea it was this bad…

Because I have a firstname.lastname@popularcloudemail.domain type email, I get SOOO many people signing up for accounts with my email, forgetting that theirs had some number suffix. I get peoples phone bills, pizza receipts, Amazon orders, parking meter e-receipts, Xbox live accounts, Dropbox logins, you name it.

I NEVER thought of what that would look like at a domain level!

Nik282000
link
fedilink
77M

I read a great post where a guy bit-squatted (bought a domain that was 1 flipped bit away) Google and managed to replace the Google logo on google.com for millions of people. He did the same for facebook and ended up getting thousands of post requests with user data which normally would have failed to resolve or just timed out.

There is still plenty of unexpected fun to be had with domains.

I own my old ISP’s domain. less than twenty email addresses active. Everything else is rejected. I ran it for a week with a catch all bucket and I can tell you now many of those people should be thankful I have and not some unscrupulous scammer. Things like cellphone, social media and medical records accounts all still linked to a ISP domain that has been dead for nearly a decade. The place where I host it sent me a email recently and asked me what had happened to that domain. The user websites are still regularly queried and I’ve considered doing a goatse or tubgirl on all the linked images. Fortunately I’m not in my twenties anymore and decided not to share the chaos.

Nik282000
link
fedilink
17M

Spread the chaos! It’s the only way that people will learn!

Do it for nostalgia, relive your 20s by screwing over a defunct ISP with a gaping asshole, isp’s want to act like one.

what is “artificially increasing the ranking of other sites”?

deleted by creator

@Tenkard@lemmy.ml
link
fedilink
10
edit-2
7M

Search engines such as Google need to rank results in some way, to decide which ones to display on top.

This algorithm changes depending on new developments, both cultural and technical, see Google recently putting results from reddit firsts.

One typical way to do this is checking “how many other websites are pointing at this result”, and since traffic is money, people try to game the algorithm by creating fake websites which links to the one they want to push.

i see…thanks for the info!

mox
link
fedilink
47M

In particular, it refers to PageRank, the algorithm that set Google apart from its predecessors and upon which it was originally built.

Bravo, Inti De Ceukelaire.

Registering a domain and publishing contact details connected to it seems to be a lifetime affair. For the lifetime of the internet, that is.

Damnnn. What I don’t understand is why the old accounts still exist, they should’ve changed the accounts to use the new email address. Also, they should’ve thought to buy up the old domain and redirect it to the new domain so nobody can use that for malicious purposes.

lemmyreader
creator
link
fedilink
17M

deleted by creator

I don’t believe that would be an issue if you would go into outlook for example and change your email from john@Police.de to john@Polizei.de. If this was done then the forgot your password wouldn’t function because that email address now doesn’t have an account associated with it.

I think the issue was the account never being deleted or transferred. Which my question was why weren’t they deleted or transferred? If they were too lazy to do that then at the very least, hold onto the old domain so they couldn’t be used.

I am very glad that most my mail stuff still goes through other providers, but I do use my domain’s mail for purposes related to my server and its services, and wow, this is unnerving…

@lud@lemm.ee
link
fedilink
17M

You don’t have to worry. Just pay for the domain and you will be good.

That’s wild. I suppose there’s lots of outdated print media with all these email addresses that never gets checked if it’s out of date.

So governments should, if their country doesn’t have a government TLD, register gov.yourtld and put everything in subdomains, I guess

@lud@lemm.ee
link
fedilink
37M

Sure, but that’s pretty hard to do with thousands upon thousands of different governments and government linked entities but at national governments absolutely should.

I guess that’s what happened to one of my old websites. It became a some weird Chinese website :/

Damn. It’s amazing to read some of the HIPAA and FERPA fines out there for exposing data accidentally. Then you’ve got this kind of breach, which is probably endemic and at a much larger scale.

Great read

Good read. Makes sense and not even that complex, good that they did this experiment anyway just to prove it out to those less technical and try to get prevention steps out there.

It’s also such a waste of public money paying for x different domain all for the same municipalities, haven’t they heard of subdomains?

Considering how little a domain name costs it would probably be a waste of public money to coordinate the use of a shared domain.

They’re also under .be. Is Belgium not the registrar for those?

Why is that relevant?

Typically free of charge for the country’s public services to get a domain if the registrar is based within the country.

There are other countries that don’t actually own their TLDs like .io, .tk, .ga, .cf etc. Mali recently forcibly reposessed their .ml domain from overseas ownership IIRC

Honestly, domains are cheaper to buy than it is to prove you are eligible for that unless you need large numbers of them at once.

That was an incredible read. Terrifying actuality. So obvious once you think about it.

Create a post

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

  • Posting a link to a website containing tracking isn’t great, if contents of the website are behind a paywall maybe copy them into the post
  • Don’t promote proprietary software
  • Try to keep things on topic
  • If you have a question, please try searching for previous discussions, maybe it has already been answered
  • Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
  • Be nice :)

Related communities

much thanks to @gary_host_laptop for the logo design :)

  • 0 users online
  • 57 users / day
  • 383 users / week
  • 1.5K users / month
  • 5.7K users / 6 months
  • 1 subscriber
  • 3.11K Posts
  • 77.9K Comments
  • Modlog