Hacker Newsnew | past | comments | ask | show | jobs | submit | fencepost's commentslogin

I'm not digging into the report, but as a general problem particularly in some niche fields I worry about the "Melancholy Elephants" problem as written about by Spider Robinson back in the 80s. He was talking more about copyright, but I could easily see the same thing happening elsewhere.


I assume that this is basically just not worth pursuing for small-scale orders (e.g. $15ish for Ciglue), but for larger ones what are the reasonable approaches for scenarios that don't involve stolen card fraud?

Notably disputing a credit card charge is completely independent of whether someone owes the debt, the credit card is simply a convenient way for that payment to be handled. What's the point where other collection methods make sense? As an example, if you're consulting for someone and they pay you $x,xxx via card then charge it back, at least in most of the US I believe it's legal for you to do your own collection efforts and contact them repeatedly (this changes if you sell the debt and it's a third party attempting collections).


Correct, the debt is still valid.

You can try to collect through persistence, or take them to court, get a judgment, and then a court ordered collection. It all depends on the value of your time.

I’ve heard rumors that some merchant agreements with processors may include arbitration clauses for recovering chargebacks, but I’ve never seen it personally.


Can someone who's looked at the security of these systems give a bit more context on that?

The thing that's always concerned me with them is questions of "what level of access is required to the system(s) actually hosting my calendar data?" and "if this vendor is compromised, what level of access might an attacker in control of the vendor systems have?" Obviously this will vary by what kind of access controls backends have (e.g. M365, Google Workspace, assorted CRM systems, smaller cloud providers, self-hosted providers, etc.).

Edit: basically, with a lot of these systems, what's expected to be the authoritative data provider/storage?


These days Google fails at even the much simpler "Don't be fscking creepy."

That plus aggressive avoidance of anything resembling customer service and what sounds like an internal environment that may be moving towards cage matches makes it worth avoiding for anything important.


Doesn't China have that whole "social capital" thing where defaulting on debts and other bad behavior can have real long-term consequences? Or does that not apply if you're defaulting on debts to non-Chinese?


Google made it very clear years ago that they shouldn't be trusted with anything irreplaceable/that would cause major problems if you lost access.

Once it became clear that they'd shifted from "crappy customer service" to (IMNSHO) "we fetishize the complete absence of customer service" it became dangerous to depend on them. Really, what's the worst that could happen? Maybe someone spams emojis in live chat on a game livestream at the request of the streamer on a personal account, it gets banned for abuse, Google recognizes that it's linked to other services and locks down everything? But that's so unrealistic I'm sure it could never happen.

It's not like they also have the ability to identify links between multiple accounts accessed by the same person and have automated processes that might stomp the associated accounts as well. Why, that would probably require something like allowing poorly-understood automated agents to take actions on their own!


Sounds like when I was asked to give minimum hardware requirements for something doing backend processing (receive text submitted as print jobs, massage, send to printers).

The requirements as they went out were much higher than they needed to be, because I decided telling them that we weren't stressing anything on the obsolete NT desktop repurposed as the test system might not please everyone.


Worth noting that http.dog includes 218 This is Fine, which is an Apache-specific response code.

It does not, however, use a cartoon dog in a room on fire.


Huh, my initial expectation was wrong! I figured (even until close to the end of the article) that the problem was a dramatic increase in the amount of wi-fi or other 2.4GHz traffic in the area leading to interference, some of which was blocked by rain thus allowing more stable local connections.


I still think that's actually what happened here. A tree in the middle of a 2.4 or 5ghz beam would have an effect, but its branches moving by a few inches would not have this much of an effect.


So I guess I should watch out for scams being sent to "soundcloud@" on a personal domain. Oh no, how will I distinguish them from my legitimate banking email???


Clever spammers (there are some!) see the presence of company@<domain> and assume the user will have similar emails for other accounts, so it might be worth trying ebays scams to ebay@<domain> or banking scams to chase@<domain> or boa@<domain>. Sending is cheap so why not, you're not trying to fool everyone, only a few.

I use a unique string per company but it's not guessable in advance, but it's obvious when looking at it and squinting a bit, for example (and these are not the exact ones I use): sundclod@<domain> or ebuy@<domain> or amzoon@<domain>

Sure I have to remember them but it's easy for me to check and my password manager is filling them in for me 99.99% of the time.

I can filter on those emails instead, and I also know that anything coming to soundcloud@<domain> or ebay@<domain> or amazon@<domain> is definitely spam as I've never used those addresses myself.

If sundclod@<domain> appears in a leak I can (hopefully) change my account email at Soundcloud to sondclud@<domain> and then confine sundclod@<domain> to /dev/null


I have three different generations of email addresses associated with United Airlines that all receive spam. Never any disclosed breaches AFAIK, but clearly email addresses got out at several points. At some point I stopped bothering to check.

As for Soundcloud, the password I had saved for it and a tiny bit of profile information tells me a lot - a manually created password saved into a password manager, probably in 2010 or 2011 and unused after grabbing a single track.

Addresses for services I actually care about also get what's basically peppering, and have all had updates much more recently than the days of Blackberry devices.


Has this happened to you before?

I can't imagine anyone spamming in such low quantities that they'll notice a pattern like company@<domain> and act on it.

I have regularly gotten spam emails without a to, cc, or bcc field though. So I can't tell which email they were sent to. (my host doesn't bounce/drop them for some reason)

I do regularly do misspellings of the company name though, since that often trips the "invalid email" check on signup. e.g. twitter.


For the more shady sites, I use first names or fake usernames.


We are the minority of users that had enough foresight to do this. I'd bet that _most_ people on this breach don't even know about the plus/dot trick with gmail (and I am sure other providers, too).


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: