That was an incredible read. Terrifying actuality. So obvious once you think about it.
Good read. Makes sense and not even that complex, good that they did this experiment anyway just to prove it out to those less technical and try to get prevention steps out there.
Damn. It’s amazing to read some of the HIPAA and FERPA fines out there for exposing data accidentally. Then you’ve got this kind of breach, which is probably endemic and at a much larger scale.
Great read
It’s also such a waste of public money paying for x different domain all for the same municipalities, haven’t they heard of subdomains?
Considering how little a domain name costs it would probably be a waste of public money to coordinate the use of a shared domain.
They’re also under .be. Is Belgium not the registrar for those?
Why is that relevant?
Typically free of charge for the country’s public services to get a domain if the registrar is based within the country.
There are other countries that don’t actually own their TLDs like .io, .tk, .ga, .cf etc. Mali recently forcibly reposessed their .ml domain from overseas ownership IIRC
Honestly, domains are cheaper to buy than it is to prove you are eligible for that unless you need large numbers of them at once.
This needs a government / IEEE / domain registrar policy of some sort. Maybe it should simply be that all expired domains are put into stasis for 10 years.
If you want to buy it and have access to it sooner, then you need to run (and pay for) a program of works to catch and proactively kill all linked accounts, and build a register of embargoed existing email addresses that must be set to bounce.
I knew this was a problem, but wow, had no idea it was this bad…
Because I have a [email protected] type email, I get SOOO many people signing up for accounts with my email, forgetting that theirs had some number suffix. I get peoples phone bills, pizza receipts, Amazon orders, parking meter e-receipts, Xbox live accounts, Dropbox logins, you name it.
I NEVER thought of what that would look like at a domain level!
I read a great post where a guy bit-squatted (bought a domain that was 1 flipped bit away) Google and managed to replace the Google logo on google.com for millions of people. He did the same for facebook and ended up getting thousands of post requests with user data which normally would have failed to resolve or just timed out.
There is still plenty of unexpected fun to be had with domains.
I own my old ISP’s domain. less than twenty email addresses active. Everything else is rejected. I ran it for a week with a catch all bucket and I can tell you now many of those people should be thankful I have and not some unscrupulous scammer. Things like cellphone, social media and medical records accounts all still linked to a ISP domain that has been dead for nearly a decade. The place where I host it sent me a email recently and asked me what had happened to that domain. The user websites are still regularly queried and I’ve considered doing a goatse or tubgirl on all the linked images. Fortunately I’m not in my twenties anymore and decided not to share the chaos.
Do it for nostalgia, relive your 20s by screwing over a defunct ISP with a gaping asshole, isp’s want to act like one.
Spread the chaos! It’s the only way that people will learn!
That’s wild. I suppose there’s lots of outdated print media with all these email addresses that never gets checked if it’s out of date.
Some emails that came in looked as if they came from vulnerable people themselves, asking for help. It may be that they haven’t received or understood the message to update their address book.
I did not interfere with any of the e-mails, as this would go beyond the objectives of this investigation, but it is concerning, to say the least, that these individuals will never receive a reply. They would not have received a response anyway, but it makes me wonder how many cries for help get lost in abandoned e-mail inboxes.
This honestly depressed me, I know firsthand many people who need help from someone who has more or less knowledge to understand something as simple as the migration of a service or an email, it is really depressing not only to know that this happens, but also that There are people who are such bastards that take advantage of this.
Could someone explain to me how the author gained access to “I forgot my password” accounts that were not his but were in his domain? I mean, I understand that it’s on his domain, but just because I have the domain [email protected] does that mean I can redirect all emails to the main domain? Excuse the dumb question.
Edit: Thanks for the clarification! Now I understand!
What you’d buy is “domain.com” and can then redirect any emails of the form “<anything>@domain.com” or even things like “<anything>@<anything>.domain.com”.
In fact, any email ending in “.domain.com” or “@domain.com”. And you could set up a wildcard to catch all emails without having to setup that specific email first.
I think you are a bit confused about the E-mail structure.
Everything behind the @ is the domain, on your case “domain.com” Before the @ is just a name that can be used as you, the domain owner, wants.
If you want to redirect all mail to [email protected], that’s very easy to do AND you can still see the original e-mail address these nails were sent to.
So I assume for example Dropbox sent some commercial mail about current offers. Using that, he knew the old account and that it was signed up to Dropbox
If you want to redirect all mail to [email protected], that’s very easy to do AND you can still see the original e-mail address these nails were sent to.
And it’s a great way to see who’s leaking your email to spammers…
the domain is fifi.com,the dropbox account is [email protected], the fifi.com expires and after 2 years you buy it you go to dropbox and you click forgot password, then you input the email address. if the email address had and account then you receive input such as link has been sent to you. there. done.
Yes, if you have a domain you can catch all emails being sent there even if you don’t know the name - having the domain means controlling the bit after the @, so every email address with that ending.
Bravo, Inti De Ceukelaire.
Registering a domain and publishing contact details connected to it seems to be a lifetime affair. For the lifetime of the internet, that is.
Damnnn. What I don’t understand is why the old accounts still exist, they should’ve changed the accounts to use the new email address. Also, they should’ve thought to buy up the old domain and redirect it to the new domain so nobody can use that for malicious purposes.
deleted by creator
I don’t believe that would be an issue if you would go into outlook for example and change your email from [email protected] to [email protected]. If this was done then the forgot your password wouldn’t function because that email address now doesn’t have an account associated with it.
I think the issue was the account never being deleted or transferred. Which my question was why weren’t they deleted or transferred? If they were too lazy to do that then at the very least, hold onto the old domain so they couldn’t be used.
what is “artificially increasing the ranking of other sites”?
Search engines such as Google need to rank results in some way, to decide which ones to display on top.
This algorithm changes depending on new developments, both cultural and technical, see Google recently putting results from reddit firsts.
One typical way to do this is checking “how many other websites are pointing at this result”, and since traffic is money, people try to game the algorithm by creating fake websites which links to the one they want to push.
i see…thanks for the info!
In particular, it refers to PageRank, the algorithm that set Google apart from its predecessors and upon which it was originally built.
deleted by creator
I guess that’s what happened to one of my old websites. It became a some weird Chinese website :/
So governments should, if their country doesn’t have a government TLD, register gov.yourtld and put everything in subdomains, I guess
Sure, but that’s pretty hard to do with thousands upon thousands of different governments and government linked entities but at national governments absolutely should.
I am very glad that most my mail stuff still goes through other providers, but I do use my domain’s mail for purposes related to my server and its services, and wow, this is unnerving…
You don’t have to worry. Just pay for the domain and you will be good.