TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Researchers’ Typosquatting Stole 20 GB of E-Mail From Fortune 500

58 pointsby tathagatadgover 13 years ago

10 comments

unfletchover 13 years ago
I get a ton of misdirected email, but for different reasons.<p>The first is that I have a common nickname @gmail.com. There are many other users with some variation on that nickname @gmail.com, and people are careless about typos, including suffixes, etc. It's a similar cause to the article, but the username instead of the domain.<p>The second case is a more interesting one:<p>I bought an expired domain.<p>Now I get all kinds of email sent to what used to be legitimate email addresses of the old domain owners. For more than one of them it was clearly their primary email address. I was getting emails related to bank accounts, Netflix, Facebook, etc. I thought about trying to get in touch with those users, but ultimately decided to bounce their email.<p>It was something I hadn't considered when buying an expired domain, or about my own email addresses, but it's a real problem. Here's hoping my email provider never lets their domain expire.
评论 #2980141 未加载
AretNCarlsenover 13 years ago
To beat the old drum: Email isn't intended to be secure anyway. Relying on email addresses to maintain privacy and authenticity is like relying on Caller ID to verify callers' identities. (See spoofcard.com.)<p>Encrypt, encrypt, encrypt. Or, encrypt.
评论 #2979434 未加载
评论 #2978732 未加载
swaitsover 13 years ago
Pretty sure that's not "stealing".
评论 #2978561 未加载
评论 #2978573 未加载
评论 #2979072 未加载
sligover 13 years ago
Once a friend snapped hotNail.com.&#60;Our country code&#62; . The amount of email he got was amazing and that was 8 years ago.
评论 #2978621 未加载
pheaduchover 13 years ago
I have the same issue with one of my domains and I get all types of emails including highly confidential ones including banking emails.
mathgladiatorover 13 years ago
So, if you are in a fortune 500 IT department, you should probably set up a honey pot to find people doing this now.
ChrisArchitectover 13 years ago
wish this wouldn't conclude sounding like a ploy to convince everyone to buy up misspelled domains.
评论 #2978631 未加载
cfinkeover 13 years ago
Shameless (and I mean shameless) plug for my latest project that collects statistics on what domains people mistype: <a href="http://typed.it/" rel="nofollow">http://typed.it/</a> (Log in with demo@typed.it/demo for full access.)
评论 #2979351 未加载
aw3c2over 13 years ago
I only glanced over that article but 20 Gigabytes? 120000 e-mails? In 6 months? Does that include all the spam?
评论 #2978390 未加载
thereover 13 years ago
i thought this was going to be related to the memory errors causing incorrect dns lookups:<p><a href="http://nakedsecurity.sophos.com/2011/08/10/bh-2011-bit-squatting-dns-hijacking-without-exploitation/" rel="nofollow">http://nakedsecurity.sophos.com/2011/08/10/bh-2011-bit-squat...</a>