Get the latest tech news

Not OK Cupid – A story of poor email address validation


A story of poor email address validation.

Specifically, this list included trash@brong.net — an address that has never been used to send or receive email and appears in precisely one place — an article on our blog! Attackers can use unverified sign-ups to flood inboxes, making it easier to hide critical emails among the noise — something we’ve discussed our own experience of in our post on 2FA vulnerabilities. Masked emails are designed, particularly when integrated with a password manager, to make it very easy to create new addresses, and track where they are expected to be used.

Get the Android app

Or read this on Hacker News

Read more on:

Photo of story

story

Photo of OK Cupid

OK Cupid

Related news:

News photo

Recursion kills: The story behind CVE-2024-8176 in libexpat

News photo

Monster Hunter Wilds' popularity due to emphasis on story, says series producer

News photo

Social Security Workers Aren’t Allowed to Read This Story