‹ BackHN Continuity

Thread

Ask HN: Email leaked while traveling abroad?

17 points · 17 comments · thatonehack

Loading the complete thread in the background. This saved snapshot is available now. Refresh

  1. totallygeeky · · focus · HN ↗
    I don't have much to offer unfortunately, but I will say I've had an uptick on spam/unusual emails to my fastmail as well, including to some aliases. I'm wondering if there's not some way actors are searching out masked aliases, or are able to bruteforce combinations?

    Just throwing shit at the wall however, no definitive proof one way or another.

    1. csomar · · focus · HN ↗
      There are no combinations. The aliases are make-do in fastmail backend. If you have a domain, you theoretically receive all emails sent to that domain (*@domain.com)
  2. montroser · · focus · HN ↗
    The contact list of the person you emailed in 2017 was obtained by a spammer, who then sent you spam.
    1. chinathrow · · focus · HN ↗
      Either this, or Fastmail was compromised recently and more will find out soon.
    2. Transformanshen · · focus · HN ↗
      I think so too
    3. ycombinatrix · · focus · HN ↗
      Doesn't explain why the email was in German.
      1. montroser · · focus · HN ↗
        Could very well be apophenia. Germany was just one of the countries visited, and we all get spam in a variety of languages all the time, including German.
        1. ycombinatrix · · focus · HN ↗
          I don't get spam from a variety of languages.

          The only foreign language spam I got was from Pokemon Go after I playing it while visiting France & Spain. I received French and Spanish emails from them for years.

        2. thatonehack · · focus · HN ↗
          I've never received a spam email in German in my entire life. This spam email actually looks to be a legitimate email as after translating it the contents were basically to verify the email address. I don't think I've ever received an email in another language in my entire life and certainly not while I've been at Fastmail (10+ years).
    4. thatonehack · · focus · HN ↗
      OP here. I only sent 3 emails from this very specific @fastmail.com email address in the past and it was way back in 2017. The email in question has never received email with the exception of this weird email in German language within a week of visiting Germany.
      1. montroser · · focus · HN ↗
        > specific @fastmail.com email address

        You said <alias>@<user>.<domain>.<tld> above, so which one is it?

  3. aaron695 · · focus · HN ↗

    [dead]

  4. portagescout · · focus · HN ↗

    [dead]

  5. csomar · · focus · HN ↗
    How many aliases do you have? If this is the only one, then I'll be more suspect this is a fail on your end or the guy you sent a message to.

    Also, I don't see the connection to Germany?

    1. thatonehack · · focus · HN ↗
      OP here: for clarification I have "email addresses" which are <whatever>@fastmail.com (or whatever other domains fastmail offers). I then use the word "alias" for the on-the-fly alias such as trash@whatever.fastmail.com where the real email address is whatever@fastmail.com. To be clear, the email I received in German was sent to the whatever@fastmail.com (an actual email address, not an on the fly alias). The connection to Germany is that the email seems legitimate to some degree (it was to verify the email address) but it was in German and received within a week after visiting Germany. The email address was not used while in Germany and has never been put into a web form.
  6. rishitasharma36 · · focus · HN ↗

    [dead]

  7. AlisaYoki · · focus · HN ↗
    Could there have been some kind of data leak involving German companies? I mean, the services track those who are in Germany and leak their data.
  8. threecheese · · focus · HN ↗
    Your iPhone was definitely transmitting identifiers which can be passively retrieved, via BT for example. These aren't directly tied to your identity, but announce that id-0001 was in Germany.

    It's not beyond reason to guess that you stumbled into some niche ad targeting group, like "US grape juice drinkers who've visited Germany", and your old email identity was transitively linked somehow. Maybe ten years ago that email was about grape juice?

  9. dv_dt · · focus · HN ↗
    Is Verizon's fine for selling user location data high enough to be more of a deterrent than cost of doing business? The fine was even for selling to the wrong parties, implying that there are parties to access it legitimately.
  10. winstonwinston · · focus · HN ↗
    When you roam phone “leaks” mobile number and identifiers. So getting a Text (SMS or iMessage) spam would make sense, but email does not.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.