<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>A Fool's Wisdom &#187; gmail</title>
	<atom:link href="http://foolswisdom.com/tag/gmail/feed/" rel="self" type="application/rss+xml" />
	<link>http://foolswisdom.com</link>
	<description>A fool and his blog are soon parted.</description>
	<lastBuildDate>Mon, 12 Dec 2011 22:39:23 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
		<item>
		<title>Gmail&#8217;s Opportunity to Help Protect Against Tagged.com Mistake, Spam, and Phishing</title>
		<link>http://foolswisdom.com/gmail-responsible-too/</link>
		<comments>http://foolswisdom.com/gmail-responsible-too/#comments</comments>
		<pubDate>Fri, 10 Jul 2009 06:36:48 +0000</pubDate>
		<dc:creator>Lloyd</dc:creator>
				<category><![CDATA[Web]]></category>
		<category><![CDATA[Web Development]]></category>
		<category><![CDATA[Address Book]]></category>
		<category><![CDATA[Andrew Cuomo]]></category>
		<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Email Addresses]]></category>
		<category><![CDATA[Email Spam]]></category>
		<category><![CDATA[gmail]]></category>
		<category><![CDATA[Hotmail]]></category>
		<category><![CDATA[New York Attorney General]]></category>
		<category><![CDATA[OAuth]]></category>
		<category><![CDATA[phishing email]]></category>
		<category><![CDATA[Social Networking Sites]]></category>
		<category><![CDATA[Tagged.com]]></category>
		<category><![CDATA[Yahoo! Mail]]></category>

		<guid isPermaLink="false">http://foolswisdom.com/?p=2026</guid>
		<description><![CDATA[Now for the part of the Tagged.com story, I really wanted to tell. As I mentioned in &#8220;Tagged.com Spam? Phishing? Nice Guys? My Personal Story&#8221; I try to look at situations and problems from different angles. There is a clear &#8230; <a href="http://foolswisdom.com/gmail-responsible-too/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Now for the part of the Tagged.com story, I really wanted to tell. As I mentioned in &#8220;<a href="http://foolswisdom.com/tagged-com-spam-phishing-nice-guys/">Tagged.com Spam? Phishing? Nice Guys? My Personal Story</a>&#8221; I try to look at situations and problems from different angles.</p>
<p>There is a clear opportunity for online email providers and social networking sites to limit the damage of phishing and email spam by giving customers tools to regulate the flow of data.</p>
<p>Yesterday, before New York Attorney General Andrew Cuomo suing Tagged.com story broke, I cold emailed a member of the Gmail team:</p>
<blockquote><p><span style="border-collapse: collapse; font-family: arial,sans-serif; font-size: 13px;">Gmail could help web security a lot by providing:<br />
1. Authentication (OAuth) to Gmail address book making it clear that you were not providing your Gmail passsword to a 3rd party web site.<br />
2. Default level of access only provided names and salted hashes of email addresses from address book (possibly 3rd party web site part of salt)<br />
3. Allow only a limited number of actual email addresses to be requested in a time period. I&#8217;m guessing ~30 would be a sweet spot.</span></p>
<p>That would seem to be one possible solution. If this is not a good solution, I think it&#8217;s important for your team to look to tackle the problem described below in another way.</p>
<p><span style="border-collapse: collapse; font-family: arial,sans-serif; font-size: 13px;">EXPLANATION</span></p>
<p><span style="border-collapse: collapse; font-family: arial,sans-serif; font-size: 13px;">[Background information described in my "</span><a href="../tagged-com-spam-phishing-nice-guys/">Tagged.com Spam? Phishing? Nice Guys? My Personal Story</a>"]</p>
<p><span style="border-collapse: collapse; font-family: arial,sans-serif; font-size: 13px;">I&#8217;ve seen similar UI at othe web services, where everyone in your address book is selected by default. I think there is an awesome opportunity for your team to create an experience that works well for your partners and protects your customers from the type of mistake described above and more importantly from malicious sites.</span></p></blockquote>
<p><span style="border-collapse: collapse; font-family: arial,sans-serif; font-size: 13px;">Some of the problems that I think Gmail and other </span>online email address book and social networking sites <span style="border-collapse: collapse; font-family: arial,sans-serif; font-size: 13px;">should at least take partial ownership by:</span></p>
<ul>
<li><span style="border-collapse: collapse; font-family: arial,sans-serif; font-size: 13px;">Not allowing 3rd party sites to embed login forms. They should use <a href="http://oauth.net/">OAuth</a> or a similar approach. (Even on AppEngine &#8212; train us well).<br />
</span></li>
<li><span style="border-collapse: collapse; font-family: arial,sans-serif; font-size: 13px;">Having a really clear experience about what data you are giving access to (how pissed your friends might be), and a way to provide only limited data.</span></li>
<li><span style="border-collapse: collapse; font-family: arial,sans-serif; font-size: 13px;">Providing salted hashes instead of email addresses, so that a person can find their friends on a 3rd party service without having to hand over the actual email addresses of their friends.</span></li>
</ul>
<p>I don&#8217;t think I read the <a href="http://googlesystem.blogspot.com/2009/07/google-chrome-operating-system.html">Google Chrome Operating System announcement</a> until after I sent that email. When I did read the announcement, I thought about how empowering and freeing it will be for our computing to be in the cloud, but I also thought about problems like this one, and how many scary things can happen when you are no longer hold the container(the harddrive in your PC) for your information and data.  There is a lot of design still to be done to create a safe and friendly experience.</p>
]]></content:encoded>
			<wfw:commentRss>http://foolswisdom.com/gmail-responsible-too/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Tagged.com Spam? Phishing? Nice Guys? My Personal Story</title>
		<link>http://foolswisdom.com/tagged-com-spam-phishing-nice-guys/</link>
		<comments>http://foolswisdom.com/tagged-com-spam-phishing-nice-guys/#comments</comments>
		<pubDate>Fri, 10 Jul 2009 04:33:26 +0000</pubDate>
		<dc:creator>Lloyd</dc:creator>
				<category><![CDATA[Opinion]]></category>
		<category><![CDATA[Web]]></category>
		<category><![CDATA[Address Book]]></category>
		<category><![CDATA[Allen Morgan]]></category>
		<category><![CDATA[Andrew Cuomo]]></category>
		<category><![CDATA[Brad Stone]]></category>
		<category><![CDATA[gmail]]></category>
		<category><![CDATA[Greg Tseng]]></category>
		<category><![CDATA[Lawsuit]]></category>
		<category><![CDATA[LinkedIn]]></category>
		<category><![CDATA[Mayfield Fund]]></category>
		<category><![CDATA[New York Attorney General]]></category>
		<category><![CDATA[Phishing emial]]></category>
		<category><![CDATA[Rafat Ali]]></category>
		<category><![CDATA[Raj Kapoor]]></category>
		<category><![CDATA[Reid Hoffman]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[Tagged.com]]></category>

		<guid isPermaLink="false">http://foolswisdom.com/?p=2021</guid>
		<description><![CDATA[Today, the story broke about the New York Attorney General Andrew Cuomo suing Tagged.com . This situation has a personal element. Brad Stone&#8216;s New York Time (NYT) article today &#8220;New York Attorney General Sues Tagged.com&#8221; begins: &#8220;Turns out our recent &#8230; <a href="http://foolswisdom.com/tagged-com-spam-phishing-nice-guys/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Today, the story broke about the New York Attorney General Andrew Cuomo suing Tagged.com . This situation has a personal element.</p>
<p><a title="See all posts by Brad Stone" href="http://bits.blogs.nytimes.com/author/brad-stone/">Brad Stone</a>&#8216;s New York Time (NYT) article today &#8220;<a href="http://bits.blogs.nytimes.com/2009/07/09/new-york-attorney-general-sues-taggedcom/">New York Attorney General Sues Tagged.com</a>&#8221; begins:</p>
<blockquote><p>&#8220;Turns out our recent article on <a href="http://www.nytimes.com/2009/06/20/technology/internet/20shortcuts.html">the spammy social network</a> Tagged.com &#8230;&#8221;</p></blockquote>
<p><a title="Rafat Ali" href="http://paidcontent.org/bio/4/">Rafat Ali</a>&#8216;s paidcontent.org article today &#8220;<a href="http://paidcontent.org/article/419-social-net-tagged-gets-sued-by-ny-ag/">Social Net Tagged Getting Tagged…Er…Sued By NY AG</a>&#8221; begins:</p>
<blockquote><p>&#8220;High time someone asked harder questions: Tagged &#8230;&#8221;</p></blockquote>
<p><a href="http://twitter.com/lnorthrup">Laura Northrup</a>&#8216;s The Consumerist article today &#8220;<a href="http://consumerist.com/5311319/ny-attorney-general-unfriends-taggedcom-files-lawsuit">NY Attorney General Unfriends Tagged.com, Files Lawsuit</a>&#8220;:</p>
<blockquote><p>&#8220;&#8230; <span style="text-decoration: line-through;">social networking</span> contact-spamming site Tagged.com. &#8230;&#8221;</p></blockquote>
<p>As you can see by how those stories start, there is a lot of bad will for Tagged.com. Some weeks ago I was researching this very topic, but did not find the recent <a href="http://bits.blogs.nytimes.com/author/alina-tugend/">Alina Tugend</a> NYT &#8220;<a href="http://www.nytimes.com/2009/06/20/technology/internet/20shortcuts.html">Typing In an E-Mail Address, and Giving Up Your Friends’ as Well</a>&#8221; article about Tagged.com nor did I find Tagged CEO Greg Tseng <a href="http://blog.tagged.com/?p=4">response on their blog</a>. In my web searches these were buried by years of complaints about Tagged.com phishing and spamming.</p>
<p>I guess, I should go back to the beginning. June 6th, I receive a Tagged.com invite from a dear older family friend,</p>
<blockquote><p>&#8220;[redacted] sent you photos on Tagged Want to see the photos? Please respond or [redacted] may think you said no <img src='http://foolswisdom.com/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> &#8220;</p></blockquote>
<p>Clicking the link did not take me to photos, but instead to a registration form. <strong>The registration did not allow proceeding without providing my login to Gmail, and every person in my address book was selected by default to invite before proceeding. </strong>((Another email account, that I don&#8217;t use publicly also received the email invite, and since then &#8212; coincidentally I hope &#8212; has now received it&#8217;s first spam email.))</p>
<p>Oh no! I immediately let the family friend know that they signed up for what seemed to be a phishing and spam site and that it was important to change her passwords. The friend was really upset and explained that she received the invite from a professional friend of hers, and was worried for everyone else that might have received it from her.</p>
<p>I didn&#8217;t think of it much again until some weeks later, when she described still being bothered by it, how embarrassing it was, and that she didn&#8217;t feel confident using the web any more. She had removed all her photos from Flickr. So, I decided to take another look at Tagged.com and that takes us to all the complaints I described finding above.</p>
<p>I checked the Tagged.com&#8217;s site, and was surprised to find the board of directors included <a href="http://www.linkedin.com/in/reidhoffman">Reid Hoffman</a>, Founder &amp; CEO of LinkedIn, and two members of the Mayfield Fund: <a href="http://vcinme.typepad.com/">Raj Kapoor</a> and <a href="http://www.mayfield.com/team/venture-partners/Allen_Morgan">Allen Morgan</a>. All people I deeply respect.</p>
<p>I scratched my head and tried to look at the situation from different angles. I discovered that Tagged.com has <strong>rave reviews from a young audience</strong>. That the pushy, in your face Tagged.com experience works for this young audience. I guessed that Tagged.com might be tacky enjoyable like MySpace is to many young people.</p>
<p>So, I decided to reach out to CEO Greg Tseng through a mutual connection on <a href="http://www.linkedin.com/">LinkedIn</a>. The email took about a week to get to him, and July 7th I received a <strong>thoughtful and apologetic response</strong>.</p>
<p>The timing of the lawsuit seems really unfortunately for Tagged.com as it seems like they were already in the process of cleaning up their act. I fear that there is a lot of circumstantial evidence against them, and any lawsuit won&#8217;t go well.</p>
<p>Update: Read my next article &#8220;<a href="http://foolswisdom.com/gmail-responsible-too/">Gmail’s Opportunity to Help Protect Against Tagged.com Mistake, Spam, and Phishing</a>&#8220;. I think it&#8217;s at least as interesting part of the story.</p>
]]></content:encoded>
			<wfw:commentRss>http://foolswisdom.com/tagged-com-spam-phishing-nice-guys/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
	</channel>
</rss>

