Please Give Us Your Email Password

You’re so right, in my opinion you have to be pretty dumb or really new to the internet in order to provide such a valiable resource to some lame ass site you found 5 minites ago.

It’s the same thing with viruses, they ask you to click and people like morons actually do click. Remember the “I love you virus”?! Oh, someone loves me, I will open the pandora box now.

P.S: Jeff, just got the stickers, amazing quality. Where do you have them made?

Even if there is a better way of providing address book information I’d hesitate to do so. How do I know they aren’t building a spam list?

Do what FOAF does and hash the mail addresses. They you can be linked automatically to anyone you know who already is on the network, but emailing other people about the network is up to the customer, as it should be.

I’m starting to see this alot as well. The worst i saw was a “Centralized one stop banking” or something where, by providing your login credentials to your other bank accounts, you’d be able to manage them all in one place.

That’s going a little too far.

Even though its been said already I’m throwing in a vote for OAuth. The spec is simple and most of it is based on HTTP best practices. Here is a link directly to the 1.0 spec:

http://oauth.net/core/1.0/

OAuth is also being used by OpenSocial which is a good sign of its uptake: http://blog.oauth.net/2007/11/07/oauth-and-opensocial/

I currently developed an OAuth server and it only took me a couple of days (with the help of the ruby oauth gem) but most of that time was spent getting it working with Merb.

Jeff - If you think Yelp is bad, consider Mint.com, a site that asks you for the usernames and passwords for your online Bank, Brokerage, Mortgage, and other financial accounts.

I signed up with them cautiously - mostly as an experiment - and gave them the credentials of two non-significant accounts.

Then, without my explicit authorization, they sent me a “Weekly Summary” of my account balances into my e-mail inbox. Breach #1. My thought - how can I trust these guys. Here’s what ensued - taken from my e-mail to them:

"First you sent me a weekly summary by default. How dare you - what gives you the right?

I felt this was a major breach of security for me because my financial status was sent over plain email. Yikes - I thought to myself - I can’t trust these guys with my sensitive data - maybe I should cancel…

Instead, I give you the benefit of the doubt and I turned off the weekly update by logging into my account and editing the settings.

And now, exactly 1 week later, you sent the weekly summary AGAIN. Maybe you’ve got a bug, in which case your systems aren’t properly tested, or perhaps your UI was unclear, in which case you should have invested more time finding usability issues. In any case - shame on you guys for being so careless with my very personal info.

You’ve confirmed my worst fears about your service (I really hesitated giving you all my usernames and passwords), and you’ve made me wonder “what’s under the hood?”

I will be canceling my account asap.

And [in replying to your original e-mail] I’m guessing whoever does customer service can scroll down and see my financial summary too…

Why is this ok?"

What, me worry??

I thought you were all about web 2.0… no? hahaha! Not going to swallow the “people have no reasonable expectation of privacy today so i’ll just throw it away anyways” argument?

=)

Totally agree with you. I am a total security paranoid and I never understood why people would share there info this easy. People who dont live on the internet will start to think its normal to enter your details on any website.

Why not just use a standard address book import/export file?

@Jeff somewhere above: “Skip this step” is a fricking text link, not a button. Which one is the average user more likely to click on? Did they get that little trick from GoDaddy.com or something?

This reminds me of how credit currently works. If you want credit you give out your social security number.

Sites like Gmail deserve some of the blame here. They don’t give you a way to walk your data out the front door and give it to someone. This forces sites like Yelp and Facebook to ask for the keys to your house.

Gmail/Yahoo/MSN/AIM and Banks are the only parties that can fix this. Or we can simply stop using those services (good luck to you on that!).

ACAP (RFC 2244) access to address book information could make all (or part) of your address book available to whomever you wanted. If only email clients supported ACAP…or if there were more server implementations…

Of course, even allowing a small portion of your address book to be shared could present spammers with a gold mine for new addresses if not done very carefully.

Jeff, nice post - indeed, this is ridiculous.

Regarding Facebook and LinkedIn, I really don’t see where this pattern is in use. Maybe I don’t use these sites to the extent so that I see this pattern… what I do notice is that it requires an email address as a username, but not necessarily your specific email password; obviously it should be different.

To those who ask: “I need to give my email-password to thunderbird, isn’ t that evil, too, is it?”

I think one needs to distinguish two types of trust (or insecurity):
The necessary insecurity and the unnecessary.
It is necessary to trust the email client enough to give him your password, because it would be impossible for the email-client to get your emails without your password. (I do not distinguish entering the password once and storing it and entering it everytime, as I can steal it in both cases if I want).
Furthermore, I think that getting your emails manually and passing them to the client manually somehow kinda defeats the point of some email-client.
Thus, /the email-client cannot work properly without that mail password/.

On the other hand, there are sites like Yelp and similar. Giving your password into their greasy fingers is some unnecessary insecurity, as it is perfectly possible to get the contact list without your password.
Furthermore, just feeding the contact list in there manually does not defeat the point of such a site (that is, meet other people), as it is done once and never again.
Thus, /social networking sites do not need your mail password at all/!

And still, those social networking sites demand your password and refuse to work without it. Exactly this behavior is the problem Jeff wants to point out - and I agree on him with that.

Linkedin does this also and it sucks. Because now every time I login and get presented with people who are on linkedin but I did not want to extend a inmail connection to. Basically, people who I hate or do not wish to connect with. But NOOO! Every time I log in I need to know that my ex-ding-a-link-boss is on linkedin. I wish there was a way to turn it off.

Of course, we all know Jeff’s email password is “orange”.

I’ve seen those options at Xing or Linkedin instead of Yelp. I’m not sure about the risk of using it…

Asking the user to go to Live, log in, get their API key and give it to you is unfortunately asking for the user to do too much.

You have to realize that the majority of users are Lazy fricken people that have no clue how to figure out getting their API key from Live. Even if you provide step by step instructions… it’s too much. You made them Think, so they move on.

I completely agree; the only software I will give my email credentials resides on my PC and possibly is open source. I trust no one for this sort of things.
And I DO find dangerous the fact that naive people could become used to think asking this sort of things is ok…

A new “social networking for babies site”, totspot.com, went live today and their home page has exactly the same feature as well.

Given that I don’t really need the site, and given that the demonstrated lack of concern for security, I’ve asked for my account to be removed (although I have NOT provided them with an address).