funsec mailing list archives

Compromised aliases anyone? Was: ISACA, a registered trademark


From: Chris Buechler <funsec () chrisbuechler com>
Date: Wed, 09 May 2007 21:00:09 -0400

Kurt Grutzmacher wrote:
Do you sometimes use youremail-SOMETHING when giving out your e-mail
address?  Like grutz-funsec () jingojango net ?  If so, don't try that
with ISACA, they think you're going to use their trademarked letters
for your own gain... Sorta like when you paid all that money and
regular dues for the privilege of saying you're certified.

/me shakes head... Speaking of aliases like funsec@, etc., those of you that use them, have you ever had them compromised? Obviously the ones used to post to public mailing lists like funsec are going to get spammed eventually, but I mean those you gave to a supposedly reputable company or organization with a privacy policy, etc.

I've been doing the single alias per site/company/etc. for a few years and have probably given out 300-400 aliases. Of those, I've had two compromised. One a local radio station, owned by Clear Channel. The second, CIOView.com. Both now get loads of spam, and the aliases are unique enough that there's no possible way I would get spam to those addresses via any means other than a compromise of their email database.

_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: