Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Any Gmail person can tell me why Gmail is tolerating Gmail phishing emails that use Google's own services (e.g. https://storage.googleapis.com/savelinge/... ?

More info here: https://news.ycombinator.com/item?id=46665414



Spam is getting horrible lately. I get all sorts of new techniques including:

- using legitimate sites to bypass filters, like sending you a bill through a legitimate bill-creation site

- pretending to be a tracking service for something you supposedly ordered, then over the course of days pretending the package got lost on the way and offering a discount code for the 'purchased' amount, expecting you to use it on their phising site.

Gmail not only fails at spam classification, they classify these messages as important and nag you with first priority notifications and summaries.


I can’t prove it, but it feels like the world recently decided that spamming/scamming is acceptable, so the number of spammers/scammers has increased dramatically.

The number of spam calls, texts, emails, iCloud account unlock requests, etc I’ve received in the last year is insane.


I believe that these spammers now concentrate their efforts towards e-mail addresses hosted by major providers, like Gmail.

The reason is that I have an opposite experience, during the last couple of years I have received much less spam messages than before.

I have hosted my own e-mail server for more than 2 decades. Previously, I had to filter large quantities of spam messages, but lately the number of spam messages is much less than 10% of the total number of received messages.


I’m considering self hosted. I’m so tired of the major providers not even trying. And I have no serious control over blocklists.


My personal domain has the MX records pointing at Gmail. It gets far less spam than my Gmail address does.


What about fastmail.com or hey.com or proton.me? I have heard good things about all of them.


I use fastmail, I love it. I have a catchall and thus can use a different address per service. Leads to sometimes awkward conversations as to why the email address contains the company name in it, but can also be a life saver. For instance, free recently got hacked and all their email db was online. I can just block this email address and not receive the spam. Fastmail itself is reliable and fast on the web, but I only use it through IMAP anyways. It works perfectly.


Lack of accountability for the companies that allow their services & platforms to be used for spam/scamming.

Take DocuSign for instance. Still, this many years later, is a major source of phishing emails from their free trials. DocuSign could easily shut this down today by either requiring a CC for the trial, or forcing a call with a sales rep to start a trial. But they don't, they continue to allow their service to be used for wide scale phishing.

Atera, an RMM, is another one that has been a big source of malware delivery, also via the free trials.

Shutting down the trial accounts after the fact does nothing, the emails already went out.


I feel like there's no way for them to win, though. The kind of accountability you're talking about what require them to do essentially tons of KYC/AML vetting, and HN would be equally outraged about that.


It's a little hard to get outraged about that hypothetical, given that legitimate usage of DocuSign typically involves sending them documents containing all sorts of sensitive information.


Every single day since around the start of the year I get at least 1 text with the content of roughly: "FROM TRUMP: You could be the next winner of this PRIZE/MONEY!", "Click here to receive your $10,000 tariff refund!", "DEMOCRATS are trying to DESTROY EVERYTHING!". Plus I get almost daily calls that immediately hang up, and leave a 30 second voicemail with no audio.

I've always had some level of political spam, usually only close to voting months, but this year has been the worst for me.


The first two don't sound like political spam, just politically-themed regular scams.


> I can’t prove it, but it feels like the world recently decided that spamming/scamming is acceptable

In the US, we elected a well-known scammer ... twice!


You mean 60 times? It's not like you get on the ballot by being an honest person.


In addition, it feels like the past 5 years have brought on more marketing spam. I've been slowly reappearing onto marketing lists that I either never signed up for or unsubscribed from. They're coming from legitimate companies that I've done business with.


It's AI that's doing a lot of it. For a lot of spam, scammers would want to exclude anyone who may not fall for the scam due to the costs associated with dealing with people who won't pay you. Now that AI decreases the need for a human scammer to scam, expect them to start to widen their scam nets.


The decline had been happening long before AI hit mainstream.

It's been a _lot_ of years that I've hesitated to answer calls from unknown numbers.


Yeah this feels like one of those cases where the term "AI" gets broadened out so far it becomes meaningless.

This stuff is automated. The ability to automate spam calls (using the same form of APIs developers love, like Twilio) make it absurdly easy for one person to set up a spam machine. No AI required.


The lead generation was automated ten years ago ("Hello?"), but the actual scam conversation was not. Until recently, you still had to pay somebody in South Asia better than the prevailing wage of ~$1/hr to have these conversations, as well as set them up in an office with computers and managers, and bribe local police (call it $5/hr of fully burdened work product). If your success rate is ~1% and the average human portion of the scam lasts 12 minutes, you're getting 0.05 successes per hour, and you better be netting an average of $100 per successful scam (accounting for financial clearing issues / reversals!) or you're losing money on every hour worked.


You're correct about the calls, but the ability to talk with the people was the rate limiter. Even if you have many people in Cambodia or India, the scammers still needed to scam more than they paid out. Now you can have AI bots that do the first level of filtering.

Unfortunately scamming is a business and if certain actions become less expensive, I would expect more of them.


It's the natural progression of hustle culture. Profit makes right, nothing else matters.


I get these voicemails almost daily it's a cutoff message talking about "a loan just came across my desk"

It's such a good tactic too to start the voicemail with the conversation already going people are like "what? who?"


AI + FCC weakening


Not just the FCC but the entire regulatory apparatus is completely non-functional when it comes to regulating commerce.

The clear, unspoken message in the USA is now: "Enrich yourself in any way you can, as fast as you can. Buyer Beware is the law of the land."


New tools like LLMs probably make previously unscalable techniques scalable.


I think part of it is AI allowing sophistication at scale, but there's also a generational factor. The techbro + business shark culture, influencers who manipulate people being role models, and so on.


Oh no - you can definitely 100% prove it, this is the direct consequence, the exact intended consequences, of Trump gutting consumer protections - across the board, not only online but with food and laws about not dumping chemicals in rivers.

The man is the absolute worse person - unless your a rich guy, who wants to make more money by screwing over people who mostly don't even know it.

Anyone who reads this, I dare you to find out why that thing in your life you hate so much, sucks so bad - nothing is ever by accident or unintentional.

The United States, and its People, will be discovering/realizing different ways we have been absolutely f-d by that grifter for likely the rest of my millenial life, thankfully (silver lining!!) US life expectancy has dropped substantially for the 150 million Americans in the bottom 50% of income - rich people in America have to deal with this bs for almost 8 more years than we do

Oh yeah, if you want a faster out even yet - just make 30k or less per year, your life caps at 71 then.

I joke but I hate so much that people will read this and then promptly go back to sustaining this system at their job.

We work our lives away so the rich dont have to and they get to live 14 more years on average than poor people.


Curb your TDS, this trend has been going on much longer than the bad orange man.


Oh, I was just really upset having found out that the IRS is going to settle Trumps 10 billion lawsuit against the IRS, for releasing his tax returns but showed he payed 0 dollars in taxes - AND, the terms of the settlement are that the IRS cannot investigate his family or any of their businesses in the future.

That is the most corrupt thing a Leader in a western country has ever done in the modern world.


Acknowledging reality = TDS.

While you're correct that this is a trend that has been going on for a while, the keyword is trend. Do you understand what a trend is? It's a direction. Meaning, under Trump, it has gotten worse, and that is directly related to the piss-poor policy choices of this administration.

I won't mince words here. People who think policy is completely detached from outcomes are dim, and should spend less time talking because it wastes everyone's brain space.


If I put on my tinfoil hat, it seems to be something deliberate, to push us all towards accepting hardware / software attestation and better "online id" stuff - "Don't you want to identify and stop the spammers and phishers?".

Email scanning and file scanning (on our computer) became acceptable when the level of spam and malware became intolerable. But it was at cost of our privacy. Today, Gmail scans all your mails and makes money from it. Both Windows and macOS have built-in anti-virus or malware scanners, and file indexers, and thus know all the applications and files in your system (which provides for more data on your profile with them). Now with both OSes, and even browsers like Chrome and Firefox, including AI, they will now use our own computers to not only collect our personal data, but even process it on our system and use it to build even better profiles to more profitably exploit us.


It doesn't have to be deliberate; it's just the economic incentives at work. AI providers are inclined to sell AI to everyone with a pulse, and it just so happens that a lot of its use will for towards spam generation.

It also just happens that they're the ones best positioned to provide attestation and identity services.


Eh - conspiracy territory. There’s been a massive evolution in phishing and spams with LLMs.

> Evaluating Large Language Models' Capability to Launch Fully Automated Spear Phishing Campaigns: Validated on Human Subjects

> https://arxiv.org/abs/2412.00586

LLMs make phishing absurdly profitable, and can now make profits from targets who were previously economically unviable to target.


Gmail spam filtering is so bad that I believe it has to be intentional. I think they see email as a long term ad revenue opportunity and want to desensitize people to the spam.


I wonder how come I have such a diametrically different experience. I don't remember the last time any spam email got through the automatic filter into my inbox, and I had a gmail account for 20 years now.


Could be an A/B test. I’ve had mine for 17 years, it only became an issue 5 years ago.


> pretending to be a tracking service for something you supposedly ordered

There’s a leak or someone is selling the data in a lot of the delivery companies in my country. I order something then without fail the fake text message pretending to be the delivery service. Only thing they screw up is claiming it’s failed to deliver too soon and the weird urls.

Messed up these companies are either selling it or being irresponsible with data.


Seems to be involved with government services too. I signed up for a welfare program that had me input all my data before denying me the service a few months ago, and the next day I started receiving spam calls and texts using some unique pieces of information that I had submitted in that form.

Called my state senators to complain about it and ask for assistance. Enjoyed the complete lack of follow through.


I'm not seeing any of this, and I've have been using the same email address that forwards to gmail for decades at this point, and it's in every major email data breach.

I get, maybe, one actual spam email per year through gmail's spam filters.

I get more actual spam at my work email, which is not hosted by gmail, even though the email volume of emails sent from outside of my employer's network is orders of magnitude smaller than my personal email volume.


> like sending you a bill through a legitimate bill-creation site

Why aren't these things opt-in? Ditto for every other thing that sends you email. I reflexively mark anything I didn't sign up for as spam on principle.


Spam is now AI powered. Let that sink in for a bit.


Google is fine with everything if it's their service. I've completely blocked *.bc.googleusercontent.com, because it's basically used as a spam farm for years now, but Google couldn't care less as they apparently can't be bothered to even slightly inconvenience their compute engine users.


The same reason spam filtering is hard. It's not possible to catch every misuse of the service without too many false positives.


The same 5 urls has been used for 3 months


That doesn't really change the fact that it's hard. Do you know how many full movies are on YouTube that infringe on copyright? How many pirated streams are hosted on S3? How many piracy sites are behind Cloudflare. It's just very hard to police at scale and if something is flying below the radar it will be there for a while. They probably spread out their assets over many accounts, or even use misconfigured buckets with write permissions to drop some files in there.


Google's inability to scale their services should be a regulatory issue.

If their platforms (Gmail, YouTube, DoubleClick) are being used to launch scams, they're failing at scale and governments are failing at legislating / regulating.

The only way to use Google services somewhat safely is with hefty ad (and the rest) blocking.

All this ID and surveillance and privacy invasion and metadata retention and yet all these scams only seen to grow. It never seems to end up protecting anyone deserving of protection.

I wonder what it's all been in aid of...


Trust and safety doesn’t have the same maturity as cyber security. Things like trend and signal sharing between tech firms doesn’t exist, except through informal slack channels and WhatsApp groups.

The first major safety conferences for trust and safety came together only in 2023.


This argument actually doesn’t work in Google/your-point favor since finding pirated content on Google is now practically impossible.

The reality is, Google is driven strictly by incentives and there are no consequences for letting spam/scams run wild vs. pirated content which gets automatically removed when a DMCA notice is received.


There is 100% pirated content on Youtube - not too much from Hollywood and you won't find anime on it - but if you watch foreign language media, there is very often the Official account and then like 4-5 others just blatantly providing the identical content, which is promoted alongside the legitmate content, so its fairly easy to start watching legit stream and find yourself not watching legitimatly a few episodes later, playlists are huge to prevent that.

The problem with this is the piecemeal enforcement all but proves they only care about stuff they get a cut of and that fact became more clear to me recently when I was watching a random drama made in Asia that I wont name due it being one of the best historical and educational shows I've ever watched - but there was a scene (this was made in the 90s btw) that was entirely innocent, not sexualized - it was done humorously, but I'm not a pdf file either so - anyways, there were fully naked children, with absolutely no censorship, on Youtube - 100% long enough to be noticed by their trackers - they obviously just are not reviewing certain content, at all.

I don't care about piracy at all - I'd still use Youtube if it was the primary source for pirated content, the idea that there may be some obscure content, that seems totally fine, in a language nobody really uses - except for Epstein types, if ever that was discovered - that Youtube had become a haven for pdf files bc of lax application of standards - I would want Youtube split away from Alphabet and force sold on the cheap to a more responsible owner (like Tiktok minus the responsible owner part) - plus an enormous fine.

I didn't believe that such content could exist at all on the platform - until I literally saw with my eyes that it obviously can.


I kinda lost the plot here - what does piracy have to do with spam and phishing?


both deal with distinguishing legitimate vs illegitimate content.


Attempted platform moderation and abuse-enforcement.



"It's so easy when you don't know how". I'm not sure if this phrase is in common use at all, or if I just misheard it once and attributed it to mean that when the details of a problem aren't obvious, its easy to conclude the solution is simple. "Why don't they just do ___?"


At the companies I've worked at, I refer to this as the "well, can't you just...?"

Yeah, I can "just" after I "just" do A, and B, and C, and D, and E, and F, and G.

Drives me batty on top of being insulting. "Surely you realize I thought about that weeks ago, and if it were that simple, we wouldn't be having this conversation."

But hey, I get paid every 2 weeks.


It's probably possible to catch a lot more of them, but why look too hard when you can hide behind section 230 immunity and pocket ginormous profits instead of spending on this lol...


Ok, it's even harder when you do not care because they people are either freeloaders or locked into your solution because it's a customized mess.


Ah! I have no answer for it, but am happy, Virgil-like, to now have a theory why the same stupid, obvious "Costco" spam from an @gmail.com address keeps showing up in my inbox no matter how many I mark as spam.


That page looks phishing-related but doesn't appear to directly serving abusive content?

Does that XML get processed by a mailreader?

<ListBucketResult xmlns="http://doc.s3.amazonaws.com/2006-03-01"> <Name>savelinge</Name> <Prefix/> <Marker/> <IsTruncated>false</IsTruncated> <Contents> <Key>winbridge.html</Key> <Generation>1775478745793193</Generation> <MetaGeneration>2</MetaGeneration> <LastModified>2026-04-06T12:32:25.871Z</LastModified> <ETag>"3616712a8e68db66062a3f514b5fb7c8"</ETag> <Size>626</Size> </Contents> </ListBucketResult>


I am guessing that service returns the XML file as a directory listing; the file called winbridge.html does exist in that directory (and contains a JavaScript code to redirect to a different URL). (Another comment said they shortened the URL to remove PII (which I am guessing was in the fragment part of the original URL; the JavaScript code makes a new URL from randomly selecting a domain name (even though the list has only one) and appending the fragment part as the path), so I suppose the file name was removed and then this directory listing is the result.)


I shortened url to remove PII. Full url causes few redirects before landing on scam site.


They seem unable to prevent phishers from using their acquisition, AppSheet, to send relatively convincing, targeted (to nobodies like me) emails that make it to primary inbox.

So, pleas ignored, forward these recruitment scam emails to the legal/fraud/phishing teams of the impersonated brands. For a company without the appearance of caring (in my opinion), perhaps law firm letterhead can encourage necessary prioritization.


It follows the same logic as physical junk mail. We accept the fact that we will receive junk mailers in our physical mailbox and just toss them out.


We shouldn't accept that either. The USPS could stop accepting junk mail, if it were funded properly and didn't have to rely on junk mail for revenue.


The USPS doesn't even have to get involved. Just make it so that recipients can be compensated easily enough with high enough fines and the spam stops immediately.


The USPS literally has a paid service to deliver bulk mail to every address in an area.


And if the law was working correctly that would mean free money for the whole area and a bankrupt sender.


You seem to be suggesting that you're going to successfully fine a postal spam sender for using a paid service offered by the USPS to do the thing that service was designed to do. If the "law was working correctly", that service would stop existing, rather than existing and then incurring fines when used.

There are some limited mechanisms for opting out of targeted mail (e.g. things that have your name on them), and mechanisms for opting out of credit offers in particular. There are not any mechanisms for opting out of "current resident" spam sent to everyone in an area.


There is a big difference between advertising your services and trying to literally steal people's money.


This is an underrated distinction. Sadly, the line is so much more blurred now than even when I was a kid in the 90s.

There are so many businesses now which exist mainly to cheat you, operating at the very edge of what’s technically legal, and relying on their customers not really understanding the full terms of the deals they’re agreeing to. It’s sickening.


Can you post an example? Thank you.


Here are a few that I'm most familiar with.

- Seniors are sold various quackish financial products like annuities which are a terrible deal for them.

- Timeshares, which nearly never work out in the favor of the consumer (and whose value collapses 50-80% instantly if you look at what they go for on the resale market)

- Prepaid card products that cost a bunch of money to load and then incur monthly fees too (exploiting those who have for whatever reason got blacklisted from banking)

- Every financial product that has a 25%+ interest rate, actually, which isn't limited to those with bad credit. Even if you have an 899 credit score, if you walk into Nordstrom and get their credit card, you will have a close to 30% rate on that. This whole business model is obviously built on tricking people into spending money they don't have and carrying a balance.

- Salesmen hawking solar panels that come to my front door and promise me all kinds of savings. Note: Probably only half these are scams! Just have to figure out which half.

- Health insurers, pretty much across the board. They do things like declare the most dominant ambulance service in San Francisco, the SFFD, "out of network", so the SFFD then sends you a bill for $1000 if you had to use an ambulance. The neat lifehack by the insurer is that most people will just curse, cry, maybe go into debt, and pay it. Only like 10-20% of patients will file a complaint with the insurer's state regulator, and those can just be quickly paid. Result: Savings of 80-90% for health insurance company! (If this one sounds oddly specific, you can guess why.)


Every payday loan company, the "we buy houses for cash" companies, rent-to-own companies, title loan companies, the entire buy-now-pay-later ecosystem, the timeshare industry.

Seriously dotancohen, get your people under control.


Who are "my people" that need to be got under control?


Not when half those "advertised services" are in fact scams.


In the Netherlands you put a sticker on your mail box with either of these: - NO ads, NO magazines/papers - NO ads, YES magazines/papers

Some municipalities even make it opt-in so you'd need YES/YES to get mail without a name and address on it. (ie. not direct mail)

There are also laws to enable opting out of direct mail (with name and address).

In effect, junk mail is just gone once you slap a sticker on your mailbox. This is not an unsolvable problem if you just regulate things.


What jurisdiction is responsible for regulating my, Israeli, email "sticker compliance" when using Gmail, American, and the sender is in Romania?


No idea, I didn't say anything about email.


the analogy breaks at "...to get mail without a name and address on it". spam emails always have RCPT TO.


What jurisdiction is responsible for when those Romanians decide to send you anthrax in physical letters?


Who is we? We definitely don't accept that where I live.


Yeah, but junk mail funds the USPS, without it Republicans would've killed the postal service long ago, See the Pension requirement that they pushed in a vain attempt.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: