Tag Archives: email

LeWeb’08: The Revenge of E-mail (Panel)

[fr]

Quelques notes et réflexions autour de l'e-mail.

[en]

I arrived partway through this panel, and thought it was interesting. Here are a few notes followed my some of my rambling thoughts on the topic. (I’ll jump on the occasion to point you out to my friend Suw Charman’s work on “the e-mail problem“.)

The challenge for e-mail marketing is not getting through spam, but getting into the inbox (Nick Heys, Emailvision). I (Steph) had an interesting conversation a few months ago with Hervé Bloch, country manager Switzerland for Emailvision. I’m convinced there is a space for commercial e-mail communication which is respectful, not spammy, and actually adds value. My conversation with Hervé clearly contributed to me thinking that.

Nick Heys says the bottom line is trust: don’t send irrelevant stuff, respect the person’s decision, make sure it’s opt-in&

Olivier Mathiot says the opening rate has plummeted (15% opened today). People open e-mails when they know the sender and trust the content.

Catherine Barba notes that e-mail subjects are often very bad — Robert Scoble adds that there is the same problem with post titles: few bloggers know to write good titles (for viewing in FriendFeed or Technorati).

Strategy from the public: separate accounts (I do that — one for signing up, one for human beings. I have to admit that over the last year I’ve been using my “good” address more and more to sign up for stuff& need to think about that).

Robert mentions that he gets more and more “business” stuff through DMs, which is disastrous because he can’t sort them, forward them, copy other people on the response.

Somebody in the audience mentioning that teenagers have on average 7 e-mail addresses (I find that surprising, to be honest). He says that e-mail is being used to define personas, and separate things out, and that’s where we’re going. I think he misses the point that teenagers do not behave like adults (you can’t draw conclusions about adult behavior by studying teenagers), that putting up barriers between different parts of your life is characteristic to that phase in life, and that ultimately, it is not necessarily a healthy thing when done in an extreme way.

My experience is that we are caught in between two movements: one that tends to separate out parts of our lives, and one that tends to bring our whole life together (integration). We are somewhere in the middle of that tension between two extremes, and neither of those extremes are viable: complete openness and transparency doesn’t work (we do need some privacy) and complete separation between aspects of our lives, taken to the extreme, is split personality disorder.

I do use two (or more) e-mail addresses, but it’s quite clear that over time, their usage tends to seep one into the other. I know from people who use separate addresses for work and personal exchanges that it breaks down for them too.

One completely underused “tool” (or rather, feature) of e-mail is filters. Particularly amongst non-techy people (and possibly techies too), I find that those who are most overwhelmed with their e-mail also do not use filters at all. Filters help you prioritise, keep “for possible future reference but not that interesting now” e-mails out of your inbox, and are pretty easy to set up.

Similar Posts:

Posted in Conferences, Connected Life | Tagged Culture, e-mail, email, Events, leweb08, overload, user/07467067922840649993/state/com.google/read | 5 Comments

Paypal Scam Nearly Got Me

I consider myself pretty web-savvy and spam/hoax-aware. Today I very nearly got fooled into giving my PayPal information to some shady characters.

This morning I got an e-mail from PayPal — or so I thought. It looked nice and branded, no spelling or grammar mistakes, security warnings telling me not to give my password or anything to anybody, and even a link inviting me to go and see PayPal’s Security Tips page. It was just asking me to login on the site and check my data there (that’s what I understood then, re-reading it now, it says they will verify the information I have entered, which is much more fishy).

I had already made a mental note of one of the PayPal warnings, which is to not trust any other site than https://www.paypal.com/ (I’m not linking it so as not to encourage you to click on links which seem to point there — you’ll understand why in a minute). Now, remember this was early morning for me (don’t you also check your e-mail in the morning?). I clicked on the login link, and noticed the browser was sending me to a website identified by an IP address (194.183.4.23 in this case). I stopped everything, and clicked the nice blue link that said https://www.paypal.com/us/cgi-bin/cmd=profile-update. The login page looked furiously like the real PayPal login page, and I was about to login with no second thoughts when I noticed the name in the browser bar was http://www.ssl2-paypal.com/support/update.html — not the link I had clicked on!

I had seen this address before, in another “PayPal” e-mail I had got a couple of weeks back. Already then they had managed to fool me, even though the e-mail was less well crafted than this time. I smelled a rat, so finally typed https://paypal.com/ in my browser and logged in there. Nothing special happened.

I dug out the previous e-mail, slightly worried now. You see, although I had been suspicious about this first e-mail, I do remember that I had logged in somewhere. But to this moment I’m not sure if I logged into the fake website or if I had the sense to point my browser to the real PayPal website myself before logging in. I think I did, I hope I did, and in any case I just checked my account for fraudulous activity and changed my password. The first e-mail was really bad, but I was convinced enough that it came from PayPal to forget about it, just making a mental note that their copywriting was really really poor.

This made the second scam e-mail seem all the more real: when I got it, I thought “oh, so that last e-mail must really have been a fake, this is what a real one looks like.” Poor unsuspecting me.

At this point, I still thought the second e-mail was a “real” one, but that the ssl2-paypal people had someway managed to hack a redirect on the official PayPal site. I hadn’t looked at the e-mail source yet, see?

Anyway, I decided to report the first e-mail I had received.

Coming back home at the end of the day, I had an automated response from PayPal regarding my complaint. It again stated all the security measures to take, in particular the one about always typing https://paypal.com in your browser. And I thought: “you doofuses, you had better stop putting clickable links in your e-mails if you want people to get used to typing the address!”

I was going to respond to them with a more politically correct comment in that direction when I went to have a second look at the e-mail (which, I remind you, I still thought legitimate) I had got in the morning. And that is when I realised that the beautiful blue link was in fact a fake link, disguised as a real one. You can put anything in the href attribute of an achor tag — the catch here is that their link looks a lot like the blue links e-mail reading programs create when they encounter plain-text URL’s.

So, there we go. I was nearly caught by those not-that-dumb spammers. Remember the golden rule:

Always TYPE the address in your browser, don’t CLICK on links in PayPal or other e-mails.

Similar Posts:

Posted in Stuff that doesn't fit | Tagged e-mail, email, fake, hoax, information, internet, masquerade, paypal, report, scam, security, site, spoof, tip, verify, website | 16 Comments