frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Ask HN: Are cross-platform UI frameworks suitable for camera apps?

2•Austin_Conlon•59m ago•1 comments

Ask HN: When has a "dumb" solution beaten a sophisticated one for you?

49•amadeuswoo•1w ago•64 comments

Tell HN: Poshmark instantly leaked my email to scammers

5•hardenedmetapod•2h ago•5 comments

Ask HN: Share your personal website

926•susam•4d ago•2363 comments

Ask HN: How to get a job after a career break?

5•shivajikobardan•4h ago•1 comments

Ask HN: Is it still worth pursuing a software startup?

174•newbebee•1d ago•210 comments

Ask HN: How to bullet proof yourself from AI?

6•max_•2h ago•3 comments

Ask HN: How are you doing RAG locally?

406•tmaly•4d ago•156 comments

Ask HN: How can we solve the loneliness epidemic?

779•publicdebates•3d ago•1214 comments

Ask HN: What did you find out or explore today?

215•blahaj•4d ago•408 comments

Ask HN: Is replacing an enterprise product with LLMs a realistic strategy?

6•chandmk•13h ago•7 comments

Ask HN: Claude Opus performance affected by time of day?

38•scaredreally•2d ago•37 comments

Tell HN: YouTube gave my username switzerland to a half government organization

36•faebi•2d ago•9 comments

Ask HN: One IP, multiple unrealistic locations worldwide hitting my website

42•nacho-daddy•3d ago•25 comments

Ask HN: Why is Google tolerating impersonation of Gmail from it's own domain?

5•dvh•11h ago•1 comments

Why are websites trying to talk at me?

2•LeratoAustini•12h ago•4 comments

Tell HN: The way I do simple data management for new prototypes

12•AndreyK1984•2d ago•8 comments

Ask HN: What are you working on? (January 2026)

256•david927•1w ago•877 comments

Ask HN: How have you or your firm made money with LLMs?

10•bwestergard•2d ago•8 comments

Ask HN: Iran's 120h internet shutdown, phones back. How to stay resilient?

114•us321•5d ago•99 comments

Tell HN: Google Trust and Safety is a joke

4•tokyobreakfast•14h ago•2 comments

Ask HN: Browser extension vs. native app for structured form filling?

5•livrasand•1d ago•5 comments

Ask HN: How do you safely give LLMs SSH/DB access?

82•nico•3d ago•106 comments

Ask HN: Who's using DuckDB in production?

7•yakkomajuri•1d ago•4 comments

Ask HN: What are your best purchases under $100?

82•krishadi•2d ago•231 comments

The $LANG Programming Language

264•dang•4d ago•70 comments

Ask HN: How to make spamming us uncomfortable for LinkedIn and friends?

12•zx8080•3d ago•7 comments

Ask HN: Distributed SQL engine for ultra-wide tables

23•synsqlbythesea•3d ago•20 comments

Tell HN: DigitalOcean's managed services broke each other after update

76•neilfrndes•5d ago•50 comments

Ask HN: ADHD – How do you manage the constant stream of thoughts and ideas?

120•chriswright1664•4d ago•148 comments
Open in hackernews

Tell HN: Poshmark instantly leaked my email to scammers

5•hardenedmetapod•2h ago
Browsing for an obscure piece of electronics, I ran across a Poshmark listing that had it for considerably cheaper than anywhere else.

I didn't have an account yet, so I signed up with Google SSO and was able to place the order.

About an hour later I got an email as if I was the seller telling me to click this link to verify my account for my funds to be deposited.

Obviously phishing. Upon closer inspection, I had two earlier that were properly filtered to spam that were about 30 minutes after the order.

So the question here is what part of their system is so fundamentally broken that scammers instantly get my email? Does the seller get that upon me making that purchase?

And if that's not the case, then that means somebody has completely compromised their system.

Comments

myself248•2h ago
Yikes. I wonder if there's a way to differentiate between the bad-seller and the poshmark-is-compromised case.
chrisjj•2h ago
Sure. Be a seller.
hardenedmetapod•2h ago
There's a third case that I never considered.

Google SSO is the promoted way of signing in and it auto assigns your email to the username without any special characters so scammers could just be scraping new accounts and making a best guess at the email.

Lame.

chrisjj•2h ago
> So the question here is what part of their system is so fundamentally broken that scammers instantly get my email?

Perhaps none. Did the T&Cs permit this disclosure?

hardenedmetapod•1h ago
Not that I can see offhand. It mentions using your email for correspondence and copyright disputes.