this post was submitted on 10 Aug 2026
215 points (99.5% liked)

Not The Onion

22221 readers
918 users here now

Welcome

We're not The Onion! Not affiliated with them in any way! Not operated by them in any way! All the news here is real!

The Rules

Posts must be:

  1. Links to news stories from...
  2. ...credible sources, with...
  3. ...their original headlines, that...
  4. ...would make people who see the headline think, “That has got to be a story from The Onion, America’s Finest News Source.”

Please also avoid duplicates.

Comments and post content must abide by the server rules for Lemmy.world and generally abstain from trollish, bigoted, ableist, or otherwise disruptive behavior that makes this community less fun for everyone.

And that’s basically it!

founded 3 years ago
MODERATORS
top 50 comments
sorted by: hot top controversial new old
[–] daychilde@lemmy.world 97 points 4 days ago (2 children)

Every time I have imposter syndrome (at 51 years old, even), I see crap like this and think: Why do I sell myself short? Because I'm not the smarted tool in the shed, but jesus christ I ain't THIS stupid. Anyone pulling that stupidity should feel nothing but shame. Ugh.

[–] some_designer_dude@lemmy.world 52 points 3 days ago (2 children)

I’m not the smarted tool in the shed

🤦‍♂️

[–] daychilde@lemmy.world 65 points 3 days ago (2 children)

DO NOT MAEK FUN OF MY TYEPING, I AHVE IMPROSTER SYNDORM

hehehe

Thankfully I do understand irony. And I'm leaving it there so others can point and laugh. :D

[–] fedorato@lemmy.world 10 points 3 days ago (1 children)

Thanks mate - you made me spit out my tea 😆

[–] daychilde@lemmy.world 5 points 3 days ago

oh geez, I didn't mean to cause a disaster! D: lol

[–] mPony@lemmy.world 4 points 3 days ago

well, the years start comin' and they don't stop comin'

load more comments (1 replies)
[–] WorldsDumbestMan@lemmy.today 1 points 2 days ago (1 children)

You understand that you can have all the knowledge in the world, and your actual IQ would still not change?

[–] daychilde@lemmy.world 2 points 2 days ago (1 children)

Yep. IQ had extremely limited value, telling you basically how quickly you learn compared to others.

I used to work with adults with cognitive and developmental disabilities -my wife did too and for example she taught them Shakespeare. They were capable of learning and did. I saw discussions that showed they understood and found it interesting (more than I find Shakespeare interesting even hehe).

I happen to have a decently high IQ but I can tell you very much personally it doesn't lead to success in life. Lol

The ADHD didn't help either though. Heh

[–] WorldsDumbestMan@lemmy.today 0 points 2 days ago (1 children)

I have an average IQ and interest in many subjects, but my operating memory is confirmed borked, I have heavy ADHD symptoms, and the most ADHD unfriendly life you can imagine.

It really does feel impossible to make meaningful advancements.

But I do feel that, even if you can eventually memorize and build on knowledge, there is just a world of difference in what a 70 and 130 IQ person can do.

[–] daychilde@lemmy.world 0 points 2 days ago (1 children)

Awww, I just noticed your username. <3

In theory, the main diference between… well, let's say like 80-85 because getting down to 70 is a bit lower than most people think… but yeah, the difference between that and like you say around 130ish is mainly just that I would expect the two kids in school sitting side-by-side - the 80ish IQ kid takes a little longer to learn the concepts. They have to put in a bit of time and practice compared to the 130ish kid, who tends to pick up on the concepts easier.

But here's the thing: When that 130ish kid runs into something they don't get immediately, they flail around and struggle even harder thn the 80ish kid because they're not used to having to work to understand new concepts. So that 130ish kid is going to tend to give up, whereas the 80ish kid will keep on pressing forward.

[–] WorldsDumbestMan@lemmy.today 2 points 2 days ago

My verbal IQ is carrying me. There's very real consequences where not picking up on a que and understanding a task instantly, results in people remembering me as the guy who "doesn't know shit".

So they skip over me, and don't even bother training me.

Which resulted on days where there's "no work", and so less pay.

[–] iampivot@lemmy.world 3 points 2 days ago

I owned nothome.com for a while. A lot of people used to suffix their domain name with the 'not' prefix when giving out email addresses.

[–] Smoogs@lemmy.world 2 points 2 days ago

...so people actually reply to noreply?

[–] givesomefucks@lemmy.world 37 points 4 days ago* (last edited 4 days ago) (12 children)

Sounds like this guy knows way more than me...

“It is too much,” Solovewicz says, emphasizing that people shouldn’t assume a domain is unmonitored. “I’m at the point where this would now be a full-time job to handle every single one of these—that’s part of my motivation to talk about this, it is my responsible disclosure. You guys need to fix your systems and not do this and not leak your customer data and your employee data and your own internal data.”

But couldn't he just set up an "out of office" so that every single time he gets an email, a response is sent saying:

Hey bro, this is a real email address, you just sent me stuff you probably shouldn't. No big deal, but you're going to keep getting this automated emails. Please fix your security.

If you get stuck in a loop of automated messages (likely) that's going to flow a massive flag up at the company, and someone is going to look at it why it's happening.

It's impossible for a human to handle it, but that doesn't mean it can't be handled.

[–] RobotToaster@mander.xyz 23 points 4 days ago

The domain would get flagged as spam for sending that many emails

[–] daychilde@lemmy.world 15 points 4 days ago (1 children)

Anytime you autoreply to email, it means a spammer can spoof the sender and spam you with hundreds of emails, which you will faithfully reply with "This address is not monitored" - but you're sending those replies out to people who didn't send them to you, and typically attaching the original message, meaning the spammers get a free spam reflection service from you - you sending their spam to all those people.

So please don't use autoresponders.

[–] kn33@lemmy.world 6 points 3 days ago

Or only use it on domains with SPF set up for hard fail, and for emails that pass SPF

load more comments (10 replies)
[–] A_norny_mousse@piefed.zip 29 points 4 days ago (3 children)

I'm confused as to how and why people would even want to send an email to anybody@noreply.net.

I often get email that says "do not reply to this email" and it appears to be sent from noreply@our.domain. This I understand. So am I understanding correctly that many companies/mailing systems use @noreply.net in the same manner?

But why? Why not to noreply@our.domain?

[–] snrkl@lemmus.org 26 points 3 days ago (1 children)

I have a first name.lastname@gmail.com email address.

Every single week I get a different person's legitimate email because they forget their email is firstname.lastname12345@gmail.com or some other number, and sign me up for stuff..

I get bank statements, rent notices, holiday bookings, xbox live accounts, kayak club membership emails, pizza delivery receipts, Amazon.com accounts and purchases...

You name it....

XKCD calls it "Reverse ID Theft" - I call it "Identity Donation": it's like people think: "here... Be me for a bit... See how you like it..."

https://xkcd.com/1279/

[–] W3dd1e@lemmy.zip 10 points 3 days ago

Well that XKCD comic nailed it. There is a doctor in another state with my name and occasionally patients send me their prescription questions.

I also had to specifically ask a lady with a similar phone number to stop giving mine out.

load more comments (2 replies)
[–] Blackmist@feddit.uk 7 points 3 days ago (1 children)

I send all my test emails to test@tickle.com. I've no idea if anybody owns that, but if they do I hope they enjoy all the bizarre invoices I've sent there over the years...

[–] Flagstaff@programming.dev 2 points 2 days ago

Why would you send a test email to an account you or someone you know doesn't control?

[–] AlphaOmega@lemmy.world 19 points 4 days ago (1 children)

But why? Why are they sending corporate data to a website they don't own?

What's the point?

[–] blueduck@piefed.social 39 points 4 days ago (4 children)

The @deleteduser.com example is the easiest to explain

A user, Bob, has an account and has attached his email address. Later, Bob says he wants to delete the account. For legitimate reasons, the company doesn’t want to delete all associated records (think, user generated content or user to user interactions that shouldn’t simply disappear. Or maybe audited transactions.)

The company also doesn’t want to have those associated records pointing to nothing … maybe the schema doesn’t support that (eg required foreign key constraints) so it has to point to something

So the company changes Bob’s account details. They delete his profile picture, his phone number, etc. but Name and Email are required by the database. Their deletion process changes Bob’s name to deleted_user and they change his email to deleted@deleteduser.com thinking that’s a dead domain that’ll never be valid to receive emails.

Later, another process triggers an email. Someone sends Bob’s account a message, replies to a thread, etc. this process doesn’t know / care that Bob’s account was deleted so it fires the email to deleted@deleteduser.com

There are a lot of problems with the decision making here, and there are better ways to handle all of this. But these are all rational decisions in the moment that can cause an email to be sent to an “invalid” email address

[–] A_norny_mousse@piefed.zip 15 points 3 days ago* (last edited 3 days ago) (1 children)

As in my other comment, I don't understand why they don't use deleted_user@our-company.com? It doesn't take an IT-specialist to see the dangers in using a domain they don't control.

But I guess that's the point of this article: the jaw-dropping stupidity.

[–] perfectly_boiled_pizza@lemmy.world 7 points 3 days ago (1 children)

Most people who aren't interested in tech have to be taught this as they have no idea what e-mail actually is.

I worked in a company where we had to write addresses like that 10-30 times a day.

Someone once used fucking gmail and all hell broke loose.

[–] A_norny_mousse@piefed.zip 1 points 3 days ago (1 children)

Most people who aren’t interested in tech have to be taught this as they have no idea what e-mail actually is.

I would have accepted this 20 years ago, but not anymore. People need to have a basic understanding of how the tools they use daily work. I know, they don't. And it's one of my pet conspiracy theories that Big Tech abstracts their users away from how things actually work on purpose. The results are devastating, esp. when it comes to where IT tech crosses politics.

[–] Gumus@lemmy.dbzer0.com 1 points 3 days ago (1 children)

Also general education is commonly lagging at least a decade after current tech. I know email has been around for longer than that, but IT education is in a sad state.

[–] A_norny_mousse@piefed.zip 1 points 3 days ago

That certainly is part of the problem.

[–] grue@lemmy.world 5 points 3 days ago (2 children)

It's still a stupid solution with all sorts of 'code smells' and bad design, but the least they could do in a case like that is use @example.com.

load more comments (2 replies)
[–] AlphaOmega@lemmy.world 5 points 3 days ago

Thanks. That kind of makes sense.

[–] nibbs@lemmy.zip 3 points 3 days ago (1 children)

As you say, "at the time, a reasonable decision". What I don't understand tho, is, why nobody, for five seconds, maybe thought, how it could be a good idea to just filter this standard address at the SMTP server to be redirected to something sensible inside the org. My best guess is, different departments / sub orgs.

[–] blueduck@piefed.social 4 points 3 days ago

Distributed decision making, and these are all systems that are transactional or regulatory and not necessarily driving revenue / customer value.

The IT / Systems team was told “stand up an SMTP server so we can send emails” and there’s no more discussion of capturing / trapping / dead boxes. And as an engineer if you start to add that scope, “why are you taking so long? I just need to send emails.”

And then the delete account project is “GDRP says we need to delete accounts. So delete them in the least expensive way possible.” Which means, as an engineer, don’t spend a ton of time on this. In my previous company, we were still manually deleting accounts. As in SRE connected to the DB and ran a SQL command, by hand, with a piped in user ID.

The notifications team is responsible for sending messages. Why do they care, or should be responsible for, identifying if a user is deleted? They’re responsible for maintaining the SPAM/unsubscribe list but not the user accounts.

it’s distributed decision making, no one cross-cutting or thinking about these edge cases that impact multiple systems

[–] ChanchoManco@lemmy.zip 5 points 3 days ago

This reminded me of the guy that bought asdf.com, according to the website he would get all sorts of mails at asdf@asdf.com I remember this from way back on the boom of the internet, surprised the site is still up.

[–] jtrek@startrek.website 8 points 4 days ago (1 children)

I've used example.com in tests because my understanding is that domain is for examples and tests, and it's pretty harmless if something accidentally really sends an email

[–] RustySharp@programming.dev 9 points 3 days ago (2 children)

If I were the NSA running example.com, I too would say it's "totally harmless, for realsies, trust us".

[–] XeroxCool@lemmy.world 5 points 3 days ago

Xkcd.com/792

[–] some_kind_of_guy@lemmy.world 5 points 3 days ago (1 children)

It's the IANA who has it reserved

[–] RustySharp@programming.dev 4 points 3 days ago (1 children)

Yes. Yes. Totally not the NSA.

[–] BeardedGingerWonder@feddit.uk 5 points 3 days ago

It's in the name "I Am Not the American national security agency - IANA"

load more comments
view more: next ›