Sihai network

Millions of e-mail accounts sell for 50 yuan, and the seller claims to earn one iPhone 7 a day

Nowadays, with the Internet in power and big data, people no longer seem to have any privacy. Their identity information is under the prying of the Internet, and there is no hiding place. Recently, a report that the price of a million e-mail accounts is 50 yuan has put Netease on the cusp of the storm.

The price of one million email accounts is 50 yuan

On May 7, it was reported that "on a certain exchange platform, someone openly peddled Netease e-mail accounts. The price of a million e-mail accounts was only 50 yuan. The seller claims to be able to send marketing messages to these e-mails and display 'files' that are said to contain millions of e-mail accounts. The seller claimed, "when I made the most money, I made money to buy an iPhone 7 one day.".

In response, Netease e-mail said on May 7 that it is illegal to sell Netease e-mail accounts publicly, involving only the e-mail address and not the user's sensitive information. "After investigation, the illegal activities mentioned in the report only involve the e-mail address and not the user's sensitive information. Please don't worry. We have reported the case to the public security organ for the first time, and are actively cooperating with the police to crack down on this illegal and criminal act. '

But this view has been questioned by netizens. Some netizens think that 'e-mail address is the same as mobile phone number, and will not tell strangers'.

In response to netizens' queries, Netease exclusively replied to Beijing Business Daily that the email address is not only used for users' daily communication, but also the information that users need to use when registering / binding and using other networking products. To a certain extent, it belongs to the information that individuals will authorize the use of specific objects in some scenarios.

Netease disclosed that all services of Netease account use mechanisms such as HTTPS protocol (hypertext transmission security protocol) and desensitization display of email account to protect Netease email address.

Two ways of collecting e-mail address of black property

At the same time, Netease introduces two ways of collecting email addresses: collecting and importing email addresses from Internet products by illegal means. At present, most of the platforms on the market have certain anti crawling means to intercept, but some products, because of their weak defense, have user email addresses stored on their websites. If any link is broken, the registered email addresses of users of the products may be leaked; Through permutation and combination, the black product simulates the generation of e-mail address, and through certain technical means to verify, washes out the registered e-mail address.

This is not the first time that Netease e-mail has encountered security problems. In 2015 and 2017, Netease e-mail was also involved in information leakage incidents. In 2017, the black cloud vulnerability reporting platform announced the discovery of a vulnerability, which will lead to the leakage of over 100 million data in Netease's 163 and 126 e-mail boxes, involving transaction proof data, e-mail account numbers, passwords, and user security of over 100 million data.

However, Netease e-mail said that the database was not attacked and leaked, but hackers in other websites to obtain the same name with Netease e-mail account and password, and log in.

On the protection of e-mail address, Netease disclosed that all services of Netease account adopt the HTTPS protocol to ensure the security of information transmission; the e-mail account is desensitized on all interactive interfaces of the account security center; the access of the e-mail data center is provided with a strict audit mechanism.

In addition, for the protection of personal e-mail address, Netease suggests that users: regularly check and kill computer viruses, upgrade system software; do not input important personal account information in untrusted devices and websites; once suspicious situation is found, please report it as soon as possible, and timely modify the account password.