# What is"suntimesmail.com"??

**URL:** <https://boards.straightdope.com/t/what-is-suntimesmail-com/678193>\
**Category:** About This Message Board\
**Created:** [January 7, 2014, 11:27pm UTC](https://boards.straightdope.com/t/what-is-suntimesmail-com/678193 "2014-01-07T23:27:17Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Lobsang](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/lobsang/32/4067_2.png) [@Lobsang](https://boards.straightdope.com/u/Lobsang)\
**Post date:** [January 7, 2014, 11:27pm UTC](https://boards.straightdope.com/t/what-is-suntimesmail-com/678193/1 "2014-01-07T23:27:17Z")

</div>

The email we got about the hack displayed a link pointing to the change password page within this site, but **behind** that link was the true link pointing to [suntimesmail.com](http://suntimesmail.com)

This type of thing usually rings alarm bells about Phishing. What’s the deal with that?

---

<div class="post-metadata">

**Author:** ![Hank\_Beecher](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/hank_beecher/32/7275_2.png) [@Hank\_Beecher](https://boards.straightdope.com/u/Hank_Beecher)\
**Post date:** [January 7, 2014, 11:32pm UTC](https://boards.straightdope.com/t/what-is-suntimesmail-com/678193/2 "2014-01-07T23:32:05Z")

</div>

My thoughts too.

---

<div class="post-metadata">

**Author:** ![Knorf](https://avatars.discourse-cdn.com/v4/letter/k/58956e/32.png) [@Knorf](https://boards.straightdope.com/u/Knorf)\
**Post date:** [January 7, 2014, 11:33pm UTC](https://boards.straightdope.com/t/what-is-suntimesmail-com/678193/3 "2014-01-07T23:33:21Z")

</div>

[http://boards.straightdope.com/sdmb/announcement.php?f=2](http://boards.straightdope.com/sdmb/announcement.php?f=2)

---

<div class="post-metadata">

**Author:** ![Lobsang](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/lobsang/32/4067_2.png) [@Lobsang](https://boards.straightdope.com/u/Lobsang)\
**Post date:** [January 7, 2014, 11:36pm UTC](https://boards.straightdope.com/t/what-is-suntimesmail-com/678193/4 "2014-01-07T23:36:19Z")

</div>

> [@Knorf](#):
>
> [http://boards.straightdope.com/sdmb/announcement.php?f=2](http://boards.straightdope.com/sdmb/announcement.php?f=2)

Yes. I read that. It doesn’t explain why one URL is hidden behind another. Even if it is a legitimate URL owned by chicagoreader, it’s still a very suspicious thing to see under the circumstances.

---

<div class="post-metadata">

**Author:** ![Lips\_Obsession](https://avatars.discourse-cdn.com/v4/letter/l/bbce88/32.png) [@Lips\_Obsession](https://boards.straightdope.com/u/Lips_Obsession)\
**Post date:** [January 7, 2014, 11:52pm UTC](https://boards.straightdope.com/t/what-is-suntimesmail-com/678193/5 "2014-01-07T23:52:45Z")

</div>

Agreed completely.

To be safe I changed the password after manually navigating to the board.

---

<div class="post-metadata">

**Author:** ![Keeve](https://avatars.discourse-cdn.com/v4/letter/k/f07891/32.png) [@Keeve](https://boards.straightdope.com/u/Keeve)\
**Post date:** [January 7, 2014, 11:58pm UTC](https://boards.straightdope.com/t/what-is-suntimesmail-com/678193/6 "2014-01-07T23:58:16Z")

</div>

Straight Dope is owned by the Chicago Reader, and the Wikipedia article on the [Chigago Reader](https://en.wikipedia.org/wiki/Chicago_Reader) explains:

> [@](#):
>
> In 2012, the Chicago Reader was acquired by Wrapports LLC, parent company of Sun-Times Media.

---

<div class="post-metadata">

**Author:** ![running\_coach](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/running_coach/32/15836_2.png) [@running\_coach](https://boards.straightdope.com/u/running_coach)\
**Post date:** [January 7, 2014, 11:58pm UTC](https://boards.straightdope.com/t/what-is-suntimesmail-com/678193/7 "2014-01-07T23:58:19Z")

</div>

> [@Lobsang](#):
>
> Yes. I read that. It doesn’t explain why one URL is hidden behind another. Even if it is a legitimate URL owned by chicagoreader, it’s still a very suspicious thing to see under the circumstances.

At the bottom of the announcement page.

Copyright © 2013 Sun-Times Media, LLC.

ETA Missed it by _that_ much!

---

<div class="post-metadata">

**Author:** ![Keeve](https://avatars.discourse-cdn.com/v4/letter/k/f07891/32.png) [@Keeve](https://boards.straightdope.com/u/Keeve)\
**Post date:** [January 8, 2014, 12:00am UTC](https://boards.straightdope.com/t/what-is-suntimesmail-com/678193/8 "2014-01-08T00:00:32Z")

</div>

> [@Lobsang](#):
>
> Yes. I read that. It doesn’t explain why one URL is hidden behind another. Even if it is a legitimate URL owned by chicagoreader, it’s still a very suspicious thing to see under the circumstances.

I totally agree, and that’s why I refused to use that link. But in fairness, my guess is that in their rush to inform us, they didn’t realize which domain they were using to send the email.

---

<div class="post-metadata">

**Author:** ![Lobsang](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/lobsang/32/4067_2.png) [@Lobsang](https://boards.straightdope.com/u/Lobsang)\
**Post date:** [January 8, 2014, 12:03am UTC](https://boards.straightdope.com/t/what-is-suntimesmail-com/678193/9 "2014-01-08T00:03:24Z")

</div>

> [@runner pat](#):
>
> At the bottom of the announcement page.
> 
> Copyright © 2013 Sun-Times Media, LLC.
> 
> ETA Missed it by _that_ much!

I get this, and I understand. My point is, when people get an email that alarms them, it doesn’t help when a ‘click here to enter your password details’ link in an email shows one URL and hides another, regardless of what the other one is. Those who’ve learnt how phishing works are immediately further alarmed by this!

Why not just provide the legitimate link?

---

<div class="post-metadata">

**Author:** ![Keeve](https://avatars.discourse-cdn.com/v4/letter/k/f07891/32.png) [@Keeve](https://boards.straightdope.com/u/Keeve)\
**Post date:** [January 8, 2014, 12:08am UTC](https://boards.straightdope.com/t/what-is-suntimesmail-com/678193/10 "2014-01-08T00:08:20Z")

</div>

Excellent point, **Lobsang**. The truth is, a lot of this conversation whooshed me, because I never looked to the link, or what was behind it, until just now. I was focused on the fact that the email itself came from [reply@suntimesmail.com](mailto:reply@suntimesmail.com).

---

<div class="post-metadata">

**Author:** ![Lobsang](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/lobsang/32/4067_2.png) [@Lobsang](https://boards.straightdope.com/u/Lobsang)\
**Post date:** [January 8, 2014, 12:13am UTC](https://boards.straightdope.com/t/what-is-suntimesmail-com/678193/11 "2014-01-08T00:13:59Z")

</div>

> [@Keeve](#):
>
> Excellent point, **Lobsang**. The truth is, a lot of this conversation whooshed me, because I never looked to the link, or what was behind it, until just now. I was focused on the fact that the email itself came from [reply@suntimesmail.com](mailto:reply@suntimesmail.com).

I didn’t notice that 🙂  
What’s more, my reader (Thunderbird) shows a warning that the email might be a scam.

---

<div class="post-metadata">

**Author:** ![choie](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/choie/32/7829_2.png) [@choie](https://boards.straightdope.com/u/choie)\
**Post date:** [January 8, 2014, 1:32am UTC](https://boards.straightdope.com/t/what-is-suntimesmail-com/678193/12 "2014-01-08T01:32:00Z")

</div>

It’s almost certainly just a simple tracking code used by the site’s owners when sending out mass emails. The email is being sent by the suntimes server on behalf of the SDMB (not surprisingly since the former owns the latter). The mail server converts links in the email to this tracking URL so that it can, well, track how many people click on the link. It’s obviously more useful in marketing or promotional messages where you want to see how many clickthroughs you get. In this case they used the same mass email system and kept the link-tracking option “on,” either by design or just carelessness. It’s nothing nefarious, just a way for those doing the mailing to note which links get clicked on, and where the traffic comes from.

It’s certainly good to be cautious about where links are actually going, because it is a common phishing device, so I think it’s great that you noticed such things.

Fortunately, since we know the S-T owns the SDMB, in this case there’s nothing scary, just regular housekeeping stuff.

---

<div class="post-metadata">

**Author:** ![Senegoid](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/senegoid/32/6606_2.png) [@Senegoid](https://boards.straightdope.com/u/Senegoid)\
**Post date:** [January 8, 2014, 1:48am UTC](https://boards.straightdope.com/t/what-is-suntimesmail-com/678193/13 "2014-01-08T01:48:13Z")

</div>

But the change-password link in **Ed Zotti** ’s announcement looks perfectly cromulent, so I used that one. (Besides which, I haven’t seen the e-mail yet. This thread is the first thing I’ve seen about it.)

No-way, no-how should anyone EVER click on a link if the visible link actually _looks_ like a URL and the real link is different. That’s an absolute flaming red-phishing-phlag. Even if you know The Dope is owned by Sun Times and the real link looks kinda-sorts like it really comes from Sun Times.

ETA: Okay, just checked my e-mail. No such message there! Do messages like that only go to paid members?

---

<div class="post-metadata">

**Author:** ![Kenm](https://avatars.discourse-cdn.com/v4/letter/k/bc79bd/32.png) [@Kenm](https://boards.straightdope.com/u/Kenm)\
**Post date:** [January 8, 2014, 2:04am UTC](https://boards.straightdope.com/t/what-is-suntimesmail-com/678193/14 "2014-01-08T02:04:43Z")

</div>

> [@Senegoid](#):
>
> Okay, just checked my e-mail. No such message there! Do messages like that only go to paid members?

I received the email and I’m not a paid member.

---

<div class="post-metadata">

**Author:** ![Keeve](https://avatars.discourse-cdn.com/v4/letter/k/f07891/32.png) [@Keeve](https://boards.straightdope.com/u/Keeve)\
**Post date:** [January 8, 2014, 2:05am UTC](https://boards.straightdope.com/t/what-is-suntimesmail-com/678193/15 "2014-01-08T02:05:19Z")

</div>

> [@Senegoid](#):
>
> Okay, just checked my e-mail. No such message there! Do messages like that only go to paid members?

Nope. I’m not a paid member. Maybe you’re not looking at the email account that they have on file for you. Go check your profile.

---

<div class="post-metadata">

**Author:** ![Measure\_for\_Measure](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/measure_for_measure/32/557_2.png) [@Measure\_for\_Measure](https://boards.straightdope.com/u/Measure_for_Measure)\
**Post date:** [January 8, 2014, 4:28am UTC](https://boards.straightdope.com/t/what-is-suntimesmail-com/678193/16 "2014-01-08T04:28:53Z")

</div>

> [@choie](#):
>
> It’s almost certainly just a simple tracking code used by the site’s owners when sending out mass emails. The email is being sent by the suntimes server on behalf of the SDMB (not surprisingly since the former owns the latter).

Yes, standard practice in the industry. I’ve even seen financial institutions pull stunts like this.

Terrible practice as well, given phishing concerns. It’s a flag for me that the organization doesn’t care about its customers. Of course we sort of knew this: while the adminstrators and mods here are excellent, we are but a microdot within the larger corp.

---

<div class="post-metadata">

**Author:** ![kbear](https://avatars.discourse-cdn.com/v4/letter/k/4491bb/32.png) [@kbear](https://boards.straightdope.com/u/kbear)\
**Post date:** [January 8, 2014, 8:41am UTC](https://boards.straightdope.com/t/what-is-suntimesmail-com/678193/17 "2014-01-08T08:41:52Z")

</div>

> [@Keeve](#):
>
> Nope. I’m not a paid member. Maybe you’re not looking at the email account that they have on file for you. Go check your profile.

lol. Now I know why I never received the email reminding me to renew my paid account. Haven’t used that address since 2004!

---

<div class="post-metadata">

**Author:** ![Mislav](https://avatars.discourse-cdn.com/v4/letter/m/77aa72/32.png) [@Mislav](https://boards.straightdope.com/u/Mislav)\
**Post date:** [January 8, 2014, 9:23am UTC](https://boards.straightdope.com/t/what-is-suntimesmail-com/678193/18 "2014-01-08T09:23:49Z")

</div>

I used a link to change my password is that OK?

---

<div class="post-metadata">

**Author:** ![sandra\_nz](https://avatars.discourse-cdn.com/v4/letter/s/eada6e/32.png) [@sandra\_nz](https://boards.straightdope.com/u/sandra_nz)\
**Post date:** [January 8, 2014, 10:03am UTC](https://boards.straightdope.com/t/what-is-suntimesmail-com/678193/19 "2014-01-08T10:03:19Z")

</div>

Whenever I’ve received messages like this, I’ve always used my own bookmark to navigate to the site in question. It surprises me that companies still put links into emails like this!

---

<div class="post-metadata">

**Author:** ![wibble](https://avatars.discourse-cdn.com/v4/letter/w/73ab20/32.png) [@wibble](https://boards.straightdope.com/u/wibble)\
**Post date:** [January 8, 2014, 11:38am UTC](https://boards.straightdope.com/t/what-is-suntimesmail-com/678193/20 "2014-01-08T11:38:23Z")

</div>

Personally, I wonder how legitimate this ‘hacking event’ is; my cynical mind wonders whether it’s in fact just a scam to get more long-absent eyeballs (such as mine) back to a perhaps-languishing forum.

I can’t find an option to delete my ‘account’ here, which is the most sensible course of action in terms of protecting one’s identity if one doesn’t intend to revisit a place anytime soon…

AKA “How do I get out of this chicken-shit outfit?”

[Next page](https://boards.straightdope.com/t/what-is-suntimesmail-com/678193.md?page=2)
