Earlier quoted context omitted.
I know a guy who uses a service that creates a unique email account for every service he signs up for. That way, he tells me, if he ever gets any spam, he can delete the account and it doesn't affect any of his other email accounts.
With gmail, you don't need it - foo+bar@gmail.com will end up as foo@gmail.com and you can filter by To: header.
Yahoo Triples Estimate of Breached Accounts to 3B
61–70 of 311 posts
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#62Earlier quoted context omitted.
With gmail, you don't need it - foo+bar@gmail.com will end up as foo@gmail.com and you can filter by To: header.
Yeah, you do realize spammers know that, too? They will just strip part after the +
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#63I think the issue right now is that private user information is viewed as an asset, not a liability. If we could find a way to make it more of a liability, companies would be less likely to collect it just for the sake of having it, and they would be more proactive in securing it.
User accounts? Really? This is Yahoo we’re talking about. You really do need user accounts to run an email service
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#64Re: Yahoo Triples Estimate of Breached Accounts to 3B
#65Re: Yahoo Triples Estimate of Breached Accounts to 3B
#66I think the issue right now is that private user information is viewed as an asset, not a liability. If we could find a way to make it more of a liability, companies would be less likely to collect it just for the sake of having it, and they would be more proactive in securing it.
User accounts? Really? This is Yahoo we’re talking about. You really do need user accounts to run an email service
Exactly, regardless of that companies keep asking users for a whole collection of personal data, not always making it obvious which fields are actually required because it's good business for them to get as much personal data as possible.
Average users are usually unsure about a lot of this stuff and naive enough to enter their real data for fear of getting caught "lying".
This happens because companies see this data as an asset instead of a liability, from the companies view not asking for that data/tricking users into giving it away means missing out on assets.
But if you instead make the personal data a liability, by enforcing standards for keeping/sharing it with hefty fines, then fewer companies will go out of their way asking users for personal information they have no business asking for in the first place because it would put them in a position of liability for what happens with said data.
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#67Earlier quoted context omitted.
With gmail, you don't need it - foo+bar@gmail.com will end up as foo@gmail.com and you can filter by To: header.
I’ve run a fair amount of email campaigns where we strip out the + if gmail is the domain to ensure it doesn’t end up in some weird filter. Dick move, I know. Tell marketing that though. I personally use gmail through a vanity domain and have a catch all rule, so I end up signing up with a fake email account for every domain (hn@mydomain.com) and then the catch all forwards it to my real account (me@mydomain.com).
At which point you should wind up in the "how widely can I advertise that you're a spammer and all your outbound email should all be routed straight to /dev/null for sending mail to an email address you were never given" filter.
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#68I think the issue right now is that private user information is viewed as an asset, not a liability. If we could find a way to make it more of a liability, companies would be less likely to collect it just for the sake of having it, and they would be more proactive in securing it.
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#69I think the issue right now is that private user information is viewed as an asset, not a liability. If we could find a way to make it more of a liability, companies would be less likely to collect it just for the sake of having it, and they would be more proactive in securing it.
We need laws that give companies incentive to store very little data on us outside of what's absolutely required for the functioning of the service. And if they do store additional info, and their servers are breached, then automatic hefty fines should be paid (right after the mandatory notification to authorities and the public).
That should encourage companies to either minimize data collection or use end-to-end encryption, where most of that additional data would be stored on the client's device. This would have to exempt them from liability, and it should since the data wouldn't be on their servers if breached.
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#70Looks like both Equifax (2.5m additional accounts) and Yahoo chose today as a good day to bury bad news (the papers being filled with Las Vegas, Puerto Rico, etc). Slimy moves from their PR teams.