Live data from Hacker News

Firefox Relay

relay.firefox.com

21–30 of 160 posts

Re: Firefox Relay

#21
post #3

Earlier quoted context omitted.

It's rare though. I have been using alias services like Anonaddy and SimpleLogin for nearly two years. I have seen only on website block SimpleLogin, and it was a Pixelfed instance. I simply signed up on another Pixelfed instance as these are federated. These alias companies also have multiple domains, so in a way these blocks can be worked around.

Mailinator's domains are pretty much all blocked in lots of cases. There are lists filled with such domains that services often seem to use.

Mailinator is very famous. I never heard about the other services in this sub thread though. It could be that they are allowed because few people know that they exist.

Re: Firefox Relay

#23

You can create aliases on Gmail with "+". firstname.lastname+spam@gmail.com. Probably works with other email providers too.

This is a standard and every semi-smart spammer can strip the "\+.+" part so it works only with legit websites that you want to handle in a special way.

Re: Firefox Relay

#24

You can create aliases on Gmail with "+". firstname.lastname+spam@gmail.com. Probably works with other email providers too.

Yes, that is standard subaddressing but not all email providers support it (I've never heard of a Microsoft Exchange server supporting it). One problem with it is it exposes your real email address. Another problem, as the Wikipedia article notes, is there are a lot of inputs with poorly written validation that won't accept '+' as a valid email address character (they often only allow a-z, '.', and '@').

https://en.wikipedia.org/wiki/Email_address#Subaddressing

Re: Firefox Relay

#25

I'm conflicted about this. For me, the best implementation of private alias is the Apple one: %randomwords%[at]icloud.com. It's way harder to wildcard block [at]icloud.com, as there are legit users of the icloud domain, than a wildcard block for: [at]mozmail.com. Unfortunately, using the apple implementation is just one more stone into their walled garden. I really wish firefox could create a legit free [at]firefox (…

> They bought Pocket (which I loved) and now it's on life support.

I've been waiting a long time to find someone who thought that Pocket was a good idea. Can you expand on what you like about it being integrated into firefox natively as opposed to an extension?

Re: Firefox Relay

#26
I've been using this pattern for years.

I have a custom domain just for signups, and I sign up with [service].[username]@customdomain. The domain simply has a catchall email "accounts@customdomain"

Combined with a password manager (Bitwarden) this is absolutely brilliant.

* Spam: if I get any spam, I know exactly which company is responsible, whether directly, through selling user data or because of breaches. And I can simply block the whole alias.

* Multiple accounts: If you need a second account with some service, you simply use a new alias. No need to worry about secondary emails just for a few accounts.

* Mitigate data leaks: if some database gets compromised, all they get is a throwaway email. They also can't try to log in to other accounts or do password resets if they get a hold of the password. (somewhat redundant with a password manager and unique passwords, but still)

* Privacy: all those ad data aggregators have a harder time connecting me between accounts. (of course they still use names, address, credit card info, etc; but it helps)

* Easy self-hosting: email hosting can be a pain. But in this case you only need to receive, never send. And receiving basically always works, even with the most broken email server setup.

A downside is the unique domain name. I always wanted a shared domain with lots of users to further reduce exposure.

I actually thought about starting a service that provides this, but it's a niche product with non-trivial technical hurdles and potentially lots of support demands, so I'm happy that Mozilla is offering this.

The only downside is that people get really confused when they have to deal with your email, for example when calling support. But it's never been a real issue.

Highly recommended!

Re: Firefox Relay

#27

I've been using this pattern for years. I have a custom domain just for signups, and I sign up with [service].[username]@customdomain. The domain simply has a catchall email "accounts@customdomain" Combined with a password manager (Bitwarden) this is absolutely brilliant. * Spam: if I get any spam, I know exactly which company is responsible, whether directly, through selling user data or because of breaches. And I c…

> of course they still use names, address, credit card info, etc

I haven't used this service, only heard about it. It might cover your missing piece for credit card info.

https://privacy.com/

Of course, privacy.com ends up being the one that can aggregate your CC information together.

Re: Firefox Relay

#28

I've been using this pattern for years. I have a custom domain just for signups, and I sign up with [service].[username]@customdomain. The domain simply has a catchall email "accounts@customdomain" Combined with a password manager (Bitwarden) this is absolutely brilliant. * Spam: if I get any spam, I know exactly which company is responsible, whether directly, through selling user data or because of breaches. And I c…

This is almost identical to my approach. One minor difference is that I got on the free Google Apps for Business plan a decade or so ago. So deliverability is there, which does come up from time to time. i.e. Occasionally you need support, and the service wants you to email them/reply to their email from the email you use with their service. So in Gmail, I have to set up an account/alias so I can send the email.

I did self-host this way back, using MailEnable on Windows Server. It... worked. But I don't recommend it!

The other downside is that the catch-all sometimes gets a lot of [gibberish]@[customdomain]. It's not too bad now, but there was a period where gibberish hexidecimal aliases were spammed regularly.

Re: Firefox Relay

#29

You can create aliases on Gmail with "+". firstname.lastname+spam@gmail.com. Probably works with other email providers too.

This is a standard and every semi-smart spammer can strip the "\+.+" part so it works only with legit websites that you want to handle in a special way.

Fastmail has subdomain addressing [0] to solve that.

whateveryoulike@username.domain.tld is the same as username+whateveryoulike@domain.tld

[0]: https://www.fastmail.help/hc/en-us/articles/360060591053-Plu...

Re: Firefox Relay

#30

I've been using this pattern for years. I have a custom domain just for signups, and I sign up with [service].[username]@customdomain. The domain simply has a catchall email "accounts@customdomain" Combined with a password manager (Bitwarden) this is absolutely brilliant. * Spam: if I get any spam, I know exactly which company is responsible, whether directly, through selling user data or because of breaches. And I c…

Your single point of failure is your account at your registrar, where your domain can be hijacked. Once your domain is taken over - all of your accounts which are connected to this domain are also owned. So you're still only one hack away here.
Post reply on HN