Live data from Hacker News

Firefox Relay

relay.firefox.com

31–40 of 160 posts

Re: Firefox Relay

#31
post #8

This is cool, however, personally I feel like for my use case that integration with 1Password and Fastmail is better because I don't want to depend on a browser that I cannot use everywhere to manage this. In the same way that I avoid Sign in with Apple - what am I supposed to do when I need to Sign in without Apple?! I find 1P+FM is a much more cross-platform solution. However, I commend Firefox for creating this fu…

(Relay engineer here.)

While we provide a Firefox extension with which generating an alias is just a click away, you're not dependent on Firefox specifically: you can generate and access your generated alias through the web interface at https://relay.firefox.com in any browser.

Re: Firefox Relay

#32
post #30

I've been using this pattern for years. I have a custom domain just for signups, and I sign up with [service].[username]@customdomain. The domain simply has a catchall email "accounts@customdomain" Combined with a password manager (Bitwarden) this is absolutely brilliant. * Spam: if I get any spam, I know exactly which company is responsible, whether directly, through selling user data or because of breaches. And I c…

Your single point of failure is your account at your registrar, where your domain can be hijacked. Once your domain is taken over - all of your accounts which are connected to this domain are also owned. So you're still only one hack away here.

That is accurate for any and all approaches with email, but it does not negate the (significant) incremental improvements this strategy grants you.

Re: Firefox Relay

#33
post #4

Doesn’t seem like I can sign up in Australia, payment is not accepted..

(Relay engineer here.)

Unfortunately the Premium service that we launched yesterday is only available in a limited (but growing) number of countries. The free version should be available to you though.

Re: Firefox Relay

#34
post #30

I've been using this pattern for years. I have a custom domain just for signups, and I sign up with [service].[username]@customdomain. The domain simply has a catchall email "accounts@customdomain" Combined with a password manager (Bitwarden) this is absolutely brilliant. * Spam: if I get any spam, I know exactly which company is responsible, whether directly, through selling user data or because of breaches. And I c…

Your single point of failure is your account at your registrar, where your domain can be hijacked. Once your domain is taken over - all of your accounts which are connected to this domain are also owned. So you're still only one hack away here.

Well, sure. But my registrar requires 2FA and has good support. The domain also has a hard lock for transfers, which would require a signature and id.

A targeted hack that could get 2FA tokens or a social engineering attack on the registar aren't threat vectors I'm concerned about. I'm not that interesting.

Much better than being at risk of, for example, Google cancelling your Gmail account for whatever reason, or your mail account getting hacked.

Re: Firefox Relay

#35
post #30

Earlier quoted context omitted.

Your single point of failure is your account at your registrar, where your domain can be hijacked. Once your domain is taken over - all of your accounts which are connected to this domain are also owned. So you're still only one hack away here.

That is accurate for any and all approaches with email, but it does not negate the (significant) incremental improvements this strategy grants you.

> "That is accurate for any and all approaches with email"

The likelihood of a takeover of @gmail.com or @icloud.com is much lower though.

Re: Firefox Relay

#36
post #24

You can create aliases on Gmail with "+". firstname.lastname+spam@gmail.com. Probably works with other email providers too.

Yes, that is standard subaddressing but not all email providers support it (I've never heard of a Microsoft Exchange server supporting it). One problem with it is it exposes your real email address. Another problem, as the Wikipedia article notes, is there are a lot of inputs with poorly written validation that won't accept '+' as a valid email address character (they often only allow a-z, '.', and '@'). https://en.w…

> I've never heard of a Microsoft Exchange server supporting it

It's supported on Exchange Online/Office 365 environments. There's a switch to enable it. We use it in our organisation.

Re: Firefox Relay

#37
Urgh, on one hand i love the idea and i think its a good business venture for mozilla.

On the other hand, they are injecting little scare bubbles into everybody's website to advertise this, and that rubs me up the wrong way so much i want nothing to do with it.

Re: Firefox Relay

#38
post #16
post #7

You can only hope that the service will last long enough and not be discontinued like Firefox Send. Otherwise you have created online accounts with dead alias emails. I create the alias mail addresses in my postfix installation under /etc/aliases

I have domains with catchall so every email is different, can be created on the fly and can be easily revoked. This is the simplest solution I think.

If you rely on catchall, doesn't that make it more difficult to eliminate spam from breaches or bad actor companies/services? With aliases and no catchall, I just delete a one-time-use alias and all spam goes away. Can you do something similar even if you are using catchall?

Re: Firefox Relay

#39

I've been using this pattern for years. I have a custom domain just for signups, and I sign up with [service].[username]@customdomain. The domain simply has a catchall email "accounts@customdomain" Combined with a password manager (Bitwarden) this is absolutely brilliant. * Spam: if I get any spam, I know exactly which company is responsible, whether directly, through selling user data or because of breaches. And I c…

Heh, I work on Relay and I do the same :) While the approach is great, especially in situations away from my computer where I can't generate a new alias in advance, working on it I discovered that using Relay still has a couple of advantages:

- My other addresses are unguessable.

- It's far easier to block emails sent to a single alias. With my own domain, I'll have to go and add a filter into which I copy-paste the particular alias I want to block. With Relay, I can just open the dashboard and hit the toggle next to the alias labelled with the domain I used it on.

- I was looking for ways to give Mozilla money for a long time (though now I'm working there, so I guess I'm also taking its money).

In general, my setup now is to keep using my old setup for long-term accounts with somewhat more reliable services, and use Relay for e.g. requesting a quotation or having a single thing shipped to me.

Re: Firefox Relay

#40
post #27

I've been using this pattern for years. I have a custom domain just for signups, and I sign up with [service].[username]@customdomain. The domain simply has a catchall email "accounts@customdomain" Combined with a password manager (Bitwarden) this is absolutely brilliant. * Spam: if I get any spam, I know exactly which company is responsible, whether directly, through selling user data or because of breaches. And I c…

> of course they still use names, address, credit card info, etc I haven't used this service, only heard about it. It might cover your missing piece for credit card info. https://privacy.com/ Of course, privacy.com ends up being the one that can aggregate your CC information together.

I've been using this service for years and love it.
Post reply on HN