Live data from Hacker News

Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

github.com

121–130 of 304 posts

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#121

I've started using my own domain to avoid giving out my "real" addresseverywhere. It doesn't always work, but it usually does.

I do the same but my worry is that any kind of smart enough spammer or stalker can use the domain as a fingerprint.

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#123

Earlier quoted context omitted.

This is not outside of the realm of possible. Google does nothing to stop spammers, makes up their own non-public rules and doesn't communicate with the Internet community, so Gmail addresses are already on shaky grounds. For instance, for starters, go search through all of your email for any email sent from Google servers where the "Reply to:" doesn't match the "Mail from:", and tell me if there are any legitimate i…

It's really difficult creating a fake google account nowadays

I've created several ones over the course of months without any issue. I wasn't even asked for a phone number.

Of course if you do it constantly or from third-world IP addresses, I understand they refuse your attempts.

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#124

It's arguably the case that Firefox Relay is no different from the other services in this list. If someone can use it to create ~unlimited identities for almost free, that serves the same purpose as any other disposable email service. And frankly, there's no sense in getting upset about a directory of services that allow the creation of unlimited disposable identities. If it wasn't this github repo, it would be anoth…

I find that the services most vulnerable to sybil attacks are malicious ones funded by "growth and engagement" - see my comment above: https://news.ycombinator.com/item?id=29960340

If you charge for the service, a lot of attacks suddenly become pointless or unprofitable, implicitly mitigating the problem.

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#125
post #28

Earlier quoted context omitted.

> people use disposable email addresses all the time to avoid paying for our product. From the prospective subscriber’s perspective, that’s your problem to worry about — not theirs. > We don’t sell any data. How should users know that? It’s also not just a matter of selling data — almost all companies will spam your email address, even if you check the box asking them not to.

>From the prospective subscriber’s perspective, that’s your problem to worry about — not theirs. exactly...which is why there are blacklists like the one linked in the OP.

Businesses that don't accept my email address don't get my business.

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#126

Earlier quoted context omitted.

> I want to know what you would call this unsolicited, non-transactional commercial email. Commercial email, differentiated from spam in that you have a commercial relationship with Amazon that you initiated and agreed to (i.e. solicited), and as such, they are allowed to market to you until such time as you ask them to stop. I can see my opinion on this matter isn't a common one on HN.

> I can see my opinion on this matter isn't a common one on HN. Your opinion isn’t common among anyone other than marketers trying to justify sending spam.

..And people who spend a lot of time fighting actual spam, as in, actual unsolicited junk email, who have to deal with false positives from uninformed users who think the 'report spam' button is the appropriate response to them getting an Amazon email they don't like.

I'm disappointed to see that attitude here.

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#127

The reason disposable email addresses exist and are popular is because services have abused users' trust to not use these emails for shady ad revenue and marketing schemes. It's further compounded by shoddy security that leads to leaks and exposure of people's personal email addresses to pwned compromised lists. People don't want to give up their personal email addresses so that they can be spammed or hacked. Until s…

I’m the founder of a small bootstrapped SAAS and people use disposable email addresses all the time to avoid paying for our product. We don’t sell any data.

Once the my data is in your server. There is no way for me to know what you are doing with my data. You could be selling it. How will I know?

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#128
post #52
post #4

Is iCloud's "Hide My E-mail" on the list too?

No. Apple's "Hide My Email" uses the same `icloud.com` domain as the rest of their email addresses (unless you're using the "Sign-in with Apple" feature which uses `privaterelay.appleid.com`). Blocking `privaterelay.appleid.com` would be kinda pointless since you'd be breaking your "Sign-in with Apple" feature, but if you don't support that feature you could block it (theoretically, one could create a login for SiteA…

Genuinely curious, does anyone actually use an "@icloud.com" address to sign up for anything? I was under the impression that iCloud emails were only used as a FQDN for internal Apple services, but it's been ages since I've had an iCloud account.

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#129

Earlier quoted context omitted.

I’m the founder of a small bootstrapped SAAS and people use disposable email addresses all the time to avoid paying for our product. We don’t sell any data.

Out of curiosity, what does your service do and how do you know that these users would've paid for the service otherwise? As in with piracy, the argument is that it hurts sales but it's very difficult to determine whether that is really true.

I can't speak for the OP but free trial period abuse is very common.

"Would have paid for the service" vs "Are actively working to use the service without paying for it" are two different things.

I worked for a company that had some free tools on the web, with no published API. Those tools were scraped well above the T&C limitations to be mined by other companies.

We had a "free forever" account that you could use to monitor a single domain. Within the user table there were multiple instances of 20 to 300 (worst case) myaccount+@mycompanydomain.com trying to abuse the single domain rule without paying for it. In one case, the results were being packaged up to be shown in somebody else's product.

I'm certainly not advocating for spam or selling data (the company I mentioned didn't do this either), but abuse it the more common use case that web businesses deal with. To combat abuse, 90% of the battle is to identify where the abuse is coming from first.

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#130
post #51

Earlier quoted context omitted.

Why doesn't it always work? I'm also using my own domain, not sure why'd that ever 'not work'.

As an experiment, I once tried to see if online services accepted role-based emails (like admin@domain info@domin sales@domain contact@domain). Surprisingly, the game Eve Online was super-strict in refusing these types of addresses. Most other services were fine though.

EVE Online has highly sophisticated user fingerprinting to prevent fraud and real money trading. So even if you got through with that email address it wouldn't be long before an issue was raised for your account.

With EVE, fraud comes in many ways and most would presume credit card fraud but because you can earn ISK in-game, which can be converted/sold for PLEX (their game-time subscription currency, worth real $) many items (Capital Ships, High Experience Characters, Corporations) are bought and sold for real money outside of the platform - which in some cases, is revenue that EVE would/could benefit from if PLEX was purchased from them directly and used legitimately instead.

So aside from basic things like blocking utility email addresses, they have sophisticated algorithms that monitor user accounts for unusual activity. The definition of unusual is constantly growing/changing and it is monitored and managed by a dedicated "security" team.

Source: Friend of friend works in that security team.

Post reply on HN