Live data from Hacker News

Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

github.com

161–170 of 304 posts

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#161
post #118

Earlier quoted context omitted.

We did, it's called non-disposable email. A non-unique pseudoanonymous identity that's somewhat difficult to mint in bulk. If you don't like "accounts of well-known service providers" -- email or login-with-whoever then sources of identity that "everyone" has that are hard to get many of are government ids, phone numbers and credit cards. Like what else is there? For super technical people we could do something like…

I don't really get this. Where do you draw the line between disposable and non-disposable email? What prevents anyone from creating @gmail.com addresses?

The phone number requirement?

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#162
post #118

Earlier quoted context omitted.

We did, it's called non-disposable email. A non-unique pseudoanonymous identity that's somewhat difficult to mint in bulk. If you don't like "accounts of well-known service providers" -- email or login-with-whoever then sources of identity that "everyone" has that are hard to get many of are government ids, phone numbers and credit cards. Like what else is there? For super technical people we could do something like…

I don't really get this. Where do you draw the line between disposable and non-disposable email? What prevents anyone from creating @gmail.com addresses?

You need a valid phone number to create a gmail account, and you can only have a few accounts attached to the same number. Google is "trusted" because they actively try to prevent spammers from joining their platform. Disposable email platforms don't, they let you create as many as you like.

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#163

Earlier quoted context omitted.

At that point we'd be better of figuring out a proper protocol that allows websites to talk to the password manager directly.

Something like OpenID connect?

Well, ideally without the centralized server in between.

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#164

I wish Google would start offering disposable relay emails that were indistinguishable from their regular ones, since nobody could afford to block all of @gmail.com.

This is obviously distinguishable but you can use the "+" aliases. For example, if you are bob@gmail.com, you can use bob+blah@gmail.com and use that to filter email.

The problem is that even though "+" is a perfectly valid character, a lot of services don't accept it.

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#165
post #67

One of the comments on the issue [1] says: > My reasoning on including this is that an email with a mozmail domain is never going to be a primary email and is always going to forward to some other address. This is laughable and sad at the same time. I have a few tens of email addresses that are used for different purposes and with different classes of sites and services. None of them are “primary” and I wouldn’t real…

The difference with Apple's hide my address feature, is that it will only give you one per site. So even though it's an address generated specifically for that website, it's still your "primary" email for that domain. If you signup for Netflix using the feature, you can't cancel your account and then signup with a new Apple email, it will only allow you to login with your original one. This negates the primary reason…

> If you signup for Netflix using the feature, you can't cancel your account and then signup with a new Apple email, it will only allow you to login with your original one.

You absolutely can. You can generate as many as you want, whenever you want

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#166
Interesting project. I was recently inundated with abusive account signups, and it seemed like the "fast path" for attackers was to register an outlook.com domain, and use that to create a Github account. I guess Microsoft does no validation on these signups. It was especially painful since legit users used outlook.com and Github, so I couldn't just block them. (Fastmail is in second place here, but had no legitimate use, unfortunately.)

For emails that I don't want an ongoing obligation to read... I used to have a custom alias for mailinator (nospam.jrock.us MX ). At some point I guess I got rid of it, perhaps because mailinator stopped offering that service. Unsurprisingly, nobody ever looks up the MX record to implement the denylist. Worked perfectly every time.

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#168

Earlier quoted context omitted.

I’m the founder of a small bootstrapped SAAS and people use disposable email addresses all the time to avoid paying for our product. We don’t sell any data.

Disposable email domains aren't the issue here. Creating a disposable @gmail account to avoid paying is possible too. Don't use emails to assert user identity. Most companies use credit cards for that. Or make it so that creating another account from scratch is more of a hassle than paying. Better yet, offer free tiers.

You can only create a small number of gmail accounts, since ever account needs to be linked to a valid phone number. Google actively work to prevent using their platform in this way.

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#169

The reason disposable email addresses exist and are popular is because services have abused users' trust to not use these emails for shady ad revenue and marketing schemes. It's further compounded by shoddy security that leads to leaks and exposure of people's personal email addresses to pwned compromised lists. People don't want to give up their personal email addresses so that they can be spammed or hacked. Until s…

Yup. Sign up for a trial of something and suddenly you're getting 3 emails a day. --- "Ravenstine, kick your goals into overdrive now" "Check this feature out!" "We're the best, but don't take our word for it" "Your account is waiting for you" "This will be like money in your pocket" "Don't miss out on our webinar" "The gift that keeps on giving" "It's been a while..." "So this is goodbye, Ravenstine?" --- F--- YOU!…

Worse, they purposely come from the same email address. So if you want meetup alerts for upcoming meetings, too bad, because now you will get all these marketing materials from the same email, which is now subscribed to various promotional lists. I already told google to put that email straight into my inbox and now I get all that junk too. This is 100% intentional because most people aren't going to click unsub per domain or start writing rules analyzing the ever changing subject line.

You can tell which companies have especially corrupt and greedy corporate cultures by how they treat your email address. Whenever I find myself witnessing behaviors like this I do my best to move off the platform and bad mouth them whenever I can.

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#170
This was inevitable. If you’re leaking the info that you’re using a proxy, it’ll eventually be used by people who want to.

One solution is a traditional webmail provider being willing to reuse that primary user domain for forwarding addresses. There are two that I know of doing this, Fastmail with @fastmail.com and Apple with @icloud.com. These domains probably won’t ever be blacklisted, because you’d also blacklist a ton of primary email addresses. (Aliases, which most providers have, tend to be too inconvenient and quantity limited.)

Another solution is to use different addresses at your own domain, which trades anonymity against the company you sign up with for freedom to change providers.

I think all three of these, including announced proxies like MPR, can be the best solution depending on whether you just want to be able to cut contact or you want privacy, and from whom.

Post reply on HN