Live data from Hacker News

Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

github.com

211–220 of 304 posts

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#211
post #92

Earlier quoted context omitted.

Password managers should start supporting this flow. Allow the password manager to read your Gmail, or for cloud-based managers log up with an @1password.com email... Not trivial technically, and maybe turning password managers into SSO providers, but that's a lucrative business in itself.

At that point we'd be better of figuring out a proper protocol that allows websites to talk to the password manager directly.

Don't we already have that with WebAuthn? It should be possible for the authentication request to be directed to the password manager. Less secure than using a hardware key, but more secure than password, email, or text message authentication.

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#212

The reason disposable email addresses exist and are popular is because services have abused users' trust to not use these emails for shady ad revenue and marketing schemes. It's further compounded by shoddy security that leads to leaks and exposure of people's personal email addresses to pwned compromised lists. People don't want to give up their personal email addresses so that they can be spammed or hacked. Until s…

I’m the founder of a small bootstrapped SAAS and people use disposable email addresses all the time to avoid paying for our product. We don’t sell any data.

> We don’t sell any data.

Not only do I have zero reason to trust you when you say that (because every person planning on selling my data ways the same thing).

But I also have zero reason to trust you're skilled or resourced enough to adequately secure my data (or have sufficient motivation to do so).

And I also know that one day you'll likely sell your SAAS, and will have no control over what the people you sell it to will do.

If you've got enough traction that people are willing to jump through minor disposable email address hoops to use your product for longer than the free trial, but not enough traction to convince them to pay for it, I reckon you'd be better off building more features that add value and reconsidering your free trial plan - instead of devoting any dev effort into rejecting disposable emails.

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#213
post #175

Earlier quoted context omitted.

I don't really get this. Where do you draw the line between disposable and non-disposable email? What prevents anyone from creating @gmail.com addresses?

Nothing, but if you try to create 1000 of such emails you’ll get banned by Google.

A normal user wouldn't make anywhere near that many and to a bot developer, "banned by Google" doesn't present even the slightest of challenges. Source: I develop web scrapers for many sites that really don't want to be scraped, including Google/Abc properties.

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#214

Earlier quoted context omitted.

I'm curious - I see on your profile that you're a DevOps engineer presumably using a lot of online services on a daily basis, so what approach do you use to deal with email that would justify your opinion here? Do you just let it fill up your inbox and essentially make it unusable as it's saturated with marketing spam? Do you read every single incoming email (if so how do you find time and how do you justify spending…

> so what approach do you use to deal with email that would justify your opinion here? When I get email I don't want from a company I have an account with, I scroll to the bottom and click 'unsubscribe'. I then don't get anymore of those kinds of emails. What I absolutely do not do is throw a hissy fit and click 'report spam' (which not fucks up my own bayes classifiers and makes false positives more likely, but send…

If only all companies actually had an unsubscribe link in their emails…

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#215

I've started using my own domain to avoid giving out my "real" addresseverywhere. It doesn't always work, but it usually does.

I do the same but my worry is that any kind of smart enough spammer or stalker can use the domain as a fingerprint.

It's been reported[1] that PayPal (and probably other services as well) use the entire domain name as a fingerprint, banning everyone connected if there is a serious issue. Since they're presumably more closely linked in a way than a Gmail/Protonmail/etc email domain shared by unrelated users.

[1] https://news.ycombinator.com/item?id=29940133

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#216

Earlier quoted context omitted.

… which makes it the prospective subscriber’s problem, pushing nearly all risk onto them, and requiring them to trust that the service won’t spam them or sell their e-mail address.

What alternative do you suggest?

Depends hugely on the SAAS and it's current and desired customer base.

But some obvious candidates are

1) discontinue free trials.

2) provide enough obvious value to convert the current funnel of free trials into paying customers at a high enough rate that you don't care about the "freeloaders"

3) radically differentiate the support available on free trial accounts.

In the long run, and dev effort/time spend integrating email domain blacklists is just time taken away from building features that add value to the service/company. It's only possible that spending that time adding features will turn the conversion rate up, but its guaranteed that fencing off the top of the funnel will reduce the number of conversions.

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#217
post #164

I wish Google would start offering disposable relay emails that were indistinguishable from their regular ones, since nobody could afford to block all of @gmail.com.

This is obviously distinguishable but you can use the "+" aliases. For example, if you are bob@gmail.com, you can use bob+blah@gmail.com and use that to filter email. The problem is that even though "+" is a perfectly valid character, a lot of services don't accept it.

I've seen at least one site simply strip the +tag and spam my real email directly. Since Gmail is so popular, I'm sure the marketing piranhas had the stripping code written and deployed within half an hour of that feature being announced.

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#218
post #67

One of the comments on the issue [1] says: > My reasoning on including this is that an email with a mozmail domain is never going to be a primary email and is always going to forward to some other address. This is laughable and sad at the same time. I have a few tens of email addresses that are used for different purposes and with different classes of sites and services. None of them are “primary” and I wouldn’t real…

My primary address IS a forwarding service. One of those ones that exist to let you give the address out to anyone you want, and still be able to change your actual email service provider, without having to change your address -- because, hey, it's your primary one, right?

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#219

Earlier quoted context omitted.

Of course not.

Why not, then?

A few reasons. The hide my email addresses use the same domain as regular icloud email addresses. Apple always gets what it wants. They don't want to be sued by Apple.

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#220
post #28

Earlier quoted context omitted.

>From the prospective subscriber’s perspective, that’s your problem to worry about — not theirs. exactly...which is why there are blacklists like the one linked in the OP.

Businesses that don't accept my email address don't get my business.

That's great, but there are very little businesses of 1.
Post reply on HN