Live data from Hacker News

Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

github.com

261–270 of 304 posts

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#261
post #118

Earlier quoted context omitted.

We did, it's called non-disposable email. A non-unique pseudoanonymous identity that's somewhat difficult to mint in bulk. If you don't like "accounts of well-known service providers" -- email or login-with-whoever then sources of identity that "everyone" has that are hard to get many of are government ids, phone numbers and credit cards. Like what else is there? For super technical people we could do something like…

I don't really get this. Where do you draw the line between disposable and non-disposable email? What prevents anyone from creating @gmail.com addresses?

Sometimes it's hard. We try to keep our little list useful but it can never be a full solution -- I hope it cannot ever be and people value their privacy enough to not give up the freedoms of internet and TCP/IP.

As of gmail -- one of the guidelines for the list addition is whether you need to go through some sort of a registration. If you do then it is usually not treated as disposable by us.

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#262

Earlier quoted context omitted.

You actually don't need have to have a phone number to use Gmail. You can skip that step.

I don't think so. I have numerous old Google accounts with their passwords in my password manager. Not for gmail, but for Google Groups lists, Google+ and various other services that no longer exist. Whenever I log in (in an account container of course) I cannot continue without adding a phone number. Have not found a way to skip the step (well, have not tried for some months now, trying to avoid Google increasingly)…

Where could I get disposable phone numbers from at a reasonable cost? So that I can receive just the first SMS. These are not valuable accounts, I don't need password reset years later.

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#263
post #107

This project seems to work under the pretense of fighting the spammers. Maybe it actually does. But it also deprives people of their right to not be tracked constantly, to remain anonymous. A world with no crime is a world without individual freedoms. The way this is so casually and openly discussed here is slightly terrifying.

To work around our list while having a decent level of privacy just do not use a complete burner address. You can e.g. make a pseudonym address with an actual provider like gmail, fastmail, protonmail etc. Heck we even have an allowlist with some "shady" providers that balance on the edge included in the repo, just browse: https://github.com/disposable-email-domains/disposable-email...

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#264

The reason disposable email addresses exist and are popular is because services have abused users' trust to not use these emails for shady ad revenue and marketing schemes. It's further compounded by shoddy security that leads to leaks and exposure of people's personal email addresses to pwned compromised lists. People don't want to give up their personal email addresses so that they can be spammed or hacked. Until s…

The reason disposable emails exist, and that countermeasures exist, is because it's a power struggle, plain and simple. People like to have control over a situation, from either side, and also abuse their power from both sides.

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#265

Earlier quoted context omitted.

Or even if you didn't sign up.. I get constant emails from sales people that must have farmed my LinkedIn or something, even though I have it pretty strictly protected. Often even having scheduled a call with me without my consent. Usually for solutions I have absolutely nothing to do with if they'd actually taken the time to look at my profile. Of course I mark them as spam and blacklist them. I often see followups…

I buy corporate contacts from farms and I think they get a lot of them from apps that force you to upload all your contacts as the price to use them. Your personal contact information is probably in dozens of your friends and colleague's phones.

Interesting.. It could be but I kinda doubt it. I'm actually very careful with my data. The only such app I use is whatsapp. I'm very hesitant to install most apps and all the ones I use the most are from F-Droid (open source). The apps that do spying/telemetry etc I all use inside a work profile where they can't access my contacts or pictures and I run a tracking blocker inside that work profile. This makes Whatsapp awkward to use as but these days I just use a matrix bridge anyway so I can override the whatsapp label.

On LinkedIn I blocked my last name to non-contacts (everyone else it just shows my initial) because our work has a simple email address naming scheme (first.last@company.com). But still I get an absolute ton of them. Literally several per day. It's so annoying, though most of them are not as persistant as I mentioned in my post above.

All of them seem to be from the US by the way, and always trying to propose meetings during US timezones so they seem unaware that I'm in Europe. I'm kinda suspecting a data leak in the past or something.

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#266
post #170

This was inevitable. If you’re leaking the info that you’re using a proxy, it’ll eventually be used by people who want to. One solution is a traditional webmail provider being willing to reuse that primary user domain for forwarding addresses. There are two that I know of doing this, Fastmail with @fastmail.com and Apple with @icloud.com. These domains probably won’t ever be blacklisted, because you’d also blacklist…

Posteo.net also allows creating aliases, so effectively you can create disposable email addresses. The aliases use the same domain.

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#267

The reason disposable email addresses exist and are popular is because services have abused users' trust to not use these emails for shady ad revenue and marketing schemes. It's further compounded by shoddy security that leads to leaks and exposure of people's personal email addresses to pwned compromised lists. People don't want to give up their personal email addresses so that they can be spammed or hacked. Until s…

I would go further and say disposable online identities are getting more and more important.

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#268

This seems perfectly fine. A list of disposable email domains should contain disposable email domains like Firefox Relay, iOS "Sign in with Apple", Fastmail's random e-mail generator and others. Weird that Apple's domains aren't on the list, though. Hell, Gmail and Outlook should be on the list as well, because creating email addresses there is so quick and easy they might as well be considered throwaway services. I'…

> Gmail .. should be on the list as well, because creating email addresses there is so quick and easy GMail does antispasm. It’s easy to create a disposable gmail, but it is much harder (I supposed) to use that address for outgoing spam/fraud/etc.

(I'm an engineer on Relay.) Relay has anti-abuse protections too, which is why it was removed from a similar list: https://github.com/wesbos/burner-email-providers/pull/339

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#269
post #14

Earlier quoted context omitted.

repo seems to be owned by a google employee

I started the repo and have nothing to do with Google.

There are 2 members in the disposable-email-domains organization on GitHub.[1]

You (martenson) are one of them. The other member (di), who is a "core maintainer" of the project according to the README changelog,[2] is also a member of the Google organization on GitHub.[3] di describes himself as part of the "@google open source security team"[3] and the website linked from his profile says that he is "a Developer Advocate at Google".[4]

[1] https://github.com/orgs/disposable-email-domains/people

[2] https://github.com/disposable-email-domains/disposable-email...

[3] https://github.com/di

[4] https://dustingram.com/

Post reply on HN