Live data from Hacker News

Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

github.com

281–290 of 304 posts

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#281

This seems perfectly fine. A list of disposable email domains should contain disposable email domains like Firefox Relay, iOS "Sign in with Apple", Fastmail's random e-mail generator and others. Weird that Apple's domains aren't on the list, though. Hell, Gmail and Outlook should be on the list as well, because creating email addresses there is so quick and easy they might as well be considered throwaway services. I'…

Fastmail uses @fastmail.com (the default domain) for randomly generated aliases. Good luck blocking the hundreds of thousands of fastmail users by trying to block the minority using masked addresses.

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#282

Earlier quoted context omitted.

> I’m the founder of a small bootstrapped SAAS and people use disposable email addresses all the time to avoid paying for our product. So, make it worthwhile to pay for the product.

that's not really how it works. If you create something and unless you license it permissively that product is yours and you get to set the terms and conditions. If it is now mainstream to basically feel you're entitled on setting the terms for other businesses or stealing their software then nobody needs to complain when any email relay service gets just blacklisted. If people now think it's okay to abuse multiple a…

> that's not really how it works.

Yes, it really is how it works.

> If you create something and unless you license it permissively that product is yours and you get to set the terms and conditions.

And if you want people to pay for it, you have to offer enough marginal value over not paying for it so that they choose to do so. The concrete, social, and personal moral consequences of violating social norms can provide part of that value by weighing negatively on the “not” side, in the case there is an available but “not permitted” mechanism which gives the benefits without paying. But that doesn't change the basic fact that you have to provide adequate value if you want people to voluntarily pay.

> If people now think it's okay to abuse multiple accounts to avoid paying for software that they use

Then models where you give the full service for free for each account with the limits actually applied that people are exploiting that way probably isn't the right model for that SaaS.

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#283
post #46

Earlier quoted context omitted.

It’s also a privacy concern. A single email address ties your identity across platforms, which may be convenient, but could potentially be abused.

It's not just a potential concern: this is how a variety of ad services are starting to track users across sites (typically via a hashed email address, but given the ubiquity of email/password dumps, de-anonymising is relatively practical).

Starting? This has happened for ages.

Ad companies' customers willingly share the email addresses in hashed form so the ad companies can correlate this against their own lists (by doing the same hashing and checking for a match).

The same happens with phone numbers as well.

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#284

One thing I learned operating a payment processor for a decade is that by far the email domains of choice for people trying to do evil were big free email providers like google, ms, yahoo and so on. A few operators would use something like mailinator (the kind of thing that is being blocked here). By evil I mean everything from attempting to hack us and our users, to financial fraud, to just trying to get a merchant…

When it comes to fraud a non-trivial chunk of it originates from idiots who unwillingly do it (by getting hacked or duped into participating into the scheme), so seeing "normal" email providers there is no surprise.

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#285
post #241

Earlier quoted context omitted.

Fastmail is excellent. They have subdomain addressing, which is kind of like plus addressing, but better (not all places let you sign up with plus addressing). I've got my own domain, for example: mydomain.com. So my fastmail email address is depingus@mydomain.com. But with subdomain addressing, I can sign up for services with unique email addresses that look like: social.hackernews@depingus.mydomain.com Fastmail wil…

I did the same thing a few years back, I love it. It has allowed me to find where my emails are being leaked. So far not too many which is good, the biggest and worst were ledger and instagram.

I know Facebook is cancer and all but I'm still surprised they'd be leaking them as their business model relies on capturing personal data but not giving it away.

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#286

Interesting project. I was recently inundated with abusive account signups, and it seemed like the "fast path" for attackers was to register an outlook.com domain, and use that to create a Github account. I guess Microsoft does no validation on these signups. It was especially painful since legit users used outlook.com and Github, so I couldn't just block them. (Fastmail is in second place here, but had no legitimate…

> perhaps because mailinator stopped offering that service

That is untrue. Mailinator definitely still supports pointing any domain to it's MX records and will allow all incoming email (modulo DoS protection, abuse, etc). Such email will arrive in the respective Mailinator inbox (i.e. bob@yourdomain.com goes to the "bob" inbox)

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#288

Earlier quoted context omitted.

I buy corporate contacts from farms and I think they get a lot of them from apps that force you to upload all your contacts as the price to use them. Your personal contact information is probably in dozens of your friends and colleague's phones.

Interesting.. It could be but I kinda doubt it. I'm actually very careful with my data. The only such app I use is whatsapp. I'm very hesitant to install most apps and all the ones I use the most are from F-Droid (open source). The apps that do spying/telemetry etc I all use inside a work profile where they can't access my contacts or pictures and I run a tracking blocker inside that work profile. This makes Whatsapp…

Just to be clear (and you might have read it this way) - I meant that people you know, who have you in their contacts, have installed apps on their phones which pulled in all their contacts and that meant the app got your contact info from them. I'm 99% certain that's where the sites I buy my data get theirs. One of the sites won't even let me log in without giving up all my contacts, but I have a $15 phone on Boost with zero contacts on it to use in these kind of scummy scenarios.

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#289

Earlier quoted context omitted.

Interesting.. It could be but I kinda doubt it. I'm actually very careful with my data. The only such app I use is whatsapp. I'm very hesitant to install most apps and all the ones I use the most are from F-Droid (open source). The apps that do spying/telemetry etc I all use inside a work profile where they can't access my contacts or pictures and I run a tracking blocker inside that work profile. This makes Whatsapp…

Just to be clear (and you might have read it this way) - I meant that people you know, who have you in their contacts, have installed apps on their phones which pulled in all their contacts and that meant the app got your contact info from them. I'm 99% certain that's where the sites I buy my data get theirs. One of the sites won't even let me log in without giving up all my contacts, but I have a $15 phone on Boost…

Ahhh now I get you. Yes that is indeed very likely. I tend to focus too much on keeping my own yard safe and forget I'm walking through everyone else's too.

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#290

Earlier quoted context omitted.

Why not, then?

A few reasons. The hide my email addresses use the same domain as regular icloud email addresses. Apple always gets what it wants. They don't want to be sued by Apple.

How can Apple sue them for adding their domain name to a blacklist?
Post reply on HN