Live data from Hacker News

Using a catch-all domain is a mistake

notcheckmark.com

221–230 of 304 posts

Re: Using a catch-all domain is a mistake

#221
Before Cloudflare, I built a company around this called Unspam. It wasn’t commercially very successful, but it allowed you a ton of power around routing/filtering emails on a per-email basis (e.g., require senders to certain emails to pass a Turing test, add a header to others, turn up or down spam filtering by the address). I haven’t had the problem the author references, but mostly because I preface conversations with: “This is going to sound weird, but my email is…”

There’s a security benefit in making your email not-the-same across services. Yes, perhaps many of mine are guessable if you know the pattern I use. But it defeats non-targeted scanning. People target me (I was just sanctioned by Russia along with Mark Zuckerberg and Marc Benioff! Woot!!) yet exactly zero people have targeted me this way.

I’m still one of the few remaining Unspam users. Works great to this day. (Impressive given I wrote the PERL that powers it.) Actually think someone could spend a week with Cloudflare + Workers + Email Routing + Area1 and replicate the functionality+++. I’d gladly pay $5/mo for that. Wouldn’t be a big business. But an example of a bootstrappable lifestyle business that could easily cash flow enough to healthily sustain a couple developers.

Let me know if you build it:

crazyhnidea@matthew.unspam.com

Re: Using a catch-all domain is a mistake

#222
post #142

Earlier quoted context omitted.

I have a couple too: Panicked phone call from a jeweller who wanted to know how and why '[their] domain was in my email address'; think he sort of understood once I explained, but still said something like 'can't be too careful in this business' - well sure ok but what am I going to do with.. oh nevermind! Password lockout/reset over the phone, reading my 100ch 'memorable phrase' as generated by pass... Gave the guy…

That is a major downside with putting gibberish in for answers to security questions… let’s hackers socially engineer support into letting you get access by saying something like, “oh man, I just mashed on my keyboard for that I don’t remember!” You would hope it wouldn’t work, but it probably will.

That's why I always put legit but wrong answers in. Can't really guess because they're all different and made up, but also can't say, "Oh I just mashed the keyboard".

Re: Using a catch-all domain is a mistake

#224
post #156

Earlier quoted context omitted.

I have been using a catchall domain since 2004 and it has been a lifesaver. The sad part is when your email leaks from big companies, you definitely know. I started getting viagra spam delivered to equifax@mydomain.com back in 2007, long before their "big data breach", so it was only a matter of time before that companies pattern of poor security caught up with them. Email should have always been a bidirectional addr…

> Email should have always been a bidirectional address, representing the relationship between the sender and receiver, and not a wide open receiver for anybody who happens to have your address. That does seem beneficial for the most part, but do you have ideas about how to handle the use cases like establishing new relationships (what, if anything, do you put on business cards?) or allowing the general public or a b…

To take the tracking logic further, I think you'd do `businesscard-@example.com`, `-@example.com`, `@example.com` etc. Maybe come up with something snazzy yet still unique-ish for the presentation slides.

In practice, I suspect the intention is mostly to use catch-all addresses for situations where the email address is a key in a database and like a login and stuff and not an entry in an individual's contacts list.

Re: Using a catch-all domain is a mistake

#225

Earlier quoted context omitted.

> I don't really know exactly, but she told me something about me using their stuff without their acceptance, when I tried to explain that's my own domain she told me I cannot use their name, because that's a copyright infringement. Weird. I can't tell you how many non-techy people think I'm part of their company because I have yourcompany@mydomain. Sigh. Big companies have ruined the internet by having everyone have…

The "best" is when you can't even sign up without having an account at a Large Company e.g. gmail or outlook. I'm not sure what that's supposed to prevent issues with. Sure, you can add "+thing" after the username portion, but those that know this bog standard trick can still automatically derive your email address and get around your filters. At least with a dedicated username portion a human has to think for a seco…

> those that know this bog standard trick can still automatically derive your email address and get around your filters

Not if you default the other way around and autodelete all mail that doesn't have a "+thing". :V

Re: Using a catch-all domain is a mistake

#226
post #133

Earlier quoted context omitted.

You'd think anyone competent in tech would instantly recognise that for what it was. Using an email like that for a specific purpose shouldn't be that uncommon. And they should recognise that it was an internal address. Crazy.

I assume Shopify’s position there is that the email address provided with the app is probably visible to end users somewhere and could cause confusion. The policy itself seems reasonable enough just shitty enforcement.

Based on their difficulty articulating the actual issue, I'm pretty confident that this wasn't intentional. Probably someone in a body shop following a checklist.

The specific box is labeled:

    2. App submission contact email
    
    This is the email we will use to communicate
    with you during the app submission review process.
There are separate boxes for support email, review notification email, etc. So I think the reviewer was simply confused.

Re: Using a catch-all domain is a mistake

#227
> Clerk: Do you...do you work for Hilton?

If you don't feel bad about doing this, then the answer here may be "do you have an employee discount available?" (This is quite often the reason they ask you that question)

But yeah, I'm another happy user of a catch-all. No issue with sharing the accounts between domains - a password manager does this for me. And even if something like gap/banana happened - who cares, I'd just create a new account.

Re: Using a catch-all domain is a mistake

#228
One problem I have with catchall is passing my emailadresses between "rings of trust". Example: say I have an email for close friends and family: me@example.com. Everywhere else I use spam@example.com. All's well, until some well wishing family member decides to give me a gift in a form of subscription, or something like that, and uses my email they know: me@example.com. And just like that the whole carefully built house of card collapses.

Re: Using a catch-all domain is a mistake

#230
post #228

One problem I have with catchall is passing my emailadresses between "rings of trust". Example: say I have an email for close friends and family: me@example.com. Everywhere else I use spam @example.com. All's well, until some well wishing family member decides to give me a gift in a form of subscription, or something like that, and uses my email they know: me@example.com. And just like that the whole carefully built…

Yes I'm at my 4th email for close friend and family... All 3 times previously they've been leaked
Post reply on HN