Live data from Hacker News

Everyone Wants Your Email Address. Think Twice Before Sharing It

nytimes.com

21–30 of 76 posts

Re: Everyone Wants Your Email Address. Think Twice Before Sharing It

#21
Currently I use Fastmail to host my own domain, and then for every new service I save the account in 1Password using service@service.mydomain.com

It's a bit extreme, but surprisingly little extra effort. That said, most of the accounts I create are throwaway.

For phone numbers I have an old, unused Google voice number I give out. It's a real number, but never checked, except for once every 90? days, to keep it active.

I'd love it if OnePassword integrated with something like https://randomuser.me to generate a new profile for every awful service that needs an account to work.

Re: Everyone Wants Your Email Address. Think Twice Before Sharing It

#22

An easier way to spin up emails for every account: For some email providers, if you add a "+" modifier to your email address, anything after the + will be ignored and still routed to your main email address. But email systems will still treat them as unique email addresses. (So abc123+Netflix@gmail.com and abc123+nytimes@gmail.com would both be delivered to abc123@gmail.com. This limits their ability to link your acc…

I tried this. Tried this with my domain as well. Spammers have figured this out. They start spamming random emails on my domain and since there's catch all I do receive them. Randomly generated emails from dedicated services (duck.com, HME etc) work better. I can just disable them and don't have to worry about other random emails. Handling all this on my own domain is going to cost me a lot in both money and time and…

Are we talking about data being shared across services or spammers? Spammers play by different rules because they can just generate infinite email addresses on the fly and not have to worry about storing them unless they get a hit. I would consider that a different vector than your legitimate email address being shared.

In my experience, a private email domain is a neon sign for spammers. I would never recommend a private domain for privacy or anti-spam reasons.

Re: Everyone Wants Your Email Address. Think Twice Before Sharing It

#24

Earlier quoted context omitted.

It seems like some backend code could easily strip the “+” and everything after it before saving an email to a database. Not sure how viable this is but I’ve also never tried it.

That's the trick - not all email providers behave this way, so systems would have to throw out legitimate emails. Also, most of the automated email systems are not as sophisticated as people think. Ours actually relies on + wildcards for internal testing.

How many legitimate emails have a + in them and don't use such an alias system? I'm sure they exist, but are probably even less frequent than the amount of people using this alias system, thus it's more profitable to strip it out.

Re: Everyone Wants Your Email Address. Think Twice Before Sharing It

#26
It's pretty ridiculous to think we can win a cat-and-mouse game of surveillance mitigation as individuals against some of the world's largest corporations. Some web services/sites are even starting to create nuisance hurdles around VPNs they know about, if they don't just block them outright, China style. We need to make surveillance of this kind a crime to make it stop. We need privacy laws that are comprehensive and have teeth.

Re: Everyone Wants Your Email Address. Think Twice Before Sharing It

#27
post #21

Currently I use Fastmail to host my own domain, and then for every new service I save the account in 1Password using service@service.mydomain.com It's a bit extreme, but surprisingly little extra effort. That said, most of the accounts I create are throwaway. For phone numbers I have an old, unused Google voice number I give out. It's a real number, but never checked, except for once every 90? days, to keep it active…

Not quite randomuser.me, but 1Password integrates with Fastmail to generate masked emails on the fly.

https://1password.com/fastmail/

Re: Everyone Wants Your Email Address. Think Twice Before Sharing It

#28
post #21

Currently I use Fastmail to host my own domain, and then for every new service I save the account in 1Password using service@service.mydomain.com It's a bit extreme, but surprisingly little extra effort. That said, most of the accounts I create are throwaway. For phone numbers I have an old, unused Google voice number I give out. It's a real number, but never checked, except for once every 90? days, to keep it active…

Your own domain helps zero to prevent linking your activity across sites.

Fastmail masked emails + 1Password helps though.

Re: Everyone Wants Your Email Address. Think Twice Before Sharing It

#29

Earlier quoted context omitted.

That's the trick - not all email providers behave this way, so systems would have to throw out legitimate emails. Also, most of the automated email systems are not as sophisticated as people think. Ours actually relies on + wildcards for internal testing.

How many legitimate emails have a + in them and don't use such an alias system? I'm sure they exist, but are probably even less frequent than the amount of people using this alias system, thus it's more profitable to strip it out.

What do you mean by "profitable"?

If you are just trying to datamine for random email addresses, you can do that with a random string generator. If you want a list of Netflix customers accounts, you probably want the same exact email they signed up with.

Besides, you can always make a Gmail rule to junk any emails coming in without a modifier.

Re: Everyone Wants Your Email Address. Think Twice Before Sharing It

#30
post #21

Currently I use Fastmail to host my own domain, and then for every new service I save the account in 1Password using service@service.mydomain.com It's a bit extreme, but surprisingly little extra effort. That said, most of the accounts I create are throwaway. For phone numbers I have an old, unused Google voice number I give out. It's a real number, but never checked, except for once every 90? days, to keep it active…

Is your intent privacy?

I've thought through similar setups, but if the intent is to break cross-platform correlation to a user/device ID and related de-anonymization, I keep coming back to these questions:

- How do I know fastmail doesn't sell data? If every one-time domain is tied to a static fastmail account, and the fastmail account has my real info and sells it, then the obfuscation per-service is moot.

- Google certainly is selling data, and its hard to have an account with them that's totally clean and doesn't need an existing "anchored"/tracked piece of infra to set it up (existing phone number, etc). SO, the VOIP number from Google is once again linked up to my IRL data, and the obfuscation is again moot.

The best I can think of is the theory that a LLC's privacy protections will be stronger than an individual. If I wrap everything in a LLC (phone provider, AWS acc with services like Chime, etc), then the correlation surface areas looks like a random LLC using all these retail services and its delinked from my IRL, assuming AWS/Google don't protect a LLC's data from selling into adtech (and I speculate it might protect it actually).

Post reply on HN