Live data from Hacker News

Everyone Wants Your Email Address. Think Twice Before Sharing It

nytimes.com

41–50 of 76 posts

Re: Everyone Wants Your Email Address. Think Twice Before Sharing It

#41

Earlier quoted context omitted.

What do you mean by "profitable"? If you are just trying to datamine for random email addresses, you can do that with a random string generator. If you want a list of Netflix customers accounts, you probably want the same exact email they signed up with. Besides, you can always make a Gmail rule to junk any emails coming in without a modifier.

Profitable, whether for the company itself or for some oxygen waster to get some metric ("engagement"?) that justifies their salary/promotion. I'm not saying they will strip out the + from the primary email address used for login/etc - that would be dangerous for many reasons and could deny access to users. But they are absolutely likely to strip it out for obnoxious behavior which is only valuable at scale and indiv…

My career is to build and maintain marketing email systems. So just from my professional advice, it's still a legitimate hack.

I'm not saying there is not someone out there trying these shenanigans, but in 95%+ of situations you are still going to catch people sharing your data with a + modifier.

Re: Everyone Wants Your Email Address. Think Twice Before Sharing It

#42
post #21

Currently I use Fastmail to host my own domain, and then for every new service I save the account in 1Password using service@service.mydomain.com It's a bit extreme, but surprisingly little extra effort. That said, most of the accounts I create are throwaway. For phone numbers I have an old, unused Google voice number I give out. It's a real number, but never checked, except for once every 90? days, to keep it active…

I've been thinking of running a setup like this specifically to rat out who's been selling my e-mail addresses, since the spam would be directed at the service@service.mydomain.com. Did you find any interesting results from your setup? Some surprising services who sold your address?

And did you find you got much spam to non-existent addresses? I used to use a catch-all setup, and got a large amount of spam, but that must have been 25ish years ago.

Re: Everyone Wants Your Email Address. Think Twice Before Sharing It

#43
post #16

Firefox Relay is a handy assistant to at least stymie email tracking and is neatly integrated with the browser. The free tier gets you a few masked emails that forward to your actual inbox. You can't reply through the masked email without paying, but that might not be necessary for all. It feels like retaining some semblance of privacy is a losing battle. Data clean rooms are industry standard now and many companies…

> How are these kinds of practices still legal?

In the EU they are not, and as someone who has been using a custom email address for almost every service for the last 15 years or so, I have noticed that this almost doesn't happen anymore.

The only cases where an email address receives spam anymore is after breaches, or very old addresses that have been sold more than 10 years ago.

Re: Everyone Wants Your Email Address. Think Twice Before Sharing It

#44
post #21

Currently I use Fastmail to host my own domain, and then for every new service I save the account in 1Password using service@service.mydomain.com It's a bit extreme, but surprisingly little extra effort. That said, most of the accounts I create are throwaway. For phone numbers I have an old, unused Google voice number I give out. It's a real number, but never checked, except for once every 90? days, to keep it active…

I've been thinking of running a setup like this specifically to rat out who's been selling my e-mail addresses, since the spam would be directed at the service@service.mydomain.com. Did you find any interesting results from your setup? Some surprising services who sold your address?

Actually, I think it's only happened once or twice in years. I was expecting more spam than I get.

Could also be that random domains aren't that valuable to sell.

Re: Everyone Wants Your Email Address. Think Twice Before Sharing It

#45

Earlier quoted context omitted.

I've been thinking of running a setup like this specifically to rat out who's been selling my e-mail addresses, since the spam would be directed at the service@service.mydomain.com. Did you find any interesting results from your setup? Some surprising services who sold your address?

And did you find you got much spam to non-existent addresses? I used to use a catch-all setup, and got a large amount of spam, but that must have been 25ish years ago.

Very little.

Could also be that Fastmail has good filtering.

Re: Everyone Wants Your Email Address. Think Twice Before Sharing It

#46
post #21

Currently I use Fastmail to host my own domain, and then for every new service I save the account in 1Password using service@service.mydomain.com It's a bit extreme, but surprisingly little extra effort. That said, most of the accounts I create are throwaway. For phone numbers I have an old, unused Google voice number I give out. It's a real number, but never checked, except for once every 90? days, to keep it active…

Is your intent privacy? I've thought through similar setups, but if the intent is to break cross-platform correlation to a user/device ID and related de-anonymization, I keep coming back to these questions: - How do I know fastmail doesn't sell data? If every one-time domain is tied to a static fastmail account, and the fastmail account has my real info and sells it, then the obfuscation per-service is moot. - Google…

I owned and ran my own email domain for a long time. Initially on my own hardware for fun, then a VPS, then GSuite, then Fastmail. That's over around 20 years.

So, it wasn't planned - it evolved. Somewhere in the Fastmail era I was reading their docs around wildcarding and thought I'd try it out.

My primary domain is my name though, so for extra privacy (anality) I bought another that has no link to me in the name.

There are still gaps in it. e.g. any merchant site still needs my physical address, and plenty need my cell number. But, generally, it's just an attempt to minimize a digital footprint and see what privacy I can get.

That and just why not? I self-host enough stuff, that I see this as another aspect of the same mentality - having a little more control.

It's not perfect security, it's not completely clean. Hopefully it's enough to get me out of the easy target bucket though.

Re: Everyone Wants Your Email Address. Think Twice Before Sharing It

#47
post #39
post #28

Earlier quoted context omitted.

Your own domain helps zero to prevent linking your activity across sites. Fastmail masked emails + 1Password helps though.

Of course it does, nobody will take into account the special case of people who use subdomains or even just non-standard email address separators, unless they are a rather determined government agency and then all of a sudden almost no method works anymore for privacy. I'm pretty sure even Google doesn't care about the dozens of people who use a different email address for different services.

This was my thinking here - yes, it has flaws in the approach, but it also gets me out of the main buckets that spammers will hit, and ad brokers will generally be selling.

It's a little friction, that maybe goes a long way. Pretty hard to actually evaluate though. Gives me the warm and fuzzies and I got to play around setting it up, so all good there.

Re: Everyone Wants Your Email Address. Think Twice Before Sharing It

#48
post #27
post #21

Currently I use Fastmail to host my own domain, and then for every new service I save the account in 1Password using service@service.mydomain.com It's a bit extreme, but surprisingly little extra effort. That said, most of the accounts I create are throwaway. For phone numbers I have an old, unused Google voice number I give out. It's a real number, but never checked, except for once every 90? days, to keep it active…

Not quite randomuser.me, but 1Password integrates with Fastmail to generate masked emails on the fly. https://1password.com/fastmail/

Yeah, I tried that for a while, and I have some Apple generated forwarders too.

In the end in places like a store that wants you to sign-up for X% off, or something it's easier to just to give them storename@domain.com and see what happens.

It's actually pretty low friction in terms of management.

Re: Everyone Wants Your Email Address. Think Twice Before Sharing It

#50
post #18

I've found fastmail's masked email to be a great solution to this. I don't give any services my primary address these days.

I tried this, but the thing I didn't like about it was that it ties you into Fastmail. I like using a custom domain so it's relatively easy to change your email provider, but masked emails are in the format xxx.xxx@fastmail.com so you'd need to revisit all of those accounts if you want to change your email provider to someone else. I'm currently trying using a catch-all with servicename@mydomain.com, and will be interested to see how much extra spam comes in through the catch-all.
Post reply on HN