Live data from Hacker News

Show HN: An ad free temporary mail service

news.ycombinator.com

41–50 of 96 posts

Re: Show HN: An ad free temporary mail service

#42

I'm always a little suspicious of these services. People use them to create throw-away accounts, which they abandon after one use. Those accounts remain active and are useful for botting (vote manipulation, comment spam, etc). Whoever owns the email domain can do a password reset to do an account take over. I'm curious about the privacy policy. The title says that you don't have ads, but there's tons of discussion ab…

> People use them to create throw-away accounts

A separate use case is when there's a free download that's email-gated, rather than account-gated. Examples would be Gumroad, certain 3D print platforms and such. I'd rather not wind up having my email just be added to some marketing list.

Re: Show HN: An ad free temporary mail service

#43

Earlier quoted context omitted.

I don't agree with this and I think the right approach is to simply not require visitors to give up their email accounts if they don't want to. If you want to block a malicious attacker, then you can use a captcha. A serious malicious attacker wouldn't have a problem paying a few dollars to buy a domain, creating a catch-all address and if he wants to take it one step further he can even have it look like a legitimat…

Aliases you can discard are ad blockers for emails, disposable services are for bots, scams, and fraud. If you know the space, you'll be aware CAPTCHAs are trivially defeated today, regardless of the provider. I certainly agree people shouldn't be asked to provide an email if it's unnecessary, but again for the issue of bots, scams, and fraud, you generally need some sort of unique relatively hard to get many of iden…

Life's too short to give a real email address to any random web site that requires registration. One reason is privacy, as they will inevitably sell one's data to a thousand data brokers. Second reason is to avoid having to deal with all the spam, that will again inevitably come. Even if unsubscribed from everything, we've change our policy emails and other nonsense will keep wasting one's time.

Re: Show HN: An ad free temporary mail service

#45

Earlier quoted context omitted.

A) The connection is fully encrypted. B) That would make the UX horrible. C) I had Tor enabled in the beginning, but when I got complaints from people on Tor doing really shady stuff with it I had to disable it.

The woes of supporting an "I don't want to leave any crumbs" threat model. There are countless of pro-privacy projects who call themselves that simply because their service can be used to increase privacy, but they do not actually do much to protect privacy beyond that. Many even use Google Analytics. For B, simply support both. This site is popular enough for there to be no risk sharing: Guerrilla Mail.

Take a look at your network requests though, there isn't a single third-party script running on the site.

I understand what you mean, but it has to apply to the use-case. If the service I was running was to support journalists, then I would agree with you, but taking these measures would help promote spam as users would be able to get around the rate-limiting that I've set.

Re: Show HN: An ad free temporary mail service

#46
post #43

Earlier quoted context omitted.

Aliases you can discard are ad blockers for emails, disposable services are for bots, scams, and fraud. If you know the space, you'll be aware CAPTCHAs are trivially defeated today, regardless of the provider. I certainly agree people shouldn't be asked to provide an email if it's unnecessary, but again for the issue of bots, scams, and fraud, you generally need some sort of unique relatively hard to get many of iden…

Life's too short to give a real email address to any random web site that requires registration. One reason is privacy, as they will inevitably sell one's data to a thousand data brokers. Second reason is to avoid having to deal with all the spam, that will again inevitably come. Even if unsubscribed from everything, we've change our policy emails and other nonsense will keep wasting one's time.

I have my own SMTP server that I use for all purposes. I have set up a separate address for each person/service that I use email with. If I receive spam or other unwanted messages, then it is easy to delete that email address, which will cause the SMTP server to return an error message to any client that tries to send messages to that address.

Re: Show HN: An ad free temporary mail service

#48

Most such services are blacklisted, or very soon to be blacklisted. You can use Gmails and rotate them, and use "." "+" "number" tricks though, but typically, use Gmails is the way to do.

That's another way yes and I've actually seen another site do this, but I wasn't able to find it in my browser history.

Re: Show HN: An ad free temporary mail service

#49

Earlier quoted context omitted.

Aliases you can discard are ad blockers for emails, disposable services are for bots, scams, and fraud. If you know the space, you'll be aware CAPTCHAs are trivially defeated today, regardless of the provider. I certainly agree people shouldn't be asked to provide an email if it's unnecessary, but again for the issue of bots, scams, and fraud, you generally need some sort of unique relatively hard to get many of iden…

>Aliases you can discard are ad blockers for emails, disposable services are for bots, scams, and fraud. What is the difference between the two though? This kind of reasoning is why people can't run their own email servers anymore and instead have to rely on the big services. >If you know the space, you'll be aware CAPTCHAs are trivially defeated today, regardless of the provider. They are a lot more reliable than an…

> What is the difference between the two though?

If you have a hundred aliases on say, Fastmail, and someone reports one of them, Fastmail can investigate the abuse you are involved in and can suspend your account. But the places you are using those aliases have no way to identify the main account of an alias, they can only report the alias, and Fastmail, the company providing your core service, is the only one that has the ability to deanonymize that relationship. Most of the services who allow these excess aliases are paid services or have identity checks, so other service providers can trust they will do a reasonable job to prevent abuse.

Meanwhile, if you bother to investigate how your service is being used, the percentage of users using it to abuse other sites will inevitably approach 100%. As bot spammers realize you're another set of free email addresses they can stack up, they'll swarm to each new domain you rotate to. If you are as privacy focused as you say, you'll have no tools at your disposable to regulate this either, they have plenty of IP addresses to work with, mostly compromised devices on residential IPs that are part of botnets, that will look like real users from a cursory glance.

> This kind of reasoning is why people can't run their own email servers anymore and instead have to rely on the big services.

That's why it's so fundamental that you understand rotating your domains is abuse, and it hurts the email ecosystem. Every time someone like you thinks this is okay, you make more service providers lock down what email domains they accept, punishing folks like me who just want their own domain on their email. Because disposable mail services do this, we all get punished for your bad behavior.

> Why not use phone numbers instead

Well, that's what a lot of major providers do. Gmail makes it much harder to get going without a phone number these days, mostly for that reason. I certainly don't want to have to give my phone number to every site I sign up with, but if that is, in your opinion better for privacy, by all means, enjoy the fruits of you screwing over email for this.

Re: Show HN: An ad free temporary mail service

#50

How about redefining the problem a little bit so that it is something else than what others are doing? For example, the platform approach? Allow people to easily set up a temporary email service with their own domain. That would go around the problem needing changing domains all the time. You could make it easy for people to search and buy their temp email domain through you. Or if that is too much, work, allow peopl…

That's great advice and although there's already an open source solution available, there's some hassle involved in setting it up.

I will definitely look into these solutions and although I've seen some of them around, there could maybe be a way to implement a better alternative that's both easy to use and safe so it doesn't get abused.

Post reply on HN