Live data from Hacker News

Show HN: An ad free temporary mail service

news.ycombinator.com

61–70 of 96 posts

Re: Show HN: An ad free temporary mail service

#61

Earlier quoted context omitted.

The fact they constantly have to rotate to avoid blocks is because they are used for abuse and are attempting to essentially attack network services. Something like private aliases attached to a real account you actually have adds privacy, but retains accountability. (You can create aliases on Proton, Fastmail, Outlook, etc. but they are attached to your real account so abuse is manageable.) A service rotating tempor…

I don't agree with this and I think the right approach is to simply not require visitors to give up their email accounts if they don't want to. If you want to block a malicious attacker, then you can use a captcha. A serious malicious attacker wouldn't have a problem paying a few dollars to buy a domain, creating a catch-all address and if he wants to take it one step further he can even have it look like a legitimat…

For that matter, it's pretty easy to setup a catch all address forwarder. Cloudflare offers this, as did Google Domains. Not sure if Squarespace still offers this explicitely, been meaning to try to get out of Squarespace since the shift. Mostly been lazy.

Re: Show HN: An ad free temporary mail service

#62

Earlier quoted context omitted.

I don't agree with this and I think the right approach is to simply not require visitors to give up their email accounts if they don't want to. If you want to block a malicious attacker, then you can use a captcha. A serious malicious attacker wouldn't have a problem paying a few dollars to buy a domain, creating a catch-all address and if he wants to take it one step further he can even have it look like a legitimat…

Aliases you can discard are ad blockers for emails, disposable services are for bots, scams, and fraud. If you know the space, you'll be aware CAPTCHAs are trivially defeated today, regardless of the provider. I certainly agree people shouldn't be asked to provide an email if it's unnecessary, but again for the issue of bots, scams, and fraud, you generally need some sort of unique relatively hard to get many of iden…

I've come to the decision to charge $5/year for a site I'm going to put online in the next year... only to cover the transaction fees and mostly actual costs. If it takes off, should at least pay for itself and discourage fake accounts. But not every site/service will get that many people to even pay that much.

On the latter bit... not sure if I completely disagree with that take as well. As much as I also dislike SSO for other reasons, it is nice as at least some level of validation.

Re: Show HN: An ad free temporary mail service

#63

Earlier quoted context omitted.

Another fun fact, of course, is that CAPTCHAs not only suck for most people in general, they're especially frustrating for blind users, people who have privacy settings in their browser (hi Cloudflare!), etc. It's one somewhat irritating tool in the toolbox, but honestly abuse-enabling services like disposable mail providers really just need to be taken down. We need to stop giving free help to criminals. Privacy is…

In your ideal world we would be all be: - Be hooked to a bunch of paid plans for stuff that's currently free. - At the mercy of all the big providers that could one day just decide to turn our account off without a reason. - Receive more spam than we currently do as all service providers would have our email addresses. Although these would all be aliases, we would have to spend a decent amount of time organizing fold…

> At the mercy of all the big providers that could one day just decide to turn our account off without a reason.

This had me genuinely concerned when a lot of the superfuous account bans were happening on Twitter and Facebook around the 2020 election cycle. Retweeting a joke could knock you off, and I'd been using Twitter as a 2FA for many/most sites where it was offered at the time.

Now, I'm much more inclined to choose email/password options. I've also been using a wildcard domain for most new things. Ex: site@mydomain, etc for every site, store, etc I use.

Re: Show HN: An ad free temporary mail service

#64

Earlier quoted context omitted.

> What is the difference between the two though? If you have a hundred aliases on say, Fastmail, and someone reports one of them, Fastmail can investigate the abuse you are involved in and can suspend your account. But the places you are using those aliases have no way to identify the main account of an alias, they can only report the alias, and Fastmail, the company providing your core service, is the only one that…

> Fastmail can investigate the abuse you are involved in and can suspend your account. What if the Fastmail account is simply just using their free 30 day trial, how will they track the user then? My point is that the malicious user will still have a way, while the legitimate user is punished by having to pay a fee to the email provider. > Every time someone like you thinks this is okay, you make more service provide…

> How about no one gets punished and service providers verify phone numbers instead of emails and we get to keep our inboxes clean?

There are plenty of scammer bots/accounts that get around this just fine.

Re: Show HN: An ad free temporary mail service

#65

How about redefining the problem a little bit so that it is something else than what others are doing? For example, the platform approach? Allow people to easily set up a temporary email service with their own domain. That would go around the problem needing changing domains all the time. You could make it easy for people to search and buy their temp email domain through you. Or if that is too much, work, allow peopl…

Worth mentioning, if you want a docker-compose ready email server/service there's mailu[1]. It's relatively easy to get up and running, and will guide you through the DNS records for secure mail. I've got a couple test domains up so far, and it's mostly been good. Some outlook.com (not o365) domains have been problematic though, I'm sure everyone has stories here.

If the article's solution were open-source, would be interested in seeing the UI/UX. I also looked into WildDuck with great interest but the lack of good UI/UX is mostly what held me back. If I didn't have to work for a living, and was less lazy, I might have written something.

    1. https://mailu.io/

Re: Show HN: An ad free temporary mail service

#66
post #8
post #6

Earlier quoted context omitted.

This is what the top sites do, e.g. temp-mail.org And they also don't allow you to view all the active domains which helps against getting blacklisted quickly

I find it amusing that a .org site (temp-mail.org) has ads all over it while a .com site (temporarymail.com) does not, given that .org was mostly used by non-profits while .com is intended for commercial use.

It's not 1997 anymore. Anyone can buy any domain name and use it for any purpose. Except .gov and .edu obviously

Re: Show HN: An ad free temporary mail service

#67
post #8
post #6

Earlier quoted context omitted.

This is what the top sites do, e.g. temp-mail.org And they also don't allow you to view all the active domains which helps against getting blacklisted quickly

I find it amusing that a .org site (temp-mail.org) has ads all over it while a .com site (temporarymail.com) does not, given that .org was mostly used by non-profits while .com is intended for commercial use.

OpenAI is a non-profit.

(Kinda like a penguin is technically a bird.)

Re: Show HN: An ad free temporary mail service

#68
post #3

The only feature temp mail service should focus on having tons of domains. Many temp mail domains are blacklisted. only way to get around is rotating the domain name everyday. I will give it a try.

You're right about that and I'm doing my best at rotating, but it's very easy to detect these addresses as the "detectors" can simply just set a cron to grab the latest domains once an hour. I'm however thinking about creating a paid service with a low price (maybe like $2/month) just to filter out the majority of the bots and then using that money to get a lot of domains.

You could allow users to use their own domains, like https://yopmail.com/add-domain does.

Re: Show HN: An ad free temporary mail service

#69

Earlier quoted context omitted.

> If I wanted to use this for malicious intent, then I think the most valuable thing I could get away with would be a 5% discount coupon Or spinning up hundreds of accounts on a website so you can perform card testing. Or creating accounts so you can put all of the inventory for an e-commerce site into carts to reserve it for yourself. Or running sneakerbots. Or any other malicious intent where the victim is the webs…

Again, wouldn't it be easier for the attacker to just buy a domain and use that completely undetected instead of having to use a rate-limited disposable email service?

You're assuming they're doing it hundreds of times a minute. Often they're signing up for the accounts by hand to get through the captchas. The rest of it can be automated

Re: Show HN: An ad free temporary mail service

#70
post #68

Earlier quoted context omitted.

You're right about that and I'm doing my best at rotating, but it's very easy to detect these addresses as the "detectors" can simply just set a cron to grab the latest domains once an hour. I'm however thinking about creating a paid service with a low price (maybe like $2/month) just to filter out the majority of the bots and then using that money to get a lot of domains.

You could allow users to use their own domains, like https://yopmail.com/add-domain does.

I'm not sure that's a great solution though, because all the domains would use the same mail server which would basically instantly flag your domain and all your addresses as disposable.
Post reply on HN