Earlier quoted context omitted.
It's worth nothing. This is an online myth that marks out the user the way the sentence "Expert in JAVA, AWS, GCP, Oracle, and GIT" on a resume marks out the candidate.
My boss has paid many people for lists of email addresses in the past. Im pretty sure he is not a mythical being!
Someone at BrowserStack is leaking users' email addresses
111–120 of 123 posts
Re: Someone at BrowserStack is leaking users' email addresses
#112Earlier quoted context omitted.
> It’s almost universally true. It’s not. I give a unique email address to every service I register with, which means I can see who is leaking my email address. Very few of them leak my email address at all, and those that do tend to do so involuntarily through data breaches. The other main factors in spam are the sleazeballs at Apollo, ZoomInfo, et al., services that use my email address internally for more than I c…
If you dont mind, What kind of unique email address do you use and how do you manage all the aliases?
Most mail providers also support plus addresses or wildcard local parts, so you can do jim+@example.com or just @example.com. Gmail supports plus addresses, for instance. The downside is that some services reject pluses and some spammers strip out the IDs.
Re: Someone at BrowserStack is leaking users' email addresses
#113Email needs a consent revocation system effectively like how Blackberry had PINs for BBM
Hey.com works that way. You have to approve new senders before they can reach your inbox. And you can always revoke their permission to message you. I'd like to see that concept replicated to other email services. I don't particularly like all the other opinionated choices of Hey.com (especially the fact that you can't use IMAP).
The initial email verification sent to you (“click here to confirm your email address”) includes an attachment requesting an auth token. Emails with this attachment get presented to the user in something akin to a friend request for email, with a consent screen describing how they intend to use your email and for how long. Approving the request hands them a Biscuit token.
The sender attenuates this token when sending email to you or when sharing with a third party provider like Mailchimp. Any emails authorised by a token automatically skip all spam filters. This is the carrot for senders to adopt – they can stop worrying about all the deliverability and IP reputation nonsense and can just send direct from their own servers, reversing the centralisation of email and making it more reliable by skipping spam filter heuristics.
All of these emails have reliable provenance and traceability. If a leak / abuse happens, you can revoke the token and any emails sent with it. Senders can also proactively revoke any tokens provided to third-parties in case they were breached, without affecting the sender’s ability to send themselves or through other providers.
Once a critical mass hits, you can auto-deny anything without a token. At this point, all the email you receive is from somebody who has obtained your explicit consent to do so.
Re: Someone at BrowserStack is leaking users' email addresses
#114Earlier quoted context omitted.
I just do @ . It is sometimes confusing by when interacting with customer support ;-)
I had one website forward my mail to their legal department who asked me why I’m impersonating them :D Only required a short explanation though.