Live data from Hacker News

Become unbannable from your email

karboosx.net

101–110 of 204 posts

Re: Become unbannable from your email

#101

Anyone wanna share their email strategy? I'm thinking of going for the following but I'm still undecided: 1. 1 custom domain ( .com): this will be used for friends, family and any online accounts that know me IRL. Use Fastmail masked addresses with my custom domain where it makes sense like an online account for amazon. 2. 1 custom domain ( .xyz): this will be used for a blog, professional IRL interviews, corresponde…

> 1 custom domain (.xyz)

I got banned by .xyz once. I did manage to get it cleared up, but being banned by the TLD itself is pretty unpleasant. It's hard to even figure out that's what happened. And then I had to "prove" I was no longer distributing malware, with a list of what things I'd done to clean up the site and prevent further malware distribution - which was difficult as I was never distributing malware to begin with. Just a static website for a wordle variant, no ads or other 3rd party content.

Re: Become unbannable from your email

#102
post #96

Earlier quoted context omitted.

Gmail has a limited version of this. It leaks your real address, but it makes filtering easy. + @gmail.com steve+randoburger@gmail.com

I've seen places that won't allow a "+" saying it's an invalid character.

ah! the fathers of slop vibe code: copy paste coders.

the "validate email input regex" that mistakenly rejects plus sign have been copy pasted for so long it might live on forever.

Re: Become unbannable from your email

#103
post #43
post #37

Been doing this for years, and surprised he didn't seem to mention the other benefit: "infinity" email addresses. Oh, rando burger spot wants an email for some free fries? Great, hit me up at randoburgerspot@"mydomain".com .

I like that as well, but it's exhausting having to explain every time that, no, I don't in fact work at randoburgerspot...

I only had once in over 20 years someone asking me to clarify that. Maybe because I add a short standard prefix before “randoburgerspot” (which also happens to serve as a wildcard filter).

Re: Become unbannable from your email

#104

I've been doing this for years, though I don't really think of it as "having a backup" so much as "using an IMAP client". Works fine. It's really useful to be able to make up a new email address for every company who wants one; they each get their own folder. If I get any unexpected mail, it's obvious where it came from and easy to deal with, though in practice this rarely happens.

The caveat is that if your account gets banned, the IMAP access will also be blocked. An email forward is more likely to remain active, is the point made in TFA.

Re: Become unbannable from your email

#105

I’ve considered running an email server on my personal domain for some time, but the effort of changing my email hasn’t felt worth it to me, given how many services I’ve signed up for with my current email (a Gmail address). Is anyone aware of any strategies to make this easier? It’d be nice if I could set up forwarding so services would automatically use my new email, but I’m not sure if something like that exists.

You can have the Gmail emails be forwarded to your own email server, or have your server fetch them from Gmail, and then migrate bit by bit, the most important accounts first.

Before SPF and the like, it used to be trivial to also send email with a different From address (like your existing Gmail address) from your own server, but that’s not the case anymore.

Re: Become unbannable from your email

#106
post #10

Over the past few weeks I've been systematically migrating every one of my accounts to a domain under my control. During the process I've been marking them in a spreadsheet with their 2FA status (no 2FA, TOTP, security key, etc.) and adding their passwords to a password manager. This is all in case I ever need to go through the migration process again for whatever reason, or if I lose/break a Yubikey, I will know wha…

Two factor tokens that can't be backed-up create stupid make-work. Wouldn't it be great if Yubico let you back-up and restore a Yubikey? It's maddening that they haven't come up with a reasonable way to allow a purchaser to register multiple Yubikeys to enable freely restoring backups between them. (Think of if analogously to buying multiple padlocks keyed the same from the factory.) I'd prefer to be able to just set…

If the secrets are routinely copied or otherwise extracted, then it reduces their security value. What I recommend people do is buy two or more and set them up all at the same time. It is inconvenient though.

Re: Become unbannable from your email

#107

TL;DR: Step 1: Get Your Own Domain Step 2: Make Backups This is not sufficient. Even your domain can be seized. There is no way for any service dependent on the DNS System to be irrevocably owned.

Any stories of domains being seized that weren’t involved in criminal activity?

Definitely due to trademark disputes and political pressure.

Substitute “criminal activity” with “someone with power that doesn’t like what you’re doing”.

Consider the eBay stalking scandal [1] and ask if those doing the stalking would be willing to bribe or coerce someone to seize the blogger’s domain.

[1] https://en.wikipedia.org/wiki/EBay_stalking_scandal

Re: Become unbannable from your email

#108
post #4

Counterpoint: I lost a domain when a registrar went out of business, and another when a registrar bumped the price 10x and refused to give me authenticode unless I physically show up to their office. Sure, I cheapened out and used shady cheap registrars, and this all happened a while ago so things are probably more regulated now, but for comparison I never permanently lost access to hosted email. (Losing access tempo…

One time I had several domains at a registrar that began to fall apart organizationally. They couldn't transfer my domains out with their automated tools and they weren't answering my emails. I filed a dispute with ICANN and had all my domains transferred out within a week.

So at least for .com and .net there's a responsive third party with procedures to work around failing registrars.

Re: Become unbannable from your email

#109
post #99

Earlier quoted context omitted.

Why are we doing this exactly?

There’s an attack where you get signed up for mass marketing emails and your mailbox gets flooded with emails from mostly legitimate companies. Say someone gets into an account you use to purchase stuff (Amazon, etc), but they don’t have access to your email account. They sign you up for this mail flood, then start buying stuff with your Amazon account, and legitimate notifications of purchases are lost in the noise…

I'm missing what purpose the high entropy alias does; from your description the attacker knows the email address and can still sign you up for mail flood?

Re: Become unbannable from your email

#110

Earlier quoted context omitted.

Any stories of domains being seized that weren’t involved in criminal activity?

Definitely due to trademark disputes and political pressure. Substitute “criminal activity” with “someone with power that doesn’t like what you’re doing”. Consider the eBay stalking scandal [1] and ask if those doing the stalking would be willing to bribe or coerce someone to seize the blogger’s domain. [1] https://en.wikipedia.org/wiki/EBay_stalking_scandal

Definitely due to trademark disputes and political pressure.

Trademark makes sense, ICANN has a whole program around that: https://www.icann.org/resources/pages/trademark-infringement...

As for political pressure, do we have any examples?

Consider the eBay stalking scandal [1] and ask if those doing the stalking would be willing to bribe or coerce someone to seize the blogger’s domain.

Has ICANN (or registry) ever been bribed or coerced? I understand a low quality registrar can, and can possibly take over a domain, but there is recourse (and punishment such as loss of registrar status) around these situations. I would of course avoid these micronation tlds and stick to well established tlds like com/net/org.

Post reply on HN