Live data from Hacker News

Become unbannable from your email

karboosx.net

121–130 of 204 posts

Re: Become unbannable from your email

#121

Earlier quoted context omitted.

Could also be useful if someone puts a typo in your email username when sending you an important email. You'll still get the email with a catch-all emails set up on your own domain. But you won't without this.

But also annoying when your domain is very similar to another business and you keep getting their emails because of typos. My email address at my hosted domain is like jsmith@jsmith.com, and I have a catchall so I can get mail for *@jsmith.com Someone eventually bought jsmith.net for his business and now I get a lot of mail meant for jacob@jsmith.net sent to my jsmith.com domain. Fortunately he uses just the one addr…

Even having a Gmail address doesn't make you immune from someone putting in the wrong address.

I made a throwaway/spam account with a silly name back in ~2007, and then in ~2015 someone established a fairly successful company with that name. I now regularly get job applications, tax documents, and employee timesheets to my email. They even signed up for the service that controls their website with my email.

I keep waiting for them to contact me about taking over the address, but as far as I can tell they don't even realize they don't control it.

Re: Become unbannable from your email

#122

I guess the real question here is: Who is more likely to ban you, Google and co or your domain registar? For most people, who are not doing anything shady/controversial with their domain and are using a .com or .net domain (which are price regulated by ICANN), are not using a shady registrar and will always have the cash on hand to renew as needed, the answer will be Google and co. Its a good idea to set up auto-rene…

I pay for 10 years in advance, which you can do with com/net/org.

Not a bad idea, although i'd worry i'd forget to renew, may not remember something I set up a decade ago at the right time.

Re: Become unbannable from your email

#123

I guess the real question here is: Who is more likely to ban you, Google and co or your domain registar? For most people, who are not doing anything shady/controversial with their domain and are using a .com or .net domain (which are price regulated by ICANN), are not using a shady registrar and will always have the cash on hand to renew as needed, the answer will be Google and co. Its a good idea to set up auto-rene…

I guess another consideration is also, should something happen, what level of support will you get?

Most domain registrars will at least have some customer support.

But good luck getting support for a free gmail account.

Re: Become unbannable from your email

#124

Earlier quoted context omitted.

Two factor tokens that can't be backed-up create stupid make-work. Wouldn't it be great if Yubico let you back-up and restore a Yubikey? It's maddening that they haven't come up with a reasonable way to allow a purchaser to register multiple Yubikeys to enable freely restoring backups between them. (Think of if analogously to buying multiple padlocks keyed the same from the factory.) I'd prefer to be able to just set…

> It's maddening that they haven't come up with a reasonable way to allow a purchaser to register multiple Yubikeys to enable freely restoring backups between them. It is possible, using a cryptocurrency hardware wallet allowing to install tiny apps on the hardware wallets. These wallets are meant to initialized by a "seed" and there's a protocol to easily write down that seed (a list of words, all coming from a dict…

> ... These wallets are meant to initialized by a "seed" and there's a protocol to easily write down that seed...

Yes. That's a thing with some HSMs, too. That's where I've had experience with this kind of protocol.

As it stands Yubico's tokens are unusable to me for personal purposes because they can't be backed-up and restored.

Re: Become unbannable from your email

#126

Earlier quoted context omitted.

Two factor tokens that can't be backed-up create stupid make-work. Wouldn't it be great if Yubico let you back-up and restore a Yubikey? It's maddening that they haven't come up with a reasonable way to allow a purchaser to register multiple Yubikeys to enable freely restoring backups between them. (Think of if analogously to buying multiple padlocks keyed the same from the factory.) I'd prefer to be able to just set…

If the secrets are routinely copied or otherwise extracted, then it reduces their security value. What I recommend people do is buy two or more and set them up all at the same time. It is inconvenient though.

I suppose I should have preemptively made that argument and then argued against it.

My point is that there should be a mechanism to extract key material in an encrypted form. The backup could only be restored onto properly-prepared hardware (either by way of a device master key held under escrow by Yubico, or by an initial "seed" set by the user when commissioning the hardware).

Setting up multiple keys at the same time isn't just inconvenient, but actually defeats the purpose of backup. If both keys have to be present in the same place at the same time it's not a backup.

The workflow with tokens that can't be backed-up creates needless labor and risk. HSM vendors have solved this problem (albeit with tremendous vendor lock-in) but apparently that's too difficult for consumer token vendors to handle.

Re: Become unbannable from your email

#127

Anyone else have a .io domain and worried about the future?

Yeah kinda. Honestly when I signed up for it I had no idea it was a country TLD, let alone that it might disappear so easily one day. If it does go away I'll live, but it will be quite annoying to have to switch my entire digital life over to a new domain. I've had my domain for 10+ years so lots of stuff is pointed there.

Although I had not signed up for .io domain names, I did expect it to be a country TLD when I saw it, because it is two letters, so to me it seems obvious that it is.

Re: Become unbannable from your email

#128

Earlier quoted context omitted.

Definitely due to trademark disputes and political pressure. Substitute “criminal activity” with “someone with power that doesn’t like what you’re doing”. Consider the eBay stalking scandal [1] and ask if those doing the stalking would be willing to bribe or coerce someone to seize the blogger’s domain. [1] https://en.wikipedia.org/wiki/EBay_stalking_scandal

Definitely due to trademark disputes and political pressure. Trademark makes sense, ICANN has a whole program around that: https://www.icann.org/resources/pages/trademark-infringement... As for political pressure, do we have any examples? Consider the eBay stalking scandal [1] and ask if those doing the stalking would be willing to bribe or coerce someone to seize the blogger’s domain. Has ICANN (or registry) ever be…

> Has ICANN (or registry) ever been bribed or coerced?

Not that I know of. But it would be quite remarkable for an organization with a global choke point to resist attempts at influence indefinitely.

The upstream comment correctly mentioned owning a domain name being insufficient to be unbannable. There’s no mechanism with owning a domain, or DNS, that’s able to be defended by an individual (nothing like encryption, for example). It’s just someone with more power that allows it, until they don’t.

Re: Become unbannable from your email

#129

Earlier quoted context omitted.

Spamgourmet lets you do this for free without your own domain, and has other great features also.

Lots of these services get their domains blocklisted eventually, sadly.

Companies tried to block Apple’s Hide My Email in the months after its release, but I haven’t been blocked in years now. I’m assuming they quickly realised that it was here the stay.

Re: Become unbannable from your email

#130

Earlier quoted context omitted.

Yeah kinda. Honestly when I signed up for it I had no idea it was a country TLD, let alone that it might disappear so easily one day. If it does go away I'll live, but it will be quite annoying to have to switch my entire digital life over to a new domain. I've had my domain for 10+ years so lots of stuff is pointed there.

Although I had not signed up for .io domain names, I did expect it to be a country TLD when I saw it, because it is two letters, so to me it seems obvious that it is.

I wasn't aware of that convention when I signed up. I just figured it was like any other TLD.
Post reply on HN