Live data from Hacker News

Firefox Monitor

monitor.firefox.com

141–150 of 227 posts

Re: Firefox Monitor

#141
post #44

This is basically a frontend for haveibeenpwned. Creating it costed Mozilla money. Why did they do this instead of linking directly to the original page?

Yea that's what I noticed. Do they use any additional sources at least?

Re: Firefox Monitor

#142
post #55
post #39

My email appears in six breaches. Only one of the companies I recognize. I have never done business with the other five. This pisses me off. Not that the data was stolen -- these things happen. It pisses me off that my data was shared with third parties without my knowledge or consent. And no, a paragraph buried in the basement of a privacy policy does not constitute informed consent. This system would be more useful…

> I want to know who betrayed me. You can run your own email server (or have a company host a private domain for you), set up a catch-all address that only you know, then use a different email address for every site you sign up to. That way you can find out this sort of information. Using this technique, I know for example that spammers obtained the address I signed up to Stack Overflow with. The email is not shown o…

You can also do this with a single email address and the + symbol:

jimmy+facebook@gmail.com jimmy+twitter@gmail.com jimmy+hackernews@gmail.com

all go to jimmy@gmail.com

Re: Firefox Monitor

#143

I checked my email address and it says my data was lost by verifications.io. I've never heard of that site before and going there didn't reveal any clues. I googled the name and found a report [1] on the breach. They lost control of records on 2 billion email addresses. [1]: https://www.forbes.com/sites/daveywinder/2019/03/10/2-billio...

What if the companies 'losing' data would be court ordered to pay a reasonable sum per lost record, lets say one Dollar, to a charity.

The outcome would have been the same. They went out of business a few days after the breach was announced.

Re: Firefox Monitor

#144
post #93

Earlier quoted context omitted.

Using + isn't the best method as some services just won't allow having + sign in the email address (probably shitty email address detection) and of course spammers can simply strip the alias parts and send you mail. You'd have a better luck with *@user.your.domain if you can give each user a unique domain.

Are you suggesting buying a new domain for each email address? That could get extremely expensive to maintain. I bought a single domain @MyEmail.org, and create a new user for each site I sign up with that forwards to my gmail. 1@MyEmail.org, 2@MyEmail.org, 3@MyEmail.org etc...

No. Your case works for a single person but for more people on a single domain, you would want to do,

service1@me.your.domain service1@dad.your.domain

(Instead of me+service1@your.domain)

service2@me.your.domain service2@mom.your.domain

and so on. So, those services have no way of fooling you by tampering with the alias parts.

But of course this isn't easy unless you roll your own mail server.

Re: Firefox Monitor

#145

Earlier quoted context omitted.

You can use the + trick and . trick with Gmail addresses too. I think Outlook as well supports the + trick. The only downside to this is that there are plenty of sites that don't accept a + either knowingly or unknowingly.

this isn't a good anti-spam filter though. + addressing (even the fastmail kind) is trivial to parse and I'm 100% sure email harvesters are aware of it.

Fastmail also lets you use aliases to protect your main address. I only give out an alias with an alt domain - something like spam@jm4.eml.cc, linkedin@jm4.eml.cc, etc. No one has my real address. I basically only use it as my username. I give an alias to family. I just delete the alias or filter it to the trash if I have problems with it.

I'd be surprised if many harvesters are going to bother with rules just for Fastmail domains. First of all, they have a bunch of them. Second, the spammers' objective is to get email into your mailbox. They don't care if they use an alias to get there. Bad actors who got your info in a data breach are a different story, but there's probably some safety in numbers. There could potentially be millions of accounts to go after before they start thinking about reversing my Fastmail alias. Besides, if you use one of the generic ones like qq.com or eml.cc - or even better yet, your own domain - they're not likely to notice anyway.

Re: Firefox Monitor

#146
post #135

Earlier quoted context omitted.

Those don't meet the required standard of "an unambiguous indication by clear affirmative action" according to the UK ICO's interpretation of GDPR: https://ico.org.uk/for-organisations/guide-to-data-protectio... "You cannot rely on silence, inactivity, pre-ticked boxes, opt-out boxes, default settings or a blanket acceptance of your terms and conditions."

What kind of world do we live in where using a free service and agreeing to explicitly documented T&Cs doesn’t constitute acceptance? “You provided a contract, and I agreed even though I chose not to read it (despite you providing it), and used the service, but I didn’t really mean to agree” is the most ridiculous cop-out, in my view.

Actually this is default law in the EU if you are a "customer" and the other party is not. All "surprising" clauses within a T&C document are void.

Re: Firefox Monitor

#147
post #142
post #55

Earlier quoted context omitted.

> I want to know who betrayed me. You can run your own email server (or have a company host a private domain for you), set up a catch-all address that only you know, then use a different email address for every site you sign up to. That way you can find out this sort of information. Using this technique, I know for example that spammers obtained the address I signed up to Stack Overflow with. The email is not shown o…

You can also do this with a single email address and the + symbol: jimmy+facebook@gmail.com jimmy+twitter@gmail.com jimmy+hackernews@gmail.com all go to jimmy@gmail.com

Does a . works as well doesn't it? I can't remember if it gets stripped out or not if the email server isn't expecting it.

Re: Firefox Monitor

#148
post #130

Out of curiosity, is there a list somewhere of utilities like this that are run by Mozilla/Firefox? I don't think I would've heard about Monitor or Lockwise if I hadn't been on here when someone had posted it, so I'm curious if there are other useful services by them that I have missed.

Not sure if there's a full list anywhere, but Firefox Send is another nice one

Re: Firefox Monitor

#149
post #142
post #55

Earlier quoted context omitted.

> I want to know who betrayed me. You can run your own email server (or have a company host a private domain for you), set up a catch-all address that only you know, then use a different email address for every site you sign up to. That way you can find out this sort of information. Using this technique, I know for example that spammers obtained the address I signed up to Stack Overflow with. The email is not shown o…

You can also do this with a single email address and the + symbol: jimmy+facebook@gmail.com jimmy+twitter@gmail.com jimmy+hackernews@gmail.com all go to jimmy@gmail.com

I used this technique a few times until I realized that spammers and, most importantly, companies that sell their user databases also know about it. So it's actually pretty trivial for them to strip the +something bit before any shady business. Now I don't really care anymore. Most spam are catch automatically anyway. Even when they're not, it's actually a tiny annoyance to me. And what am I going to do if I know for sure that some company sold my data? Sue them? I will most certainly not.

Re: Firefox Monitor

#150

Earlier quoted context omitted.

this isn't a good anti-spam filter though. + addressing (even the fastmail kind) is trivial to parse and I'm 100% sure email harvesters are aware of it.

This isn’t to prevent spam, it is to identify the original leak. If the unique email address you gave to company X is used for solicitations by company Y, company X must have given it away.

Then what?
Post reply on HN