Live data from Hacker News

Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

github.com

151–160 of 304 posts

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#151

Earlier quoted context omitted.

Thanks, the first idea is a really good one for our use case. (the other ideas won't work unfortunately) And yes, it is not a meaningful number of people that do so, but over time this is very ugly and frustrating (as it requires manual intervention) and you block the disposable Email provider they used ...

I mean, if its not having a notable impact except emotionally, maybe its better to just let it be? Missing the forest for the trees and all

Probably. But if we wouldn't block certain disposable Email providers since years, maybe this would be already dozens per month.

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#152

Earlier quoted context omitted.

And how would you protect your service from users that just sign up with disposable Emails for the 7 day trial over and over again?

Just a few idea: Make it useful to have a persistent identity, so you have something to lose if you abandon the account (like a library of games in steam, or a network of friends on facebook). Require a payment method and limit how many free trials can be activated with the same card. Require a phone number since they a harder to get than emails.

If someone wants to use disposable email addresses out of fear of having the service sell or abuse their permanent email address, they will most likely also not be willing to reveal their phone number.

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#153
post #28

Earlier quoted context omitted.

>From the prospective subscriber’s perspective, that’s your problem to worry about — not theirs. exactly...which is why there are blacklists like the one linked in the OP.

… which makes it the prospective subscriber’s problem, pushing nearly all risk onto them, and requiring them to trust that the service won’t spam them or sell their e-mail address.

What alternative do you suggest?

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#154
post #92

Earlier quoted context omitted.

Password managers should start supporting this flow. Allow the password manager to read your Gmail, or for cloud-based managers log up with an @1password.com email... Not trivial technically, and maybe turning password managers into SSO providers, but that's a lucrative business in itself.

At that point we'd be better of figuring out a proper protocol that allows websites to talk to the password manager directly.

Something like OpenID connect?

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#155

It's arguably the case that Firefox Relay is no different from the other services in this list. If someone can use it to create ~unlimited identities for almost free, that serves the same purpose as any other disposable email service. And frankly, there's no sense in getting upset about a directory of services that allow the creation of unlimited disposable identities. If it wasn't this github repo, it would be anoth…

I find that the services most vulnerable to sybil attacks are malicious ones funded by "growth and engagement" - see my comment above: https://news.ycombinator.com/item?id=29960340 If you charge for the service, a lot of attacks suddenly become pointless or unprofitable, implicitly mitigating the problem.

I'd say you're wrong. My business is just me, and I offer a free plan to let folks kick the tires. My biggest competitors charge nothing for their services, so I can't compete if I don't offer a free plan.

I don't think you could produce data that shows what you're suggesting, and in fact I think the reality is that the opposite is quite true. Any business that offers trials or free options is vulnerable to abuse, and any amount of abuse will eventually begin to eat into business resources. And business who do charge for their products don't have the "growth and engagement" money to burn on bad actors.

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#156

Earlier quoted context omitted.

I'm curious - I see on your profile that you're a DevOps engineer presumably using a lot of online services on a daily basis, so what approach do you use to deal with email that would justify your opinion here? Do you just let it fill up your inbox and essentially make it unusable as it's saturated with marketing spam? Do you read every single incoming email (if so how do you find time and how do you justify spending…

> so what approach do you use to deal with email that would justify your opinion here? When I get email I don't want from a company I have an account with, I scroll to the bottom and click 'unsubscribe'. I then don't get anymore of those kinds of emails. What I absolutely do not do is throw a hissy fit and click 'report spam' (which not fucks up my own bayes classifiers and makes false positives more likely, but send…

So you're accepting that for every company you sign up for you should expect at least one spam that requires time & attention to deal with (some may require login, etc)? Fair enough but I disagree that this is something we should all be accepting just for the benefit of a minority that happens to work in marketing.

> of those kinds of emails [emphasis mine]

Also keep in mind that scummy companies have caught on to that and now have dozens of different categories of marketing emails and unsubscribing merely unsubscribes you from one of them.

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#157
post #118
post #97

Earlier quoted context omitted.

I really don't see how "determine unique legal identity" is such a requirement? What are you running, e-voting? If that's really what you need, the relevant jurisdiction is likely to have some adopted e-identity system. If not, go back and question how you can solve your issues with as little PIIs as strictly necessary.

We did, it's called non-disposable email. A non-unique pseudoanonymous identity that's somewhat difficult to mint in bulk. If you don't like "accounts of well-known service providers" -- email or login-with-whoever then sources of identity that "everyone" has that are hard to get many of are government ids, phone numbers and credit cards. Like what else is there? For super technical people we could do something like…

I don't really get this. Where do you draw the line between disposable and non-disposable email? What prevents anyone from creating @gmail.com addresses?

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#158
post #67

One of the comments on the issue [1] says: > My reasoning on including this is that an email with a mozmail domain is never going to be a primary email and is always going to forward to some other address. This is laughable and sad at the same time. I have a few tens of email addresses that are used for different purposes and with different classes of sites and services. None of them are “primary” and I wouldn’t real…

The difference with Apple's hide my address feature, is that it will only give you one per site. So even though it's an address generated specifically for that website, it's still your "primary" email for that domain.

If you signup for Netflix using the feature, you can't cancel your account and then signup with a new Apple email, it will only allow you to login with your original one.

This negates the primary reason for blacklists like in OP, in that users generate multiple disposable addresses, within the one domain, for their single identity, usually to circumvent account limits, user blocks etc.

This whole thread is going on about spam but most have misunderstood what "spam" the blocklist is trying to tackle. It's there to tackle people signing up with a disposable address, spamming or abusing the platform, getting blocked and then creating a new account to do the same thing again.

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#160

Earlier quoted context omitted.

> so what approach do you use to deal with email that would justify your opinion here? When I get email I don't want from a company I have an account with, I scroll to the bottom and click 'unsubscribe'. I then don't get anymore of those kinds of emails. What I absolutely do not do is throw a hissy fit and click 'report spam' (which not fucks up my own bayes classifiers and makes false positives more likely, but send…

So you're accepting that for every company you sign up for you should expect at least one spam that requires time & attention to deal with (some may require login, etc)? Fair enough but I disagree that this is something we should all be accepting just for the benefit of a minority that happens to work in marketing. > of those kinds of emails [emphasis mine] Also keep in mind that scummy companies have caught on to th…

What I "accept" is that getting an email I'd rather not have gotten is not a day-ruining event worth rudely snarking at strangers on the internet for, and the level of entitled rage and piling on generated in response to a calmly stated ask (let's save 'spam' for things that actually meet an objective, commonly-accepted standard used by most groups that actually try to stop it) is ridiculous.
Post reply on HN