Live data from Hacker News

An Ode to Apple’s Hide My Email

empty.coffee

151–160 of 298 posts

Re: An Ode to Apple’s Hide My Email

#151
post #5

I've been using yopmail for years to avoid spam, but the problem is that a lot of services have blocked yopmail and other disposable email addresses. The nice thing with "hide my email" and Fastmails "masked addresses" is that the two services use a popular domain, so sites can't easily block it.

Yep, I used to use Mailinator, sometimes others, but they eventually end up blocked in Marketing-hungry websites. Even myname+random@gmail.com and similar can get blocked from registration on some websites now. The difference here is the power of iCloud. Services can't afford to block it. This is similar to Domain Fronting [1]. Maybe we should call this email fronting? [1] https://en.wikipedia.org/wiki/Domain_frontin…

This raised a bigger question for me- How did the system get to a point where only big players can set up a service like this?

Re: An Ode to Apple’s Hide My Email

#152
post #98

Earlier quoted context omitted.

According to https://www.xfinity.com/Corporate/Customers/Policies/Subscri... you have to give up your rights to a class action and a jury trial to get Comcast service. Additionally, they spend a ton of money lobbying and otherwise unfairly impeding competition, so in many places in the US, they are the only option, so it's give up your civil rights to lawsuits, or stay offline (or pay a wireless carrier who does the…

I’m no lawyer, but I wonder if this is more of a “go away” clause and if it would survive a real courtroom. Your lawyer would undoubtedly say “don’t waste your time and money”, but I question how many of our rights we can really, actually give up in a contract.

> but I question how many of our rights we can really, actually give up in a contract.

Theoretically, probably none. Otherwise, you'd be able to hire a hitman on yourself, have slaves, or restrict a person's free speech because they're an employee.

Re: An Ode to Apple’s Hide My Email

#153
post #91
post #49

The most popular open-source alternatives are SimpleLogin[1] and AnonAddy[2]. The former one was just acquired by ProtonMail[3]. [1] https://github.com/simple-login/app/ [2] https://github.com/anonaddy/anonaddy [3] https://protonmail.com/blog/proton-and-simplelogin-join-forc...

Mozilla also has Firefox Relay: https://relay.firefox.com/ (Disclosure: I'm on the Relay team.)

I don't know how much I can trust Mozilla with my privacy. I know it's not Mozilla's fault, but 90% of my millions of DNS requests that leave my house go to Mozilla tracking services. It's kind of scary how much information Mozilla has on people, just based on what leaves my house (and no one uses Firefox). I have no idea if Mozilla does any aggregation on that data, but it's a bit worrying IMHO.

Re: An Ode to Apple’s Hide My Email

#154

Earlier quoted context omitted.

I do a simplified version of this. I just use a catchall account with Fastmail and then pick email addresses in the domain randomly. If someone abuses the address, I block it. I specifically do not use addresses that make it obvious what my strategy is. I end up just using a name and number that would look right at home on gmail. I'm also not trying to stop tracking, so much as I'm trying to have my own semi-permanen…

I've been happily using fastmail for years and I think I'm going to be forced to stop. My outbound emails are constantly getting caught in spam and it recently cost me a job offer.

if you're having this issue I would reach out to Fastmail support. A real human will dig through the smtp logs and find out what the issue is. Based on my experience... Fastmail is very on top of spam, blacklists and other deliverability issues.

Re: An Ode to Apple’s Hide My Email

#155
post #5

I've been using yopmail for years to avoid spam, but the problem is that a lot of services have blocked yopmail and other disposable email addresses. The nice thing with "hide my email" and Fastmails "masked addresses" is that the two services use a popular domain, so sites can't easily block it.

Yep, I used to use Mailinator, sometimes others, but they eventually end up blocked in Marketing-hungry websites. Even myname+random@gmail.com and similar can get blocked from registration on some websites now. The difference here is the power of iCloud. Services can't afford to block it. This is similar to Domain Fronting [1]. Maybe we should call this email fronting? [1] https://en.wikipedia.org/wiki/Domain_frontin…

The "+" symbol is easy to detect.

The other benefit for apple is that if a generated email address for Home Depot has non Home Depot content, it's easy to block, since it's clear it got sold to a email marketing company.

And then Apple can then threaten the corporations to not sell their mailing lists or risk being cut off from sending to icloud, or worse, having a header in the email from Apple saying that "Home Depot doesn't respect your privacy and sells your email address to 3rd party marketing companies. Here's a telephone number where you can complain."

Re: An Ode to Apple’s Hide My Email

#156

Earlier quoted context omitted.

I wish they'd let users decide what they want to use as additional factors. I would like to ban phone calls, emails, SMS, and TOTP entirely from all my accounts, especially those that hold credentials for other services, and use only WebAuthn. I'd love to use Apple's keychain for credentials for convenience but it can quickly become the weakest link, when it should be the strongest.

What’s wrong with TOTP? Isn’t it exactly as secure as WebAuthN?

You have to have the generator somewhere to get the code. If it's in software, you must have access to that software, and it must be secure. With WebAuthN, it can be a hardware token and usually multiple of them stored in various locations that only you can access (safe deposit box, physical safe, etc).

Re: An Ode to Apple’s Hide My Email

#157
post #81

Earlier quoted context omitted.

I've been thinking of a new way to use my email... - Only use one email address: hi@example.com - Always add a filter: hi+hn@example.com - Send all emails without a filter to SPAM Since it's not a common strategy, it is much more likely that spammers remove the +hn before sending an email than add one.

would not recommend not only can you not sign up to many services, customer support can often get confused when you need to email reply to them and you cannot email from your aliased email. they see you as a separate user not in their system, or the wrong person replied to the support ticket, etc.

On Fastmail, at least, this isn't a big issue. For a catchall account, if I reply to an email[0] it automatically addresses the reply as from the alias. It is editable in place, too, in case I want to give it some other name.

[0] In their webmail client, of course

Re: An Ode to Apple’s Hide My Email

#158

I have a unique email address for every single service that I sign up for, similar to this, though selfhosted. I've been doing this for years and it works wonderfully. If someone misuses my email address, or gets annoying, I can simply turn off the address. Bam! It's the easiest Postfix config in the universe, essentially just: virtual_alias_domains = domain1.com domain2.com virtual_alias_maps = hash:/etc/postfix/vir…

I've just started doing this and it's so nice. "Gee who signed me up for a newsletter... why, it's that hotel chain I stayed at 3 months ago! Naughty, naughty." Makes the management much nicer, and I can maintain my fun username for silly projects and a slightly more professional one for business inquiries and such. Highly recommended! Domains are cheap and Fastmail makes the process absolutely painless.

Re: An Ode to Apple’s Hide My Email

#159
post #5

Earlier quoted context omitted.

Yep, I used to use Mailinator, sometimes others, but they eventually end up blocked in Marketing-hungry websites. Even myname+random@gmail.com and similar can get blocked from registration on some websites now. The difference here is the power of iCloud. Services can't afford to block it. This is similar to Domain Fronting [1]. Maybe we should call this email fronting? [1] https://en.wikipedia.org/wiki/Domain_frontin…

This raised a bigger question for me- How did the system get to a point where only big players can set up a service like this?

Email marketing ruined communication for everyone.

I once ran my own email server for several years off a domain from no-ip.org running from a local server in my home. Most places accepted email from it just fine, occasionally though some places had their mail server reject my IP because it was in a DNS black hole.

Then you had the spoofers pretend to be att.com/verizon.com so they had to implement SPF and DKIM.

Then you had to uphold your reputation and the security of your servers otherwise your address would get put on one of the DNS black hole blocks.

Worse was if your IP address was already used to send spam -- you somehow had to get the black hole lists to remove your IP.

At some point about 15 years ago, I gave up and moved to gmail, and I never really looked back on it again.

Re: An Ode to Apple’s Hide My Email

#160
post #124

A useful feature the article doesn't mention: In macOS Mail and iOS Mail, when you reply to an email or send a new one, you can choose the "From" address: The options are the usual accounts you have set up, plus, now, a "Hide my Email" proxy generated on-the-fly. I've found it very handy on several occasions.

Thanks for sharing! I totally missed this.
Post reply on HN