Live data from Hacker News

Firefox Monitor

monitor.firefox.com

181–190 of 227 posts

Re: Firefox Monitor

#181
post #39

My email appears in six breaches. Only one of the companies I recognize. I have never done business with the other five. This pisses me off. Not that the data was stolen -- these things happen. It pisses me off that my data was shared with third parties without my knowledge or consent. And no, a paragraph buried in the basement of a privacy policy does not constitute informed consent. This system would be more useful…

One of the recent big breaches was from Apollo and when I searched for information on that, I found that they built their database from scraping the web.

Re: Firefox Monitor

#182
post #135

Earlier quoted context omitted.

What kind of world do we live in where using a free service and agreeing to explicitly documented T&Cs doesn’t constitute acceptance? “You provided a contract, and I agreed even though I chose not to read it (despite you providing it), and used the service, but I didn’t really mean to agree” is the most ridiculous cop-out, in my view.

Firstly a Contract is a Meeting of Minds, the forty pages of small type in a PDF are nice, but it's laughable that you pretend you thought everybody read those before using your free service. And if they didn't read them, they clearly cannot agree with just every random term you threw in there and so it can't all be part of that meeting of minds, so there is not, in fact, a contract with people with those terms. OK,…

> Firstly a Contract is a Meeting of Minds

Re: this, I'm still fascinated how a contract that both parties are not aware of the existence of is even allowed to be treated as a contract in the first place. In many cases like local software, when you accept the T&C, the other party has no idea this happened in the first place, so they can't even claim to have a contract with you. That you can have a contract with "informed" consent from a party from a party (and interestingly this is regarding the other party, not you the consumer) that has no information about the contract's existence just blows my mind.

Re: Firefox Monitor

#184

Earlier quoted context omitted.

You can use the + trick and . trick with Gmail addresses too. I think Outlook as well supports the + trick. The only downside to this is that there are plenty of sites that don't accept a + either knowingly or unknowingly.

this isn't a good anti-spam filter though. + addressing (even the fastmail kind) is trivial to parse and I'm 100% sure email harvesters are aware of it.

They can filter out the boxname part of temporal+boxname@mytld.com, but they can't, in general, filter out boxname@temporal.mytld.com - it would break too many things. I guess it's possible to recognize mail for mytld.com is handled by FastMail, but I'm not sure anyone bothers. In my case, almost all spam I get comes to an alias I have in my Facebook profile, and the rest of it to an alias I put on my website - so in both cases, I assume spammers just scrapped the e-mail address.

Re: Firefox Monitor

#186

Earlier quoted context omitted.

This isn’t to prevent spam, it is to identify the original leak. If the unique email address you gave to company X is used for solicitations by company Y, company X must have given it away.

Then what?

Depending on my mood and whether the company is local, write a complaint to the company that leaked the address or to an appropriate government institution. In my country, a local computer security news site started a tradition of telling the offending companies that they can either apologize and donate some money to a charity (and send back the proof of payment), or you'll bring the issue up with Personal Data Protection Office, which will be more than happy to fine them.

Re: Firefox Monitor

#187
post #84

Earlier quoted context omitted.

If you run your own email, you can catch the moderately motivated spammer: use a character other than + as the segmenter, and a honeypot +. Here, ‘-’ is the segment character, is the actual delivery address, and triggers an immediate block.

> triggers an immediate block. This doesn't work. I've seen legitimate companies just strip everything from the + onwards.

Well, "legitimate". There's no legitimate reason for a company to remove anything from user-provided e-mail address.

Re: Firefox Monitor

#188
post #39

My email appears in six breaches. Only one of the companies I recognize. I have never done business with the other five. This pisses me off. Not that the data was stolen -- these things happen. It pisses me off that my data was shared with third parties without my knowledge or consent. And no, a paragraph buried in the basement of a privacy policy does not constitute informed consent. This system would be more useful…

>This system would be more useful if it could report how these companies got my data. I want to know who betrayed me. The company might not have sold your info. They might have been hacked. There really isn't any way to know for sure FWICT.

Or the info may have been transfered to third party for "legitimate" reasons, and then "stolen" by an employer of said third party. From the second-hand stories I heard personally, this is a common practice with call centres subcontracted by Polish telcos.

Still, it doesn't matter. Whether the company sold the data or got it taken from them, they are still at fault.

Re: Firefox Monitor

#189
post #39

My email appears in six breaches. Only one of the companies I recognize. I have never done business with the other five. This pisses me off. Not that the data was stolen -- these things happen. It pisses me off that my data was shared with third parties without my knowledge or consent. And no, a paragraph buried in the basement of a privacy policy does not constitute informed consent. This system would be more useful…

>does not constitute informed consent. Most contracts that keep modern day businesses running work by pretending uninformed consent counts as consent. If we required true informed consent things would grind to a halt. Which may not be a bad thing.

They wouldn't grind to a halt, but a lot of dishonest businesses would find themselves in a world of trouble. Which is all positive in my books. The market will go as low as people allow it to.

Re: Firefox Monitor

#190

Earlier quoted context omitted.

> triggers an immediate block. This doesn't work. I've seen legitimate companies just strip everything from the + onwards.

Well, "legitimate". There's no legitimate reason for a company to remove anything from user-provided e-mail address.

Legitimate reason != legitimate company
Post reply on HN