Live data from Hacker News

An Ode to Apple’s Hide My Email

empty.coffee

191–200 of 298 posts

Re: An Ode to Apple’s Hide My Email

#191

I have a unique email address for every single service that I sign up for, similar to this, though selfhosted. I've been doing this for years and it works wonderfully. If someone misuses my email address, or gets annoying, I can simply turn off the address. Bam! It's the easiest Postfix config in the universe, essentially just: virtual_alias_domains = domain1.com domain2.com virtual_alias_maps = hash:/etc/postfix/vir…

> It's not as shiny as Apple's thing, but it's 100% selfhosted and I own the domain. Apple's system is "shiny" because it provides near total anonymity, whereas your setup has all the deliverabilty issues of a self-hosted domain and rather uniquely identifies you...at the domain level? I'm not sure why you are maintaining a hundreds-of-lines virtual table and a web UI, instead of just using a regex or two to capture…

Apple's system will only work until they decide to shut you out or shut down this service for whatever reason. Anonymity is not really a concern for most uses, privacy, longetivity and reliability of reception is though.

I still want to use random unique addresses even for important and trusted services, not just for throwaway uses. So third party domain is not an option.

I use self-hosted unique addresses mostly for registering to services, so forwarding those messages in both directions through Apple's service would expose all those services to a silent takeover via password reset by Apple's employees in control of this service. So this service is exactly as useful as those random throwaway email inboxes available on the web. More polished maybe.

Re: An Ode to Apple’s Hide My Email

#192

Earlier quoted context omitted.

Are your domains set up correctly? That sounds suspiciously like something isn't set up correctly and their client's thought it was spam.

I use an @fastmail domain. The issue was how they handle RSVPs when your default calendar is an external one. RSVPing from within Fastmail attempted to Accept as my old Gmail address, who wasn't invited to the interview. On the interviewers end it looked like I didn't respond.

In some contexts, fastmail is viewed as a "throwaway" email provider. I ran into this when I was trying to provision a couple of VMs at a hosting provider. My fastmail email address was rejected. After contacting their support, they said they did not accept "throwaway" email addresses. I had to use a gmail acccount. The irony did not seem apparent to them.

Re: An Ode to Apple’s Hide My Email

#193
post #58

I have a unique email address for every single service that I sign up for, similar to this, though selfhosted. I've been doing this for years and it works wonderfully. If someone misuses my email address, or gets annoying, I can simply turn off the address. Bam! It's the easiest Postfix config in the universe, essentially just: virtual_alias_domains = domain1.com domain2.com virtual_alias_maps = hash:/etc/postfix/vir…

I'm doing the exact same thing. Built a small web app that lets me manage all my email aliases for the domain. Unfortunately there are a couple of websites that do only allow a select list of whitelisted domains meaning I cannot use my own, but for the other 99% it works wonders. I wish I had had this idea ten years ago, it would have saved me so many headaches.

Who whitelists email domains? Do they explain why?

Re: An Ode to Apple’s Hide My Email

#194

Earlier quoted context omitted.

TLS is unaffected by any government laws. What I assume OP is referencing is a law that makes end to end encryption problematic in Australia but Fastmail has never offered end to end encryption. Neither do most email providers so it doesn't matter.

If you get a PGP browser extension they all do. It’s pretty inconvenient to use though, sending encrypted attachments and giving the password offline is probably the only thing most people are up to.

The location of the fastmail office has zero impacts on this. If the complaint was that the PGP extension was developed in Australia then that would be a valid complaint. But email hosts themselves are not private against government requests.

Re: An Ode to Apple’s Hide My Email

#195
post #58

I have a unique email address for every single service that I sign up for, similar to this, though selfhosted. I've been doing this for years and it works wonderfully. If someone misuses my email address, or gets annoying, I can simply turn off the address. Bam! It's the easiest Postfix config in the universe, essentially just: virtual_alias_domains = domain1.com domain2.com virtual_alias_maps = hash:/etc/postfix/vir…

I'm doing the exact same thing. Built a small web app that lets me manage all my email aliases for the domain. Unfortunately there are a couple of websites that do only allow a select list of whitelisted domains meaning I cannot use my own, but for the other 99% it works wonders. I wish I had had this idea ten years ago, it would have saved me so many headaches.

Is your app available?

Re: An Ode to Apple’s Hide My Email

#196

Earlier quoted context omitted.

Actually, Apple allows SMS and recovery keys as a fallback and there is an account recovery option if none of these work. https://support.apple.com/en-us/HT204915 Google on the other hand… I’ve seen two people lose their Gmail accounts even they knew the password because google required verification from a mobile device that no longer existed. :|

I think Google also has recovery keys. I have a slip of paper with ten long strings on them that Google told me could be used to regain access to my account.

Said accounts did not have two-factor enabled.

Re: An Ode to Apple’s Hide My Email

#198
post #116
post #109

Earlier quoted context omitted.

>your post is mostly a conspiracy theory. Do you frequently bet that people are doing the right thing with no oversight? How often does that prove to be true?

I would take the bet in this case without hesitation. Apple is too big and has too many potential internal whistle blowers to run a clandestine email monitoring operation.

>Apple is too big and has too many potential internal whistle blowers to run a clandestine email monitoring operation.

This calls for an interrobang. APPLE?‽!

This is an absurd reversal of the burden of proof - where I think you go very wrong is to imply or assume the natural state of a large organization is compliance with legal or ethical norms. There's a reason they have legal and compliance departments! There's a reason the laws and rules keep metastasizing! And the same silos that allow lack of compliance, allow potential whistleblowers to be intimidated - "you don't understand the context" they can say.

Every time you take one of those online courses at the beginning of a job, they tell you to report anything unethical or illegal to a hotline or ombudsman or something, and then they tell you that you will be protected...unless you make false or malicious allegations, of course. You have to be pretty obtuse or literal not to understand the threat. They are telling you how it will go down - I mean, what sort of asshole would make a federal case out of the CEO parking in handicapped spaces?

Or, maybe I should've just gone with sarcasm and some hyperlinks:

Apple is too big and has too many potential internal whistle blowers to run a clandestine wage fixing operation, and huge conspiracy theories are nonsense, which is why this never happened:

https://www.theregister.com/2015/09/03/apple_wagefixing_clos...

Also, Apple is too big and has too many potential internal whistle blowers to run a clandestine insider trading operation, and conspiracy theories are nonsense, which is why the person responsible for insider trading compliance definitely did not insider trade Apple stock:

https://www.sec.gov/news/press-release/2019-10

Next up: Ukraine is a conspiracy theory!

Re: An Ode to Apple’s Hide My Email

#200
post #98

Earlier quoted context omitted.

According to https://www.xfinity.com/Corporate/Customers/Policies/Subscri... you have to give up your rights to a class action and a jury trial to get Comcast service. Additionally, they spend a ton of money lobbying and otherwise unfairly impeding competition, so in many places in the US, they are the only option, so it's give up your civil rights to lawsuits, or stay offline (or pay a wireless carrier who does the…

I’m no lawyer, but I wonder if this is more of a “go away” clause and if it would survive a real courtroom. Your lawyer would undoubtedly say “don’t waste your time and money”, but I question how many of our rights we can really, actually give up in a contract.

Arbitration costs companies far more than lawsuits do. There was a guy that used to make tons of money off Arbitration clauses. Basically, the company is on the hook for hotel stays, transportation, food, etc. for the arbiter as well as anyone else that may not be local to the venue in question.

The reason companies went with this approach was to stop class action lawsuits from happening, which is where the real damage happens. One enterprising law firm started doing pooled Arbitrations (filing for hundreds or thousands at a time), which costs the company more than a class action would. Some companies have removed such clauses because of this.

Post reply on HN