Live data from Hacker News

Show HN: NBox – Sign up anywhere without giving your email address

nbox.notif.me

201–210 of 212 posts

Re: Show HN: NBox – Sign up anywhere without giving your email address

#201

Earlier quoted context omitted.

I'd think spammers would have caught on to that and would either start sending e-mail to nico@domain.com or nico+someotherdomainname@domain.com

You think spammers are people going through emails? It is all automated.

Well obviously it's automated. I didn't mean manually finding name+domain@mydomain.com e-mail addresses and manually editing them to just name@mydomain.com.

Re: Show HN: NBox – Sign up anywhere without giving your email address

#202
post #93

Earlier quoted context omitted.

Easier to use sub-/plus-addressing rather than maintaining a list.

That seems like a white pattern to me.

If only delivering mail to existing email addresses is a white pattern, sure.

Re: Show HN: NBox – Sign up anywhere without giving your email address

#203
post #127

Earlier quoted context omitted.

Been there done that. If you catch all e-mail you will also get a lot of spam to random addresses like say sven@marak.com, lollerskates95@marak.com and so on and so forth. So then you need spam filtering anyway, or you need to configure which addresses are valid. I still host my own e-mail but I no longer do catch-all. There are only a few sites and services I care about. For those I have trusted them with my e-mail…

If you host your own domain you'll likely need spam filtering for abuse@ or at least postmaster@ (or ignore RFCs, like most unfortunately do..).

I forward abuse@, security@, postmaster@, hostmaster@, webmaster@, info@ and dns-admin@ for my main domain, and actually mostly don't get any spam to any of them except from dns-admin@, which I have listed as contact in WHOIS for some of my domains.

Re: Show HN: NBox – Sign up anywhere without giving your email address

#204
post #95

I've had a catch-all for *@mydomain.com forward to my primary email address for 10+ years. In that time I signed up for services and websites with [domain]@mydomain.com thinking I'd catch all those dirty scoundrels selling my email address and have an easy way to filter unwanted mail. But you know what really happened? I wound up with hard to remember email logins and caught less than a handful of services sharing my…

Fastmail has an elegant solution for this called subdomain addressing. For example, let's say your email address is joe@fastmail.com. You can use amazon@joe.fastmail.com or facebook@joe.fastmail.com, spotify@joe.fastmail.com, etc...

https://www.fastmail.com/help/receive/addressing.html

Re: Show HN: NBox – Sign up anywhere without giving your email address

#205
post #95

I've had a catch-all for *@mydomain.com forward to my primary email address for 10+ years. In that time I signed up for services and websites with [domain]@mydomain.com thinking I'd catch all those dirty scoundrels selling my email address and have an easy way to filter unwanted mail. But you know what really happened? I wound up with hard to remember email logins and caught less than a handful of services sharing my…

It's also a nightmare if/when you sell your domain, because you have to go clean up all those accounts. You can get one email forwarded by the new owner, but N is a no-go.

Re: Show HN: NBox – Sign up anywhere without giving your email address

#206
post #154

So what's it like when NBox goes under and you can't recover your password on any of your sites?

Hi midnitewarrior, here is a post where I try to answer that (valid) concern: https://www.producthunt.com/posts/nbox/comments/483328

Yes, that is your intention, but when funding gets pulled, investors rarely like spending more money on letting things "unwind", they have not company or brand to protect, so consumers' concerns take a back seat to investors.

The other problem with this is that there is now a middle man in my security chain. If you get hacked, potentially all of my accounts can be hacked. If you have a rogue employee, same thing. If you have a flaw in your security, I too am at risk from a centralized source.

Re: Show HN: NBox – Sign up anywhere without giving your email address

#207
post #95

I've had a catch-all for *@mydomain.com forward to my primary email address for 10+ years. In that time I signed up for services and websites with [domain]@mydomain.com thinking I'd catch all those dirty scoundrels selling my email address and have an easy way to filter unwanted mail. But you know what really happened? I wound up with hard to remember email logins and caught less than a handful of services sharing my…

It was worth it until large hack attacks which stole database of one of the mailing list company (forgot name) -- then spam started pouring on many-many legitimate addresses...

Only downside, is when company merges or renames: if it merged I end up with to accounts which have half of the history; if it renames -- hard to remember original email (recent example wayfair's old name was something else).

Now, I'm switching to single email -- it's just simpler

Re: Show HN: NBox – Sign up anywhere without giving your email address

#208
post #199

Earlier quoted context omitted.

Can you say something from the service perspective? Why shouldn't a service flag you as malicious and refuse users with email from your domain? What do you do to prevent mass account creation on the service? Thanks!

Hi ecesena, > Why shouldn't a service flag you as malicious and refuse users with email from your domain? Some services might block our addresses some day, but that would be a mistake because nBox is not a disposable email service. > What do you do to prevent mass account creation on the service? If your question is in regard to services which might block us, I don't think they care about mass account creation, a few…

Thanks! The non-disposable is a good point.

As for my 2nd question it was related. Often time spammers rely on tools like nbox to create a massive amount of accounts on services like Winterest, so Winterest has to flag your domain as potentially malicious.

I was wondering if you have any countermeasures to this problem, such as a rate limit on the number of accounts one can create per service. I'm sure Winterest would appreciate :)

Re: Show HN: NBox – Sign up anywhere without giving your email address

#209

A link to the chrome extension on the landing page would be quite useful (Otherwise visitors need to go to the chrome web store and search for it...and some of them are too lazy to do it). But otherwise I really like the idea. I'll give it a try ;) P.S. here's the link for the extension: https://chrome.google.com/webstore/detail/nbox-your-registra...

thanks ported it to Edge and Firefox https://github.com/Scrxtchy/nbox-everywhereElse

Hi tenryuu, you're right extensions can be ported more easily than before, thanks for your contribution!

The Firefox extension was following the validation process, it's now published: https://addons.mozilla.org/en-US/firefox/addon/nbox/

Re: Show HN: NBox – Sign up anywhere without giving your email address

#210
post #199

Earlier quoted context omitted.

Hi ecesena, > Why shouldn't a service flag you as malicious and refuse users with email from your domain? Some services might block our addresses some day, but that would be a mistake because nBox is not a disposable email service. > What do you do to prevent mass account creation on the service? If your question is in regard to services which might block us, I don't think they care about mass account creation, a few…

Thanks! The non-disposable is a good point. As for my 2nd question it was related. Often time spammers rely on tools like nbox to create a massive amount of accounts on services like Winterest, so Winterest has to flag your domain as potentially malicious. I was wondering if you have any countermeasures to this problem, such as a rate limit on the number of accounts one can create per service. I'm sure Winterest woul…

You mean fraudsters trying to take advantage of account creation on Winterest?

For a given service we authorize only one address, but we haven't implemented a rate-limit yet.

Post reply on HN