Live data from Hacker News

Using a catch-all domain is a mistake

notcheckmark.com

201–210 of 304 posts

Re: Using a catch-all domain is a mistake

#201
post #120

I'm using catch all since forever. I regret nothing. Two stories: I don't use mails like facebook@domain uber@domain - that's too obvious. And knowing that may often disclose that I actually have an account registered on given page. I don't want that, so I go full random, using few words I have in mind, current few words from the song I'm listening too, etc. So password manager helps me with e-mails too. But Sometime…

Another no regrets catch-all user. Looking into my rules, I have 4 "to" addresses that get sent to spam.

Two stories as well:

a) After contacting a company, I got a mail from their legal department asking me to explain why I’m using their trademarked name in my email

b) Using an online-shop that requires emailing the owner for your order (so he can send you a PayPal invoice and then snail-mail you the music CDs you ordered…) I got a personal message attached of him asking why his label’s name is in my email address.

In both cases, a short explanation was sufficient, though.

Re: Using a catch-all domain is a mistake

#202

Earlier quoted context omitted.

> I don't really know exactly, but she told me something about me using their stuff without their acceptance, when I tried to explain that's my own domain she told me I cannot use their name, because that's a copyright infringement. Weird. I can't tell you how many non-techy people think I'm part of their company because I have yourcompany@mydomain. Sigh. Big companies have ruined the internet by having everyone have…

The "best" is when you can't even sign up without having an account at a Large Company e.g. gmail or outlook. I'm not sure what that's supposed to prevent issues with. Sure, you can add "+thing" after the username portion, but those that know this bog standard trick can still automatically derive your email address and get around your filters. At least with a dedicated username portion a human has to think for a seco…

Which companies are those? Is there a list somewhere? The only time I ever encountered this was with AliExpress.

Re: Using a catch-all domain is a mistake

#203

Earlier quoted context omitted.

I have been using a catchall domain since 2004 and it has been a lifesaver. The sad part is when your email leaks from big companies, you definitely know. I started getting viagra spam delivered to equifax@mydomain.com back in 2007, long before their "big data breach", so it was only a matter of time before that companies pattern of poor security caught up with them. Email should have always been a bidirectional addr…

>Email should have always been a bidirectional address, representing the relationship between the sender and receiver, and not a wide open receiver for anybody who happens to have your address. Ideally, this would also be the case for physical mail. Multiple revokable tokens, not publicly tied to your physical address.

Not having your mailing address tied to your physical address would also have major benefits when people move. Simply update your address with the post office and you're done.

The whole idea of revokable tokens would pose an issue for any company that sends bills, as I assume revoking address tokens would be common with them. I'm sure there are many situations like this.

Re: Using a catch-all domain is a mistake

#204
post #156

Earlier quoted context omitted.

I have been using a catchall domain since 2004 and it has been a lifesaver. The sad part is when your email leaks from big companies, you definitely know. I started getting viagra spam delivered to equifax@mydomain.com back in 2007, long before their "big data breach", so it was only a matter of time before that companies pattern of poor security caught up with them. Email should have always been a bidirectional addr…

> Email should have always been a bidirectional address, representing the relationship between the sender and receiver, and not a wide open receiver for anybody who happens to have your address. That does seem beneficial for the most part, but do you have ideas about how to handle the use cases like establishing new relationships (what, if anything, do you put on business cards?) or allowing the general public or a b…

I think it's simply a hybrid approach: you'd handle those unknown contacts with many:1 addresses (since there's no real alternative, as you imply), and you'd handle most known contacts with 1:1 addresses.

A benefit is that you might let messages to some or all of those 1:1 addresses be sorted one way (e.g., they ping you) while messages to some or all of the many:1 addresses are sorted another way (e.g., you only check for them with a much longer interval). But then again, a diligently-maintained contact list can be leveraged to achieve same...

Re: Using a catch-all domain is a mistake

#205
post #120

I'm using catch all since forever. I regret nothing. Two stories: I don't use mails like facebook@domain uber@domain - that's too obvious. And knowing that may often disclose that I actually have an account registered on given page. I don't want that, so I go full random, using few words I have in mind, current few words from the song I'm listening too, etc. So password manager helps me with e-mails too. But Sometime…

That dude missed the biggest benefit

When someone tries to call into a provider and impersonate you, to take over your account… they would fail because they don’t know your login even!

Whereas, for most people, they’d sweet talk the person on the other line into resetting the password. Happened to me with GoDaddy, they almost rerouted my @mydomain.com email and then it would have been really bad

Re: Using a catch-all domain is a mistake

#206

Title says that using a catch all domain (whatever that is) is a mistake, but the bulk of the article about it being a mistake to use the other party's company name as the local part of a throwaway e-mail address which you use for communicating with that party. There is nothing about the catch all aspect being a mistake. You don't have to give a Hilton hotel an address like hilton@example.com; it could be bob-2022-05…

iCloud+ has something like this as well. So far I've only used it with Sign In with Apple, or whatever it's called. Your comment led me to go check out the iOS Settings and it looks one-off random emails aliases can be made in there.

Of course at this point my email is so many places it almost seems like a lost cause. What I wouldn't give to have a reset button for the entire internet. I would be much more careful with my address than I was 20 years ago.

Re: Using a catch-all domain is a mistake

#207
post #156

Earlier quoted context omitted.

I have been using a catchall domain since 2004 and it has been a lifesaver. The sad part is when your email leaks from big companies, you definitely know. I started getting viagra spam delivered to equifax@mydomain.com back in 2007, long before their "big data breach", so it was only a matter of time before that companies pattern of poor security caught up with them. Email should have always been a bidirectional addr…

> Email should have always been a bidirectional address, representing the relationship between the sender and receiver, and not a wide open receiver for anybody who happens to have your address. That does seem beneficial for the most part, but do you have ideas about how to handle the use cases like establishing new relationships (what, if anything, do you put on business cards?) or allowing the general public or a b…

Actually, centralized databases like DNS are a symptom of a larger problem: society is so used to the idea that you can centralize power, votes, money etc. in one place. It is why we have celebrities and state governments, and privately owned social networks. It is also why smart contracts are still based around blockchains and they allow weird things like flash loans, because only one transactiom can run at a time for the whole world.

So the problem is that bill.gates@gmail.com or bill@microsoft.com is accessible to anyone who can use the SMTP protocol. And a phone number is accessible to anyone who texts it. That’s crazy.

Instead, we shouldn’t have DNS or centralized domains at all. DNS is just a glorified search engine that only really helps you find the root resource at a site, the /index.html thing. The vast majority of URLs on the Web aren’t going to be verbally shared anyway so you may as well store them as non-human-readable strings and let people save some local or hosted index. The titles and other metadata can be taken just like google does.

In this case, sending an email would require the recipient to have given out a capability that was received by you. And if some capability was compromised, they’d just deactivate it. It’s like this dude’s email aliases, but far better

Re: Using a catch-all domain is a mistake

#208
I've been using a catchall domain for 25+ years. Caught some companies leaking or selling my email addresses, too (the one I was most irritated with was Godaddy).

Including the company's name in the salted address is usually confusing to support staff, so I just use its initials or something memorable. Some places also seem to have dirty and suspicious word filters (for instance, mail to my child's school will just silently get dropped because of my domain name, and I have to use a gmail account instead).

Re: Using a catch-all domain is a mistake

#209

Earlier quoted context omitted.

The "best" is when you can't even sign up without having an account at a Large Company e.g. gmail or outlook. I'm not sure what that's supposed to prevent issues with. Sure, you can add "+thing" after the username portion, but those that know this bog standard trick can still automatically derive your email address and get around your filters. At least with a dedicated username portion a human has to think for a seco…

Which companies are those? Is there a list somewhere? The only time I ever encountered this was with AliExpress.

Did that change? My AliExpress account is using myname@mydomain.co.uk

Re: Using a catch-all domain is a mistake

#210

Title says that using a catch all domain (whatever that is) is a mistake, but the bulk of the article about it being a mistake to use the other party's company name as the local part of a throwaway e-mail address which you use for communicating with that party. There is nothing about the catch all aspect being a mistake. You don't have to give a Hilton hotel an address like hilton@example.com; it could be bob-2022-05…

Tamarind is found here: https://www.kylheku.com/cgit/tamarind/tree

It's a CGI application used with Apache.

That code you see there does evrerything, using the raw HTTPS stream and environment variables from the server. There are no libraries, no web framework, nothing.

- cookie handling / session persistence

- generating HTML responding to requests

- reading/writing e-mail aliases file

- authenticating via IMAP or SASL

Post reply on HN