Live data from Hacker News

Show HN: NBox – Sign up anywhere without giving your email address

nbox.notif.me

211–212 of 212 posts

Re: Show HN: NBox – Sign up anywhere without giving your email address

#211

Earlier quoted context omitted.

That seems like a white pattern to me.

If only delivering mail to existing email addresses is a white pattern, sure.

I don't follow.

If I configure me.example.com to accept emails matching the pattern "memail42@me.example.com", then I can generate as many on-the-fly unique emails as I want, without maintaining any lists, and without catch-all forwarding of random spam to my inbox.

If I use me+anything@me.example.com, I get the same exact feature, but the downside is "+anything" is recognized by some and either disallowed or used to generate more patterns.

If I use subdomains (like anything@me.example.com) I have the spam issue.

With a white pattern scheme, you can choose your own pattern (so sites can't really catch on), not have to maintain any lists, and avoid spray-and-pray spam.

Re: Show HN: NBox – Sign up anywhere without giving your email address

#212
post #210

Earlier quoted context omitted.

Thanks! The non-disposable is a good point. As for my 2nd question it was related. Often time spammers rely on tools like nbox to create a massive amount of accounts on services like Winterest, so Winterest has to flag your domain as potentially malicious. I was wondering if you have any countermeasures to this problem, such as a rate limit on the number of accounts one can create per service. I'm sure Winterest woul…

You mean fraudsters trying to take advantage of account creation on Winterest? For a given service we authorize only one address, but we haven't implemented a rate-limit yet.

Yes exactly, fraudsters exploiting your service to have as many email as they need to create very many accounts on Winterest.

If you have 1 single email account per service that is fine.

I think you should call out these two aspects on your site, to show that you're increasing privacy for users, but also protecting services from being abused exploiting nbox. It should reduce the likelihood to be blacklisted.

Post reply on HN