Live data from Hacker News

An Ode to Apple’s Hide My Email

empty.coffee

211–220 of 298 posts

Re: An Ode to Apple’s Hide My Email

#212
post #91

Earlier quoted context omitted.

Mozilla also has Firefox Relay: https://relay.firefox.com/ (Disclosure: I'm on the Relay team.)

I use mozmail and on the fly emails are great but so easy to exploit and spam. For example, my custom domain is foo.mozmail.com. I enter my on the fly email address bar@foo.mozmail.com on attackers website. Voila. Now they know my custom domain name "foo" and can use it to send email to all possible on the fly addresses. e.g. 1@foo.mozmail.com 2@foo.mozmail.com so on and so forth. Now my custom domain name as a whole…

You don't have to use the custom @domain.mozmail.com address with Firefox Relay—you can use @mozmail.com with one of the auto-generated random aliases.

Your complaint is similar to using RFC 822 "me+site.com@domain.com" style emails and then worrying that sites are going to learn that your real email is "me@domain.com" by stripping off the part after the plus sign. Call me optimistic or naive, but I don't think that sites are doing that...

https://people.cs.rutgers.edu/~watrous/plus-signs-in-email-a...

Re: An Ode to Apple’s Hide My Email

#213
post #83

Earlier quoted context omitted.

The problem with self hosted email is that your domain becomes a unique (or near-unique with a few domains) tracking reference.

Only if the entity on the other end understands this though, right? Which they probably don’t. Otherwise everyone @example.com is the same person.

It's worth a lot of money for the ad-tech (consumer tracking) industry to understand.

If a domain only occurs once in a user database, it's likely to be a personal domain. A data broker that sees the same domain in a few different datasets (once in each) can be quite confident that the domain is an individual's.

Re: An Ode to Apple’s Hide My Email

#214
post #198
post #116

Earlier quoted context omitted.

I would take the bet in this case without hesitation. Apple is too big and has too many potential internal whistle blowers to run a clandestine email monitoring operation.

>Apple is too big and has too many potential internal whistle blowers to run a clandestine email monitoring operation. This calls for an interrobang. APPLE?‽! This is an absurd reversal of the burden of proof - where I think you go very wrong is to imply or assume the natural state of a large organization is compliance with legal or ethical norms. There's a reason they have legal and compliance departments! There's a…

Excellent rebuttal and good links.

But they are both for one-offs - single events or single rogue employees. One offs always happen. Systematic, Enron-style ingrained fraud is quite another.

The idea that Apple is systematically reading people's emails - with all the multitude of supporting rogues employees, right down to SREs to keep things running that would need to be in on the act - is absurd, truly a ticket on the consipiracy theory train.

Re: An Ode to Apple’s Hide My Email

#215

Hang on, though: doesn't this essentially hand Apple a big list of which domains you communicate with and how frequently? There's also nothing stopping them reading the emails on the way through. I know a lot of people trust Apple more than Google, but you're essentially signing up for a vendor-locked product that you're hoping Apple will continue to support, with no guarantee they won't collect - even at an aggregat…

There is no lock in - you can login to "whatever app" and update your email to a new one anytime you like. It's just an email address in the end. Also, unless you're encrypting your emails, can't everyone read your emails "on the way though" anyway?

With google, even if you’re encrypting. Gmail, even in the shiny incarnation, only supports server-hosted private keys. A private key that you must give to your service provider is about as useful as a chocolate teapot, imho.

Re: An Ode to Apple’s Hide My Email

#216
post #58

Earlier quoted context omitted.

I'm doing the exact same thing. Built a small web app that lets me manage all my email aliases for the domain. Unfortunately there are a couple of websites that do only allow a select list of whitelisted domains meaning I cannot use my own, but for the other 99% it works wonders. I wish I had had this idea ten years ago, it would have saved me so many headaches.

Who whitelists email domains? Do they explain why?

The most recent incident I remember was with a debrid service. I opened a ticket with their support and was told that the point of the policy was to combat abuse of their service. Not entirely sure why a paid service that accepts cryptocurrencies would care about email addresses.

Re: An Ode to Apple’s Hide My Email

#217

Earlier quoted context omitted.

Nice! I do something similar, but using an automatic aliasing scheme so that I don't have to manually configure an email address for each service and other users can use this without me knowing their aliases. In my setup, aliases can contain wildcards, represented as percent signs. If an alias phil.%@domain1.com is set up, all your examples will be sent to the respective aliased address. I use Postfix Admin with a My…

Why not just use phil+craigslist@gmail.com or phil+kmart@gmail.com? same effect and lands in the same phil@gmail.com address

How do you mean? This is exactly what I can do with my setup. If you are referring to the use of Gmail: I prefer to run my own infrastructure as long as this is possible.

Re: An Ode to Apple’s Hide My Email

#218
post #81

Earlier quoted context omitted.

I've been thinking of a new way to use my email... - Only use one email address: hi@example.com - Always add a filter: hi+hn@example.com - Send all emails without a filter to SPAM Since it's not a common strategy, it is much more likely that spammers remove the +hn before sending an email than add one.

would not recommend not only can you not sign up to many services, customer support can often get confused when you need to email reply to them and you cannot email from your aliased email. they see you as a separate user not in their system, or the wrong person replied to the support ticket, etc.

But why would you not be able to reply with the aliased email? I do this regularly. Of course your mail client needs to support this, but using Mutt this is absolutely no problem (just change the FROM header) and I have heard from other users who use Thunderbird that they can also create new identities (just not as easy on the fly). In fact I wrote a small script for Mutt that would automatically set the correct sender if I reply to an email that contained a wildcard. Works pretty well.

Re: An Ode to Apple’s Hide My Email

#219
post #214
post #198

Earlier quoted context omitted.

>Apple is too big and has too many potential internal whistle blowers to run a clandestine email monitoring operation. This calls for an interrobang. APPLE?‽! This is an absurd reversal of the burden of proof - where I think you go very wrong is to imply or assume the natural state of a large organization is compliance with legal or ethical norms. There's a reason they have legal and compliance departments! There's a…

Excellent rebuttal and good links. But they are both for one-offs - single events or single rogue employees. One offs always happen. Systematic, Enron-style ingrained fraud is quite another. The idea that Apple is systematically reading people's emails - with all the multitude of supporting rogues employees, right down to SREs to keep things running that would need to be in on the act - is absurd, truly a ticket on t…

>One offs always happen. Systematic, Enron-style ingrained fraud is quite another.

The fines for wage fixing totaled over $400 million, and although I realize that was collective and not only Apple, how can you possibly say it's not systematic Enron-style ingrained fraud? It wasn't $400 million stolen from one employee! There were all those other companies involved too!

As I see it, it's arguably not Enron-style only because the company didn't collapse as a consequence.

But that makes it more like compromised emails, not less! The more remote serious punishment is for something, the more likely the thing is.

Is it plausible that the worst possible breach of privacy would lead to Apple going under? I think not.

I also think you're arbitrarily excluding the possibility of anything between an all-encompassing plan and a "rogue employee". Pretty much everything that happens falls in between! Many things that are hardly planned at all happen anyway!

A thing that was in the news recently, that did not relate to Apple, was that thousands of PwC (Canada) employees were sharing answers to internal training.

The auditors were cheating on the exams that were supposed to test auditing ethics and skills! Clearly everybody was not aware this was going on, but also clearly it was not an isolated rogue employee!

Management apparently said "whoops, we'll add controls to prevent this" and got assessed a not-very-huge fine.

Which seems to evade the question and problem of how they hired so many people with no ethics to watch over the proverbial henhouses of other companies!

If you've worked for any large organization, you've seen how they declare they adhere to the dogma of finding the root cause of a failure and preventing it going forward. And yet, how often do you see people fix the exact thing that failed a test and blatantly ignore the wider implications?

It seems kind of frightening that the PCAOB (I think) doesn't really seem to see an issue with a slap on the wrist and a promise to do better being the penalty.

Re: An Ode to Apple’s Hide My Email

#220

I have a unique email address for every single service that I sign up for, similar to this, though selfhosted. I've been doing this for years and it works wonderfully. If someone misuses my email address, or gets annoying, I can simply turn off the address. Bam! It's the easiest Postfix config in the universe, essentially just: virtual_alias_domains = domain1.com domain2.com virtual_alias_maps = hash:/etc/postfix/vir…

I do the same thing, but instead of rolling my own UI, I use ViMbAdmin [1] (listening on my VPN). It's a great tool for managing aliases.

[1]: https://www.vimbadmin.net/

Post reply on HN