Live data from Hacker News

Unroll.me

daringfireball.net

31–40 of 55 posts

Re: Unroll.me

#31

Earlier quoted context omitted.

> signing up meant compromising your personal emails Assuming someone only signed up with their personal address. Curious how many .gov email addresses are in their database...

It only works with major emails services like Gmail, Yahoo, etc, I believe.

Plenty of agencies on services like Google Apps for Government.

Re: Unroll.me

#32
post #18

> operating under the radar The privacy policy is clear and easy to find and understand. You can be annoyed with yourself for not reading it. You can decide the service isn't worth the tradeoffs. You can be annoyed with yourself for being naive about how free products work. But it's illogical and disingenuous to call this "under the radar" or blame the service for your own surprise about how it works. We have free wi…

We've all agreed to things we didn't expect, because none of us are willing to invest thousands of dollars worth of our time to check the side effects of trivial transactions. Instead we make the rational decision to trust our counterparties and to hope they don't disappoint us too often.

This situation sucks, and is a new problem, which deserves a solution. Contracts have always existed, but bespoke contracts for each minor transaction are a new development.

Long-term, we have two choices. The first is that industry devises reasonable standards that simplify the process for end-users. The second is that government will devise standards and impose restrictions on us. I suggest we acknowledge the issue and work on a solution, instead of just insulting those who correctly identify the problem.

Re: Unroll.me

#33
Great, I'm sold on leaving unroll.me but I think there is a deeper problem here. Email is so insecure and if you're already using Gmail then who knows who Google is selling your emails to. Google is just a lot better about keeping it a secret. Fooling yourself into thinking your emails are secure if you're not using Unroll.me is a joke. Also, please suggest a secure alternative when telling people to leave a service over security. I'd love to switch to something else that gives me some false sense of security but shutting off unroll.me and allowing my inbox to implode with spam is not a great option right now.

Re: Unroll.me

#34
post #16

I prodded unroll.me a couple of years ago about their data retention policy. Their answer was sketchy so I ended up not using the service. I'm surprised it took this long for someone with reach to look into them. Original thread: https://twitter.com/elahd/status/575692415132135425 DMs: http://imgur.com/H0UABYa

I have tried the service, and my interactions with it have confirmed all perceived sketchiness:

In a moment of desperation, I signed up for this a while back. I found it not to be useful and tried to remove my account with the site, which turns out to be essentially impossible.

I ended up revoking access to my email account and continued to receive emails from unroll.me that the service "has lost its connection to your account," which I found hilarious, because in my desperate attempt to get rid of spam, I created more.

I've tried to unsubscribe from these unroll.me emails several times before, and the unsubscribe link takes me to a page containing all the subscriptions that the service once found on my account (the one you'd see if you were trying to use the service---so all that data is still there, for sure, and it has been many months), and I have never actually been unsubscribed.

Re: Unroll.me

#35
post #5

Basically a repost of https://news.ycombinator.com/item?id=14180463 Had to search my inbox as a sanity check to make sure I hadn't signed up for the service. Turns out I hadn't, but it was pitched on Product Hunt both in April 2015 and May 2016. I'm hoping at least security folks made the mental connection that signing up meant compromising your personal emails. That's the single reason I didn't bother.

> Had to search my inbox as a sanity check to make sure I hadn't signed up for the service. Wouldn't you remember granting a third party full access to your email inbox? That doesn't seem like a trivial decision to make.

For someone who grew up before webmail existed, and where mail apps were a local thing, it's really easy to forget that granting a third-party app access to your e-mail often grants that access to a third-party company these days.

It wasn't that long ago that the worst thing that would happen with a third-party mail client was that it would suck and you'd have to stop using it.

Re: Unroll.me

#36
post #16

I prodded unroll.me a couple of years ago about their data retention policy. Their answer was sketchy so I ended up not using the service. I'm surprised it took this long for someone with reach to look into them. Original thread: https://twitter.com/elahd/status/575692415132135425 DMs: http://imgur.com/H0UABYa

I have tried the service, and my interactions with it have confirmed all perceived sketchiness: In a moment of desperation, I signed up for this a while back. I found it not to be useful and tried to remove my account with the site, which turns out to be essentially impossible. I ended up revoking access to my email account and continued to receive emails from unroll.me that the service "has lost its connection to yo…

...and they still have all of your emails! You can't take back the emails they've already archived, which (presumably) is everything that was in your inbox before you disconnected your Gmail account.

Re: Unroll.me

#38

This may sound silly, but I consider any application that requests full read access to my Gmail account to be akin to asking for my social security number. I remember when the big wave of smart email apps first came out a few years ago, and the horror was the expressed here when it was revealed that these apps basically route all of your email through their servers in order to do processing on it. Sadly at lot of the…

"This may sound silly, but I consider any application that requests full read access to my Gmail account to be akin to asking for my social security number."

Have you ever emailed your social security number, had your social security number emailed to you, or signed up for any sort of service to your gmail account including your paycheck management company, your tax returns, your bank, or anything else that via email password reset could be used to access your social security number?

Certainly I'd go so far as to say that almost anybody's "real" gmail account could certainly be leveraged to get the last four digits of your social security number. Given the low entropy of the other 5 numbers given other details [1], even if you can say with a straight face that your email has never had your very, very regex-able social security number in it, it's still got most of the bits, most likely. Perhaps not enough to automatically target you without a bit more machine learning than I think we quite have at the moment, but... getting perilously close, honestly. Someone who really dedicated themselves to taking "gmail inboxes" and writing a system to determine social security numbers from that could probably do pretty well. It wouldn't quite be just "fire some machine learning at it", but the system as a whole seems pretty feasible to me.

[1]: http://www.stevemorse.org/ssn/ssn.html . It isn't quite as bad as it seems for many of us, because we didn't all used to get SS numbers at birth, so my SS number does not correspond to my birth. But if you have my last 4 numbers and a handful of other bits of information about where I've lived, it's distressingly few bits between me and my identity getting stolen.

Re: Unroll.me

#39
post #38

This may sound silly, but I consider any application that requests full read access to my Gmail account to be akin to asking for my social security number. I remember when the big wave of smart email apps first came out a few years ago, and the horror was the expressed here when it was revealed that these apps basically route all of your email through their servers in order to do processing on it. Sadly at lot of the…

"This may sound silly, but I consider any application that requests full read access to my Gmail account to be akin to asking for my social security number." Have you ever emailed your social security number, had your social security number emailed to you, or signed up for any sort of service to your gmail account including your paycheck management company, your tax returns, your bank, or anything else that via email…

Oh, I would not be surprised if my SSN is floating somewhere out there because of something like this. So that's a good point. I was more making the comparison because I was looking for an analogy to something most people at least try to guard heavily.

Re: Unroll.me

#40
post #25
post #18

> operating under the radar The privacy policy is clear and easy to find and understand. You can be annoyed with yourself for not reading it. You can decide the service isn't worth the tradeoffs. You can be annoyed with yourself for being naive about how free products work. But it's illogical and disingenuous to call this "under the radar" or blame the service for your own surprise about how it works. We have free wi…

> You can be annoyed with yourself for not reading it. Do how do you spend reading every click-wrap agreement you accept? We condition users not to read these things, so we can't be surprised when they don't read them.

> Do how do you spend reading every click-wrap agreement you accept?

No, but I don't complain about the consequences. If I agreed to terms that gave my house to unroll.me, they'd never be able to enforce it because it's egregiously inappropriate. I take that much for granted. The actual unroll.me terms are not egregiously inappropriate. They may be distasteful to most people here, but it's not offensive or inappropriate that the terms are allowed to exist.

Post reply on HN