Live data from Hacker News

Browsing your website does not mean I want your spam

medium.com

41–50 of 251 posts

Re: Browsing your website does not mean I want your spam

#41
post #21

Earlier quoted context omitted.

This is really pushing the boundaries of the CAN-SPAM act. You're not allowed to send unsolicited emails. You shouldn't be allowed to pretend that visiting a site is a solicitation. Edit: I misunderstood the mechanism of collecting the addresses. This isn't skirting "unsolicited mail", but it is circumventing the ban on harvested email addresses.

> You're not allowed to send unsolicited emails. Actually, you ARE allowed to send unsolicited email, even commercial (UCE). It has to be clearly labeled, contain the postal address of the sender, and contain unsubscribe links. Also, CAN-SPAM only applies to senders in the U.S. (unfortunately). https://en.wikipedia.org/wiki/CAN-SPAM_Act_of_2003#Applicabi...

> CAN-SPAM only applies to senders in the U.S.

Given that SMTP is a relay system, would the first US-soil SMTP gateway machine a message travels through be its legal "sender" (in the way that e.g. the importer of a foreign medical device is liable if it's not FDA-approved)? One would think this would legally force those gateways, when handling foreign-originated spam, to slap their own address on them with their own unsubscribe link, that would—if clicked—then block those messages from coming through that gateway.

Re: Browsing your website does not mean I want your spam

#42
I feel less paranoid now for my browsing process. Almost everything I search is in an incognito window, from shopping and research to programming and how-tos. And when I'm done with looking for a new dog leash or Python module, I close that window. Only things in my main browser are the regular sites I visit and am logged into (email, HN, reddit etc.)

I started this after learning about the filter bubble but I've noticed how helpful it is when searching on Amazon, Wayfair, or Sears. I get non-machine-learned results every time while my wife using her primary browser with cookies often cannot see the same results I do. If I find something on Amazon, I copy-paste the URL without the ?query-string and replace 'www' with 'smile'. It seems like a hassle but it's no different from cleaning your feet before stepping inside the house after playing in the park.

This post just highlights that my practice to avoid unpermitted-profile-building-and-linking is for a good reason. I also have my own @example.com domain that I use and have certainly caught companies selling my info. However, even without being emailed, I don't want algorithms the determine what is best for me based on criteria I choose not to share.

Re: Browsing your website does not mean I want your spam

#43
This is why I have the username part of my email address tailored to each site/service I register with. So I have a hackernews@example.org, amazon@example.org, etc. Human beings get my real email though (because it would be weird if I told John Smith to email me at johnsmith@example.org). If people start abusing this (politicians do this a lot), I can just block say timkaine@example.org, and never hear from them or people they've sold and traded my email to.

Re: Browsing your website does not mean I want your spam

#44
post #21

Earlier quoted context omitted.

This is really pushing the boundaries of the CAN-SPAM act. You're not allowed to send unsolicited emails. You shouldn't be allowed to pretend that visiting a site is a solicitation. Edit: I misunderstood the mechanism of collecting the addresses. This isn't skirting "unsolicited mail", but it is circumventing the ban on harvested email addresses.

> You're not allowed to send unsolicited emails. Actually, you ARE allowed to send unsolicited email, even commercial (UCE). It has to be clearly labeled, contain the postal address of the sender, and contain unsubscribe links. Also, CAN-SPAM only applies to senders in the U.S. (unfortunately). https://en.wikipedia.org/wiki/CAN-SPAM_Act_of_2003#Applicabi...

It's pretty amazing the number of senders that do not obey the requirement for a minimal unsubscribe flow:

> Any opt-out mechanism you offer must be able to process opt-out requests for at least 30 days after you send your message. You must honor a recipient’s opt-out request within 10 business days. You can’t charge a fee, require the recipient to give you any personally identifying information beyond an email address, or make the recipient take any step other than sending a reply email or visiting a single page on an Internet website as a condition for honoring an opt-out request. Once people have told you they don’t want to receive more messages from you, you can’t sell or transfer their email addresses, even in the form of a mailing list.

To me it seems more of an honor-based system rather than one there's any enforcement for. Much like the Do Not Call list.

Re: Browsing your website does not mean I want your spam

#45
post #14

Earlier quoted context omitted.

Reporting it as spam impacts their entire operation. Disabling tracking only helps yourself.

But does it? No matter how many times I click "Report Spam" Google is not going to wholesale block LinkedIn's E-mail operation. At least those E-mails will start showing up in my own spam folder, but that's hardly affecting "their entire operation".

This is like refraining from voting in an election because "my vote won't matter." If enough people "Report Spam" then even LinkedIn's email operation will start to be impacted.

Re: Browsing your website does not mean I want your spam

#46
post #21

> This transaction breaks a core promise using the internet: just because I visit a website doesn’t mean I consent to getting spam from it. No it doesn't. There is no core privacy premise of the internet, and certainly not one that everybody used it signed up for. I'm not condoning this behavior, but we're in territory that we don't have prior art for. It used to be totally fine for one shopkeeper to mention to anoth…

This is really pushing the boundaries of the CAN-SPAM act. You're not allowed to send unsolicited emails. You shouldn't be allowed to pretend that visiting a site is a solicitation. Edit: I misunderstood the mechanism of collecting the addresses. This isn't skirting "unsolicited mail", but it is circumventing the ban on harvested email addresses.

>You're not allowed to send unsolicited emails.

Sorry, this is completely false information that is easily verifiable by looking at the wikipedia page for the can spam act: https://en.wikipedia.org/wiki/CAN-SPAM_Act_of_2003#Sending_b...

>But when sending unsolicited commercial emails, it must be stated that the email is an advertisement or a marketing solicitation.

Re: Browsing your website does not mean I want your spam

#47
post #21

> This transaction breaks a core promise using the internet: just because I visit a website doesn’t mean I consent to getting spam from it. No it doesn't. There is no core privacy premise of the internet, and certainly not one that everybody used it signed up for. I'm not condoning this behavior, but we're in territory that we don't have prior art for. It used to be totally fine for one shopkeeper to mention to anoth…

This is really pushing the boundaries of the CAN-SPAM act. You're not allowed to send unsolicited emails. You shouldn't be allowed to pretend that visiting a site is a solicitation. Edit: I misunderstood the mechanism of collecting the addresses. This isn't skirting "unsolicited mail", but it is circumventing the ban on harvested email addresses.

California and New Jersey have laws that go above and beyond the protections outlined in CAN-SPAM. I used to work for a company that sent spam (I swear, I didn't know until after I'd already accepted the job), and we avoided sending to those states. If more states would adopt laws like this, we could dramatically curtail spam.

As for what constitutes solicitation, I wish it was that simple. In some instances, companies will buy your email address from another company, and they believe that constitutes consent. In other words, you did business with Company Foo, and I did business with Company Foo, so you consented to do business with me. It's insane.

Having been inside one of these businesses, I have three pieces of advice.

First: Mark spam emails as spam when you see them. You only have to get a few of your messages marked as spam to get your IP address blacklisted. You have far more power over spammers than you think. Not only that, but spammers fear this so much that they keep databases of complainers, and they'll leave you alone in the future. Sometimes they'll even share lists of complainers with other companies so they won't risk your wrath.

Spam companies love non-complainers. Even if you don't open the spam, not complaining helps their numbers with the email provider. By not complaining, you're sending a signal to your email provider that this is a good email, and other users would like to receive it. Not only that, they'll remember you as a person who can be relied upon to not complain, so you'll get more spam than other people.

Second: Read EULAs. We did business with some super-shady companies who sold us tons of really invasive user info. One company even sold us the contents of people's email. Not just meta data, we could actually read the content. They don't mention any of this on their site, but it's subtly stated in the EULA. Read them and check for references to sharing your data with business partners.

I've steered clear of some browsers and email clients as a result of vague EULAs that leave the potential for harvesting my data and selling it.

Third: This one is going to be unpopular on Hackernews, but the best way to avoid being fingerprinted by advertisers is to block JavaScript by default. There are bajillions of ways to uniquely identify your computer, right down to having your browser report which fonts you have installed. Almost every single technique relies on Flash, Java, or JavaScript. Ad-blockers help, but they don't catch everything.

I use NoScript to turn off JavaScript by default, and I only enable a site if it seems legitimate and the site is broken without it.

Here's a terrifying list of the things advertisers can do to uniquely identify you without consent and without a cookie. As the article says, disabling JavaScript by default is by far the most effective method for protecting yourself from fingerprinting: https://wiki.mozilla.org/Fingerprinting

It's a little inconvenient, but good security always is. The locks on your front door are inconvenient (what if you lose your key?), but hopefully they're even more inconvenient for would-be intruders.

Re: Browsing your website does not mean I want your spam

#48

> This transaction breaks a core promise using the internet: just because I visit a website doesn’t mean I consent to getting spam from it. No it doesn't. There is no core privacy premise of the internet, and certainly not one that everybody used it signed up for. I'm not condoning this behavior, but we're in territory that we don't have prior art for. It used to be totally fine for one shopkeeper to mention to anoth…

> There is no core privacy premise of the internet, and certainly not one that everybody used it signed up for.

There is in Europe, in the Charter of Fundamental Rights of the European Union (basically the EU's Bill of Rights).

Re: Browsing your website does not mean I want your spam

#49
post #41

Earlier quoted context omitted.

> You're not allowed to send unsolicited emails. Actually, you ARE allowed to send unsolicited email, even commercial (UCE). It has to be clearly labeled, contain the postal address of the sender, and contain unsubscribe links. Also, CAN-SPAM only applies to senders in the U.S. (unfortunately). https://en.wikipedia.org/wiki/CAN-SPAM_Act_of_2003#Applicabi...

> CAN-SPAM only applies to senders in the U.S. Given that SMTP is a relay system, would the first US-soil SMTP gateway machine a message travels through be its legal "sender" (in the way that e.g. the importer of a foreign medical device is liable if it's not FDA-approved)? One would think this would legally force those gateways, when handling foreign-originated spam, to slap their own address on them with their own…

Mail is not actually sent over a series of SMTP relays, though. It's basically routed directly to the MX SMTP server for the domain.

Re: Browsing your website does not mean I want your spam

#50

Earlier quoted context omitted.

> You're not allowed to send unsolicited emails. Actually, you ARE allowed to send unsolicited email, even commercial (UCE). It has to be clearly labeled, contain the postal address of the sender, and contain unsubscribe links. Also, CAN-SPAM only applies to senders in the U.S. (unfortunately). https://en.wikipedia.org/wiki/CAN-SPAM_Act_of_2003#Applicabi...

It's pretty amazing the number of senders that do not obey the requirement for a minimal unsubscribe flow: > Any opt-out mechanism you offer must be able to process opt-out requests for at least 30 days after you send your message. You must honor a recipient’s opt-out request within 10 business days. You can’t charge a fee, require the recipient to give you any personally identifying information beyond an email addre…

There have been a handful of prosecutions, but not nearly enough.
Post reply on HN