Live data from Hacker News

Don't verify email addresses by sending spam to them

milek7.pl

51–60 of 67 posts

Re: Don't verify email addresses by sending spam to them

#51
post #38
post #23

Earlier quoted context omitted.

That'd be nice, but I'd even settle for the plain pdf attached to the email.

Unencrypted sensitive data in an email is a really bad idea. I hope they never do that. Although what I would really like, and think is long overdue, is an extension to email that normalises encryption and sender verification. It's ridiculous that email can be spoofed like that. (The same is even more true for phone numbers.)

Indeed. We really either need email to get decent, user-friendly encryption and verification, or replace email with a new, ubiquitous, decentralized, system that has first class support for encryption.

I have a laundry list of other issues I'd like fixed in email, but I'd be happy just to get end to end encryption and sender verification.

Re: Don't verify email addresses by sending spam to them

#52
post #42

Earlier quoted context omitted.

To me, paperless means they ATTACH MY STATEMENT TO THE EMAIL. Not signing up to any paperless until they do, none yet have met this bar. The statement is supposed to be a snapshot of the status of the account at a given moment, if you have to open their website to view it they could regenerate it from whatever crap data they have lying around at the given moment. If it can change every time you look at it, it's a qua…

Many places don't attach the statement because it has sensitive information. Add that with "email is not secure" which we've been yelling for years (well, me since 1996). Sending it via email is risk exposure for them.

It is long since time we made email secure. Or replaced it with something else that would allow us to send messages to people securely (in a decentralized way).

Having to log in to a half-maintained, slow web portal with terrible UI that is down 25% of the time is a really terrible way to get your sensitive and often important documents.

Re: Don't verify email addresses by sending spam to them

#53

Hey! Founder of Pangram here. We use Zerobounce and CustomerIO for email validation. I had no idea this was happening. Not entirely sure which one this is coming from, but this is not intentional on our part. Will dig deeper and eliminate the part of the stack that is sending spam — definitely not good that this is happening.

I'm reading the ZeroBounce docs and it seems very relevant. Look at this step:

"We recheck all unknown emails using IPs from different geographical locations". This matches exactly what this article describes as getting these emails from a range of locations.

The step before that is just "Proprietary Technology", which sounds like a good cover for what's going on here. How else are you testing an email address after between "real time SMTP server check"?

Re: Don't verify email addresses by sending spam to them

#55
post #23

Earlier quoted context omitted.

That'd be nice, but I'd even settle for the plain pdf attached to the email.

For things like financial records, I would not want plain PDF in the email. I think it needs encryption for confidentiality. I am geeky enough to use PGP or S/MIME if they had the option, but I can definitely see how vendors would see this as too fringe with retail customers. I would not like the typical "secure email" which is nothing more than a volatile link back into yet another website.

I get that, but I don't care.

I want the PDF (or CSV) emailed to me as an attachment because that's the workflow that doesn't suck.

Everything else sucks in one way or another, and much of it is security theater.

Re: Don't verify email addresses by sending spam to them

#56
post #46

Earlier quoted context omitted.

Is it really? Who can read it today? Your email provider and theirs? Gmail won't deliver messages without TLS any more, so everyone supports it or they're effectively kicked out of email.

TLS just encrypts the IMAP / SMTP sessions, no guarantee it’s stored encrypted, let alone end to end

You didn't answer this question:

> Who can read it today?

Re: Don't verify email addresses by sending spam to them

#57
a botnet is not spam, garbage text is not spam, spam is defined primary by being unsolicited AND unwanted. This is solicited.

Don't confuse the map for the territory. What we see here is a so called "expert" in anti-spam technology completely losing site of the goal and complaining that world should conform to their system. This is learned helplessness masquerading as expertise.

Re: Don't verify email addresses by sending spam to them

#58
post #46

Earlier quoted context omitted.

TLS just encrypts the IMAP / SMTP sessions, no guarantee it’s stored encrypted, let alone end to end

You didn't answer this question: > Who can read it today?

Well, the email providers. And that could easily include Google without you even realising.

It's true that email isn't quite as insecure as it used to be (it was once compared to shouting your message at someone and expecting them to shout it in the right direction until it reached the intended recipient), but there are still many things missing compared to other forms of direct messaging, and there's good reason why many people and organisations don't want it used to send sensitive information.

Re: Don't verify email addresses by sending spam to them

#59
post #52
post #42

Earlier quoted context omitted.

Many places don't attach the statement because it has sensitive information. Add that with "email is not secure" which we've been yelling for years (well, me since 1996). Sending it via email is risk exposure for them.

It is long since time we made email secure. Or replaced it with something else that would allow us to send messages to people securely (in a decentralized way). Having to log in to a half-maintained, slow web portal with terrible UI that is down 25% of the time is a really terrible way to get your sensitive and often important documents.

email can be read by any server in the chain between the sender & recipient. It's not secure. PGP doesn't fully fix this, it still leaks message content (subject) and metadata. So does S/MIME. That doesn't mean attachments are leaked, but it does mean email isn't compliant with any of the standards which require communicating securely.

Re: Don't verify email addresses by sending spam to them

#60
post #52

Earlier quoted context omitted.

It is long since time we made email secure. Or replaced it with something else that would allow us to send messages to people securely (in a decentralized way). Having to log in to a half-maintained, slow web portal with terrible UI that is down 25% of the time is a really terrible way to get your sensitive and often important documents.

email can be read by any server in the chain between the sender & recipient. It's not secure. PGP doesn't fully fix this, it still leaks message content (subject) and metadata. So does S/MIME. That doesn't mean attachments are leaked, but it does mean email isn't compliant with any of the standards which require communicating securely.

Right. I'm saying this state of affairs is unacceptable for the dominant digital messaging system in 2026.
Post reply on HN