Earlier quoted context omitted.
Why make hundreds of accounts?
To troll hundreds of different niche internet groups of course.
Yahoo Triples Estimate of Breached Accounts to 3B
71–80 of 311 posts
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#72Re: Yahoo Triples Estimate of Breached Accounts to 3B
#73Earlier quoted context omitted.
User accounts? Really? This is Yahoo we’re talking about. You really do need user accounts to run an email service
How much do you actually need to know about someone to serve up email to them?
(I’m expecting some idealized “solutions” from people with idealized beliefs about mass market tech skills.)
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#74Earlier quoted context omitted.
With gmail, you don't need it - foo+bar@gmail.com will end up as foo@gmail.com and you can filter by To: header.
I’ve run a fair amount of email campaigns where we strip out the + if gmail is the domain to ensure it doesn’t end up in some weird filter. Dick move, I know. Tell marketing that though. I personally use gmail through a vanity domain and have a catch all rule, so I end up signing up with a fake email account for every domain (hn@mydomain.com) and then the catch all forwards it to my real account (me@mydomain.com).
Which works, until the Gmail users who bother using + addresses with filters start giving all legitimate senders + addresses and sending everything thst doesn't have one and doesn't come from Google straight to deletion (possibly with a stop by “mark as spam” en route.)
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#75I think the issue right now is that private user information is viewed as an asset, not a liability. If we could find a way to make it more of a liability, companies would be less likely to collect it just for the sake of having it, and they would be more proactive in securing it.
Alternatively, if it's truly an asset, can it be taxed as an asset? If I give a company a car, that is taxed. If I give a company my data which is worth more than a car, it isn't. Is it possible that current accounting/tax law can be interpreted so that these are viewed similarly?
The more common data you give away is worth even less. Your "gift" is akin to giving away a few grains of sand to a glassmaker who provides a free grain counting service.
Now let's say you dumped a lot sand that we could value at $10K. Any smart sand-counting glassmaker will claim his once "free" sand counting costs $10K, which amounts to an equal, zero-profit trade.
[0]: http://www.bankrate.com/finance/credit/what-your-identity-is...
[1]: https://qz.com/460482/heres-what-your-stolen-identity-goes-f...
[2]: http://www.businessinsider.com/heres-how-much-your-personal-...
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#76Earlier quoted context omitted.
How much do you actually need to know about someone to serve up email to them?
For a consumer mail service, you to need to know enough to let them recover their account, possibly with decades of un-backed-up correspondence with and photos of since-deceased friends and relatives, when they’ve forgotten their password, and without letting someone else recover their account. This is a hard problem. (I’m expecting some idealized “solutions” from people with idealized beliefs about mass market tech…
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#77Re: Yahoo Triples Estimate of Breached Accounts to 3B
#78Earlier quoted context omitted.
I’ve run a fair amount of email campaigns where we strip out the + if gmail is the domain to ensure it doesn’t end up in some weird filter. Dick move, I know. Tell marketing that though. I personally use gmail through a vanity domain and have a catch all rule, so I end up signing up with a fake email account for every domain (hn@mydomain.com) and then the catch all forwards it to my real account (me@mydomain.com).
> I’ve run a fair amount of email campaigns where we strip out the + if gmail is the domain to ensure it doesn’t end up in some weird filter. Which works, until the Gmail users who bother using + addresses with filters start giving all legitimate senders + addresses and sending everything thst doesn't have one and doesn't come from Google straight to deletion (possibly with a stop by “mark as spam” en route.)
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#79Earlier quoted context omitted.
I’ve run a fair amount of email campaigns where we strip out the + if gmail is the domain to ensure it doesn’t end up in some weird filter. Dick move, I know. Tell marketing that though. I personally use gmail through a vanity domain and have a catch all rule, so I end up signing up with a fake email account for every domain (hn@mydomain.com) and then the catch all forwards it to my real account (me@mydomain.com).
> I’ve run a fair amount of email campaigns where we strip out the + if gmail is the domain to ensure it doesn’t end up in some weird filter. Which works, until the Gmail users who bother using + addresses with filters start giving all legitimate senders + addresses and sending everything thst doesn't have one and doesn't come from Google straight to deletion (possibly with a stop by “mark as spam” en route.)
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#80Earlier quoted context omitted.
> I’ve run a fair amount of email campaigns where we strip out the + if gmail is the domain to ensure it doesn’t end up in some weird filter. Which works, until the Gmail users who bother using + addresses with filters start giving all legitimate senders + addresses and sending everything thst doesn't have one and doesn't come from Google straight to deletion (possibly with a stop by “mark as spam” en route.)
The problem is not all legitimate sites/sources will actually accept '+' as a valid email character even though the RFC says it's a valid email character.