Live data from Hacker News

Become unbannable from your email

karboosx.net

81–90 of 204 posts

Re: Become unbannable from your email

#81

Anyone wanna share their email strategy? I'm thinking of going for the following but I'm still undecided: 1. 1 custom domain ( .com): this will be used for friends, family and any online accounts that know me IRL. Use Fastmail masked addresses with my custom domain where it makes sense like an online account for amazon. 2. 1 custom domain ( .xyz): this will be used for a blog, professional IRL interviews, corresponde…

I just use a Fastmail address for my resume and such. I dont want to use my personal domain because while not offensive it sounds a bit silly.

Re: Become unbannable from your email

#83

"How to become unbannable" Step 1 : go with the one company that's known worldwide for abusive & permanent bans with no recourse. This post is a bit too generic, but it's true that using your own domain for mailing is the best solution to avoid getting locked out. Although you need to pick a good registrar, too...

well your recourse is repointing the domain

It's worth pointing out just in case someone might forget/not think of it... Don't register your domain or DNS with Google Domains / GCP if you host your email with Google Workspace... since if you get locked out of the Google account you could be unable to update your DNS.

The saddest thing though is that in some ways Gmail is harder to hack into than some registrars. I remember a postmortem write-up from a guy who had his personal domain easily hijacked by social engineering someone at the domain registrar, which then served as the foothold of a larger identity theft attack against him. Google, by virtue of simply not even doing customer service, is much harder to social engineer, so the author of that piece pointed out that ironically if he'd put more of his eggs in the GOOG basket, he'd have been safer.

Re: Become unbannable from your email

#84
post #37

Been doing this for years, and surprised he didn't seem to mention the other benefit: "infinity" email addresses. Oh, rando burger spot wants an email for some free fries? Great, hit me up at randoburgerspot@"mydomain".com .

Gmail has a limited version of this. It leaks your real address, but it makes filtering easy.

+@gmail.com

steve+randoburger@gmail.com

Re: Become unbannable from your email

#85
post #76

Earlier quoted context omitted.

1) what does it mean for an email *address* to be cryptographically strong? 2) in case of hard to remember address, what do you do if asked to write it down with no access to your records? (It happened to me once before)

> what does it mean for an email address* to be cryptographically strong?* Something someone couldn’t guess, like: @domain.com c4694056-63dd-476f-9823-2548aa3d754a@domain.com > in case of hard to remember address, what do you do if asked to write it down with no access to your records? It’s a tradeoff. You’d probably want to use the cryptographically secure addresses sparingly. Another option would be to use your pas…

Why are we doing this exactly?

Re: Become unbannable from your email

#86
post #10

Over the past few weeks I've been systematically migrating every one of my accounts to a domain under my control. During the process I've been marking them in a spreadsheet with their 2FA status (no 2FA, TOTP, security key, etc.) and adding their passwords to a password manager. This is all in case I ever need to go through the migration process again for whatever reason, or if I lose/break a Yubikey, I will know wha…

Two factor tokens that can't be backed-up create stupid make-work.

Wouldn't it be great if Yubico let you back-up and restore a Yubikey?

It's maddening that they haven't come up with a reasonable way to allow a purchaser to register multiple Yubikeys to enable freely restoring backups between them. (Think of if analogously to buying multiple padlocks keyed the same from the factory.)

I'd prefer to be able to just set the same DKEK on the devices myself. Failing that I'd settle for Yubico being the arbiter. It would make the devices substantially more useful and less scary in loss / destruction scenarios.

Re: Become unbannable from your email

#87

Creating aliases for the addresses you are actually using, e.g. a netflix@ signup is preferred over a general catch all, .. and all that spam senders can generate approach.

Some services will also ban you for this. Samsung, Amazon, ... so you have to use generic or random words on left side.

Been using this with Amazon and plenty of other services for decades, not sure where you’re coming from.

Re: Become unbannable from your email

#88

I guess the real question here is: Who is more likely to ban you, Google and co or your domain registar? For most people, who are not doing anything shady/controversial with their domain and are using a .com or .net domain (which are price regulated by ICANN), are not using a shady registrar and will always have the cash on hand to renew as needed, the answer will be Google and co. Its a good idea to set up auto-rene…

I pay for 10 years in advance, which you can do with com/net/org.

Re: Become unbannable from your email

#89

TL;DR: Step 1: Get Your Own Domain Step 2: Make Backups This is not sufficient. Even your domain can be seized. There is no way for any service dependent on the DNS System to be irrevocably owned.

Any stories of domains being seized that weren’t involved in criminal activity?

Re: Become unbannable from your email

#90
post #83

Earlier quoted context omitted.

well your recourse is repointing the domain

It's worth pointing out just in case someone might forget/not think of it... Don't register your domain or DNS with Google Domains / GCP if you host your email with Google Workspace... since if you get locked out of the Google account you could be unable to update your DNS. The saddest thing though is that in some ways Gmail is harder to hack into than some registrars. I remember a postmortem write-up from a guy who…

> Don't register your domain or DNS with Google Domains / GCP if you host your email with Google Workspace... since if you get locked out of the Google account you could be unable to update your DNS.

This seems like a potential rabbit hole.

Use a different domain with your registrar than the domain you’re registering. Same thing with DNS host. Do you have two domains with two registrars and two DNS hosts? Presumably if either one gets compromised, the control of one domain could be used to gain control of the other. And you’ve quadrupled your attack surface by having two domains with two registrars and two DNS providers.

I don’t disagree with you, but I also don’t know a robust solution for this (happy to hear one, if you have it).

Post reply on HN