Show HN: NBox – Sign up anywhere without giving your email address
nbox.notif.me
nbox.notif.me
But you know what really happened? I wound up with hard to remember email logins and caught less than a handful of services sharing my email address without my permission.
It wasn't worth it.
Big mistake.
First off, I got FLOODED with e-mail bounce-back spam because spammers send e-mail with forged From: headers and I'd get all the errors.
Second, I discovered that nobody is actually selling my e-mail address except for one gaming forum I used years ago. Not even Facebook has sold my e-mail address.
Third, I've run into issues when replying to e-mails. I filed a support ticket with a company once, where the e-mail address I had registered with them was company@mydommain.com. They responded via e-mail, and when I replied to said e-mail, their ticket system rejected it since the From: address was my main address of myname@mydomain.com.
Now that I want to just switch to a single e-mail account with gmail, I find myself needing to try to find every e-mail address I've used @mydomain.com and changing them with the website. Meh...not worth it.
Won't FB be among those least likely to sell your email address? FB has tons of ways to make money using your data. Your email address offers very low marginal utility over all the rest of your data.
"thus the marginal utility of a good or service is the change in the utility from an increase in the consumption of that good or service." [1]
The third problem is more serious. I use Thunderbird. I googled and there are a couple of addons that makes it easy to edit the from address without having to create new Thunderbird identities.
https://github.com/absorb-it/Virtual-Identity
https://freeshell.de//~kaosmos/index-en.html#editsender
Both are somewhat unsafe, one because of the site certificate, the other because of the download site.
The first problem looks like a showstopper tough.
These days I don't even use Thunderbird. I just have gmail retrieve all my e-mail from my POP3 server. Though FWIW, I still have Thunderbird installed with all my e-mail going back to 2003. I imagine there's a way I could capture every e-mail address I've used then manually go to each web site and change my registered e-mail address.
This is the one I use.
If your Fastmail address is dfinniger@fastmail.com then you can randomly create emails like:
some-domain@dfinniger.fastmail.com
and it will automatically send them to your main email.
It's very convenient, and the cost per year is likely to be less than your hourly rate multiplied by the number of hours it'd take to set up self-hosting.
* monster.com
* linkedin
* Pragmatic Programmers (pragprog.com)
* audioscrobbler (now part of last.fm)
* The London Cycling Campaign
* The Economist's subscription department * Dropbox
* Adobe
* ...
The list is long!These aren't small numbers, either. We're talking about 68 million logins for Dropbox and 150 million for Adobe. To put those huge numbers in perspective, combined that's over half the population of the USA.
Can you elaborate ? I have been meaning to set up just such a mechanism as it has always seemed like a good idea ...
It seems like "rsync.net@example.com" would be very easy to remember and associate with the site (rsync.net, in this example) ...
As you say, using a password manager, or just picking a nameOfService@example.com style of email, means remembering the email addresses is pretty easy. n.b. you may need to also set up your email client to let you send emails with a customisable address too.
Spammers who send stuff to randomAddressTheyMadeUp@example.com can be mostly blocked because these tend to have a messy jumble of text and numbers - I use a simple regex to throw away these kind of spams. I use procmail to do the blocking, but I'm sure there are many other tools that would work just as well.
Recently I came up with another solution that I know some have used:
Stick to one email address and have a whitelist. Anything not in the whitelist is "spam" (including irritating LinkedIn emails, etc). If I get email from anyone not in the whitelist, they get sent an email with a website link asking them to confirm their identity by submitting their email address. Once they do that, they are whitelisted and all their quarantined emails show up in my inbox.
The only remaining part is constructing that whitelist. I wrote a script to go extract all the From addresses and just dumped them in there. So people who've emailed me in the past will not deal with going to the website to confirm their identity.
If I get email from an entity I no longer want to see in my inbox, I press a keystroke to remove them from the whitelist. Likewise, if I go to my quarantine folder and see an email I'd like to whitelist, it's done with a keystroke.
Been using it for less than a month, and it is quite effective so far.
You know, the sender header is just a text string... What stops you from putting whatever e-mail alias you registered with as sender, for those occasions?
Cognitive load. I don't want to:
1. Think about it. 2. Figure out which email address goes with which To: field. 3. Find a way to automate all this.
In the end, my solution would be less work to get rid of unwanted emails than using a catch-all. Why should I do the extra work in maintaining the system, when the sender can do the tiny amount of extra work instead? More fundamentally, why should anyone feel they have the right to just insert anything into my inbox? I should control the inbox - not them.
By default I only ever receive a limited number of emails from any new emailx@mydomain, unless I explicitly go to @mydomain and allow a specific emailx@mydomain to pass that limit.
My only irritation is that some vendors block @mydomain as a valid email address, in which case I use an ancient email address in its place. Needless to say that vendor will never see my main email.
This is to stop somebody eventually gaining control of the domain when it expires, setting up a catchall on it, and then being able to login to every single account you used with that address.
Some registrars protect a domain after expiration so nobody can hijack it and claim it as their own, but you often have to pay extra for this service.
Only downside, is when company merges or renames: if it merged I end up with to accounts which have half of the history; if it renames -- hard to remember original email (recent example wayfair's old name was something else).
Now, I'm switching to single email -- it's just simpler
I sore it in a password manager, so remembering the address is no problem.
If you use a "regular" character like "." as a separator virtually all sites will accept the email as valid vs using something like "+".
You could easily argue this is a symptom of a different problem.
1. Before the actual sending of the mail data, the sending server connects to your mail server and after a polite introduction sends 'RCPT TO: xxxx@yyyy.com'. This is where your unique-for-that-site email address is used.
2. Later on during the transmission, all the 'real' mail headers are sent, and this is where the To, From, Subject, and CC headers are set. If you were BCC'd there is no 'BCC' header, so the 'To' header normally has the mail address of the original 'To' recipient. Or in a lot of cases the 'To' header is omitted entirely. Depending on your mail client, you will either see your name in the To field, or something like 'Undisclosed Recipients'.
Spammers typically shake it all up, so that the 'To' header rarely matches the 'RCPT TO:' value.
In my bespoke anti-spam system, I re-inject the 'RCPT TO:' and 'MAIL FROM:' into the mail headers (prefixed with X-) so i can easily see in my client what is actually going on.
It's worth it and only 1 password
s/+.*@/@/gAnother user commented that you could just register your own domain and do this; that's great for the average hacker news reader, but not so great for the average Joe so a service like this (if done correctly) would be pretty convenient.
Things that jump out right away as bad about this NBox.
1) It just auto generates an email for me. That's going to be a pain in the ass to remember.
2) Wait; how do I login? I literally don't understand how to login to this app short of going to the site and I get auto logged in by the Chrome extension?
3) Why do I even need a Chrome extension to get my email; where is the password protection so I can login from a different device or god forbid my computer crashes?
4) Not every service asking for an email address is a web service. If I sit down for dinner at an Applebees and order a meal a server is going to tell me the appetizer is free if I just provide my email address... and I want that free appetizer minus the side of spam...
As someone else noted mailhero.io is basically the same service as this, but it's big flaw is that the real email address is exposed since it's always included in the provided email address.
spam.u.later@mailhero.io (ah; real address is later@mailhero.io) Also; many other email services (including GMail can do the samething as mailhero using + addressing and adding rules.
1) "That's going to be a pain in the ass to remember": the extensions are there so you don't have to.
2) "how do I login?": we're currently developing this side the service.
3) See 2)
4) We're planning on proposing mobile apps too.
To put it into context, nBox is fairly new and we did not implement all our ideas before knowing if people were gonna be interested.
In regards to the extension though; that's just such a bad direction to go IMHO. Most email is being read on phones these days anyway; does NBox even work from a phone today?
It works on android phones with chrome, but like you said I wouldn't remember the generated addresses, so we think the extension is a big part of the service, and unfortunately, extensions are not available on mobile. We're working on the subject to find the best solution possible.
A password manager generates random data for the password textbox. Your extension generates random data for the email textbox. Perfect!
Somewhere in this issue of websites blocking + addresses there is a some irony as + addressing is a more recent email standard and so some people have legitimate email addresses with + symbols in them; in fact last I knew Microsoft Exchange still wasn't supporting + addressing due to the need to support legacy users.
For example, I would sign-up for HN using hackernews@marak.com and for Reddit using reddit@marak.com
Simple and effective.
I still host my own e-mail but I no longer do catch-all. There are only a few sites and services I care about. For those I have trusted them with my e-mail address. For all others I use 3rd-party throwaway mail services.
I get less spam now than I did with catch-all.
I have learned to keep a personal e-mail address for friends & somewhat trusted people, but never businesses. Businesses (and all government offices, kids' school,...) get their one-time address. If spammers somehow get to it, it is much easier to cut them off, and I also know who leaked the address to them.
Of course, http://www.mailcatch.com/ rules for those one-time "no, I will not let you spam me" registrations.
I use a completely different domain than the one that's publicly associated with me though. Maybe that helps.
A couple of years ago, maintaining the blacklist passed the point where this was a viable technique for me.
It has the advantage of being able to spontaneously create email addresses when signing up for things, while still blackholing most guessed addresses.
I like this idea a lot.
If I configure me.example.com to accept emails matching the pattern "me<anything>mail42@me.example.com", then I can generate as many on-the-fly unique emails as I want, without maintaining any lists, and without catch-all forwarding of random spam to my inbox.
If I use me+anything@me.example.com, I get the same exact feature, but the downside is "+anything" is recognized by some and either disallowed or used to generate more patterns.
If I use subdomains (like anything@me.example.com) I have the spam issue.
With a white pattern scheme, you can choose your own pattern (so sites can't really catch on), not have to maintain any lists, and avoid spray-and-pray spam.
I suppose google domains might be OK for personal email.
The only downsides I see are that (very few) sites still complain about the perfectly legal + symbol and some sites / bots are probably starting to reverse engineer that since it still exposes your username. But so far, I've yet to have a single site or service expose my primary mail account, so it at least helps.
Finally: this is a fantastic hack for testing your own signup flows. :)
Believe I saw this on HN recently: http://haacked.com/archive/2007/08/21/i-knew-how-to-validate...
With qmail the "standard"[1] was username-alias@example.com, rather than username+alias@example.com. I rather prefer that - but then my (user)name(s) don't contain any hyphens.
Either way I think it looks better with system usernames - firstname.lastname@example.com was/is usually handled as a separate form of alias look-up anyway.
[1] http://www.lifewithqmail.org/lwq.html#dot-qmail-files See section "4.1.5. extension addresses"
[ed: and I recall using tmda as an anti-spam system - it inserts an encrypted tag in the alias portion, that can be stamped with an expiry date, and tied to a sender address (eg hmac(userkey, sender@example.com+01012018) => xyxyzzzzz - give sender@example.com the address user-xyxyzzzz@example.net - and mail to that address will be accepted from only sender@example.com until 1/1/2018.
With a service aggregating these, we see many users from NBox. Perhaps this is not a concern for your use case, but it seems a tradeoff worth considering.
Depends who is tracking you.
If I register some non-personally-identifiable domain "e.g.: bumblebutt.example" and use a WHOIS proxy, you're can only be given up by a registrar... which usually means a warrant.
Still paranoid? Pay for the domain using bitcoin you got in exchange for cash/services (there are a lot of registrars that take bitcoin).
The benefit of a public site is that you can't use the hostname as an identifer for a single person.
nBox generates for you an email address for each site, for free.
- Effortlessly thanks to our browser extensions
- Addresses are anonymous and private
- Delete the addresses you don't want any more
- Be notified according to your preferences on each email
I'm looking to share the service. Any feedback is very welcome.
Thanks!
My question is therefore how do you plan to fund this indefinitely if it is "Just Free, Forever" and is unlimited? You say it is part of promoting your brand, but it looks like that brand (or at least the domain) has been around for less than a year, so not much history. If it isn't you company's main product, what is to stop you from deciding the costs of providing this becomes too expensive for the promotion it is giving you?
I tried to answer it there: https://www.producthunt.com/posts/nbox/comments/483328
Why shouldn't a service flag you as malicious and refuse users with email from your domain?
What do you do to prevent mass account creation on the service?
Thanks!
> Why shouldn't a service flag you as malicious and refuse users with email from your domain?
Some services might block our addresses some day, but that would be a mistake because nBox is not a disposable email service.
> What do you do to prevent mass account creation on the service?
If your question is in regard to services which might block us, I don't think they care about mass account creation, a few email addresses are enough to bypass limits on emails.
As for my 2nd question it was related. Often time spammers rely on tools like nbox to create a massive amount of accounts on services like Winterest, so Winterest has to flag your domain as potentially malicious.
I was wondering if you have any countermeasures to this problem, such as a rate limit on the number of accounts one can create per service. I'm sure Winterest would appreciate :)
For a given service we authorize only one address, but we haven't implemented a rate-limit yet.
If you have 1 single email account per service that is fine.
I think you should call out these two aspects on your site, to show that you're increasing privacy for users, but also protecting services from being abused exploiting nbox. It should reduce the likelihood to be blacklisted.
I'd say the use case is to filter "semi-wanted" emails.
P.S. here's the link for the extension: https://chrome.google.com/webstore/detail/nbox-your-registra...
The Firefox extension was following the validation process, it's now published: https://addons.mozilla.org/en-US/firefox/addon/nbox/
http://www.faqs.org/faqs/mail/addressing/index.html
TL;DR - Most SMTP servers support delivering mail to addresses like foo+bar@email.com, in which case it will be received by foo@email.com. You can specify whatever string of alphanum chars you'd like after the plus sign.
Sorry, couldn't resist. I got burned by this, I used it to sign up to a newsletter, and when I tried to unsubscribe, I kept putting in my actual email address with no results. Took me two weeks to think of checking the "to" field and realising I'd used a plus address
Anyways, thanks for your hint.
1. You need to have multiple domains. If your solution is just one host name and your service becomes popular, it will become blacklisted in a matter of months.
2. The volume of spam you'll receive is huge. Really huge. Even if your service is only moderately successful. It costs money to keep such a service running.
If I'm willing to give a fake registration email I probably don't care about privacy and this is just for throwaway anyway. I'm not going to give any personal info to a website I don't trust with my email in the first place.
I also don't understand how this is not going to be blacklisted like any other anti-spam email service.
Maybe I'm not the target for this product bu this seems to bring nothing new in a slightly more annoying way.
This is somewhat tangential to your points, but I see this type of comment a lot. Chrome extensions are just renamed zip files that contain all the JS, HTML, and CSS for their extensions. It is easy to take a look at the source code if you have any privacy doubts. The author might try to obfuscate the JS, but it should be trivial to see if there are outgoing connections being made. Google also makes it simple to disable extensions with a couple clicks if you want to keep particular extensions disabled except when you are actively using them.
> Extensions are a privacy concern and consume memory needlessly.
Yes, that's why we don't ask for any permission, so the extension only gets activated when you click on the button.
> I'm not going to give any personal info to a website I don't trust with my email in the first place
Everyone can get hacked, governments, big companies... so who do you trust enough to give your email?
> I also don't understand how this is not going to be blacklisted like any other anti-spam email service.
Some services might block our addresses some day, but that would be a mistake because nBox is not a disposable email service.
I love that service, it's saved me countless headaches.
- email are less guessable with nBox
- if 33mail gets hacked, spammers will get your email address
I've been a satisfied user of SpamGourmet (www.spamgourmet.com) for years, and the only (argueable) downside I've seen is how upset customer-service representatives get upset while reading my address. How does your service compare?
- With spamgourmet the addresses are designed to expire after X emails, so it's intended for services you don't care about. - Once I know one spamgourmet address, I can try to guess other addresses of yours. - We don't ask for your personal email. If spamgourmet gets hacked, spammers will get your information.
> - With spamgourmet the addresses are designed to expire after X emails, so it's intended for services you don't care about.
This is configureable; it can be turned off entirely (allowing a trusted sender to send an unlimited number of e-mails to an address), or the allowance can be 'refreshed' (so that, after, say, 5 e-mails sent to an address, you can allow 5 more as a further probation).
Edit: https://www.producthunt.com/posts/nbox/comments/483328
> bdav24: Hi water42, don't ever trust anyone with your data, governments and big companies get hacked every day. Our angle: we don't ask for any personal information
You will be able to route/read all of an individuals inbound mail ?
That said, for targetted attacks we won't be able to do better than Google and others, the risk is never 0.
> You will be able to route/read all of an individuals inbound mail ?
You mean to handle the load? We can scale at any time if we need to, but our current setup can already handle a lot.
This seems like an interesting idea if they own a whole bunch of different domains, but they don't specify this, and my attempt to sign up for an address failed. (open firefox -> click create my nBox -> click Sign up for a service (i type https://facebook.com) -> receive message saying "To create your nBox Allow the notifications" -> No simple info about how to do this is given, so I give up)
Having said that, I plan on using this.
If I click "Not Now", the prompt goes away and nothing happens. Perhaps I am misunderstanding how the service works?
Usually if I forget the password to a service they can send me a reset link, what would my options be with NBox?
We're currently working on the "account creation" part of nBox.
2. Possibly offer the ability to self host this?
The other problem with this is that there is now a middle man in my security chain. If you get hacked, potentially all of my accounts can be hacked. If you have a rogue employee, same thing. If you have a flaw in your security, I too am at risk from a centralized source.