Customer's 20-year-old email account shut down over unusual address
cbc.ca
cbc.ca
"your email address may not be your own"
If you entrust your email to a third party, you are taking a risk. IMO that risk is a lot bigger if the third party is your ISP, because they know they are in a very strong negotiating position with respect to you. That's why I have never relied on my ISP for my email service (even though they offer it, I don't use it). It's very cheap nowadays to get ownership of your own domain and full control of the email addresses under that domain. Yes, you still have to depend on your hosting company for those services, but you are in a much stronger position with them than with your ISP, because hosting is so much more competitive.
This is why I think private keys combined with some kind of immutable log (cough...blockchain...cough) are far better as identity tokens than anything based on DNS.
First come, first served registey with some form of expiry implemented via smart contracts might be possible, but it seems unlikely any one registry would ever become 'the canonical registry', as that just puts is back in the same situation as DNS.
This is a hard problem to solve without asking folks with big sticks/guns to enforce policy decisions.
I will give my ideas more thought down the road. We have already tried this with PGP but it had too many issues to be practical. In any case, whatever we end up building is going to be better than DNS which is one entity with too many pairs of hands controlling it, all the way from ICANN to the registries to malicious social engineers.
You might as well say "...in any society." If a government doesn't claim a monopoly on violence, someone else will.
Whichever entity (even if nominally a collection of entities considered together) has (whether or not it claims) a monopoly on the legitimate use of force is the government, whatever it calls itself.
This is falsified by many historical examples. I gave one upthread (some of the American colonies, such as Pennsylvania in the early 1700s). Another would be saga period Iceland, which existed for several centuries with no government that monopolized force.
I think history does show that societies without a government that monopolizes force are vulnerable to a failure mode which basically consists of an outside entity being willing to invest enough resources to overwhelm the force available within the society, and thus establishing a government by takeover. This is what happened in both of the examples I gave above (Iceland was taken over by the King of Norway, and Pennsylvania ended up caught up in the general tightening of everything when the British decided to get tough on the colonies after the French and Indian War).
In other words, any time a group of people try to set up for themselves a place where they can live the way they want to, interfering with no one else and with no one else interfering with them, it doesn't last; someone else always ends up coming in and taking over and trying to tell them what to do. I view this as a bug, not a feature.
I was merely recognizing the fact that, in today's world, governments, at least of developed countries like the US, do have overwhelming force at their disposal compared to private citizens. Whether that is because they have a monopoly on violence or for some other reason is irrelevant to the point I was making, which is simply that private citizens have to recognize and deal with the reality and limitations of what "ownership" means in today's world.
Correct me if I am wrong, but is a registry even obliged to offer a renewal of your domain when your current lease expires? Without jumping through the whole loop of "owning and defending a trademark", what legal recourse do individuals have when faced with malicious takeovers?
(A) Pay for an email address.
(B) Run your own email server.
(C) Use the email provided by your ISP
Just running your own server got a lot easier, and you can buy stock Gmail or Outlook Web clients under your own domain.
No, today there is another one:
(D) Pay a hosting company to host your own domain and its email. This is kind of like running your own server, but without having to run the machine yourself, have an Internet connection that supports that (most ISPs forbid hosting services on your publicly visible IP address in their terms of service), etc.
I used to run my own server, but I got tired of constantly dealing with spam filtering, RBLs, etc. I just forward several accounts across a handful of domains to my gmail account, and I have gmail setup to send 'from' my own domain (with validation).
I could switch to another service (or my own server) and other than me, no one would notice a thing.
How do you set this up? I have several domains pointing to my gmail but can't send from them...
Edit, should have just googled, https://support.google.com/mail/answer/22370?hl=en
Edit 2: this really: https://blog.alexlenail.me/i-want-to-send-emails-from-my-goo...
I would consider Gmail to fall underneath option A rather than option B. If Outlook Web is Microsoft's GSuite competition then it is not running your own server either.
You don't have to deal with Sendmail cf files, and there are secue options other than qmail.
Though yes, it's rather the PITA.
(E) Use university or organization e-mail account [1]
(F) Buy your own domain and set up mail forwarding to another account or service [2]
[1] Okay, not really much better than your ISP account, but it's a different dynamic and still slightly better, though not everyone would have this option.
[2] I can't actually find a positive reference to mail forwarding being an option around the exact time-frame, but I know I had done this for some people around the early 2000's at least. Though it's a variant of (A) it's still distinct because it's a domain, not just an account.
If more people would realize the importance of email address as the key to their online identity, this might open up a business opportunity for banks. My bank knows me, they have the proper ways for offline identification (if I loose my online access and I have quite good confidence on them. I would not expect the bank to run full email service for me, but they could provide forwarding service. Should I run to trouble with the actual mail provider, let's say Google blocking my account, I could just work with the bank to setup forwarding to other location.
If I hit reply on an automated email I would expect it to get an automated response with clear links to helplines/addresses/etc at the very least, and ideally to go through to the actual customer support system. Is that unexpected? I'd imagine that less technically aware users would expect a similar thing.
I think that's a little hyperbolic. Companies use noreply because replying to that email is not the correct path for support. If you want support, go through the real support system (which likely has additional features around sorting support requests, paid support, antispam etc).
> I would expect it to get an automated response with clear links to helplines/addresses/etc
It would be a minor pain for me to set up and keep up-to-date email based auto-reply systems for everything. Most users don't expect such a thing to exist, and it's far easier just go to the website and use the FAQ/Contact us pages there. I do occasionally check the noreply inbox for some services, and I've never once seen anything other than spam or out-of-office notifications in them. It's wouldn't take a ton of effort, but for nearly no reward.
In other words: Make it as comfortable as possible for yourelf, fuck your customer. I have one point where I manage my electronic communication that is very well set up for the job, and that is my email client. If you expect me to use your user interface in order to communicate with you, I won't be your customer.
If you set up a real email address as the "from" field, then when you send out an email to a list of any significant size, you can expect to get a bunch of autoresponses like vacation notices, out of office, so-and-so does not work here anymore, etc. Then someone has to go through and clear all those out, looking for real replies.
If you use a "noreply" email address, then you can avoid that. But then you should put the real support email address in the body of the email, so that people can get service. I agree it is annoying when companies seemingly have no way to get support.
We send automated notifications from an address that’s manned by humans. Approximately 14000 a day. Rules for out-of-office in a large number of languages have been in place for years.
(And ‘does not work here anymore’ - we want those replies. If they’re getting mail notifications, they’re also getting sms and phonecalls. That’s an email worth handling before we phone the wrong person at 3am.)
I'm not sure if the fact that they refuse to migrate his emails to a new account is a matter of terrible customer support, technical debt, or incompetence.
More importantly with POP - you mail gets downloaded to your device and then that's it. It's yours, secure, for you to manage. With IMAP there's always the possibility of the ISPs server hiccuping and deleting mail off your machine that you thought you had safely downloaded.
I used to be a POP fanatic, mostly because I didn't like the idea of leaving copies on the server. But then, the NSA probably logs everything, so hey.
It might not be correct now but at one point the Electronic Communications Privacy Act stipulated that data left on a server for more than 180 days is considered to be abandoned and the government can easily and legally access it.
[1]http://my.eastlink.ca/customersupport/internet/faqs/email.as...
Likely explanation: bounced emails landed in his mailbox, and his access to them is problematic. Migration would mean they have to "clean the data", which as we know can never be done to 100%, plus it is time consuming / expensive.
I'm not protecting the company, just pointing out the forces.
In any case, it's not their stated reason. If they're sending emails using noreply already (which are bouncing), that's a completely different issue, and I wonder if he wouldn't have a case for them impersonating him :)
I find it unlikely that anyone cold emails "noreply".
While I'm pretty on board with the notion of some kind of internet access as a modern human right, I can't really see an argument for a right to a specific email address with a specific email provider. It's shitty that they've only given him 30 days. And, it's shitty that they didn't do something about it much, much sooner (noreply has been around for a long time as a common address for customer service emails, though maybe not 20 years), before his life became so entangled in this specific email address.
But, I don't think the law is on his side. I doubt he'd find a lawyer to take the case without paying a lot for the service. And, I really doubt he'd win such a lawsuit.
he trusted then to handle his private personal email. instead they sent out millions of messages faking that it was from his account, when they could have used, literally, any other combination of words to tell the recipients that they should not reply to the message. change no to dont, and it is even more functional to the intended purpose.
it's so trivial to use another bogus email on the from field that his lawyer should have no problem claiming it might have been a malicious employer harassing him. because, really, that's the only explanation that is actually plausible.
It's still a significant counterparty risk though.
The hosting/email provider is obviously not a problem at all, as you can switch to a different provider at any time (just make sure to keep the domain registration and the service provider separate) if your current provider is an asshole--or you can just host your own server if you want to avoid any providers messing with your emails.
Similarly; you are at the whim of the NICs, with the .ly domains being a great example of a TLD taking back domains for whatever reason. https://benmetcalfe.com/blog/2010/10/the-ly-domain-space-to-...
Are you comfortable with sharing their reason (if they gave one) for doing that to you? That seems like a situation that would quickly cause a mass exodus of customers to a competitor.
Years ago when I first started helping people build a web presence, I used 1&1 Inc. as both a registrar and hosting provider. When one of my clients wanted to move to a cheaper host, I was happy to help her make the move, however 1&1 did everything short of taking ownership of the domain to stop her from doing so. They would delay the transfer, lock the domain after I'd unlocked it, and wouldn't respond to support requests. I finally had to threaten legal action to make them release the domain to the new registrar. I immediately pulled all of my own domains to a new registrar and moved my sites to a new host. They tried to delay my move as well, and again I had to say "lawyer" a few times before they let go.
You sign up with Google and follow a process they have, which involves setting some MX records and CNAME records on your custom domain to point to google's hosts.
This was free within some limits... I guess I assume it still is? (I set this up years ago. Google's never asked me for money for it.) I don't remember what the limits are. I and my family never hit them. I guess there are limits on the number of accounts and storage space.
I suppose since it's free it's a matter of time before they stop doing this, but so far so good.
The speed of downloading the archive is no big issue; it should take a day and a half. And you can sort through it by importing into Gmail and using their preconfigured filters. But the biggest problem is resetting all your old online accounts to use a new e-mail address.
To change the address, you may have to confirm an e-mail to your old address, so migrating all your accounts has to be done within the 30 day window.
Alternately, signing up for new accounts isn't always easy. Financial and government services may require special codes be sent by postal mail, and a confirmation possibly mailed back (along with waiting for it to be processed) before you can reset or create a new account. Creating new accounts also loses you any time or money you may have invested into an online account. And each recipient still needs to update their address books with the new address, probably by hand.
He certainly never owned the domain, the servers, the connection, or the name, so the isp is legally justified. But it's a much bigger pain in the ass than people realize, and giving him more time and assistance would be a big help, especially since he's in the middle of a big life change already (closing on a house).
At least criminals who encrypt your files let you pay a ransom. Wonder if Google should do that too, "We shut off your account for reasons we won't explain. But if you pay us $1200 you can get it back"
Hard to know what the causes are here: could be anything from the dominance of free services (i.e. you can't 'take your money elsewhere') to laws that make it harder to do business anonymously.
Institutional collusion. I don't mean explicit, agreed-upon conspiring; I mean the sort of industry signaling you see everywhere, like cellphone provider and airline pricing.
FB, say, ups the intrusiveness in one way, and the other surveillance firms watch carefully. If the blowback is manageable, yay, new normal has been achieved.
The company believes that email may lead some to "believe that information coming from this address is from Eastlink."
Sounds like this Eastlink person doesn't know most mail servers receive mail quite happily from anything@any.domain, as anyone who's ever received spam knows.
The problem with their argument is that any email ending in @eastlink.ca will lead some to believe that information is from Eastlink.
If you're giving customers an eastlink.ca email adddress, how can anyone tell if an email from emailname@eastlink.ca is from an Eastlink employee or not?
Given that Eastlink wanted to take back noreply@eastlink.ca (sans subdomain) and that they're a smaller, regional Canadian ISP, I would guess their process for handing out email addresses is less sophisticated than Comcast's.
(1) when you pay for an online service, a firm owes you a service.
(2) when you use an online service, a firm owes you nothing. Be OK with the idea that the service may disappear tomorrow.
Email is an increasingly important form of communication, and you should always have a service contract with the firm hosting your emails, with the consumer protections that come with the exchange of money for services.
I recommend fastmail.com or mailbox.org to all my family members when the topic comes up.
Compare that with gmail that came out of beta in 2009, belongs to a company that is known for serially shutting down much-used and much-loved services, and whose profitability (that of gmail not google) is not entirely clear.
It's not particularly hard to explain to lay people and a story like this is the perfect opportunity.
When I started I had the intention to just kill the address when I ever will get too much SPAM, but surprisingly this never happened. I think most SPAM bots just filter out all noreply@... addresses.
I doubt that technically it is in any way "difficult" or "complex" to set the account to "receive only" for - say - three months and then set it to "read only" (i.e. only an accessible snapshot of the e-mail account to a given date) for another - say - three months.
I had recently something simlar happening, with another provider of free web-mail, where I have had an account for - if maybe not 20 - at least 17-18 years, I beleive I was among one of the first users at the time. They decided to close the service (which is as said OK to me, after all it was a free service with just a few ads when logging in) but they did so rather abruptly and more than that I continue getting on another account of mine notifications about mails arrived to that address that is now inaccessible, which should mean that the e-mail account is still "on" and that it was simply prevented accessing it, even in read only mode.
As often happens, no way to contact (or no response from) the support.
Only as a sort of "hall of shame":
There's no real need for a "noreply" address to be standardized or conventional, though. Nobody except someone at that particular domain should be introducing noreply@ addresses into the email system (and hopefully only as reply-to addresses).
1. I get credit card bills from no-reply@alertsp.chase.com. Does payment constitute a reply?
2. Why should I want to do business with a company that doesn't want to hear from me?
3. Standardization re: email address is hard to find. Plenty of sites won't accept a '+' in a gmail address, but gmail advertised that for years as a feature.
The unreasonable action is giving someone 30-days to change their email, considering how integral email's are to security these days (password resets etc...) Eastlink made the mistake of allowing this, now they are forcing someone else to pay.
Spam is a completely different story, and rarely uses no-reply emails.
If you want to blackhole any information you request from companies than scratch your head why you can't find your tracking information or flight status/itinerary that's completely up to you. Ignoring the valid, reasonable and typical use cases is just absurd
Ok, I don't disagree but that's besides the point. For better or worse, a certain kind of convention grew around 'noreply' emails.
but its like he said: he doesn't own that email address though he thought he did. I went through this a few years ago, and I got a domain instead, which I do own.
They should give him a year and help him transfer to a new account (copy emails over, etc). 30 days isn't much time to find every site you've signed up for in the last 20 years.
I don't disagree. There should be a lot of leeway for their customer to get their accounts in order.
There might be such a convention now. There absolutely was not such a convention 20 years ago when he registered it.
On top of that, the refusal to move the mail to a new address is abusive. It's not that difficult to do. So he's in the sad situation of having decades of mail deleted. Because "fuck you, Eastlink screwed up, and you're going to pay for it"
How any can defend such actions is beyond me.
That's why I said it was bad luck.
>How any can defend such actions is beyond me.
Just to be clear, I'm not defending the manner with which they took his account. He is (was?) their customer for 20 years and they should give him ample time to make arrangements. I'm simply stating that I understand why they would want to regain control of that email.
It's only their marketing emails that need a "noreply" address and there is no reason that address has to be exactly "noreply". There is no confusion with any other user or company, because their no reply addresses are noreply@theirdomain.com.
Do their marketing letters need a "noreply" address? "This letter comes from nowhere, you can not reply to this letter"?
Why do their marketing emails need it, then?
This is not "bad luck".
This is "extreme cruelty".
Also, since you like conventions, grandfathering in decisions made before a convention became reality is also a convention.
Second, this is why I have been a customer of pobox.com for over a decade. They don't host mail, they just provide forwarding and spam filtering, directing my mail at whatever endpoint I pick (and with most clients, including gmail, I can use them as my outgoing mail agent too). Changing mail services is as simple as a couple of clicks in their UI. Since their overhead is low and they get paid for their services, I expect them to be around for a long, long time.
That's just unbelievable! How bad is their customer service?
Not much sympathy here; if you want your personal address to be noreply, get your own mail domain.
Although it's not listed by RFC 2142 as a special alias, it de facto is.
For instance, in my SMTP setup, I reject messages that are from noreply@<any-domain>. (A small white-list of exceptions applies.)
A noreply address is a rude indication meaning "I want to talk to you, but I don't want to hear from you". Yeah, well, likewise here then: while I have your TCP connection, which does accept datagrams from me, let me tell you what I think with my RST segment.
While it may be a de facto special alias today, that status was much less certain when he got it. The time for his email provider to reject the address was when he requested it.
Didn't he receive even one single e-mail from "noreply" addresses in the last 20 years to recognize that, hey, people are using this thing, which is the same as mine!
> The time for his email provider to reject the address was when he requested it.
Do any of the same people even work there any more, you know?
Maybe at that time, you could have gotten "abuse" or "postmaster" if you had asked for those from the same provider. Sometimes such things slip through the cracks.
I do not know. What point are you making here? Regardless of the answer to that question, the provider is still using a specious justification to cancel an account they have provided for twenty years.
They want to seize it from him so that they can spam people with "noreply@theirdomain.com", which they shouldn't be doing. E-mails should be sent with valid return addresses that someone picks up, or not sent at all.
I.e. since if this fellow contacts you by e-mail with his "noreply" account and you write back, he then actually replies, his use of it is more legitimate then what they are likely planning.
Its funny given that usually hacker news users are always so progressive demanding every company become innovate at warp speed and yet theres actually replies defending this guy. boggle
You're relying on a directory service ... somewhere, somehow. Your postal-service address is only as solid as the property and/or tenancy registry that's associated with that address.
(There may be some way of coming up with a p2p system based on UUIDs and PKI plus a web-of-trust reputational vouching, but that is not an alternative I can switch to tomorrow for general use.)