Show HN: Email encoder – protect your public emails from bots and crawlers
freetools.dev
freetools.dev
For the last 10+ years I personally have not tried any more to hide my email address on the web. It's visible in thousands of places (mailing list archives, websites, git commits) and the volume of spam is absolutely manageable (~100 a day, 99+% filter rate with spamassassin and blocking some networks).
USERNAME at that Googly Maily Thing
and other "creative" ways to hide it. I just know if I put an e-mail out on the web, I usually have it as a "mailing" list type of ID, so I'm not just placing mine out there.
Neat app though.
https://support.cloudflare.com/hc/en-us/articles/200170036-W...
Contact Me:
echo 'c29tZS5lbWFpbEBzb21lLmFkZHJlc3MK' | base64 -d echo `something` | base64 -d > ./some.file.txtThe redirection of base64's output to a file is addressing the concern that the output from the program would trick the terminal into executing code.
What you are describing is the risk of sending a small string of ascii into base64 would cause a buffer overflow and trick a text decoding binary into executing code. This is of course a risk with parsing data especially if it were binary.
If we really wanted to go deep down a rabbit hole of theoretical risk then I would concede that if you did not force your character set of your terminal to something that could not possibly interpret extended character codes then there is a risk albeit highly unlikely that there could be hidden strings you are copy/pasting. This could occur with any executable and pasting of data to which I would partially mitigate by forcing my terminal to have a LANG/LC_ALL of C unless I specify otherwise and would probably even take care to be explicit with IFS. This is a deep rabbit hole and I would be surprised if a majority of people copy/pasting from sites like stackoverflow / stackexchange took these precautions. Further mitigations could include executing code as a AppArmor/SELinux confined user or pasting the code into a sandboxed environment. There are infinite rabbit holes we could go into here and would be happy to cover some of them.
More likely when copy and pasting text especially if from a web page would be that the site is malicious and using CSS or javascript to trick your system into copying entirely different contents into your copy/paste buffer. [1] This would also benefit from running in a highly sandboxed environment.
$ echo 'cm0gLXJmIC8K' | base64 -d
rm -rf /
$ # was echoed, but not run