You can now send replies from your Duck Addresses
duckduckgo.com
duckduckgo.com
> Get a free, personal @duck.com email address. Emails sent to it will forward to your regular inbox, with creepy email trackers removed.
Totally genius! I fear there will be a cat-and-mouse-game but hopefully DDG will keep relatively up to date.
[1] https://www.spreadprivacy.com/introducing-email-protection-b...
https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...
Basically it seems like a gimmick or app-download-bait.
Kept the app installed for about two months. Was still waiting for beta access when I uninstalled it.
I never used the app as browser or anything. Neither gave it notification permission. Maybe that was the reason.
This interface is a half page web form, right ?
Right ?
While I'm a happy user of DDG's search engine, their e-mail service is not something I'd use.
With apple, I believe the illusion that it’s not necessary for them to sell my data.
Do we have similar insights about duck, besides our believe they won’t sell our data?
> We will not allow an ownership change to weaken these privacy guarantees. DuckDuckGo (officially Duck Duck Go, Inc.) is a privately held, independent company, and has been since its founding in 2008. If we are ever acquired by another organization, or if another organization purchases this service, we will email you with details. However, we will not proceed with any deal that weakens these Privacy Guarantees.
As a (former) lawyer, I'd say that this provision is something I've considered necessary for a business to make a credible promise not to sell out at a later date. I have never seen such a provision before, and it makes me feel more confident that they've thought this stuff through and are willing to be held to their promises.
But yeah, there's always a chance that these protections will go away. That's why it's important that they don't keep data right now, so if anything changes later you can just stop using the service (assuming you check HN daily so you'd know if anything was up!).
The nonprofit would be financed by ddg or whoever buys ddg, but the management of nonprofit would be forbidden from sharing the data regardless of how much anyone pays.
At least I think so.
err no.
I love DDG and have run web search through them since they started, there are great
But I already have mail clients I use and they are not for for hand held computers owned by by G or A.
I just downloaded it and think I'll enjoy it if it doesn't have the browsing quirks of firefox, it has a great "inferno" animation when you hit the button to close all tabs and delete history. Works with my password manager, promises to block trackers, meh, why not?
So will SpamGourmet[2].
Of course the problem with all these services is that you're giving yet another third party access to your communication and giving up your privacy to them.
They are all, as far as I know, completely unaccountable regarding what they do with the information they get from your private communication.
No matter what they say in their privacy policies, press releases, or PR, there's no way (as far as I know) to reliably verify any of their claims.
That said, I'd still rather deal with a company which at least claims to respect privacy rather than one that (like Facebook or Google) either spit on it or make money off tracking me and datamining everything they can about me.
[1] - https://www.fastmail.help/hc/en-us/articles/4406536368911
Masked Email gives you more privacy (the identity behind the receiver is unknown) and with data breaches, there's is no login data leaked.
Duck's Email Protection does also remove trackers from the forwarded mails. So senders can't trace back whether you have opened the mail. I hope they also remove click trackers, but I am unsure how they would implement that technology with the referral codes in the URL.
most they should know is it was delivered. which is significantly better than nothing.
Let me know if there's anything you are missing from your existing email service, always looking for ways to improve!
If someone's mail is compromised, or they lose their primary email address, a refund would hardly make up for it. This basically reads as "you'll have to force us to participate by taking legal action"..
Would you expect language that offers compensation for any damages incurred, for example due to a hack or the loss of an email? I do not believe any email provider has such provisions. Of course we are still liable for any misconduct as specified by law.
Would this not be a process of consumer arbitration?
For example, If I believe there is misconduct, a GDPR or privacy violation say, is the process not to open a dispute with the EU, and then maybe go to an arb? I'm not aware that other email providers say upfront that they wouldn't participate in such a process.
But I will have another look and probably support it when I find some time.
Edit: It's fixed now, we support the process. But please just send en email to us it's much easier ;)
EDIT: I should also mention most disposable email domains get added to the denylist after much use/abuse. By multiplying the domains/IPs serving disposable mailboxes, we greatly reduce the chance of being listed at all.
So I guess I’m making things slightly better for everyone :)
Edit: Though I may be mistaken: I haven't tested them in years.
Surely a more productive way to solve this is to not use such a terrible service? Rather than having to resort to a third party to strip it for you...
The nasty thing is that an increasing number of businesses block such onetime addresses (there are lists on github). Linux Foundation a prominent offender. They send me their marketing BS, but I cannot unsubscribe because "my address is invalid". My bank is a recent addition. They still send me email, but several functions in my online banking don't work because I have to "confirm" my email first and the one they have on file and works is not accepted.
I hope such services would be widely used that no serious business can afford to block them.
From a businesses point of view it's a tricky one because disposable addresses are widely used when someone's trying to abuse a service. Personally I find blocking email providers pretty gross, but you can see how someone facing a torrent of malicious traffic from accounts associated with disposable addresses could get annoyed enough to just block them.
15 years ago, a catchall email domain was unthinkable since spammers would try dictionaries of words against a domain in hopes of finding legitimate email addresses. However, this no longer seems to be a trend.
If the day comes that people can't use their own domains then companies will effectively cut off the very communication with their customers and prospects they desired to have in the first place.
I have noticed that more websites are starting to block Mozmail but I am quite happy about the services so I will probably buy the subscription service and use a custom domain.
I've been working on a similar project: https://shroud.email. It currently has basic tracker blocking like duck.com, but it's FLOSS and I'm working on docs for self-hosting.
With apple, I believe the illusion that it’s not necessary for them to sell my data.
Do we have similar insights about duck, besides our believe they won’t sell our data?
Nothing really guarantees anything, and your data can leak to others even without intent to monetize, as we saw with Siri.
So I generally avoid services than can, not necessarily plan to, misuse my data.
(Disclosure: I volunteered for ToS;dr.)
I see it says that now, it just didn't register to me
Does this work with gmail for anyone else? It definitely does not for me.
Seems like there was a light delay in rolling out, or perhaps a bit too early PR.
Great work, but they desperately need to rebrand.
Worth mentioning that its back-end app[1] is also open source, not just their Android[2] and iOS[3] apps. So basically open source + custom domain = no lock in. But I'm not so sure how easy it is to set up your own back-end server (I imagine it's like setting up your own email server, which isn't trivial)
[1]: https://github.com/simple-login/app
Is it the @duck.com domain or removing tracking pixels in emails (which every decent email client does already anyway?).
(Disclosure: I work on Firefox Relay and also use my own custom domain with a catchall.)
- different email addresses can't be cross-referenced
- spammers can't guess additional emails to reach you at
- no risk of leaking personal information via the domain
I appreciate that there's definitely a risk in adding a third party, but I think it's clear that there's also benefits of a shared domain, making it a trade-off?
(Oh, and to be fair, with a custom domain there's a relatively similar risk: it's relatively easy to lose control of a domain.)
The risk of leaking personal information via a domain is the same risk as giving your real name when you signup for a service, or use your real name when you send emails. Most registrar solutions have a proxy WHOIS and if someone serves a court order to get your real name they are just as likely to get it from your registrar as they are a third-party company. Losing a custom domain is about as risky as picking a shady registrar, doing illegal things which will get you banned from an alias service if they are getting subpoenaed about your illegal stuff, or not paying your bill. I still think it is inherently better than an regular alias domain which is much more likely to get blacklisted than a custom domain.
Oh sure, I can do that! So for me, one reason to use aliases is to be able to trace who leaked my email. However, it's pretty obvious if my email address is news.ycombinator.com@mydomain.com, that everything @mydomain.com is going to me. (And possibly, but I'm not an expert on this, if you use a service that handles that for you, it might even be automatically detectable via my MX records?)
And if you know that, you can both know that facebook.com@mydomain.com is also me, and that you can send me an email at whatever@mydomain.com to also reach me.
Whereas if my email address is, say, sd4k23@mozmail.com, then you can't know my other random aliases, while I'm still able to see who I gave that email address to via the relay.firefox.com dashboard.
> The risk of leaking personal information via a domain is the same risk as giving your real name when you signup for a service, or use your real name when you send emails.
Yep! I'm just saying that minimising the opportunities for me to make a mistake is a benefit.
Note that I'm not saying you should switch to a service like this; I'm just trying to show why I've started using both: my custom domain for sensitive services, and Relay for one-offs/few-offs (e.g. if I just want to get a coupon code or something).
SimpleLogin for a custom domain uses MX, SPF, DKIM, and DMARC records to help protect you. Yes, if someone does a reverse lookup they can detect that you are using the service, but if you are using an email forwarding service they can more easily detect the provider. I find it very rare for anyone to actually check the records. With their custom domain service you can also use a subdomain, so instead of polluting your bare domain, you can create a unique subdomain for email addresses. You can also use random aliases, so the addresses are not easily guessable (at all).
> Whereas if my email address is, say, sd4k23@mozmail.com, then you can't know my other random aliases, while I'm still able to see who I gave that email address to via the relay.firefox.com dashboard.
No, but then I know the entire mozmail domain is shared and so spammers will target it more frequently.
> Note that I'm not saying you should switch to a service like this; I'm just trying to show why I've started using both: my custom domain for sensitive services, and Relay for one-offs/few-offs (e.g. if I just want to get a coupon code or something).
I can agree there, if you are just creating temporary emails that you don't care if you lose then an alias-provider domain is fine. However, like most people the risk is that they either don't use an alias for other services that are more important or that they do and then the provider shuts down and they can't verify their account.
Is this true? That sounds very illegal, at least in Europe under GDPR.
I don't know about GDPR, but usually a company has your email after you do business with them, so you probably implicitly agreed at some "continue" button to let them use your email as a part of marketing campaigns.
> The message will be sent from your Duck Address. Since DuckDuckGo doesn't create the message itself, we can't guarantee that it will not include your forwarding address or other identifiers.
https://www.mailbox.my/setup_clients.html
(Disclosure: My project)