The case for unique email addresses (2020)
musings.tychi.me
musings.tychi.me
Edit: multiple typos
lyft@account.example.com
liftcarshare@example.com
email@lyft.com.example.com
example.com@com.lyft.example.com
Generate random email addresses so you can't easily guess what others I might have given out. Then keep track of the mapping.
A service like simplelogin.io makes this easy.
When creating an account somewhere, fastmail automatically generates a new email for the site via an API in one click.
Highly recommend.
E: Ah, I didn't see the schema one of the parent commenters suggested - your question makes a lot more sense now. I still don't really care about the creation date, though, but I do care about the email having a random component, since if someone were to figure out my naming schema, they could check whether I've signed up for any given service.
Sometimes their front-end is not aware of this restriction and will let you register, but then you'll have unresolvable issues. I've spent some time on tech support phone calls with companies that have this issue.
Occasionally a company will implement blocking their own name in a user-provided email after the user is already registered. I've had this happen a few times too. Suddenly the account will disappear without explanation.
The way we don't see most software companies supporting linux desktop users simply because it is not profitable, we can hypothesize that the spammers won't spend time-energy-money on getting the +company filtered out.
One of them, Avvo, has yet to admit it... but it's quite clear.
Recently I had a text message to my phone number asking me if I wanted life insurance, and whether I preferred to be contacted at ‘tesla@<myserver.net>‘ or continue our conversation via text. I have plenty of life-insurance through my company…
Funnily enough, Elon didn’t reply to my tweet asking him if this was standard Tesla policy… Never did like that rat-bastard.
1. I allow wildcards only on a subdomain. The friendly alias on the top level domain is only for real human beings I want to talk to, not robots or marketers. I don't allow cold messages to the subdomain into my inbox because of issues I've had with spammers in the past.
2. I use a random username as the address and store it in bitwarden. It isn't named after the company but I can match it there if I ever need to. Recently BW added a generator for this, but I was already doing it manually by freehanding on the keyboard.
3. Seive rules. I put newsletters in a reading list folder, receipts in a receipt folder, etc. Everything else sent to that subdomain gets sent to a purgatory folder that deletes anything older than 90 days, so I don't accumulate a bunch of garbage. If I am signing up for a newsletter that I don't care about enough to tune the rule, then I probably wasn't going to read it anyways.
As a result I have not had a low value message reach a high value folder in probably 5 years. Skimming the folder I can see that Illinois politicians are still trading my address around even though I moved out of the state 4 years ago.
In a broader sense, as I learned to grow out of my 1990s-era rage about spam, I've found that my online life has gotten a lot less stressful. No, I still do not like commercial email in my inbox. But constantly being angry about it and trying to fight it did not result in me getting any less of it. All it did was made me a bitter person. Something something accept the things I cannot change...
Well no, not if you have assigned them a unique address. That is the whole point of the exercise, no? Stop doing business with them _and_ block their unique address.
It's completely disingenuous to say that you can't do anything with the information gained from learning who is selling, sharing or otherwise allowing email address lists to be compromised. It's almost maliciously disingenuous.
You can do infinitely more with this information than you can about any other kind of spam:
1) you can demand to know how and why your address was shared with third parties
2) you can insist on disclosure, particularly if you live in a state or country that mandates it, for any breach they may blame it on
3) if they ignore you, you can publicly shame them on social media and inform others
4) most importantly, you can STOP accepting email at that unique address, and stop any future spam.
I really wonder these naysayers want. They clearly want the rest of us to not expend the tiniest bit of energy to maintain any agency in the control of our own email, but why? I really wish I knew. They're not helping people by telling them to save - what? - minutes of time per month? I'm so curious.
No one is telling you what to do, they're just saying that they didn't find it valuable for them personally. My experiences are similar.
You can do whatever you want with your email (...except send me spam...)
You're going to need a hell of a lot of freetime to do all that.
I think it's a fucking travesty how quickly society rolled over on privacy and tracking because a bunch of short sighted people think its ok for companies to buy and sell your data, but it's such a common practice, and it's not like ANY of the above things are going to change shit.
To be blunt:
1) This going to be AFTER a daisy chain of emails/calls/both to get to ANYONE who feels like giving you an answer, and it's basically going to boil down to "oh its part of the TOS. Sue us or fuck off". The TOS is likely bullshit, but I hope you've got millions to prove it.
2) Again, even getting to this point takes a dizzying amount of time, and for what? To know they're greedy fucks selling your data to the highest bidder? You knew that the moment you got spam.
3) Uh huh. The kind of people who care already know. My experience with informing others about this has mostly been "so what". I spent waaay to long convincing people who HATE the current administration (from literally either side) that maybe it's not so great that amazon/facebook/etc knows damn near every single thing about them if they're one government request away from having it the hands of the people they despise. It's preaching to the choir at best.
4) Or you can just give out a junk account to start with and let them send as much spam as they want. If you really want to actually hurt them you should probably write a small script to hit a vpn, then open the email, then delete it (as clickthrough metrics are what they're looking at).
As for what "naysayers" want, well i can only speak for myself, and it's "real legal options". I think a lot of this is "security theater" with the amount of fingerprinting and other nonsense going on. You can spend all day trying to be the invisible man on the net and still have MORE than enough known about you because a friend or family member can't be bothered to care.
Absolutely wrong.
Go ahead and keep arguing for giving up. Good for you. And go ahead and bring up all sorts of incorrect or completely irrelevant stuff. Good for you.
The point is that I don't understand apologists like you who want everyone to just give up. Are you a paid shill?
There's no actual discussion of what a unique email should be. Or how that could possibly work and be practical given that any payment related site will also need your real name and address.
Which is unfortunately because the topics are very relevant to the modern discussion about privacy, and I think there are ideas in there that are worth telling, but in this form it's just hard to follow
Oct 2020, 19 comments https://news.ycombinator.com/item?id=24814029
Related recent quasi-dupeversation:
Using a catch-all domain is a mistake, 18 days ago, 296 comments https://news.ycombinator.com/item?id=31585463
It can be some secret mydomain.org, but that still links all my profiles together.
I could buy a different domain for every company, but that’s cost prohibitive, and also piercing WHOIS privacy is just another data sharing agreement away.
Posting this because I’m hoping somebody has a better answer.
https://support.apple.com/guide/icloud/create-and-edit-addre...
> Change the forwarding address Every unique, random address you create with Hide My Email is forwarded to the same email address. You can change the forwarding address at any time. On iCloud.com, go to Account Settings, then click Manage in the Hide My Email section. Scroll to the “Forward to” section, then choose a different address. The “Forward to” section is below your list of active addresses and above your inactive addresses.
what many sites don’t let you change is the address associated with your account, but that’s not the fault of the email provider.
BTW I build a simple spreadsheet-like GUI for Postfix to manage the list, as it's grown quite large:
I found problems with the + syntax occasionally, where I could sign up with that address but wasn't able to log in because their code stripped the + or the + and anything after that.
Now I do 3 levels:
1) use Hide My Email with most companies
2) use me@my_domain with people I want to talk to
3) use my gmail address with Advanced Protection for really important things.
I was going to use my_domain for really important things but it has 2 attack surfaces (registrar and Apple (I use their MX service)) whereas Gmail only has one. And there was an old (2014) article [0] here posted recently about how someone lost their Instagram handle because somebody social engineered GoDaddy into giving the attacker control of the person's domain.
[0] https://medium.com/@N/how-i-lost-my-50-000-twitter-username-...
At this point, I don't even bother whether I receive spam on that email or not, since it's just something I'm probably not going to read. I mean, who cares about LinkedIn notification or Amazon receipts, if I need them, I know where to find them. The default spam filter of my mail provider and a few custom filters based on from domain names are enough to keep my inbox manageable.
And even private mail is not that important anymore, given that most of the communication with real people is now done through various messengers.
Or I just receive booking confirmation minutes after booking. Even if I don’t read it or save immediately, it’s still there in inbox ready to be searched for and found if needed.
The only exception is business mail, but there I usually communicate only with people from my company or my address book, so there’s no spam problem there.
There are other benefits that the article author does not cover, that become clear when you think about how threat actors analyze breach data.
I've uploaded it to my GitHub: https://github.com/t0astbread/sievegen
Of course that's not a perfect approach in terms of privacy but for most purposes, it strikes the right balance between privacy and "hard to accidentally lose control of" for me.
Maybe there are security benefits? If every site has both a unique email and PW I figure automated attacks are a bit less likely. Could someone figure my clever email scheme out? Easily.
My thinking is it's like being chased by a bear when out hiking with friends. You don't have to outrun the bear, just one of your friends. I'm probably not willing to achieve perfect security, but if I can be slightly more difficult to figure out than <next person on the list> maybe that helps?
Edit: nothing to do with spam or even emails really, but here it is: http://www.angel.net/~nic/passwd.sha1.html
https://33mail.com is one, for instance (disclaimer: happy customer here.)
>>SMTP Error (450): Failed to add recipient "support@33mail.com" (4.1.8 <xxx@xxx.com>: Sender address rejected: Domain not found).
Hmmm don't even know how to contact them.
If you don't know, it generates a random email that forwards to your real iCloud account. You have full control on both deactivating the email (pausing it) or deleting it (permanent).
Apple will automatically suggest one of these emails when filling in an email form element which makes it even easier.
Incredibly helpful when signing up for new accounts or any other purpose.
Spam filters are so good that the spam never sees my inbox (I use RunBox.com email because of their extreme privacy).
The only downside: I have to keep this domain FOREVER. If I sell it, and someone else connects it to a mail service, they will have access to all of my email addresses.
https://www.vsta.org/spam/Traveler.html
(Ancient formatting, use reader mode if you're in Firefox.)
tl;dr Mail is broken because there's no authorization. Make your address act as an authorization token which is (1) transitive, and (2) revocable.