I have had this happen a few times.
> Canaries are also a good indicator to detect if a company has been compromised.
Yep, this is a fantastic use case.
I have had this happen a few times.
> Canaries are also a good indicator to detect if a company has been compromised.
Yep, this is a fantastic use case.
I've noticed a couple breaches, and also a few unexpected transfers of my email address between semi-related parties.
Just once it appeared an address was sold via a marketing list, after filling out a lead-form for a free online conference hosted by multiple companies that you've seen on HN.
Surprisingly, unsubscribing tends to stop emails from everyone.
It is fun to receive a survey about "an anonymous company you have used in the past"... sent to myemail+uber@gmail.com.
*yet less reliable, '+' in email addresses isn't always accepted, and when it is sometimes only partly, e.g. signup works but password reset doesn't
Plusaddressing is valid and has been since 1982[1]. It's part of RFC822 and the subsequent RFC2822.
The fact that many websites do not allow + in an email address during validation is a common programming mistake and the sign of an undertrained engineer.
[1] https://people.cs.rutgers.edu/~watrous/plus-signs-in-email-a...
Or just sanity.
I am totally onboard (https://news.ycombinator.com/item?id=31797121#31822961) with having compliant parsers (or just not using them)
But the RFC from what I can recall is _wild_. I can't find the part so maybe I am mixing something else up, but I believe you can embed comments into an email address.
All I am saying is that the possible scope of valid email addresses is likely so large, trying to write a parser for them is a sign of an underexperienced team rather than not having one at all.
There won't be a general approach to deduplicating addresses that map to the same mailbox as the mapping rules aren't always public. But for Gmail, the rule is public, so a best effort deduplication could strip the +.
Also, depending on the legislative framework, it might be illegal: If I give company my email address with a plus and an identifier in it, I give them permission to contact me under that specific email (with the plus on it). If I as a result receive emails under another address (without the plus on it), this might be a GDPR violation.
For example: A lot of pentesting companies offer "darknet research" as part of their engagement; these have a non-nefarious use for these leaks, including private addresses: Given a list of customer's employees it's easy to guess some obvious Gmail/GMX/Yahoo/... addresses and check if they might be affected by any leaks (password reuse is pretty popular, especially with the not so technically minded). Troy Hunt, who runs haveibeenpwned, uses these lists as well; I suppose he normalizes Gmail, too.
Yes, OP could still be an evil /dudett/..., but while "innocent until proven guilty" might not be a HN rule, it's still something I like to assume about random people in the internet.
Not that spam laws are enforced or particularly enforceable.
In either case, the existence of the different authorised email address is irrelevant.
I used to use + addressing schemes, but abandoned it for the reasons you mentioned (websites breaking horribly).
I think there’s an unofficial Terraform provider but I haven’t looked recently.
Nice, hadn't thought about :-)
My favourite is services that let you sign up with a + in the address but then break when you try and login or reset your password.
I personally use Thunderbird and AWS SES to send mail, but many people who grew up on web interfaces are intimidated by Thunderbird.
That surprises me; it's web interfaces that intimidate me.
It's the only thing I missed when I switched to Fastmail. (Which has since added it too, but not before I left in favour of my own SES-based solution.)
Iirc there was a section of settings called 'sending & receiving', and there was a drop-down to select 'reply from same address' or similar.
I.e. if your main email address is ojford@ojford.com but you're also preconfigured e.g. foobar@ojford.com you could set that option to have Gmail use either ojford@ojford.com or foobar@ojford.com as your return address, depending on the originating email's TO address. However, if you _also_ have a catchall address and somebody sends to newservice@ojford.com, even with the setting set your return address would be ojford@ojford.com.
How does it work?
If a company to which you have provided an email address, gets compromised, it's likely that you'll start getting automated pishing emails to that address? And that the address ends up in... some "warning" database like Have I Been Pawned, and you'll get notified?
Or something else?
Seems like a good idea :-)