(This is what Tildes use: https://tildes.net/settings/account_recovery , and I found it very genius)
(This is what Tildes use: https://tildes.net/settings/account_recovery , and I found it very genius)
I like Apple's approach to generating random throwaway emails.
I also like apple’s method, but it is not either-or.
Perhaps someone should deliberately leek a bogus database that contains the bcrypt hash of davey.jones.490@well-known-email-provider.com and see if that account starts receiving spam ... probably it won't.
There is (almost certainly) no associated e-mail account, but the following is the SHA-256 hash of firstname.lastname.threedigits, something like "davey.jones.490". I'm half-expecting someone to reply with the solution, though I think there are about 36 bits of entropy in my choice:
b8b6395265714064afb525f37e9969a7dbf09a4a2afa28812e917580be2dc667
It does not work if you actually want to send emails, for instance notifications.