Everyone Wants Your Email Address. Think Twice Before Sharing It
nytimes.com
nytimes.com
It feels like retaining some semblance of privacy is a losing battle. Data clean rooms are industry standard now and many companies happily share their bounties with others for profit. That appears to be the future along with consolidating businesses based on data-driven insights for demographics. How are these kinds of practices still legal? When does data collection and sharing become such a glaring issue that constitutional rights can be invoked in a landmark lawsuit? Or can we expect anti-trust suits to limit companies hoarding vast repositories of data?
It feels naive to ask these questions, but they're fundamental to societal health and progress, democracy, and arguably the planet.
In the EU they are not, and as someone who has been using a custom email address for almost every service for the last 15 years or so, I have noticed that this almost doesn't happen anymore.
The only cases where an email address receives spam anymore is after breaches, or very old addresses that have been sold more than 10 years ago.
It's a bit extreme, but surprisingly little extra effort. That said, most of the accounts I create are throwaway.
For phone numbers I have an old, unused Google voice number I give out. It's a real number, but never checked, except for once every 90? days, to keep it active.
I'd love it if OnePassword integrated with something like https://randomuser.me to generate a new profile for every awful service that needs an account to work.
In the end in places like a store that wants you to sign-up for X% off, or something it's easier to just to give them storename@domain.com and see what happens.
It's actually pretty low friction in terms of management.
I have put in some blocks before where services don’t let you unsubscribe.
Fastmail masked emails + 1Password helps though.
I'm pretty sure even Google doesn't care about the dozens of people who use a different email address for different services.
It's a little friction, that maybe goes a long way. Pretty hard to actually evaluate though. Gives me the warm and fuzzies and I got to play around setting it up, so all good there.
I've thought through similar setups, but if the intent is to break cross-platform correlation to a user/device ID and related de-anonymization, I keep coming back to these questions:
- How do I know fastmail doesn't sell data? If every one-time domain is tied to a static fastmail account, and the fastmail account has my real info and sells it, then the obfuscation per-service is moot.
- Google certainly is selling data, and its hard to have an account with them that's totally clean and doesn't need an existing "anchored"/tracked piece of infra to set it up (existing phone number, etc). SO, the VOIP number from Google is once again linked up to my IRL data, and the obfuscation is again moot.
The best I can think of is the theory that a LLC's privacy protections will be stronger than an individual. If I wrap everything in a LLC (phone provider, AWS acc with services like Chime, etc), then the correlation surface areas looks like a random LLC using all these retail services and its delinked from my IRL, assuming AWS/Google don't protect a LLC's data from selling into adtech (and I speculate it might protect it actually).
So, it wasn't planned - it evolved. Somewhere in the Fastmail era I was reading their docs around wildcarding and thought I'd try it out.
My primary domain is my name though, so for extra privacy (anality) I bought another that has no link to me in the name.
There are still gaps in it. e.g. any merchant site still needs my physical address, and plenty need my cell number. But, generally, it's just an attempt to minimize a digital footprint and see what privacy I can get.
That and just why not? I self-host enough stuff, that I see this as another aspect of the same mentality - having a little more control.
It's not perfect security, it's not completely clean. Hopefully it's enough to get me out of the easy target bucket though.
I spent a good while reading about adtech from the practitioner side (i.e. adtech devs) vs. from the privacy side, and it was illuminating. Basically, the fears of privacy advocates get laid out in plain "this is a great feature for user correlation" speak, without any of the feature-masking used when adtech discusses it in privacy terms with privacy-conscious audiences.
In short, my takeaway from that research was it only takes 1x merchant or infra provider which can correlate a "masked" domain/VOIP number/PO box with something IRL of yours to basically undo the whole privacy effort. Without ironclad knowledge the vendor doesn't sell data (which is hard to get), it's as good as safely assuming the data got sold (or the pixel in the webpage did it, and so on).
Tough to think through! I think LLC'ing ones life, if in the US, is the only way to truly do it or get a reasonably high guarantee. You'd get corporate privacy guarantees which are unfortunately stronger than individual privacy guarantees in the states.
Did you find any interesting results from your setup? Some surprising services who sold your address?
Could also be that Fastmail has good filtering.
Could also be that random domains aren't that valuable to sell.
One of the surprisingly useful areas is with deliveries. Emails from delivery companies (especially from abroad) often don't specify what it is they're delivering or who it's from. But with this set up I can easily check that with the email address they're sending to, to know who it's from
I also use catch-all and no noticeable increase in spam.
It even works multi-level, like x.y.domain.com will use the MX records of domain.com (provided there are none for x & y).
This is worth mentioning as x.y.domain.com does not work if you have a *.domain.com SSL certificate.
It seems that fastmail only does *.domain.com and not *.*.domain.com: https://www.fastmail.help/hc/en-us/articles/360060591053-Plu...
Hope that helps
For some email providers, if you add a "+" modifier to your email address, anything after the + will be ignored and still routed to your main email address. But email systems will still treat them as unique email addresses. (So abc123+Netflix@gmail.com and abc123+nytimes@gmail.com would both be delivered to abc123@gmail.com.
This limits their ability to link your accounts against each other. And you can see if someone shares your data when you start getting hits on your Netflix email address.
Firstly, we can see that they're using the email exactly as provided (for sending, at least), else filters on the mail we receive wouldn't work.
Secondly, the + trick works because it's valid in email addresses under RFC 5321 and RFC 5322 - the fact that Gmail (and others?) direct all addresses of the format 'foo+bar@gmail.com' to the mailbox of 'foo@gmail.com' is a quirk, not a given. Anyone wanting to trim '+bar' would have to know it's safe to do so for particular providers, and I doubt anyone wants to maintain that list and do extra backend work just in case they want to share on the sly.
Gmail is also pretty popular, so it's not much work to just hardcode it there.
Also, most of the automated email systems are not as sophisticated as people think. Ours actually relies on + wildcards for internal testing.
If you are just trying to datamine for random email addresses, you can do that with a random string generator. If you want a list of Netflix customers accounts, you probably want the same exact email they signed up with.
Besides, you can always make a Gmail rule to junk any emails coming in without a modifier.
I'm not saying they will strip out the + from the primary email address used for login/etc - that would be dangerous for many reasons and could deny access to users.
But they are absolutely likely to strip it out for obnoxious behavior which is only valuable at scale and individual failures don't matter - such as ad targeting, email spam, etc. In this case, it doesn't matter if you fail to spam the 0.001% of users with + as part of their actual username if it means you manage to spam the 2% that use + as an alias separator.
I'm not saying there is not someone out there trying these shenanigans, but in 95%+ of situations you are still going to catch people sharing your data with a + modifier.
This sounds extremely naive to me. Why would it limit their ability when this feature of gmail has been publicly known forever? All they need to do is ignore everything after the plus when cross-referencing accounts.
Capital 'S' spammers don't care because they hit wide swaths of email addresses by generating random strings. They don't waste money buying data.
On the other hand, when someone is buying your data from Equifax, there might be some real bright actors out there, but the majority of firms engaging in this kind of behavior are not as technologically robust as you would think. So you will still catch people sharing your email address regularly.
Besides, if you have + modifiers in your email, they don't know what sort of shenanigans you might actually be doing with it. For all they know, it's a DLL with a re-router or it junks all non-modified emails.
In my experience, a private email domain is a neon sign for spammers. I would never recommend a private domain for privacy or anti-spam reasons.
I do get a lot of spam sent to [someone else's email] where my own email address was BCC'd.
- My main personal address is the most protected and only give it out to friends, bank, family, etc.
- I have another address that I give out to Amazon, ebay, couple other trusted merchants and websites.
- Next lay down, one I use for merchants I don't particularly trust like AliExpress. In addition, I only use the credit card that lets me generate a number, set max spending limit, and expiration.
- Finally I have a couple that I use for general websites that I figure either could get hacked or I don't trust at all.
While not 100% accurate, I can tell who has sold or "lost" my info based on the spam I receive. My main personal has some spam but I think it stems from contacts that had their accounts compromised and their contact list was snarfed. Overall the less I assume I can trust the other entity the more spam that account has.
It is funny how accurate the tracking is though. I can search for something on my gaming pc and then a week later I see related ads on Youtube and sometimes even Tubi. My Amazon account uses a different email address than what I used to search on my gaming pc. While my gaming pc has accessed both gmail accounts, they weren't even logged in at the same time. I suppose they rely on IP address + IP metadata and collected advertising metadata to correlate accounts.
I thought since the spam floods of the early 2000s everyone knew not to put their real email to get that 5€ off coupon.
Of course tracking is a thing now too. But most people I know, even non techies are aware of that and very reluctant to give any information.
I didn’t run into the issue you mentioned, but I ran into the issue of Sony (for the PSN) telling me they wouldn’t delete a duplicate PSN account I had (conflicting with their support docs), after I waited 40 minutes to speak to someone. When I tried to bring up the support docs they ended the conversation.
I had a similar issue with Rockstar, where I ended up in captcha hell, having to solve 30 puzzles in a row for each login attempt or and again to get into areas of the site to change things. The site would not function. I got fed up to the point of wanting to delete my account. I don’t use it anyway. I did whatever the site said to do, and it said it could take up to 30 day(?). That was probably 3 months ago and I haven’t heard anything.
These two things make me uncomfortable deleting one of my Gmail accounts, so it’s still hanging out there.
I am currently paying for a US phone number I don't meaningfully use, because it's not clear that all of my important account-holding organizations reliably support a two-factor/login confirmation strategy that isn't "US phone number".
I don't care about Fox News specifically, but I hope this trend requiring sharing an email address to view ad-supported content doesn't become more popular. An example of this on Fox News is this article, which requires an email address to view: https://www.foxnews.com/world/navalnys-body-reportedly-found.... Technical users can limit tracking by using email relays, but this is a big ask for non-technical users.
Isn't this kinda normal now anyway? Like its a fact of life, not much you can do about it, why not hand out your email, its probably out there already anyway.
(OTOH I change my email every 5 years or so)
https://www.fastmail.help/hc/en-us/articles/4406536368911-Ma...
I do this with a generic-sounding domain (...mail.tld), and I purposefully don't have catch-all enabled for this domain. That way, when I disable a masked address I completely block the service I used it for from sending me emails.
To further reduce ties to Fastmail, I believe you can export a list of all your e-mail addresses used.
Also the Bitwarden password manager has an integration for SimpleLogin.