Yes, and choldgraf@gmail.com and choldgraf@ibm.com are different email-people, too. This is not a hard concept.
Yes, and choldgraf@gmail.com and choldgraf@ibm.com are different email-people, too. This is not a hard concept.
It's not a hard concept, but it's a concept that was only ever explained in school to a sliver of the population actually using email every day.
Plus, federation makes validating accounts real hard. Looking for a semi-popular Twitter user on Mastodon will bring forth 800 Twitter-to-Mastodon-bridges with plausible-looking domains, only for the real user to end up using something like "hachyderm" as their domain name. I don't know any good solutions to this problem, but that doesn't make the problem go away.
You'd be surprised (well, nobody here on HN would be) to know how many times I tell a business that my email is "their-business@my-domain.com", and they ask me how I got that email address, whether I work for their company, etc.
I once started receiving spam addressed to <mybankname>@<mydomain>.org and after several instances I reported it to MyBankName.
I explained that I only used that address in my dealings with them and so it must have leaked from them.
They said that's not how email works, you have one address that you use with all your contacts. One of them must have leaked it.
I tried to explain that I used a different host portion with each company I contacted.
They said that's not how email works, you have one address that you use with all your contacts. One of them must have leaked it.
I transferred my balance out and let the account lapse.
1. Prepend "from-", so that instead of <their-business>@example.com you give them from-<their-business>@example.com. It should at least make it easier to explain your approach when you have to.
2. ROT13 or reverse the name of the business so it's gurve-ohfvarff@example.com or ssenisub-rieht@example.com. You can design a different stateless function that maps names to email addresses. The function doesn't even have to be invertible. This is similar to a stateless password manager like https://www.lesspass.com/.
3. Use a list of pre-generated addresses you keep on your person. Think recovery codes. Of course, you can keep the list on a smartphone.
> That's why I've updated my SMTP config to handle the hyphen character the same way as the plus sign over 10 years ago.
That's clever. But doesn't it cause friction when trying to relay the address e.g. over the phone?
> to avoid "why is my business name in your email?" questions, I rot13 it.
That's a neat idea.
Every time I have to hand out my email over the phone, I brace for having to explain my catch-all to people. Depending on how tired/tech-illiterate the person on the other end sounds, I've started using plausible-sounding alternatives (contact@/hello@/email@) instead.
It's not obscure. Some code monkey at Samsung was told to filter out certain addresses, Samsung ones among them, and just used a regex or substring search on the entire address.
It's not hard to someone with exposure to a certain medium. Though its a bit dismissive like it would be for a mechanic to question why a person doesn't know know about rotors, spark plugs and other "simple" car concepts.
Since I like surprises, do tell ... how many people think that?
Maybe more, but at least six of the emails meant for others that I've received, implied they live at those six unique locations.
I know one of them likes to get the vegetarian meal option when traveling internationally by plane.
(Companies should really validate email address OWNERSHIP before spamming innocent people.)
I don't understand why this isn't part of the normal flow for implementing Verify Your Email emails.
Someone used my firstname.lastname Gmail address on trip dot com a couple of days ago to book flights, and their Verify Your Email email actually had a Not My Email-type link in it... which apparently does nothing, as I shouldn't know that if you phone trip dot com about changing your flights, they send you an email with a Change Flight link.
I just got off a chat with their support, so hopefully my fat-fingered doppelganger doesn't miss their flights from Atlanta to Sydney tomorrow.
The alternative explanation, that they roitinely use [your name].[your last name]@gmail.com as their email, and don't realize that it never works is... unlikely IMO.
I can easily imagine there are a bunch of older people who do not have email addresses, yet just about everything requires an email address, even if it's not necessary for whatever service, so people have to either make up an address, or incorrectly remember what the address was that their children or grandchildren set up for them.
Either way, that doesn't excuse the companies that spam innocent people.
I get a pile of junk from people who assume they can do that. I guess I have a lot of stupid distant relatives. It was the same for Hotmail too I got so many hotel receipts, or resume replies etc. one went on for decade or more. Yes you can reply back "no this is wrong" but nobody listens.
Abandoning the concept of celebreties and instead using social media for social interactions with people who you can "validate" their identity by walking over to them and asking them for their ID.
So yes, you will have:
@stephenking.bsky.social
and
@stephenking.bsky.otherinstance
Unless Bluesky remains a single server, in which case it's not at all decentralized.
Also, Bluesky is a centralized view of the data in the decentralized ATProto network. This means you will never end up having the problem where searching for a user on one instance will not show up because they are on another instance that they have not federated with. There are obviously tradeoffs with this, but IMO they do seem sensible. The nice thing about Bluesky is not that it is decentralized (it's not), it's that the data that it let's users interface with is decentralized, and if something goes south with Bluesky, another application can be built on the same data and users can migrate without starting from square one.
But there are moderation lists that you as a user can subscribe to. It wouldn't be hard to find a moderation list for impersonators, which would solve this problem for you.
For the record, there are other differences - on Bluesky, you use your non-default domain to login in exactly the same place, there aren't 'weird gaps' between different domains.
@zuck.bsky.app
and
@zuck.meta.com
are two different accounts.
The only “problem” bsky solves is choosing a server. But if ATProto becomes widely used, the problem will appear as in Mastodon today. The only way to avoid it is for bsky to never become really decentralised. So yet another VC-backed social media company.
I think there's no two ways around it, @stephenking.bsky.social looks better than @stephenking@mastodon.social.
Blue Sky does the names better and opts people into a default server at the moment, and I would say their desktop and mobile experience is a bit better, and that feels like they've solved something specific and technical even though, as you pointed out, the issue with domains is the same in each case.
1. That didn't work as I expected.
2. I am confused!
3. Oh, that's how it works! I learned something.
Humans go through this every day, in domains technological and not.
Sorry for the rant.
It just goes in circles with personal anecdotes that always coincidentally corroborate whatever position someone was already arguing for anyway. What would be really interesting to see is someone making the case against Mastodon but acknowledging that "people I know" weren't confused by it or vice versa.
It would be clear we were at least talking about things where "the people" had reactions to specific things for specific reasons that were in principle solveable and not merely ghosted into existence to support a point the commenter wanted to make anyway.
I think people see one another doing it and kind of collectively converge on this ritual of collective storytelling where we offer anecdotes that don't offer any kind of truth tracking accountability.
The Web still lacks a first-class concept of a user identify that you can take with you across servers.
But now you can, so we're on to the next whack-a-mole.
But it's not a hard concept, it's just unfamiliar to them.
People being confused by a concept after it has been taught to them suggests that either the concept is hard or the educational process inadequate. Confusion on initial introduction has nothing to do with difficulty.
are hard concepts from math and science bad concepts? should we discard calculus?
is potty training a toddler a bad concept? they initially struggle with it and some find it hard
is a healthy diet a bad concept? people without prior knowledge of what's healthy and what isn't are likely to struggle
I completely understood the function of the usernames from the start, but to this day I still sigh whenever I encounter a new Mastodon user on a different network because I have to do a song and dance to get them followed on my main account. The whole thing is cognitive overhead I do not want.
I work at a company that relies on engagement with customers over email I'm sure plenty of other people here do as well, and whatever people's confusion with email, somehow they figure it out when they need to and the world seems to keep turning.
At some point this conversation is no longer about the specifics of Mastodon or BlueSky, it's just general information literacy and functional literacy.
Hilariously, arguments of the form "what if people do it wrong" like this were made even for the introduction of calculators. I think it's better understood as an ordinary rite of passage than the specific identification of a genuine problem.