The author makes a good point, your email address is (arguably) more important than your home address. Perhaps there already are, but I hope for better safeguards against these kinds of attacks.
The author makes a good point, your email address is (arguably) more important than your home address. Perhaps there already are, but I hope for better safeguards against these kinds of attacks.
1. Specific known compromised TO addresses are sent to devnull.
2. Specific FROM senders are whitelisted.
3. Three or sometimes four heuristics engines evaluate. If any of them pass the mail, it goes to a separate new-senders inbox. I thus get maybe a dozen spam messages per week in that box - and five figures of messages rejected.
I used to tweak it a lot, now I just occasionally add another FROM address to the whitelist.
We need a law that just like you are required to let people drop from a mailing list, there's a law requiring one ack or click on a link to join a list. I always get on legit lists that will stop once I request. But in a month I get 100+ new lists often sending me 10-50 messages a day.
2) in case of hard to remember address, what do you do if asked to write it down with no access to your records? (It happened to me once before)
Something someone couldn’t guess, like:
<uuid>@domain.com
c4694056-63dd-476f-9823-2548aa3d754a@domain.com
> in case of hard to remember address, what do you do if asked to write it down with no access to your records?
It’s a tradeoff. You’d probably want to use the cryptographically secure addresses sparingly.
Another option would be to use your password manager to create a “memorable” password, which is usually multiple random words, like:
essay-curve-white-cable@domain.com
But again there’s only so many of these you’ll memorize, so use sparingly. Compare it to the cost of just changing the email. Maybe with a bank it’s more work and risk, so it’s worth the added effort, but if it’s the email you use to order pizza, just change it.
Say someone gets into an account you use to purchase stuff (Amazon, etc), but they don’t have access to your email account. They sign you up for this mail flood, then start buying stuff with your Amazon account, and legitimate notifications of purchases are lost in the noise with many thousands of emails from everything from Apple to Chuck’s Boat Rentals.
Using a unique and unguessable email lowers the chances of a more important account being affected (obviously at some point we’re splitting hairs).
2) Yes, this is a problem.
About once a month I go and drop myself from the latest lists. There are many magazines and whatnot where you can sign someone up for 100+ mails a day. Only a very few of them send you a message you have to ack to start the flood. Most just start the firehose without checking.
I'd like to hear what other people do to address this.