I'll look into this now that it makes more sense, thanks for the advice!
34 karma · joined December 5, 2020
I'll look into this now that it makes more sense, thanks for the advice!
I think it's cool idea though and I might give this a shot, thanks for the idea and if I do implement this then feel free to contact me through the form and I'll set "lifetime" account up for you!
I will take a closer look at this and see if it's possible to improve it in some way.
Thanks for the kind words also and the same to you! =)
Best of luck with the service also!
Feel free to share a link to your service as I'd love to check it out and best of luck running it also!
In this day and age I don't understand why they wouldn't be able to just use a headless browser instead of doing it manually - has labor really become this cheap?
Imagine having to tell someone that you can't access your accounts because you retweeted something that wasn't deemed acceptable.
Perhaps if we're lucky we will advance to having the big corps create a social credit system for us as well, ha!
- Be hooked to a bunch of paid plans for stuff that's currently free.
- At the mercy of all the big providers that could one day just decide to turn our account off without a reason.
- Receive more spam than we currently do as all service providers would have our email addresses. Although these would all be aliases, we would have to spend a decent amount of time organizing folders, identifying which aliases that are receiving the spam and turning these off without losing access to the account.
I referred to your other points in detail here also: https://news.ycombinator.com/item?id=40968143
I really enjoy that you challenge my views on this though as we both have the same goal of stopping abuse on online services, while at the same time preserving user privacy. Your plan would work if all service providers were honest and didn't abuse your trust, my plan currently works and I'm no longer getting emails from politicians asking for donations.
I've given this some thought over the years so I know where I stand morally. As I've mentioned several times already, the issue lies in the service provider for forcing the user to give up their email address, in the majority of cases it will end up with you receiving spam from many different sources as your address will be sold, leaked and more.
>good luck
Thanks for the motivation!
> Make sure your cloud service allows what you're doing, make sure you have cost controls in place, and make sure you already have a relationship with a good lawyer.
Yeah, it's an expensive service to run (if you want to run it properly at least), but as long as it helps users and I see people sending in positive comments through the contact form, it will give me the motivation to continue.
A close friend of mine is a lawyer also so the day it becomes illegal to receive emails, I'll have to give him a call.
>Trials usually both restrict features like this and require valid payment info is already entered
That's good at least, but what I'm trying to say is that anything can be abused, the same way that the
>having websites all ask for people's phone numbers is way more privacy-invasive
It costs sites way more to send out texts than it does to send out an email, I'm sure that if we were to look at the overall amount of spam one receives in their lifetime, then we would see a great decrease. It's also a lot easier to stop spam coming from phone numbers as they are all registered and regulated compared to emails that aren't.
> you can keep your inbox clean without disposable email
You can also walk to the destination without taking a car, you can get fit without going to the gym and you can cook a meal without a recipe, but it won't be as convenient.
---
I'm starting to sound like a broken record as I'm just repeating myself, but to summarize things, we are both on the same page as our goals are to stop spam to users and abuse of services. The majority of the times an email address shouldn't even be needed and when it comes to sites where spam is more prevalent (e.g you mentioned The Verge), then they could simply verify your phone, payment details and a ton of other measures (captchas, checking IPs, rate-limiting, etc).
What if the Fastmail account is simply just using their free 30 day trial, how will they track the user then?
My point is that the malicious user will still have a way, while the legitimate user is punished by having to pay a fee to the email provider.
> Every time someone like you thinks this is okay, you make more service providers lock down what email domains they accept, punishing folks like me who just want their own domain on their email.
How about no one gets punished and service providers verify phone numbers instead of emails and we get to keep our inboxes clean?
I will definitely look into these solutions and although I've seen some of them around, there could maybe be a way to implement a better alternative that's both easy to use and safe so it doesn't get abused.
I understand what you mean, but it has to apply to the use-case. If the service I was running was to support journalists, then I would agree with you, but taking these measures would help promote spam as users would be able to get around the rate-limiting that I've set.
What is the difference between the two though?
This kind of reasoning is why people can't run their own email servers anymore and instead have to rely on the big services.
>If you know the space, you'll be aware CAPTCHAs are trivially defeated today, regardless of the provider.
They are a lot more reliable than an email which is basically just a domain that anyone can buy and setup within mere minutes giving them access to endless email addresses.
>you generally need some sort of unique relatively hard to get many of identifier
Why not use phone numbers instead if the issue is truly important to them? This would cost spammers and bots way more money than emails.
Perhaps it's due to the fact that they won't be able to use the phone number to send their spam (or they could I guess, but it would cost them some money).
B) That would make the UX horrible.
C) I had Tor enabled in the beginning, but when I got complaints from people on Tor doing really shady stuff with it I had to disable it.
But as a developer of these sites I've used the majority to check my own domains and the most reliable one I've found is https://www.ipqualityscore.com/
I strongly recommend that you take another look at your signup process though and don't require users to give up their email addresses, instead make it optional and present an alternative like a captcha.
You can get all the stuff you mentioned for a fraction of the time and money it would cost to create a disposable email service and then you would also only target the service you wanted instead of sitting around and hoping that a user creates an account at the site you're looking for.
The real value would in the reputation and history of the account (e.g a popular account on a social media site or community) and this isn't a thing that someone would use a disposable email service for as they wouldn't want to risk losing access to the account.
The majority of the work was done through testing lots of emails and I must have sent at least a thousands emails to myself from different providers and sites.
I've deleted the bookmarks in an attempt to reduce the PTSD it caused, but I think the main one I visited was RFC 1341 as I had some difficulties understanding the boundaries and encoding.
What was really tricky is getting it to work with all the different types as some emails didn't have boundaries while others had them, some were encoded entirely in base64, some partially, some of them were just plaintext, others were HTML while some were mixed or even offered multiple versions depending on what the email client supported.
Best thing is honestly to try it out and just pick a random address and send a really tricky email to it, would love to see you break the parser and telling me so I can improve it.
I've been thinking about open sourcing it if anyone would want it, but right now the site has way too little attention for it to get any traction. It's a really neat script though and it's also just one file and supports all the different kind of emails (with/without boundaries, base64 emails, attachments and some other stuff).
The only reason the service provider requires your email address is to access your data.