6 ms·
> Unique-per-service email addresses work pretty well as a canary for breaches I do this too, but it taught me everything is breached - the local ambulance ser
by CookieMon 10y ago
> Unique-per-service email addresses work pretty well as a canary for breaches
I do this too, but it taught me everything is breached - the local ambulance service, the local computer store, the local car share, small businesses overseas that I've placed orders with.
Some of the big names don't seem to be, which is lucky because otherwise I'd be wondering if it was the ISPs that had been breached. Either large chunks of SMTP routes are breached and picking up confirmation emails, or there's a giant iceberg of pwnage floating beneath the surface out of view.
- jmknoll 10y ago> giant iceberg of pwnage floating beneath the surface out of view Very poetic. I'd like to see this made into one of those motivational posters and hung in the office of every dev team nationwide.
- iamdave 10y agoThe tip would be labelled "User Config", while the remaining behemoth, respectively: "DNS". For the sysadmins out there ;)
- Syzygies 10y agoI used to use unique middle addresses for magazine subscriptions, back when magazines were physical. I'd get credit offers with middle name "Byte". Consumer Reports used to include a false advertising hall of shame; I loved sending them an example sent to middle name "CR". They didn't use it, or even answer.
- bo1024 10y agoOr these places sell / give away your email address?
- freshflowers 10y ago> it taught me everything is breached More likely, sold. Every service that collects user data will get offers, and many can't resist the temptation. Doesn't matter however, businesses that will sell you to the highest bidder (and in many cases, outside the US, illegally) can't be trusted to ever seriously invest in security. So if they aren't breached, they sooner or later will be.
- SixSigma 10y agoOddly enough I have had the opposite experience. I have been running per-service emails for 10 years and wonder to myself if it is worth the bother as I can recall only one ever spreading.
- arbitrage 10y agoThat has been my experience as well. Only one alias in about 10 years ever got undeniably sold, and that was because the company went out of business and probably sold their entire portfolio.
- tacon 10y agoMy experience also is that there is pretty limited sharing, even among business partners. The worst was when the idiots at Aweber, the email marketing service, were hacked, and I had waves of spam coming in on many per domain emails. Six months later, Aweber was hacked again. Another wave.
- CookieMon 10y agoInteresting. The plot thickens. I don't have any fancy script to check these addresses - I have to go into my spam headers manually, and I've not done that for a long time. Perhaps there was a common issue a while ago that got patched. I'll have to check whether modern addresses are being spammed.
- Uberphallus 10y agoMy favourite was the unique email I used for a Russian visa application. Either the consulate was ridden with malware, or they just sold my address.
- the_mitsuhiko 10y agoWere you actually at a consulate? Most russian visas are (pre)processed by private companies.
- dmix 10y agoIn that case there are probably lots of travel companies who would buy that email list.
- Uberphallus 10y agoConsulate. Most Russian visas in Europe are processed by consular services, unless you need it done quick and/or from a remote place.
- the_mitsuhiko 10y agoI got many Russian visas in my life in Europe and not once did i not use an intermediary. In Austria if you want to go thrrough the consulate you need to go through VHS first. In London VFS does it etc.
- tbihl 10y agoShouldn't the word be"riddled with"?
- frankydp 10y agoI would be interested to know if you use a provider or host your own email. I mention that because most of the ISP do have re-targeting efforts. Also it would seem more likely that your email provider is breached as opposed to lots of other companies/servers.
- inputcoffee 10y agoHow do you guys do this? IS there a service? Do you add na.melast@gmail Or do you create them on your own domain through the hosting company?
- lobster_johnson 10y agoI use Fastmail, which provides very nice wildcard aliasing under a domain. *@mydomain goes to a single inbox. I can also create specific aliases such as foo@mydomain.
- whateverdudes 10y agoIt's often called plus addressing. Quite a common feature in mail servers and mail services. MyName+<any-random-text> at gmail.com ends up in MyName's mailbox.
- bad_user 10y agoI also do unique aliases for each account I have. Few of them have been a source of spam. I also have expiring subdomains. So I'm not using domain.com, but something like b2.domain.com. The rationale is that if I start receiving a lot of spam, I go through all the accounts I have, change all emails to use another subdomain like b3.domain.com, and then invalidate the old subdomain entirely. I haven't had to do that yet and my domain is several years old. With two big exceptions: the email address I leave on my website and the email address I publish on my GitHub profile. These 2 have dedicated throwaway domains like throwaway283728@domain.com. Because you wouldn't believe how much spam I get from that GitHub profile, not just recruiters, but also get rich offers from princes in Nigeria and Viagra pills.
- initram 10y agoBack when I ran a mail server for a small business, I would see the spammers literally going through all the permutations of email addresses for a domain. In the logs you'd see: failure to send to a@example.com failure to send to b@example.com ... failure to send to aa@example.com etc.
- update 10y ago> it taught me everything is breached Everything is breached. From websites to software to hardware, I would estimate the majority of them can be/have been exploited by advanced hackers. I'm awaiting the time when we all acknowledge that computers are fundamentally insecure.