33 ms·
Show HN: NBox – Sign up anywhere without giving your email address
- bdav24 9y agoHi, I'm David, one of the developers of nBox. nBox generates for you an email address for each site, for free. - Effortlessly thanks to our browser extensions - Addresses are anonymous and private - Delete the addresses you don't want any more - Be notified according to your preferences on each email I'm looking to share the service. Any feedback is very welcome. Thanks!
- deft 9y agoWhat's your plan when every site starts banning your addresses? I have to spend 15 minutes to find a new non-blacklisted temp-email service every time I want to use one.
- bdav24 9y agoHi deft, that's a concern we have. Some services might block our addresses some day, but that would be a mistake because nBox is not a disposable email service.
- slg 9y agoMy hesitation in signing up for any of these unifying products is the potential lock in. If I start using your service and eventually have dozens of sites directed through you, what happens when the product disappears? My question is therefore how do you plan to fund this indefinitely if it is "Just Free, Forever" and is unlimited? You say it is part of promoting your brand, but it looks like that brand (or at least the domain) has been around for less than a year, so not much history. If it isn't you company's main product, what is to stop you from deciding the costs of providing this becomes too expensive for the promotion it is giving you?
- f4rker 9y ago>Effortlessly thanks to our browser extensions That's pretty cool
- ecesena 9y agoCan you say something from the service perspective? Why shouldn't a service flag you as malicious and refuse users with email from your domain? What do you do to prevent mass account creation on the service? Thanks!
- bdav24 9y agoHi ecesena, > Why shouldn't a service flag you as malicious and refuse users with email from your domain? Some services might block our addresses some day, but that would be a mistake because nBox is not a disposable email service. > What do you do to prevent mass account creation on the service? If your question is in regard to services which might block us, I don't think they care about mass account creation, a few email addresses are enough to bypass limits on emails.
- ecesena 9y agoThanks! The non-disposable is a good point. As for my 2nd question it was related. Often time spammers rely on tools like nbox to create a massive amount of accounts on services like Winterest, so Winterest has to flag your domain as potentially malicious. I was wondering if you have any countermeasures to this problem, such as a rate limit on the number of accounts one can create per service. I'm sure Winterest would appreciate :)
- bdav24 9y agoYou mean fraudsters trying to take advantage of account creation on Winterest? For a given service we authorize only one address, but we haven't implemented a rate-limit yet.
- ecesena 9y agoYes exactly, fraudsters exploiting your service to have as many email as they need to create very many accounts on Winterest. If you have 1 single email account per service that is fine. I think you should call out these two aspects on your site, to show that you're increasing privacy for users, but also protecting services from being abused exploiting nbox. It should reduce the likelihood to be blacklisted.
- highstarter 9y agoIt's a neat concept and useful especially for heavy internet users.
- ianai 9y agoI need this for cell #s Having said that, I plan on using this.
- alkonaut 9y agoHow does it work? I mean how does it generate addresses that aren't blocked by the a services (like mailinator and similar throwaway email sites)? Does it use thousands of random domains?
- bdav24 9y agoHi alkonaut, the domain is unique at the moment. Some services might block our addresses some day, but that would be a mistake because nBox is not a disposable email service.
- jswny 9y agoSo how is this different from something like Mailinator.com? In my opinion, I can't see a use case in which I'd care enough to have my temporary email private. If I cared enough I'd just use my real email.
- jacobwg 9y agoIf I had to guess, requiring that each email address be tied to an individual person would allow NBox to stay off "temporary email address" blacklists. It's a privacy service essentially, not an anonymity service. Same reason why credit card masking services are legal, but Visa/MC/etc wouldn't allow a mass-shared CC number.
- alkonaut 9y agoBut a throwaway gmail account works the same yes?
- bdav24 9y agoHi alkonaut, yes it works the same, but it might end up piling up.
- Ajedi32 9y agoGmail accounts sometimes require you to give a phone number in order to register a new account. Not to mention creating a new email address with this looks way easier than signing up for another Gmail account.
- ryan-c 9y agoIt will not keep NBox off blacklists. I've been using sneakemail for this for like fifteen years (and they do not offer a free service), and I've run into a number of sites that ban their domains anyway. Adafruit, for example, bans their domains.
- bdav24 9y agoHi jswny, jacobwg is right, the addresses are private (and anonymous because we don't ask any information). I'd say the use case is to filter "semi-wanted" emails.
- deleted 9y ago[deleted]
- cdubzzz 9y agoWhy is it required to enable notifications from the nbox site in order to generate an address?
- bdav24 9y agoHi cdubzzz, no it's not required.
- cdubzzz 9y agoHere is what I see after I click "GENERATE AN ADDRESS" > "Generate an address for any other reason": http://imgur.com/ktTssbB http://imgur.com/ktTssbB If I click "Not Now", the prompt goes away and nothing happens. Perhaps I am misunderstanding how the service works?
- bdav24 9y agoHo sorry you're right, technically accepting webpushes is not required, but it's part of the tunnel for now. We're currently changing that, but it's not finished yet.
- cottsak 9y agoYou'll need to fix that. As other have pointed out: If I'm not a fan of spam then I'm likely not a fan of desktop notifications either.
- _Marak_ 9y agoAs an alternative, you could register a domain with a catch-all email address and simply register for new services on the fly using a unique string for each site. Have the catch-all forward to your main email account. For example, I would sign-up for HN using hackernews@marak.com and for Reddit using reddit@marak.com Simple and effective.
- chatmasta 9y agoIf you do this, make sure you lock down your account at your domain registrar. A socially engineered DNS hijack could be all it takes to obtain full read/write access to your email.
- SippinLean 9y agoCan you elaborate on the steps needed to ensure your security in this case?
- ryanlol 9y agoSpend a decent chunk of money to become a registrar yourself or go with MarkMonitor. I suppose google domains might be OK for personal email.
- sverige 9y agoThe other thing that happens is spammers use your domain to spam others. That catch-all will work for systems that test email validity for the spammer's made-up address on the From line.
- threatofrain 9y agoWould you mind elaborating? Do you mean socially tricking a GoDaddy or other domain registrar employee into changing DNS records?
- vr3690 9y agoYep. I do this and route my email through mailgun that allows me to setup rules for forwarding emails. Their free tier is pretty generous and works great for my needs. Also solves the problem of shoddy websites selling my email because I gave them an unique email address and can block all emails coming to that address easily, if needed.
- iliketosleep 9y agoI am trying to understand this. Appears to offer bulk accounts that are easy to create and permanent, targeting the market that sits between a) regular email addresses, which are permanent but a pain to sign up for, needing phone verification, etc. and b) throwaway accounts that are easy to create but cannot be kept long-term. This seems like an interesting idea if they own a whole bunch of different domains, but they don't specify this, and my attempt to sign up for an address failed. (open firefox -> click create my nBox -> click Sign up for a service (i type https://facebook.com https://facebook.com) -> receive message saying "To create your nBox Allow the notifications" -> No simple info about how to do this is given, so I give up)
- bdav24 9y agoHi iliketosleep, to allow the notifications a small window should appear at the top of the page. But not all browsers have implemented this feature. What device and browser do you use?
- iliketosleep 9y agoI'm using the latest version of firefox on win7. Upon further investigation, I think I know what happened now. There's a tiny box at the left of the address bar that enables me to unblock notifications for the site. Which means I must have automatically pressed the "disallow" button before even reading anything (a reflex response!). If I was you, I'd have an option to see a screenshot showing how to unblock notifications. It's always the stupid little things that can make a very big difference.
- bdav24 9y agoOk, I'm glad it works. Thanks for the feedback, we'll try to add that somewhere.
- ionelmarcu 9y agoA link to the chrome extension on the landing page would be quite useful (Otherwise visitors need to go to the chrome web store and search for it...and some of them are too lazy to do it). But otherwise I really like the idea. I'll give it a try ;) P.S. here's the link for the extension: https://chrome.google.com/webstore/detail/nbox-your-registrations-d/gjffheoeedkincollmimgklbckindfkk https://chrome.google.com/webstore/detail/nbox-your-registra...
- bdav24 9y agoHi ionelmarcu, yes that was our plan too (I shared before changing the account creation tunnel).
- tenryuu 9y agothanks ported it to Edge and Firefox https://github.com/Scrxtchy/nbox-everywhereElse https://github.com/Scrxtchy/nbox-everywhereElse
- bdav24 9y agoHi tenryuu, you're right extensions can be ported more easily than before, thanks for your contribution! The Firefox extension was following the validation process, it's now published: https://addons.mozilla.org/en-US/firefox/addon/nbox/ https://addons.mozilla.org/en-US/firefox/addon/nbox/
- ikeboy 9y ago1. Great idea. It's been done by Blur from Abine.com which I've been using for years. 2. Possibly offer the ability to self host this?
- bdav24 9y agoHi ikeboy, you're right the idea is not new. We don't plan to offer this possibility for the moment, but who knows, maybe one day.
- sashk 9y agoHow is this different from, let's say mailhero.io?
- bdav24 9y agoHi sashk, mailhero is very similar. One difference I see: email addresses are not guessable with nBox.
- deleted 9y ago[deleted]
- water42 9y agohow do i know i can trust the security and privacy of this?
- bdav24 9y agoHi water42, don't ever trust anyone with your data, governments and big companies get hacked every day. Our angle: we don't ask for any personal information.
- mgberlin 9y agoSo if you shut down I no longer receive any emails I have signed up for?
- bdav24 9y agoHi mgberlin, that's a valid concern, I tried to answer it there: https://www.producthunt.com/posts/nbox#comment-483412 https://www.producthunt.com/posts/nbox#comment-483412 Edit: https://www.producthunt.com/posts/nbox/comments/483328 https://www.producthunt.com/posts/nbox/comments/483328
- huhtenberg 9y agoWorking link - https://www.producthunt.com/posts/nbox/comments/483328 https://www.producthunt.com/posts/nbox/comments/483328
- bdav24 9y agoThanks, my link only works for me...
- bigtunacan 9y agoI think this is a good idea, but pretty poorly executed again. Another user commented that you could just register your own domain and do this; that's great for the average hacker news reader, but not so great for the average Joe so a service like this (if done correctly) would be pretty convenient. Things that jump out right away as bad about this NBox. 1) It just auto generates an email for me. That's going to be a pain in the ass to remember. 2) Wait; how do I login? I literally don't understand how to login to this app short of going to the site and I get auto logged in by the Chrome extension? 3) Why do I even need a Chrome extension to get my email; where is the password protection so I can login from a different device or god forbid my computer crashes? 4) Not every service asking for an email address is a web service. If I sit down for dinner at an Applebees and order a meal a server is going to tell me the appetizer is free if I just provide my email address... and I want that free appetizer minus the side of spam... As someone else noted mailhero.io is basically the same service as this, but it's big flaw is that the real email address is exposed since it's always included in the provided email address. spam.u.later@mailhero.io (ah; real address is later@mailhero.io) Also; many other email services (including GMail can do the samething as mailhero using + addressing and adding rules.
- maccard 9y agoAgree with all your points except your last. Many websites and services will disallow email addresses with + in them (and they're normally he ones I don't trust, like insurance comparison ones)
- deleted 9y ago[deleted]
- bigtunacan 9y agoI agree that is an issue with those services, but that was sort of my point. Some websites are starting to catch on that people are doing this so they are starting to block + addressing the same way they block mailinator. Somewhere in this issue of websites blocking + addresses there is a some irony as + addressing is a more recent email standard and so some people have legitimate email addresses with + symbols in them; in fact last I knew Microsoft Exchange still wasn't supporting + addressing due to the need to support legacy users.
- jv22222 9y agoCurious as to how they get ramen profitable off of this? Anyone got any ideas?
- bdav24 9y agoHi jv22222, we don't get ramen off of this project. We plan to add paying functionalities some day if they make sense.
- suhith 9y agoThese days many services ask for a phone number for 2FA just to sign up, it'd be great to have a tool that gave you multiple numbers on demand so you don't have to give out your phone number.
- Psilidae 9y agoI've been considering just buying a few prepaid SIM cards just for services like this. I'd love some throwaway phone number/ SMS-forwarding services, but most get blacklisted within a few months because spammers immediately jump all over them.
- callalex 9y agoYou could use Twilio for this without writing any software, but phone numbers are a much more finite resource and are therefore much more expensive.
- dmitrygr 9y agoThis has existed and been free for 22 years already: http://www.mytrashmail.com/ http://www.mytrashmail.com/
- bdav24 9y agoHi dmitrygr, the idea is not new, but the link you gave is for disposable email addresses, which are public. That's a different use-case from nBox, where the addresses are private.
- dmitrygr 9y agouse a uuid - it is as private as imaginable - you'll never guess mine
- bdav24 9y agoYes, that gives you some privacy of course, but I still think it's a different use-case: with disposable email services, you're usually not notified when you receive an email, and checking all the addresses must be a pain. I'd use them for services I really don't care about and nBox for wanted and semi-wanted emails.
- gkfasdfasdf 9y agos/additionnal/additional/
- mccolin 9y agoThis seems like it's almost "1Password for Email Addresses," which would be pretty great: go to site, hit key combination, have random/saved email inserted into login boxes. Combining that with email forwarding to my real email address that I can turn on and off is pretty powerful.
- bdav24 9y agoHi mccolin, thanks for the support! :)
- ajnin 9y agoPresumably if I don't want to receive spam emails I'm also unlikely to allow a website to send me notifications. I'm unlikely as well to install an extension for a very specific service I'm not going to use very often. Extensions are a privacy concern and consume memory needlessly. If I'm willing to give a fake registration email I probably don't care about privacy and this is just for throwaway anyway. I'm not going to give any personal info to a website I don't trust with my email in the first place. I also don't understand how this is not going to be blacklisted like any other anti-spam email service. Maybe I'm not the target for this product bu this seems to bring nothing new in a slightly more annoying way.
- slg 9y ago> Extensions are a privacy concern and consume memory needlessly. This is somewhat tangential to your points, but I see this type of comment a lot. Chrome extensions are just renamed zip files that contain all the JS, HTML, and CSS for their extensions. It is easy to take a look at the source code if you have any privacy doubts. The author might try to obfuscate the JS, but it should be trivial to see if there are outgoing connections being made. Google also makes it simple to disable extensions with a couple clicks if you want to keep particular extensions disabled except when you are actively using them.
- bdav24 9y agoHi ajnin, thanks for your feedback. > Extensions are a privacy concern and consume memory needlessly. Yes, that's why we don't ask for any permission, so the extension only gets activated when you click on the button. > I'm not going to give any personal info to a website I don't trust with my email in the first place Everyone can get hacked, governments, big companies... so who do you trust enough to give your email? > I also don't understand how this is not going to be blacklisted like any other anti-spam email service. Some services might block our addresses some day, but that would be a mistake because nBox is not a disposable email service.
- nkkollaw 9y agoIf the service is down or I want to stop using it I'm totally screwed, though. Usually if I forget the password to a service they can send me a reset link, what would my options be with NBox?
- bdav24 9y agoHi nkkollaw, we're very careful to limit possible downtime, and there is a system of retry for incoming emails, so we should not lose some. We're currently working on the "account creation" part of nBox.
- JadeNB 9y agoThe FAQ says that it's not a disposeable-e-mail-generator, but the description of what it does makes it seem like that's exactly what it is. (Maybe it means that it doesn't generate random e-mail addresses from a shared pool?) I've been a satisfied user of SpamGourmet (www.spamgourmet.com) for years, and the only (argueable) downside I've seen is how upset customer-service representatives get upset while reading my address. How does your service compare?
- bdav24 9y agoHi JadeBN, you're right spamgourmet is very similar to nBox. Here are a few differences: - With spamgourmet the addresses are designed to expire after X emails, so it's intended for services you don't care about. - Once I know one spamgourmet address, I can try to guess other addresses of yours. - We don't ask for your personal email. If spamgourmet gets hacked, spammers will get your information.
- JadeNB 9y agoThank you for the reply; I think that this is a useful description of the advantages of your service. Just for purposes of completely accurate comparison, though: > - With spamgourmet the addresses are designed to expire after X emails, so it's intended for services you don't care about. This is configureable; it can be turned off entirely (allowing a trusted sender to send an unlimited number of e-mails to an address), or the allowance can be 'refreshed' (so that, after, say, 5 e-mails sent to an address, you can allow 5 more as a further probation).
- talove 9y agoI've had a catch-all for *@mydomain.com forward to my primary email address for 10+ years. In that time I signed up for services and websites with [domain]@mydomain.com thinking I'd catch all those dirty scoundrels selling my email address and have an easy way to filter unwanted mail. But you know what really happened? I wound up with hard to remember email logins and caught less than a handful of services sharing my email address without my permission. It wasn't worth it.
- rsync 9y ago"But you know what really happened? I wound up with hard to remember email logins and caught less than a handful of services sharing my email address without my permission." Can you elaborate ? I have been meaning to set up just such a mechanism as it has always seemed like a good idea ... It seems like "rsync.net@example.com" would be very easy to remember and associate with the site (rsync.net, in this example) ...
- AlecSchueler 9y agoNot sure what he meant, but that's the system I use and I've never forgotten a login yet.
- joosters 9y agoI've been using the same system with my own domain for several years now, and unlike the OP, I've seen many unique emails get on to spammer lists. My blocklist of emails has got quite long! As you say, using a password manager, or just picking a nameOfService@example.com style of email, means remembering the email addresses is pretty easy. n.b. you may need to also set up your email client to let you send emails with a customisable address too. Spammers who send stuff to randomAddressTheyMadeUp@example.com can be mostly blocked because these tend to have a messy jumble of text and numbers - I use a simple regex to throw away these kind of spams. I use procmail to do the blocking, but I'm sure there are many other tools that would work just as well.
- nicholashead 9y agoThis is exactly what I do, and it's worked beautifully for me. (domainname)@mydomain.com is pretty standard/easy, and storing it in password manager makes it even easier.
- StavrosK 9y agoI've been using 33mail.com for years for this. I just give it an address like "hackernews@username.33mail.com" and it forwards email. If hackernews ever starts spamming, 33mail gives me a link to block it. I love that service, it's saved me countless headaches.
- bdav24 9y agoHi StavrosK, yes 33mail (and others) propose almost the same service. Two slight differences though: - email are less guessable with nBox - if 33mail gets hacked, spammers will get your email address
- chumali 9y agoBlur by Abine offers a similar service, it includes a password manager and the ability to mask phone and card details on the premium version. Generated email addresses can be managed on the site or through the mobile app.
- irrational 9y agoThe first thing I saw was "naviguate". Um, no, if you can't even manage to run a spell checker I don't think I can trust you.
- bdav24 9y agoHi irrational, that's fixed now, thanks. We're not native English speaker, so mistakes can slip through.
- markwakeford 9y agoSo a lot of systems these days use email password recovery, is this not just adding another attack vector ?. > bdav24: Hi water42, don't ever trust anyone with your data, governments and big companies get hacked every day. Our angle: we don't ask for any personal information You will be able to route/read all of an individuals inbound mail ?
- bdav24 9y agoHi markwakeford, that's something we're currently working on. All devices that access the account will have to be validated on the previous device(s) and will be displayed. That said, for targetted attacks we won't be able to do better than Google and others, the risk is never 0. > You will be able to route/read all of an individuals inbound mail ? You mean to handle the load? We can scale at any time if we need to, but our current setup can already handle a lot.
- midnitewarrior 9y agoSo what's it like when NBox goes under and you can't recover your password on any of your sites?
- bdav24 9y agoHi midnitewarrior, here is a post where I try to answer that (valid) concern: https://www.producthunt.com/posts/nbox/comments/483328 https://www.producthunt.com/posts/nbox/comments/483328
- midnitewarrior 9y agoYes, that is your intention, but when funding gets pulled, investors rarely like spending more money on letting things "unwind", they have not company or brand to protect, so consumers' concerns take a back seat to investors. The other problem with this is that there is now a middle man in my security chain. If you get hacked, potentially all of my accounts can be hacked. If you have a rogue employee, same thing. If you have a flaw in your security, I too am at risk from a centralized source.
- hota_mazi 9y agoMost of these new email services overlook a few very important details which guarantee that they will probably not be around in a year: 1. You need to have multiple domains. If your solution is just one host name and your service becomes popular, it will become blacklisted in a matter of months. 2. The volume of spam you'll receive is huge. Really huge. Even if your service is only moderately successful. It costs money to keep such a service running.
- bdav24 9y agoHi hota_mazi, I won't say that we can think up of everything but we have these two points in mind.
- synicalx 9y agoThis is a good idea but creating a new address for each site seems to be overcomplicating a simple problem. I just have "mynormalemailalias_spam@domain" which is used for sign ups, if I ever need to log into a site I've signed up with using that address it's easy to remember the login details and/or reset my password.
- bdav24 9y agoHi synicalx, I used that method for many years too, but with time the emails end up piling up. That's manageable of course, but it feels nice to control exactly who owns your information.
- monista 9y agoI tried to "Create my nbox" (or "Generate an address") and it sent me to Chrome addons site. Is it Chrome-only web service?
- bdav24 9y agoHi monista, nBox is heavily based on Chrome at the moment, but a Firefox extension is coming and mobile apps may follow.
- pzht 9y agoRandomly saw this, a typo on the first slider image - Navigate :)
- graphememes 9y agoThese get banned quickly, just a heads up
- imhoguy 9y agoIn my experience spamers use mostly email addreses publicly exposed (web sites, usenet, forums) and stolen address books (viruses, malware) - you can't do much about the second if that happens to your recipients.
- bdav24 9y agoHi imhoguy, spammers also happen to buy leaked data sometimes to better target people. Anyway, spam is one thing we address, but that's not the main point. It's more about control of your privacy.
- grenran 9y agoSo wait, so instead of giving your email address, you're giving another email address? That's just like email addresses with extra steps.
- bdav24 9y agoExactly! And it brings a lot of benefits.
- kchr 9y agoWhy does it feel like I am the only one using plus sign (+) feature supported by SMTP standards? http://www.faqs.org/faqs/mail/addressing/index.html http://www.faqs.org/faqs/mail/addressing/index.html TL;DR - Most SMTP servers support delivering mail to addresses like foo+bar@email.com, in which case it will be received by foo@email.com. You can specify whatever string of alphanum chars you'd like after the plus sign.
- mboehm 9y agoNormally I only read on HN, but you got me logging in, upvoting and commenting! Probably most people just don't know about the standard. (As it is probably with most standards). Anyways, thanks for your hint.
- ghusbands 9y agoI've hit enough sites that refuse to accept a + in email addresses that I gave up using it, on the basis that I couldn't remember whether or not I was using it, per site. Standard it may be, but so many sites have bad email address validation.
- bdav24 9y agoHi kchr, no you're not the only one to use the plus sign. As already discussed in this feed, the + part can easily be removed by spammers.
- roryisok 9y ago+1 Sorry, couldn't resist. I got burned by this, I used it to sign up to a newsletter, and when I tried to unsubscribe, I kept putting in my actual email address with no results. Took me two weeks to think of checking the "to" field and realising I'd used a plus address