4 ms·
> We're going away from open, federated, distributed standards and back to closed, wall-gardened, proprietary, massive identity providers. I'm not. I just crea
by nathan_long 9y ago
> We're going away from open, federated, distributed standards and back to closed, wall-gardened, proprietary, massive identity providers.
I'm not. I just create an email and password for each site I use. A password manager means that's not a big deal.
EDIT: I meant to say I create an account based on email and password. I don't actually create a separate email address per site.
- abricot 9y agoI create an email for every site. I can recommend it.
- jackweirdy 9y agoDo you do this programmatically? Or with the +suffix@.... trick?
- ibz 9y agoNeither nor. I have my own domain. Every website gets <website>@mydomain. Every email @mydomain gets forwarded to my primary email. As simple as that.
- jackweirdy 9y agoNice! Another domain owner here. Never thought to have a sink-all mailbox. Thanks for sharing.
- techdragon 9y agoI used to use this trick, but got sick of fighting the bulk spam sent to admin@, postmaster@, etc. the filters got most of it, but damn it was annoying whenever they changed tactics and a small flood would sneak by before being identified by the filters and further spam prevented.
- archi42 9y agoThat's why I moved from maintaining my own mail server (with spam filter and activate sync) to a provider. I still own the domain and have a catch-all configured for per-account mail addresses on a subdomain with the mail going to bulk folder on my primary IMAP. The subdomain also prevents the dumbfire admin@... spam. Only spam I get is on leaked addresses.
- brobert 9y agoInstead of using <service>@, sign-up with <service><secret>@ and forward only the messages that match *<secret>@
- deleted 9y ago[deleted]
- ibz 9y agoYeah, the + trick is not that great, because it is quite obvious what your real email is. This way, not so much. One could of course still guess that you are using this trick when they see that your email matches their domain name. If you're paranoid about that, you could of course just use <random string>@yourdomain for every login. And store that in your password manager.
- y03a 9y agoAnything at a custom domain that doesn't look direct to an individual (e.g. not realname@domain.tld) is a big hint to spammers that the owner uses a catch-all and thus any address will get the job done. I suppose you could go with a whitelist for every random address you give out and blacklist the ones that misbehave, but that's a lot of work and, since every company misbhaves these days, including entities like banks, you'll likely miss emails you actually need.
- ibz 9y agoI don't care much about spammers. The filter at FastMail is good enough. What I care about mostly is to make automatically correlating my identity between different websites harder.
- nathan_long 9y ago> you could of course just use <random string>@yourdomain for every login You could also use the hash of the domain name with a secret salt value. Then if you somehow lost your login info, you could still figure out what your recovery address was if you still knew the salt.
- guiambros 9y ago+1. I've been doing this for 20+ years. Every site I register gets a new account following a pattern <prefix><site>@mydomain.com. Incredibly helpful to track who leaked your email and to whom, better control spammers, etc. Just checked on Have I been Pwned, and I have 30 emails from my domain there [1]. Anecdotally, there's at least another 50-100 email addresses that I get spam regularly, so HIBP is a small subset of all the leaks. Easy to implement. I use G Suite with Gmail[2], but it works with most other providers. [1] https://haveibeenpwned.com/ https://haveibeenpwned.com/ [2] disclaimer: I work for Google, but not on G Suite team, and I pay for the service on my own.
- abricot 9y agoAdd the email to a virtual address config file.