9 ms·
I am being monitored for using a privacy focused email address when signing up for services operated by a government entity. Yep, it happens. Their AI determine
by iliketosleep 5y ago
I am being monitored for using a privacy focused email address when signing up for services operated by a government entity. Yep, it happens. Their AI determined that people using particular email providers need to be watched. Not only that, I have had payments mysteriously fail with big online merchants, and after following it up through multiple layers of support I was told that particular email services are automatically flagged. You can guess which ones.
Now what do I do? Avoid privacy-focused email addresses for anything in daily life. It seems to be a battle that cannot be won.
- 8jef 5y agoThat make sense. That's why I'm using two regular service addresses redirected to my privacy focused email address, and assign different tasks to each one of them. It even help me filter out more unwanted messages and subscriptions.
- Lunrtick 5y agoThat sounds extremely frustrating. Maybe a good workaround is a custom domain?
- 8jef 5y agoBe aware that custom domains come with their own problems. Not being blacklisted is one of them.
- bengale 5y agoI've never had this issue with a personal custom domain. Basically all businesses have custom domains so blacklisting all of them can't make sense, surely?
- tomxor 5y agoUsing a custom domain doesn't necessarily mean using a custom mail server, they can point to a really common mail server such as gmail for instance. This is how a lot of business emails are set up.
- 8jef 5y agoTrue, but then I would assume that serious monitoring apparatus would include mail server monitoring, therefore defeating the need for a custom domain, which may contribute to identify you and/or stigmatise you further. Especially if one is accounting for other traffic carried by the said custom domain.
- bengale 5y agoOh I see. Yeah we use google mail for our business and I use fast mail, both with custom domains.
- shapefrog 5y agoNow you know what it is like to be a black person walking down the street. Instead of a chosen email provider it is an inherited skin color.
- 8jef 5y agoVery true.
- C19is20 5y ago".....in certain countries".
- DINKDINK 5y ago>Now you know what it is like to be a black person What makes you think this person isn't black? Maybe the first step we can take to ensuring all people are treated with dignity and respect is to not assume Group X is that group other there, an other. Maybe we can instead assume Group X is everywhere.
- shapefrog 5y agoYou sure are making a lot of assumptions while lecturing others about how they should not make assumptions.
- lostlogin 5y ago> particular email services are automatically flagged. You can guess which ones. I can’t - is there a reason you can’t name the service?
- swiley 5y agoI would strongly recommend running your own email. I've done it since I was 17 and it's a lot easier than you would think.
- vaylian 5y agoAny tutorials/software you can recommend for this?
- nobody9999 5y ago>Any tutorials/software you can recommend for this? Not GP, but the process is pretty simple: You'll need to be able to send, receive, store and forward emails. A variety of resources are required to do this. Note that pretty much all of the software suggestions are available through the default software trees of just about every Linux/BSD distribution. 1. You'll need a domain; 2. You'll need DNS services to publish your MX records with DMARC/DKIM/SPF[17] and/or DANE[18] support. If you can/want to host your own (not difficult), lots of folks like Unbound[0][1]. And while some folks hate on BIND[2][3], it's always a good choice. There are many others[4] as well; 3. You'll need a Mail Transfer Agent[5] (MTA) to send and receive emails. Postfix[6][7] is very popular. Some folks use Exim[8][9]. And others use the venerable sendmail[10][11]; 4. You'll also need a Mail Delivery Agent[12] to store your mailboxes and serve them via a web interface and/or your mail client. Lots of folks like Dovecot[13][14]. Others use Cyrus[15][16]. [0] https://www.nlnetlabs.nl/projects/unbound/about/ https://www.nlnetlabs.nl/projects/unbound/about/ [1] https://www.redhat.com/sysadmin/bound-dns https://www.redhat.com/sysadmin/bound-dns [2] https://www.isc.org/bind/ https://www.isc.org/bind/ [3] https://www.firewall.cx/linux-knowledgebase-tutorials/system-and-network-services/829-linux-bind-introduction.html https://www.firewall.cx/linux-knowledgebase-tutorials/system... [4] https://en.wikipedia.org/wiki/Comparison_of_DNS_server_software https://en.wikipedia.org/wiki/Comparison_of_DNS_server_softw... [5] https://en.wikipedia.org/wiki/Message_transfer_agent https://en.wikipedia.org/wiki/Message_transfer_agent [6] http://www.postfix.org/ http://www.postfix.org/ [7] http://www.postfix.org/documentation.html http://www.postfix.org/documentation.html [8] https://www.exim.org/ https://www.exim.org/ [9] https://www.exim.org/exim-html-current/doc/html/spec_html/ch-the_default_configuration_file.html https://www.exim.org/exim-html-current/doc/html/spec_html/ch... [10] ftp://ftp.sendmail.org/ [11] https://www.sendmail.org/~ca/email/doc8.12/op.html https://www.sendmail.org/~ca/email/doc8.12/op.html [12] https://en.wikipedia.org/wiki/Message_delivery_agent https://en.wikipedia.org/wiki/Message_delivery_agent [13] https://www.dovecot.org/ https://www.dovecot.org/ [14] https://doc.dovecot.org/ https://doc.dovecot.org/ [15] https://www.cyrusimap.org/ https://www.cyrusimap.org/ [16] https://www.cyrusimap.org/quickstart.html https://www.cyrusimap.org/quickstart.html [17] https://trendlineinteractive.com/resources/article/what-are-dmarc-dkim-and-spf/ https://trendlineinteractive.com/resources/article/what-are-... [18] https://en.wikipedia.org/wiki/DNS-based_Authentication_of_Named_Entities https://en.wikipedia.org/wiki/DNS-based_Authentication_of_Na... Edit: Added link for DMARC/DKIM/SPF and reference/link for DANE.
- trutannus 5y ago> I am being monitored for using a privacy focused email address How exactly did you find this out? I don't think you generally get letter mail saying "Hey, we're monitoring you now". How do you differentiate monitoring behavior from something like an individual service flagging an individual transaction because of your email and killing it? I'm always deeply skeptical of claims like this since they're almost always unverifiable by any party (including the commenter).
- 8jef 5y agoBy the way, your email address provider is only one metric by which you are being monitored. Everything happening online is now being monitored, stored and AI analysed, and will be for a long time in the future as technology is evolving and new meaning can emerge from everything that is recorded. Therefore, encryption is their enemy. For now. Until they break it all. Or until we break away.
- wolverine876 5y agoThese sound like common blacklist-style defenses. As examples, mail services use RBLs to prevent spam, Cloudflare services often require captchas from Tor exit node IP addresses, many websites decline signups from throwaway email addresses like Mailinator. Credit card companies use various indicators to prevent fraud. I'm not saying these measures are perfect or fair, but they are not related to government (though government may also use them); they are just obvious ways to prevent unwanted activity such as spam, fraud, hacking attacks, etc. > Their AI determined that people using particular email providers need to be watched How do you know that government has concluded 'particular providers need to be watched', and that the decision was performed by an AI? > for using a privacy focused email address when signing up for services operated by a government entity How do you know the cause?
- fnord77 5y agoall this nonsense would go away if we had some sort of universal identification system on the internet. people act like anonymity is some kind of right, but it really wasn't in the past. You needed to prove who you are to get a loan, drivers license, etc.
- someguyorother 5y agoJust make it zero-knowledge. You use the ID server to prove that you're not a sock puppet of someone already registered, but that's all the site needs to know.
- Hyolobrika 5y agoWhat about whistleblowers?
- FridayoLeary 5y agowhat's your name then?
- conjectures 5y agoUser called fnord posts bait ideas, yeah I'm not biting.
- hncurious 5y agoIt's a cruel fate of any privacy-focused service, as they are more likely to be used by criminals. Be it mailinator or TOR or monero. This is ultimately a question of freedom vs security. Said government entity is prioritizing security over freedom.
- handrous 5y ago> Not only that, I have had payments mysteriously fail with big online merchants, and after following it up through multiple layers of support I was told that particular email services are automatically flagged. You can guess which ones. You don't need nefarious motives to explain that particular behavior. Operate a store or payment system without rejecting easy-to-sign-up-for-anonymously email addresses, especially ones with a free tier, and you'll find out very quickly why they downrank the trustworthiness of, or simply block, such services. Automated credit card fraud is huge and no fun at all to deal with.
- swiley 5y agoAnd that is why some people really like crypto currency. You get what is essentially ssh for money with all the pro and con implications.
- imglorp 5y agoNote BTC and others are pseudo-anonymous, because the whole world knows the source and destination wallet of every transaction. If someone is ever serious about finding you, they can follow the chain to wherever you cashed out and a subpoena will do the rest. There are fully anonymous coins like Monero, ZCash, etc.
- swiley 5y agoRight, but you also don't have to deal with fraudulent claw backs like with credit cards. It's not secret but it makes the integration/code easier. This is why a lot of obscure/experimental services tend to have bitcoin payment support early on and struggle with paypal/credit cards.
- handrous 5y agoRight: a vendor's not forced to care whether any bitcoin they accept was stolen, but they are forced to care whether a credit card they accept was stolen. Doing a sufficiently shitty job of keeping out purchases with stolen cards can literally end a business, in a hurry. Meanwhile nothing's going to happen about stolen bitcoin you accept—probably you'll never even know—unless there's an actual police investigation you get wrapped up in. In that respect, it's more cash-like.