7 ms·
I'm using catch all since forever. I regret nothing. Two stories: I don't use mails like facebook@domain uber@domain - that's too obvious. And knowing that ma
by dzek69 4y ago
I'm using catch all since forever. I regret nothing.
Two stories:
I don't use mails like facebook@domain uber@domain - that's too obvious. And knowing that may often disclose that I actually have an account registered on given page. I don't want that, so I go full random, using few words I have in mind, current few words from the song I'm listening too, etc. So password manager helps me with e-mails too.
But Sometimes when a website annoys me (stupid rules for passwords, crippled UX for forms, because re-writing a select component in javascript is such a brilliant idea, etc) I tend to insult the company I'm registering with using my e-mail or password, I mean mail: this.freaking.store.is.dumb@domain.com and pass: goDieInPain1312323$$$$. Once I registered account for a supermarket loyality card with some very little insult towards the supermarket. Later I got some huge amount of the points collected and their system crashed and I had to contact the support (the bonus was too high for me to give up on that). First via e-mail then via phone, when they were confirming my address. They helped me and said nothing about the name I was using.
Another story:
When I started with catch-all I was actually using mails like companyname@mydomain, and when I once contacted them via phone the person talking with me was not very into tech I think and were accusing me of... I don't really know exactly, but she told me something about me using their stuff without their acceptance, when I tried to explain that's my own domain she told me I cannot use their name, because that's a copyright infringement. Weird.
- mixologic 4y agoI have been using a catchall domain since 2004 and it has been a lifesaver. The sad part is when your email leaks from big companies, you definitely know. I started getting viagra spam delivered to equifax@mydomain.com back in 2007, long before their "big data breach", so it was only a matter of time before that companies pattern of poor security caught up with them. Email should have always been a bidirectional address, representing the relationship between the sender and receiver, and not a wide open receiver for anybody who happens to have your address.
- MiddleEndian 4y ago>Email should have always been a bidirectional address, representing the relationship between the sender and receiver, and not a wide open receiver for anybody who happens to have your address. Ideally, this would also be the case for physical mail. Multiple revokable tokens, not publicly tied to your physical address.
- al_borland 4y agoNot having your mailing address tied to your physical address would also have major benefits when people move. Simply update your address with the post office and you're done. The whole idea of revokable tokens would pose an issue for any company that sends bills, as I assume revoking address tokens would be common with them. I'm sure there are many situations like this.
- r_hoods_ghost 4y ago"Simply update your address with the post office and you're done." Welcome to the 19th century! Which is when mail redirection to a new address was introduced in the UK. I'd be amazed if it wasn't around then or earlier in the USA as well. Simply fill out a form and your mail will be redirected for up to two years (albeit at a cost). Or use a PO box and a mail forwarding service which offers filtering of junk mail. I used one for years when I used to move around a lot for less than £100 a year.
- kortilla 4y ago> Welcome to the 19th century! Which is when mail redirection to a new address was introduced in the UK. That’s not the same thing. Everyone still has your old address and you need to update it with them. Not terribly painful if you move once every 5 years. Pretty annoying and error prone if you move every 6 months.
- r_hoods_ghost 4y agoHence option 2 - the PO box.
- schoen 4y ago> Email should have always been a bidirectional address, representing the relationship between the sender and receiver, and not a wide open receiver for anybody who happens to have your address. That does seem beneficial for the most part, but do you have ideas about how to handle the use cases like establishing new relationships (what, if anything, do you put on business cards?) or allowing the general public or a broad audience to contact you (what, if anything, do you put in advertisements, on your web site, on slides of a conference presentation, in an e-mail signature on mailing lists?).
- al_borland 4y agoThe email service Hey (from the makers of Basecamp) has a feature where the first time someone emails you it goes into a screening bucket. You can then approve those senders who are allowed to email you. If you don't approve, you don't see the emails anymore. I initially signed up for the trail when the service launched. The first or second time I went to check the site/app it wasn't working. I was pretty much done with it at that point. I probably should have given it more of a chance and maybe they worked that out, but at $99/year for email my tolerance for issues is pretty low. They did (I suppose still do) have a lot of neat ideas around email though.
- Dyac 4y agoI effectively do this manually in Thunderbird. I have a saved search folder I treat as my "actual inbox" and I only add email addresses I want to receive mail from to the filter rule list.
- hunter2_ 4y agoI think it's simply a hybrid approach: you'd handle those unknown contacts with many:1 addresses (since there's no real alternative, as you imply), and you'd handle most known contacts with 1:1 addresses. A benefit is that you might let messages to some or all of those 1:1 addresses be sorted one way (e.g., they ping you) while messages to some or all of the many:1 addresses are sorted another way (e.g., you only check for them with a much longer interval). But then again, a diligently-maintained contact list can be leveraged to achieve same...
- test6554 4y agoDang, you could trade stocks with information like that.
- lupire 4y agoLloyd's is Pants: https://www.theregister.com/2008/08/28/lloyds_passwords/ https://www.theregister.com/2008/08/28/lloyds_passwords/
- inetknght 4y ago> I don't really know exactly, but she told me something about me using their stuff without their acceptance, when I tried to explain that's my own domain she told me I cannot use their name, because that's a copyright infringement. Weird. I can't tell you how many non-techy people think I'm part of their company because I have yourcompany@mydomain. Sigh. Big companies have ruined the internet by having everyone have @gmail or @hotmail or something.
- trelane 4y agoThe "best" is when you can't even sign up without having an account at a Large Company e.g. gmail or outlook. I'm not sure what that's supposed to prevent issues with. Sure, you can add "+thing" after the username portion, but those that know this bog standard trick can still automatically derive your email address and get around your filters. At least with a dedicated username portion a human has to think for a second.
- Semaphor 4y agoWhich companies are those? Is there a list somewhere? The only time I ever encountered this was with AliExpress.
- bpye 4y agoDid that change? My AliExpress account is using myname@mydomain.co.uk
- Semaphor 4y agoI don’t know, I registered some time last year. Maybe it’s also the TLD? I have .me.
- efreak 4y agoI've got a first@last.family. My dentist and several large companies refuse to accept this as a valid email address, so I have to use an email that doesn't identify me personally by name (uses efreak instead of my name). This annoys me every time I deal with them, especially since some of these sites use my email address as a username. I've been locked out from logging in on other devices a couple times for trying too many passwords when the problem was the address, not the password.
- OJFord 4y agoI have a couple too: Panicked phone call from a jeweller who wanted to know how and why '[their] domain was in my email address'; think he sort of understood once I explained, but still said something like 'can't be too careful in this business' - well sure ok but what am I going to do with.. oh nevermind! Password lockout/reset over the phone, reading my 100ch 'memorable phrase' as generated by pass... Gave the guy a good chuckle, and no he was not willing to concede by the umpteenth 'upper case A' or 'backward slash' that I obviously 'knew' the phrase and could surely be relieved from reciting the entire thing... I use shorter ones now.
- silverhydradev 4y agoI do the same thing, but for exactly the reasons you described, this type of passphrase can be vulnerable to social engineering.
- nicoburns 4y agoBitwarden can generate xkcd style English-word pass phrases that can be useful for this kind of scenario.
- yellow_postit 4y agoSame with 1Password. Has been a life saver with a family account.
- cortesoft 4y agoThat is a major downside with putting gibberish in for answers to security questions… let’s hackers socially engineer support into letting you get access by saying something like, “oh man, I just mashed on my keyboard for that I don’t remember!” You would hope it wouldn’t work, but it probably will.
- jedberg 4y agoThat's why I always put legit but wrong answers in. Can't really guess because they're all different and made up, but also can't say, "Oh I just mashed the keyboard".
- mulmen 4y ago> When I started with catch-all I was actually using mails like companyname@mydomain […] I missed out on a dentist appointment because of this. They thought I was a robot. I blame gmail.
- aendruk 4y agoMy ham radio certification was issued to a nonsensical address because the exam coordinator crammed @gmail.com onto the end without me knowing.
- cube00 4y agoI've missed out on appointments too, the business owner later told me after I finally reached them on a social platform "that address looked weird so I just deleted it" Regardless, I still regret nothing, seeing my spam free "catch all" mailbox compared to my spam infested decade old web mail is all I need to know it was the right choice.
- Semaphor 4y agoAnother no regrets catch-all user. Looking into my rules, I have 4 "to" addresses that get sent to spam. Two stories as well: a) After contacting a company, I got a mail from their legal department asking me to explain why I’m using their trademarked name in my email b) Using an online-shop that requires emailing the owner for your order (so he can send you a PayPal invoice and then snail-mail you the music CDs you ordered…) I got a personal message attached of him asking why his label’s name is in my email address. In both cases, a short explanation was sufficient, though.
- EGreg 4y agoThat dude missed the biggest benefit When someone tries to call into a provider and impersonate you, to take over your account… they would fail because they don’t know your login even! Whereas, for most people, they’d sweet talk the person on the other line into resetting the password. Happened to me with GoDaddy, they almost rerouted my @mydomain.com email and then it would have been really bad
- e40 4y agoI actually got a call from a company I bought something from, direct from their website. I had bought it using the email $company@$mydomain. Got a call (in the days before most of my calls were not spam and I answered the phone!) from a marketing person and the guy tried to bully me into ... not sure what. I couldn't even tell, like you, what he was accusing me of... I'll say, it felt really good to school him about the internet and how it worked.
- stormbrew 4y agoI use myname-shortbusinessname@mydomain and once the delivery person for a pizza place i ordered from fairly regularly asked if i worked for the store somehow. I changed the email i used with them to one that was less obvious after that. Not as exciting as getting accused of trademark infringement, but it’s interesting how people interpret these things.
- justsomehnguy 4y agoWith all those similar stories I wonder why people even bothering with changing an email recipient when some random guy asks about it. Like... delivery guy asked and?..
- thfuran 4y agoAnd they don't want to keep having that conversation, presumably.
- justsomehnguy 4y agoChances are there but slim. Personally I had a similar conversation only once and only because it was a one-man AliBaba reseller shop, so he personally processed all orders.
- stormbrew 4y agoPretty much yeah. Not only is it an annoying conversation, it's also a deeply boring one.
- bambax 4y agoI too have been using a catchall email address since some time in the last century, and it's been cool, although the post is right when they say > The truth is no one really sells your email The reason I started doing this was to monitor if someone would transfer my address, and it's never happened. You also get more spam because every firstname@yourdomain works. But the weird interactions are good! Last year I wanted to get my kid in a somewhat selective middle school (in France) and the fact that the email I was registered with was name_of_school@mydomain helped, because the principal was convinced I was and always had been a huge fan of the school, to have my email named after them... People simply don't understand you can have more than one email address -- let alone a million. That's kind of fun.
- cube00 4y agoAnother no regrets checking in. I've caught companies either selling (or leaking) my address so for me it's been worth it. Some businesses freak out that "that's our domain name, we own it, you can't possibly use it". To placate them I'll spell it backwards or give a related name that I can still work out the source. eg. fleet2022@ if I'm renting a car
- alanh 4y agoregarding 'copyright infringement,' you gotta love it when people get aggressive about IP without knowing what they are talking about; the relevant law would be trademark, not copyright
- m3047 4y agoThe phone thing has veered into outright fraud. Twitter just paid a $150,000,000 fine to the (US) FTC for letting advertisers match on telephone numbers provided for 2FA. I am really tired of people selling my burner phone to the credit people; and no, I don't own that phone number. Prove I do. Take my local credit union. Please. Jackasses let someone have access to my checking account. I don't bank online with them either, or I didn't, but last summer was trying to talk to them about a refi and I had to register online and they wanted a phone for 2FA. So of course instead of calling the land line, which is clearly and incontrovertibly mine, they called the burner. Several times. Eventually I answered it with "fuck you you frauds" and they were "oooh sir, call me back on my direct line" so I tried... from my land line in the same area code, you get the idea... and their system won't route the call to their fraud department. So I ignored them for a couple of weeks. Seriously they were so incompetent that when the actual fraudsters were probing, the first transaction was a /deposit/. When they were finally trying to clean their mess up, they /credited/ me the same amount. I'm the one who figured it out and told them well you gave me 2x their original deposit, when you really should have debited the amount in the first place. People like that are not going to safeguard your information. Ob relevance: I have my own reasons for not wildcarding domains and use this instead: https://github.com/m3047/trualias https://github.com/m3047/trualias