6 ms·
I don't agree with this and I think the right approach is to simply not require visitors to give up their email accounts if they don't want to. If you want to
by TemporaryMail 2y ago
I don't agree with this and I think the right approach is to simply not require visitors to give up their email accounts if they don't want to.
If you want to block a malicious attacker, then you can use a captcha.
A serious malicious attacker wouldn't have a problem paying a few dollars to buy a domain, creating a catch-all address and if he wants to take it one step further he can even have it look like a legitimate email service.
Disposable services are ad blockers for emails.
- ocdtrekkie 2y agoAliases you can discard are ad blockers for emails, disposable services are for bots, scams, and fraud. If you know the space, you'll be aware CAPTCHAs are trivially defeated today, regardless of the provider. I certainly agree people shouldn't be asked to provide an email if it's unnecessary, but again for the issue of bots, scams, and fraud, you generally need some sort of unique relatively hard to get many of identifier to prevent people making tons of accounts on any service which either allows posting content or costs money to provide service. Email is generally okay for this. Ultimately disposable email providers who continue to believe domain rotation is anything but an attack will force a far worse outcome, which I've already seen some major sites do: Only accept registration from Gmail, Outlook, and Yahoo accounts. (The Verge is one example where I know I had to register with a Gmail account and open a support ticket to change my email to my real email because they figured out the best way to avoid abusers on disposable email was to allowlist major providers.)
- TemporaryMail 2y ago>Aliases you can discard are ad blockers for emails, disposable services are for bots, scams, and fraud. What is the difference between the two though? This kind of reasoning is why people can't run their own email servers anymore and instead have to rely on the big services. >If you know the space, you'll be aware CAPTCHAs are trivially defeated today, regardless of the provider. They are a lot more reliable than an email which is basically just a domain that anyone can buy and setup within mere minutes giving them access to endless email addresses. >you generally need some sort of unique relatively hard to get many of identifier Why not use phone numbers instead if the issue is truly important to them? This would cost spammers and bots way more money than emails. Perhaps it's due to the fact that they won't be able to use the phone number to send their spam (or they could I guess, but it would cost them some money).
- ocdtrekkie 2y ago> What is the difference between the two though? If you have a hundred aliases on say, Fastmail, and someone reports one of them, Fastmail can investigate the abuse you are involved in and can suspend your account. But the places you are using those aliases have no way to identify the main account of an alias, they can only report the alias, and Fastmail, the company providing your core service, is the only one that has the ability to deanonymize that relationship. Most of the services who allow these excess aliases are paid services or have identity checks, so other service providers can trust they will do a reasonable job to prevent abuse. Meanwhile, if you bother to investigate how your service is being used, the percentage of users using it to abuse other sites will inevitably approach 100%. As bot spammers realize you're another set of free email addresses they can stack up, they'll swarm to each new domain you rotate to. If you are as privacy focused as you say, you'll have no tools at your disposable to regulate this either, they have plenty of IP addresses to work with, mostly compromised devices on residential IPs that are part of botnets, that will look like real users from a cursory glance. > This kind of reasoning is why people can't run their own email servers anymore and instead have to rely on the big services. That's why it's so fundamental that you understand rotating your domains is abuse, and it hurts the email ecosystem. Every time someone like you thinks this is okay, you make more service providers lock down what email domains they accept, punishing folks like me who just want their own domain on their email. Because disposable mail services do this, we all get punished for your bad behavior. > Why not use phone numbers instead Well, that's what a lot of major providers do. Gmail makes it much harder to get going without a phone number these days, mostly for that reason. I certainly don't want to have to give my phone number to every site I sign up with, but if that is, in your opinion better for privacy, by all means, enjoy the fruits of you screwing over email for this.
- TemporaryMail 2y ago> Fastmail can investigate the abuse you are involved in and can suspend your account. What if the Fastmail account is simply just using their free 30 day trial, how will they track the user then? My point is that the malicious user will still have a way, while the legitimate user is punished by having to pay a fee to the email provider. > Every time someone like you thinks this is okay, you make more service providers lock down what email domains they accept, punishing folks like me who just want their own domain on their email. How about no one gets punished and service providers verify phone numbers instead of emails and we get to keep our inboxes clean?
- borissk 2y agoLife's too short to give a real email address to any random web site that requires registration. One reason is privacy, as they will inevitably sell one's data to a thousand data brokers. Second reason is to avoid having to deal with all the spam, that will again inevitably come. Even if unsubscribed from everything, we've change our policy emails and other nonsense will keep wasting one's time.
- zzo38computer 2y agoI have my own SMTP server that I use for all purposes. I have set up a separate address for each person/service that I use email with. If I receive spam or other unwanted messages, then it is easy to delete that email address, which will cause the SMTP server to return an error message to any client that tries to send messages to that address.
- tracker1 2y agoI've come to the decision to charge $5/year for a site I'm going to put online in the next year... only to cover the transaction fees and mostly actual costs. If it takes off, should at least pay for itself and discourage fake accounts. But not every site/service will get that many people to even pay that much. On the latter bit... not sure if I completely disagree with that take as well. As much as I also dislike SSO for other reasons, it is nice as at least some level of validation.
- TemporaryMail 2y agoI think that completely depends on what the service is, but I don't think users would have anything against paying a few dollars if they find the service valuable, especially now when there are so many payment processors available. Best of luck with the service also!
- tracker1 2y agoFor that matter, it's pretty easy to setup a catch all address forwarder. Cloudflare offers this, as did Google Domains. Not sure if Squarespace still offers this explicitely, been meaning to try to get out of Squarespace since the shift. Mostly been lazy.
- 7bit 2y agoFuck captchas
- TemporaryMail 2y agoI'd rather fill out a captcha when I sign up than having to drag emails to spam on a daily basis so I can find emails that are actually important.