5 ms·
I tend to create a new email address for everything I sign up for. This makes a little harder to check :) EG: twitter@example.com, facebook@example.com, hacker
by cleaver 13y ago
I tend to create a new email address for everything I sign up for. This makes a little harder to check :)
EG: twitter@example.com, facebook@example.com, hackernews@example.com
It also makes it a little harder for people to find me on social media. Not sure if that's a bug or a feature ;)
- rfnslyr 13y agoSame here, with completely randomized passwords 60 chars long and different emails. IM INVISIBLE!
- Aldo_MX 13y agocatchall FTW I follow the following pattern with websites: If the website is important (ex. government), I use <sitename><4_numbers>@<private_domain>. My filtering rules are extremely strict, and every mail that doesn't come from the expected website gets automatically flagged as spam and deleted. If their DB leaks, I just change the 4 numbers. If I know the website and it's not an startup, I use <sitename>@<public_domain>, ex. facebook@example.com. My filtering rules only flag the messages as "maybe spam" when the sender is not in my contacts. If their DB leaks, I change the filter from "maybe spam" to "spam". If it's a website I don't know, or a startup, I use <full_domain>@<publc_domain>, ex. mystartup.io@example.com. I don't filter them, but if I start getting spam, I just simply set the email as an alias to my wormhole (an account I never check that flags anything it receives as spam). If it's a spam blog, or a website that forces me to create an account by no apparent reason, I just use the wormhole address.
- jeremyjh 13y agoThis is brilliant, thanks for sharing.
- eli 13y agoThat seems like a lot of overhead to manage. Also, you're going to have a bad day if a spam bot decides to spam thousands of <common_user_name>@yourdomain.com. Maybe that's fallen out of practice, but I've seen it happen before.
- spindritf 13y agoIt's a tried and true spamming tradition and it's going strong. I see plenty of entries like Envelope-to: <eba615c3c@my.domain> in my reject log. Addresses that were never used anywhere. Some things just refuse to die.
- Aldo_MX 13y agoNot really, in this year I had changed only 1 filter, the initial setup may be cumbersome, but the end result is worth the effort. And about the spam to random addresses, in 8 years the most extreme problem I had faced is spam to censored addresses like git...@domain.com (thanks google code).
- millerm 13y agoThat's actually a very unadvisable scheme. By doing this you make yourself a target. If any one of those are compromised, attackers will attempt to try that against a lot of popular sites (including banks). If you have your own domain (which I assume you do based on your scheme), I suggest not doing this. You would be better off coming up with a random account name for each and using a password manager to keep track of these. FYI, I used to do this too. And this is how (in a similar fashion) Mat Honan got Gizmodo's Twitter and his iCloud and Gmail accounts hacked and also had his computer remotely wiped because he used his name in every domain/service as his account name or email account name. Edited for more information.
- ivanhoe 13y agothe downside is that using random accounts on your domain requires a catch-all email rules on your server (unless you add each address by hand, but frankly that's too much of a hassle)
- cleaver 13y agoI never use a catch-all. Deleting email would quickly exceed available time. I go through the trouble of creating a new email each time. I've considered writing a script to make it easier, but my current mail provider makes that difficult.
- ParkerK 13y ago>By doing this you make yourself a target. If any one of those are compromised, attackers will attempt to try that against a lot of popular sites (including banks). And if you use the same email for everything (as is the alternative), attackers can attempt to try that against popular sites. So I don't see the downside of this method?
- millerm 13y agoThe real key is to not use the same email address across accounts. If you have your own domain, then it's easy. I actually don't like the idea of using email addresses as user IDs. I believe that was a lazy approach in the first place and this causes too many problems. I'm sure it all started that way because someone wanted your contact info, and since the only way to guarantee a valid email was to make you verify it. It has nothing to do with security. Nobody said security was easy or convenient. Anyway, to each his own. I have my own domains and do, unfortunately, have about 100 email addresses/aliases. Yeah, it can be inconvenient to maintain. I originally started using the aliases because I wanted to know who was giving out my email to spammers. I caught a few and stopped doing business with them.