this post was submitted on 15 Dec 2024
24 points (85.3% liked)

Privacy

32482 readers
237 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 5 years ago
MODERATORS
 

Basically create an alias for every combination to prevent privacy cross contamination.

For instance, not only should you make an email alias for an Eventbrite account, but for every organization you sign up for events with. You are required to enter an email (any email) for the event, which can be seen by both Eventbrite and the organization. If you enter in the email of your Eventbrite account then the org could give that away, resulting in email spam and you can't be sure if it was either Eventbrite itself or the org that sold you out. If that happens then you would probably want to delete email address but then you have to change it in other places you need to send/receive emails from.

Another example is Discourse forum sites. While Discourse is open source and self-hostable, you may not always be sure if a Discourse site is self-hosted or using paid hosting. A lot online places have both their own website and a separate discourse site. Bitwarden's forum site doesn't have a sign-in option using your Bitwarden.com account, and Raindrop.io uses canny.io to track app feedback which has also uses its own login. (I'm actually glad I made an alias for every single Discourse forum site before realizing all of this).

top 9 comments
sorted by: hot top controversial new old
[–] [email protected] 23 points 1 week ago (3 children)

Buy a domain and set your email to catchall, then make a unique email for everything and don't fiddle with aliases.

[–] [email protected] 8 points 1 week ago

There is no one-size-fits-all solution and there likely isn't a solution that works for everyone even in specific situations due to different threat models. Purchasing and using a custom domain is often listed as a good practice for maintaining a person's privacy. However, it can be even more detrimental to a person's privacy than just using a trusted email masking/forwarding service and trusted email provider. For example:

  • The domain is purchased without WHOIS protection (or without using non-personal information) or the WHOIS protection is not renewed
  • The email server is hosted on hardware that can be linked to other services that identify the individual (eg: the email is self hosted using a home IP address)
  • A self hosted email server is configured in a way that leaks information or is configured insecurely
  • The email domain is used by only one person, which enables agencies to link each individual, unique email address back to that individual and create an aggregated profile across various accounts/services
  • If the domain/DNS is not configured properly (or if the domain is not renewed), then the domain (and thus the email accounts) can be hijacked, which could lead to any additional accounts/services that are still using the domain vulnerable to a take over attack
  • The email server is hosted by a privacy invasive company/service
  • The person assumes that all emails are private since they use a custom domain on a trusted email provider (or self hosted email server), but continue to send emails containing sensitive information to email accounts running privacy invasive email services (eg: Gmail)

Please note that I am not saying that this is not a good option, but I just wanted to note some of the things that should be considered if a person decides to use a custom email domain to improve their digital privacy.

[–] [email protected] 2 points 1 week ago (2 children)

Which provider are you using? They don't all offer catch-all

I still have a 15 year old free Google workspace plan with that option, but I'm looking for an alternative, not excessively expensive

[–] [email protected] 2 points 1 week ago

Previously Tuta (I don't recommend them, they're going down a path slow enshittification)

Now Disroot, which lets you use a custom domain with a catchall for a one time payment. https://disroot.org/en/perks

[–] [email protected] 1 points 1 week ago

If you own the domain you can do everything. iCloud has a very generous 50gb plan for 1€ per month

[–] [email protected] -1 points 1 week ago (3 children)

Then you end up with an inbox full of drive-by spam to abuse/admin/aardvark/.. (insert dictionary here)../zack/ziggy.

[–] [email protected] 4 points 1 week ago* (last edited 1 week ago)

I believe there are some services, including some selfhosted ones, that allow you to quickly create (and later delete) unique aliases.

That said, I was surprised that these dictionary spam attacks don't really happen all that much, at least based on my own experience. Most of the ambient drive-by spam my server receives targets email addresses belonging to domains I don't even own. Blocking those and a few Sieve scripts gets rid of 99% of spam for me.

Interestingly, there was one time I received spam to a bogus address belonging to my own domain: A while back, one of my actual email addresses got leaked (thanks Sega) and a few months later that address got copied into another dataset but with a typo, which I assume was caused someone using OCR.

[–] [email protected] 2 points 1 week ago

Is that something you have experience with or are you just making up scenarios to pose as arguments?

Because I've been doing this for years and I don't have this issue. You could also just preemptively auto-trash anything that goes to those very common emails, but I don't and it's not an issue.

[–] [email protected] 2 points 1 week ago

Is this experience or conjecture?