Hacker News new | ask | show | jobs
by glandium 3407 days ago
> So you have to trust them with the very thing you want them to stop abusing.

"Fun" fact: I register on sites with addresses like "address-suffix@domain", with a different suffix for different sites. I won't name names, but I now receive viagra-level spam to several of them, which reasonable people would expect to be able to trust. haveibeenpwned.com confirms that one of them, off the top of my head, was part of a breach.

3 comments

Why not name names? Let's name and shame companies that are either selling your info or hiding breaches.
So in my inbox currently:

* dbox@mydomain.com (Dropbox) - first received spam two years ago.

* (Greenheart Games/Game Dev Tycoon) - highest quatity of spam after contact/info/admin

Although I just checked and the Greenheart Games address is in a mod's package.json so probably not their fault

I got spam to a email registered with Microsoft.

A company I worked for got its email list leaked when the email service they used was breached. The email service posted a "we're investigating" in a blog post on a blog that was soon mysteriously deprecated/taken down.

Microsoft sells the shit out of your email address. If you sign up for Dev Essentials you can't even opt out of emails from "partners" unless you leave the Dev Essentials program (and I'm sure leaving it wouldn't actually stop the emails). The only spam I get at my work email (with spam filtering turned off) is tied to that program.
I wonder if this is a case for a side project.

A website showing which sign ups put you at risk, by exploiting a similar email naming convention.

So everyone ends up on level pegging.

I have a catchall mailbox on my personal domain, and always sign up with unique email addresses for everything.