Hacker News new | ask | show | jobs
by pearlsteinj 1066 days ago
Totally just guessing: Maybe to reduce inbound spam that's forwarded to the buyers? If it was one central email address, spammers could just send a ton of images/PDFs to all known prefixes of that central domain, but needing to guess the prefix + right domain adds a layer of indirection? They may not do much validation on the forwarded tickets, just store it for disputes
1 comments

Wouldn't it be much cheaper and effective to add a random secret to the bit before the at rather than after?