Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If your website will block me out because I used a privacy friendly email, I want nothing to do with your website.


Yes but not always applicable unfortunately… e.g. the other day I was in Italy, I needed to park on the publicly available parking which was paid to the municipality.

No other parking available anywhere near in 30 mins walking distance. (paid or free)

I had to download a 3rd party app that asked me to register. This app isn’t by the Italian government, it’s affiliated though.

So in that situation, I want nothing to do with your website or app, because I wouldn’t able to park.


Have exactly the same situation with parking in Italy. Having a private company operating all paid parking on an island is not very healthy.


Having a handful of companies that can contact you has created a land of monopoly hyperscalers.

It's so hard to build anything big and durable because they've created these steep gradients.


"They" didn't create them. They laid out the bait - free APIs to do all sorts of stuff, and lazy-ass programmers took the bait hook line and sinker without thinking through the consequences of everyone moving their sites into "the cloud." Or didn't care.

Lot of people need to look in the mirror on this one - from programmers to execs.


I wouldn’t blame programmers. Free APIs and services were a great way to get bootstrapped, and nobody really understood why they existed: an extended period of low interest rates after the 2007/2008 crisis. The bait-and-switch wasn’t a conspiracy, it was a natural consequence of the unusual financial environment (which itself was a kick-the-can “solution” to cover up the damage caused by the GFC).

Almost none of us were deeply familiar with how rates could affect the availability and pricing of services, and the implications for infrastructure. Many of us understand this now, but too late—it’s unlikely that we see rates that low again in our lifetimes.


It's too bad there's no one willing to be a parking lot attendant on an Italian island.


You might not have used one, but there have long been parking meters / payment kiosks that take charge cards and even cash. Neither an app nor a human attendant is required. It bugs me that these are slowly being replaced by smartphone app systems.


I think there is plenty of people, but they have these obscene demands about getting paid a living wage.


Parking is expensive enough without having to pay a human.


Can you not pay with cash or card anywhere? What if you don't have a "smart" phone? I would categorically refuse to park anywhere that requires running a proprietary app on my device. Fortunately, in the States at least, I have not encountered such a place yet.


In the UK, I believe parking companies need to have a way to pay without the app but it's usually so bloody inconvenient that it's about the same as requiring it.


Physical machines can be confusing too :)

When I was in Italy last summer, I couldn't figure out how to pay with my card at the machine in a small town, where you'd park to walk into an ancient city on a hill*. I asked two Italian woman for help and even with being able to read the Italian + having paid with coins themselves, they struggled to help me understand the combination of steps required to pay with card.


In my city in Northern California our downtown uses an app for parking now. I don’t use it so it’s still an option, but you have to goto a kiosk, enter your license plate number, and pay with card. It’s made the downtown more of a ghost town (admittedly it was already dying) and the boomers with cash just don’t go. The younger 20somethings all complain “boomers are too stupid to use an app” and have no concern for privacy apparently. Welcome to the future I guess.


I have more parking apps on my phone than any other type of app. I begrudgingly download them for some semblance of convenience, but get annoyed that I'm logging in each time as it may be months since I used it, and towns changing apps means I likely have some high percentage of void apps that I keep around just in case. Living in New England doesn't help with lots of small towns, but even Cambridge has multiple apps depending on if you are parking on the street vs in a garage.


> The younger 20somethings all complain “boomers are too stupid to use an app” and have no concern for privacy apparently.

They were literally trained not to value their privacy. The first generation of ipad kids now have driver's licenses.


I hear some take pride in being “digital native” and only knowing a world where smartphones are a ubiquitous part of your life.

I’m quite content having grown up without being always online. The childhood I had where what I did between school time and when my parents expected me home for dinner were mine alone. Every event was not recorded by 50+ cameras with bad seats and posted online for nobody to watch.

A truly excellent time to be alive that I doubt we will see again


I think we might very well see those times again except it will be very challenging to find food. Good luck.


My wife changed carriers and for a day had lost her phone number. She was texting our son (who is in middle school) and his response was “prove it’s you”.

So digital native kids have learned to not trust people on the internet, don’t use your real name in an alias, etc.

“They were trained not to value privacy” is not what they are being taught in school.


You need to find a working parking metre which may or may not work, accept cards or give back change. Also most if not all of parking apps allow you to pay by the exact minute and extended your stay dynamically from the go, while with a paper ticket you need to go back to the car and get another one before it expires


I do wonder if the "illegal not to accept cash" laws in some states have been applied to this situation.

Note that sometimes the risk is low, and changing your plate is cheaper if you do get a fine...


Essentially too bad. Look at the parkmobile disaster.


The what?


basically you have to use parkmobile in many places unless you carry literally rolls full of quarters due to the depreciation of the USD, some places dont even have machines anymore. ParkMobile is a moneygrabbing operation that municipalities use to run their parking stuff - yay saas. They got hacked and leaked everyones phone numbers, license plates, history, and more.

The settlement in court was - you got I believe a $1.00 coupon to use parkmobile again - but you could only use .50 towards each transaction


That, especially the conclusion, is hilariously bad.


It's worse I just checked

"

You are eligible for up to a $1.00 credit to be applied to ParkMobile’s service fees. The code provides a $0.25 discount on ParkMobile’s service fees and may be used up to four times for a total discount of $1.00. The code will expire on October 8, 2026. For residents of California, the code will not expire. The code will only work for accounts associated with email addresses that are in the class."


I am at a loss for words.


Park City, Utah - although there were meters that could accept card or cash available, none worked. App was the only functional way to pay. This was 3-4 years ago, not during ski season but getting close to it (October or November).


Australia: some companies are app only


You can't, no. It's the same story in Sicily. You can only pay for parking using an app, if you don't have a smartphone you just can't park. Luckily the parking app they have is pretty nice, but the requirement is infuriating


Sometime ago I had to pay for parking to get access to a hiking trail (in US). The way to pay for parking was shady as hell. Just a random QR code sticker on the wall that said "pay here" that navigated to a payment portal that asked for your CC, address, license plate. I mentioned to my friend who was with me, "anyone could really just put any sort of QR code here and navigate you to a fake payment portal and steal your CC"

But like you said, what are you supposed to do otherwise?


That's actually a common scam that happens, too. It's a constant problem in my city, and while I already have the app downloaded on my phone others do not and find themselves getting nasty bills in the mail months later.


Roll the dice; pay the ticket if cited. The cost of parking.


I think in most countries the only way to challenge this kind of thing is to park illegally and then go to court and claim it was impossible for you to park legally. Which is a hard process, on purpose.


In the States, they tow your car to a yard and hold it ransom until you fork out a $1K or so (depends on the state/municipality), with accrued daily surcharges. And, good luck finding the yard. They also only take cash or debit so that you cannot run a chargeback later on. I'd rather just pay a $300 ticket, don't tow my car.


Can you sue them for not telling you where your car is and then to recover all fees resulting from you not knowing where your car is?

I suspect you could but you'd be risking a car - better try it with the clunkiest clunker you can find.


You can try, but you won't be the first and they are going to have lawyers for this exact scenario with decades of legal rulings and legislation often in their favor already. It's not usually worth the time unless you are willing to risk losing many thousands in lawyer costs if you don't win.


tutanota.com protonmail.com

create a burner for when ‘not always applicable unfortunately’


Ive bumped into these been banned too. Apples temp addresses worked well where these didnt.


Proton does require phone number now. It's not anaonymous email provider anymore.


They do have sign up with only a captcha but it seems to be ip reputation depended if you get them.

https://proton.me/support/human-verification


didn't know that, but the point of the burner is to trap junk email in an account you don't care to read


you can pay at the parking meters directly, no need for a 3rd party app


Yes, but

- the apps almost always allow you to remotely increase your stay - the apps almost always allow you to pay by the exact minute instead of by the quarter/half an hour


Unfortunately sometimes we are at some specific provider’s mercy for whatever reason like lack of appropriate alternatives.


COUGHredditCOUGH


I think Reddit falls under this category.

> If your website will block me out because I used a privacy friendly email, I want nothing to do with your website.


Yep, toxic garbage staffed largely by same. Unfortunately, it has amassed quite a bit of potentially useful information.


You don’t need an account to access the information. It’s also all been sucked up my the LLMs, for better or worse.


It's full circle now and a large portion of posts and comments are now LLM generated responses, whether by a bot or copy/pasted by a human.


All the more reason to stop visiting.


Reddit doesn't even require an email address to make an account. You can just leave the email field blank.


But it does require a valid phone number which is worse.

(I might be misremembering but they definitely require a valid something now, as I found out a while back creating a new batch of accounts to rotate)


That was switched off recently. Now it demands an email.


I don't think so. They send a confirmation mail.


I know I have created accounts on Reddit with disposable email services before.


I have been "permanently" banned for embarrassing some abusive moderators; now it has become a vendetta. I'm not sure how many user-identifying methods they attempt, but it overcomes VPN usage. I obfuscate my Web traffic now and it seems to have foiled these losers.


Use Brave browser as it avoids browser fingerprinting.


strange. i've used disposable emails for reddit accounts several times and everything worked


Last couple of accounts I created with proton accounts were immediately shadow banned

I could post but my posts were not visible to anyone else


Cowardly, despicable behavior.

Also practiced on this site.


IDK I’ve appreciated Reddit killing off good features like old version, putting a time-lock banner on mobile while logged out, trying to block VPNs when logged out, etc.

I want that company devalued and bought by Verizon or AOL to die a Yahoo death.

What is insane to me is how few people realize their stock has a higher P/E than nVidia… and it isn’t because of some bullshit minor AI data deals. It’s a youth-forward narrative machine, and everyone knows it.


FWIW, old.reddit.com is still there and working


Shh, don't remind them.


> I want that company devalued and bought by Verizon or AOL to die a Yahoo death.

If the future's your oyster for what happens to Reddit, why stop there? If it's bought by somebody, that implies that Spez gets an amount of money that is greater than $0.00. Ideally, we avoid such a grim and unjust outcome. We want it to be made effectively worthless so he goes broke.


RedReader still works. For now.


It's precisely when I want "nothing to do with your website" that I want to use a private friendly email if I'm nonetheless forced to interact with it...


I ran into this with an NVMO mobile provider. They did not like my personal email domains (assorted .net and .org) so I nagged their customer support until they manually added it. Their marketing team happily emails my personal domains once added. Some day this will probably cause a problem but my goal is to eventually get rid of my cell phone either way.


I ran into this with an NVMO mobile provider.

As of about six months ago, AT&T's web site would not accept email addresses without a three-character TLD. I had to get a customer service person on the phone to manually change my address.


Even .us ??? Pretty sure I used my usual domain (enslaves.us) with them for wireless and california landline and u-verse.


Just a guess but .us does not permit whois privacy and perhaps that may be a factor but I am entirely guessing as all my domains have whois privacy enabled and they would not say why their system rejected my domains.


Do you mean it was failing with a >3 character TLD?


could be < 3

   .io
   .co
   .ai


> could be < 3

Or any ccTLD: .ca, .fr, .se, etc.

* https://en.wikipedia.org/wiki/Country_code_top-level_domain


But those have been around forever. The newer ones (.shop, .wiki, etc.) are >3 and it makes more sense to me they wouldn't be handled correctly.


I don't know the specifics. I can imagine someone using a regex like

^[a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]+\.[a-zA-Z]{3}$

it worked for the emails that the web dev tried and you have to have a valid email address to file a complaint.


MVNO fwiw. Mobile virtual network operator.


It gets worse. The FFA keep nagging me to renew my drone registration.


I frequently buy a domain that I think is funny and use that to forward all my emails to my main email account. It's trivial to do from Cloudflare. Then after that 1 year is up, my domain goes away and so does all of the spam.


And the not spam?


I use my real email for those or I sign up with a new email from my new burner domain.


Completely agree - have you encountered this before? The Gmail plus sign alias trick has been widely known for a long time and, to my knowledge, still works well today. It would be easy enough for websites to either block + in gmail addresses or instead grab the true email.


Some sites that block "+" in email addresses are actually just doing it out of incompetence. My credit union, for example, will actually accept an address with a "+" in it, but nothing will work because some broken bit of web 1.0 plumbing along the way converted it to a space (it shows up that way on my profile page). I wouldn't be surprised to see "&nbsp" on my printed bank statements.


Oh yes, so many websites are incompetent like that.

And of course after registering with foo+bar@example.com they will happily send invoices to bar@example.com


Gmail also have "googlemail.com" alias and you can split your username with dots since they dont count like "user@gmail.com" and "u.s.e.r@gmail.com" are the same thing,

Nothing of it solves privacy though.


Spammers know to just cut out the +whatever. It's a simple regex to keep those from even getting into a database.


The + has no special meaning in the standards, and thus removing it will just result in invalid addresses in many cases…


Doesn't matter. Most email services[1] use it the way Gmail does and spam is a numbers game. Losing a few valid addresses is worth correlating all those other addresses for most spammers.

Standards only matter to nerds like us.

[1] https://proton.me/blog/what-is-email-alias#5


Except plus address users are also less likely to be receptive to spam, so it's probably better to just not bother


Spam has never been about how "receptive" the recipient is.


They can check if it's Gmail though.


Guess what? There are some dumb website or applications complaining that the email address is invalid.


I used to run a hybrid mobile app + webapp company.

Private emails regularly lead to awful customer service interactions because people cannot tell us the email they used to register. Fastmail at least is off the beaten path enough that people probably can understand. Apple, especially using sign in with Apple, is horrid. And not just people unable to tell us the email; they then create multiple accounts; try to sign in on web and use their actual email and then have 2 accounts and flip shit that their stuff is gone; etc. Oh, and regularly blame us for their confusion.


It’s up to the app architect to make a way to make this work, and to stop using emails as anything other than a UUID type of token


So I guess the solution is just to begin to allow accounts to always register multiple emails? Although I guess the issue of multiple accounts is still going to exist if the users don't know the initial (private) email that they signed up with though unless there is a different unique ID that everyone will be able to remember.

I'm curious (and not trolling by asking) what a solution might be since email has been used as a unique account identifier for so long it is hard for my brain to think of another option at the moment.


Use a platform like Authentik where the immutable characteristic of your user is a UUID.

Allow them to sign in with OpenID, etc., to put one (or more) e-mail addresses on (obviously those e-mails end up unique to that account), in my case, I always force-link e-mail addresses from Google's OpenID (mostly to prevent people accidentally creating multiple accounts). Allow phone numbers too!

Also allow usernames (and just automatically generate them); the user can change their username if they really want to.

Every other dependent system should only be using the UUID. If you have some dumb legacy system that insists on e-mails for a primary key, have an internal only domain and hang the UUID off of that.

There is a specific use case when two people want to have their own accounts but share an e-mail or a phone number for logging in. In that case you want to just let the user pick a "primary" email address and "primary" phone number (which is the only one they can log in with as a user ID) and the secondaries are just for verification. This is kind of common with people who want their spouse's phone to be able to get into their account for example (a pretty common use case for one of our apps, although they're technically supposed to make their own accounts, we allow this simple form of sharing).


Just a regular old username + password, kind of like HN allows?


I feel like email overtook usernames because it was more likely to be unique/memorable. I hate when websites ask me to remember a username (even though I'm using a password manager so I should really just calm down.)


Usernames are no less likely to be unique and memorable than an email. You presumably chose something memorable for your email, so just enter that without the @foo.com bit. There, memorable and probably unique.


That's what I set the defaults to in Authentik. Of course, you do have to watch out for poorly-designed systems that have "reserved" usernames.


If you do require an email as an ID then yes, you absolutely should allow multiple emails per address if only so that the person can recover if they lose one of their mailboxes (similarly if you support hardware keys you should allow more than one).


ChatGPT doesn’t allow private relay and hasn’t allowed it since launch may be. So it’s not always possible to not use them, of course now there is no need to use ChatGPT and I have just stopped and moved on from it


Didn't really have a choice with openrouter. I ended up using "Hide My Email" which gave me an icloud.com, which will likely no longer work according to this article.


I guess you don't use github. It won't let you sign up with @airmail.cc.


It's pretty common. Shopify blocks my email aliases. So does ikea


That's probably WHY you're using a privacy friendly email.

So...


If your website needs an email address at all.. otherwise just use null@null.null, if it accepts and doesn't require a authentication code


[flagged]


> If you insist on giving me a fake email, your business is probably a liability I don't want anyway

It's not a fake e-mail, it's a legitimate e-mail that you can send e-mail to and the user will receive, which has to be created by a paying iCloud user and not an anonymous rando off the internet.

I'd be interested to know what downsides, if any, you see for a website to accept a private e-mail address like this. Do you have a legitimate complaint about these sorts of e-mails? Again, given that private relay isn't an 'anonymous e-mail service' (it's still tied to your iCloud account so spam, etc. shouldn't be any more of an issue) but merely an 'anonymous to the person you're giving the e-mail to' service.

If your actual complaint is 'if you insist on giving me an e-mail that you can revoke unilaterally making me unable to contact you against your wishes, and which cannot be associated with other user data from other sources to build a profile of you, then you're not worth having as a customer' then that's a separate complaint - and one that means I want nothing to do with your website.


I'm curious what you think the difference is between "a paying iCloud user" and "an anonymous rando off the internet." How many Apple gift cards do you reckon get sent to fraudsters every day? Decades worth of iCloud+ surely.

I'm running a business where I need to know who you are, because my platform can be used defraud other people. If you're trying to hide who you are from our very first interaction, that's a massive red flag.

If you can trivially create hundreds of these emails, and fill in the rest of the required info with bought/stolen/generated PII, now I have a vector for mass fraud. Requiring you to use a recognized non-anonymized provider doesn't stop you, but it sure does slow you down. (It's not this simple of course, but all security works in layers)

If these terms are not acceptable to you, then great! Don't use the website, there's no need to be salty because that's what you said you wanted. Isn't it?

I don't mind either, because the number of legitimate users who are bothered by this restriction is infinitesimal compared to the number of fraudsters who would take advantage if it wasn't in place. It can be difficult to comprehend the scale of platform fraud unless you've worked in this area, many days fraudulent signups outnumber legitimate ones.


> If you're trying to hide who you are from our very first interaction, that's a massive red flag.

You conflate email with identity, just like the media companies conflated IP addresses.

It's not hiding who you are, it's hiding my real email address behind a mask that you can't choose to sell off to marketers, or spam yourself, or otherwise profit off, regardless of the nature of our relationship - I've got plenty of spam emails from companies that I closed accounts with, thus severing our relationship.

> If you can trivially create hundreds of these emails, and fill in the rest of the required info with bought/stolen/generated PII, now I have a vector for mass fraud. Requiring you to use a recognized non-anonymized provider doesn't stop you, but it sure does slow you down. (It's not this simple of course, but all security works in layers)

It's not that simple, but I guarantee it doesn't remotely slow anyone down, not at the scales we're talking. Maybe if you're talking one entity and tens or hundreds of thousands of accounts, but it's laughably naive to believe that such a person who is set up to conduct "mass fraud" can't create 100 Gmail/Outlook/iCloud email addresses a day, if not an hour, with near zero effort (it's not like they're committing "mass fraud" by hand, after all).


> I guarantee it doesn't remotely slow anyone down

I have watched the rate go down and stay down on real live dashboards.

> Maybe if you're talking one entity and tens or hundreds of thousands of accounts

We are.

I'm not so rude as to call you "laughably naive" but I am speaking from experience and you appear to be considering a hypothetical.


> If you're trying to hide who you are from our very first interaction, that's a massive red flag.

If you're trying to collect personal information that's none of your business from the very first interaction, that's a massive red flag. Like how many data leaks and customer data exposures is it going to take to understand that the data I'm giving you is a liability for me? How much spam am I expected to put up with because you give my data to a "data broker" for one reason or another? Why should I trust anything you say regarding how you will handle my data after all the embarrassing fuck-ups over the years? What is your liability if you mishandle my data, is it approximately $0? Do you have an arbitration clause in your TOS so I can't even sue you when you screw up?

There's zero responsibility from the tech industry for their continued failures in this regard and then you have the temerity to lecture me about my "red flag"? Seriously?


You not bending over and opening your wallet is, frankly, a red flag. /s


I feel as though it would be a lot easier and cheaper to open up a new gmail account than to create a new Apple account, add a gift card, sign up for iCloud+, and then create private relay e-mails to use for signing up.

Is there something about gmail that makes it less suitable for the fraudulent use cases than iCloud+ private relay e-mails? I presume you're thinking of the 'create many anonymous e-mails' feature in that regard, which makes some degree of sense. I wonder if iCloud+ throttles e-mail creation.


It sounds like you are trying to shoehorn email into some kind of “real person verification” role, when you ought to be doing actual KYC through some provider like ID.me. (If honest to god no-shit fraud is on the table.)


If I can filter/throttle fraudsters at the create account step for free, I save on the fees my KYC/IDV providers charge each time they attempt to defeat it.


At the cost of blocking legitimate users who don’t want to be spammed, don’t want to be correlated after a data breach, etc.

I have been willing to do KYC for services (usually financial) without giving out my main email. Services that put up too many barriers to this don’t get my business. I concede that there aren’t that many users like me, compared to the general public, but I’m a legitimate user.


There must be at least two of us!


[flagged]


Nowhere other than on HN have I seen so many people who are actively proud of their anti-consumer (and frankly anti-human) behaviour. It's a rather revealing look into the veil behind big tech. A lot of people have this misconception that it's evil $bigcorp forcing employees to do what earns a paycheck, but no, there's no shortage of normal people like yourself bragging about anything they can do to identify and track consumers more easily while comparing them to fraudsters for not wanting to be tracked. I suppose that's the narrative you have to concoct to help yourself sleep at night.

I'm curious, though:

> choosing to participate anonymously

Why are your name, e-mail address, and phone number not on your profile? Are you using HN with the intent to commit fraud?


Because this isn't Facebook, or your mom's of. It's a forum where your reputation doesn't matter. I'm not trying to sell you something or have you trust me.


[flagged]


They aren't giving useful information, they are posting an opinion insinuating that people who use """""fake""""" (ie. non-personally-identifying) e-mail addresses are fraudsters.

> If you insist on giving me a fake email, your business is probably a liability I don't want anyway.

They did not provide any meaningful insight into the field, they are simply insisting that e-mail addresses should be a tool for personal identification because it saves them money over doing real KYC. In other words, they believe KYC should be slanted further in favor of corporations and against customers, such that KYC is publicly available for free, because they value not doing the work of verification over humans having any privacy whatsoever.

As they are entitled to post their opinion on humans having no privacy rights, I am entitled to post mine and point out the hypocrisy of them choosing to participate in this forum privately while advocating for and boasting about denying service to other people who attempt to protect their privacy.


As others have alluded to, I'm not doing this to be anonymous, I'm doing this because companies can't be trusted not to leak my email address. Every real business that knows my real identity (banks, payroll, government, retailers, etc.) gets its own alias.

When an organization invariably leaks my email and I start receiving spam to it, I generate a new one, update my email on record, deactivate the old one, and the spam stops.


> fake email

Its a real address that I can use to monitor your behavior, since businesses send so much damn spam.

Been using them for 25 years, not gonna stop any time soon.


There's nothing "fake" about the email. It's just an alias made specifically for each recipient.


Seems like we have a meeting of the minds here. You don't want me as a customer and I don't want you as a vendor (or payment processor). Enjoy your spamming :)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: