I do this with fastmail. Besides privacy, another benefit is you can set up routing rules. e.g. for subscribing to newsletters, use <whatever>[email protected]. Anything that goes to an address that ends in [email protected] gets marked as read and is delivered to a folder for newsletters. I do a similar thing when signing up for services. It's kinda like what Gmail does with ML, but you have more control.
Do you know if they actually don't bother? The article author makes it sound like tracking companies do in fact normalize gmail addresses. I suppose my custom ___domain addresses wouldn't be too hard to normalize either if you have a way to take a ___domain and get a probability for how likely it is to be a personal ___domain. It provides a little extra friction at least, I guess.
Tyler, get to the point. I’ve been reading for 5 minutes about Facebook, Tim, and Inflection... and just got to “backstory”. The backstory has a backstory too?
I'm all for concision, particularly in technical writing. But not every article has to be like that. This article feels like a mix between an essay and a public journal entry, and I thoroughly enjoyed reading it.
For 12 years, I have had an email setup where all emails for the ___domain go to one mailbox (postmaster style). Then, I just give each service their own, unique email address without any configuration. Any spam or unusual mail is then easily-identified. Plus, it makes for easier searching, sorting and tagging. A good, secure, backed-up email & webmail setup is necessary to make it work.
For anything I don't care about and want better anonymity, I'm fine with using random, public disposable email addresses.
I've started doing this and have ended up depending on my password manager to track which emails I need for logging in to a service, which is a bit of a hassle although I think it's still worth it for the reasons you outlined. For example, did I use [service]@___domain.com or [abbreviated-service]@___domain.com, or was it [service.com]@___domain.com...?
The only service I have that problem with is Microsoft since it's a merge of like three different accounts (MSN messenger, Skype, and Office365) so I can never remember which is the right one.
Otherwise my rule is to use the central part of the ___domain name (no www or TLD), or it's easy enough to just search my email archive for messages from whatever service.
This also happens to some extent in real life. Often when I say that my email is "[email protected]" it's met with a "well, if you're just going to give me a fake address…". At which point I have to explain 1) catch-all email addresses, and 2) yes, you can own your own entire ___domain name.
Near enough everything is in my password manager. I use <service>.<month>.<year>.<nonce>@___domain so I have to so to speak.
Using keepassxc + its browser and mobile extensions make this easier than typing the address in myself. I was astounded at how bad the ux the paid pw mamagers I've used is
I have own ___domain and use unique address and password for each service. This lets me know which one leaked it.
When Adobe lost both my address and password I tried contacting their support (I was paying customer). The support person repeatedly said they checked and my credentials were safe. This regardless the fact I had proof. Very disappointing.
Since then I had couple other situations like that.
I guess companies assume users are idiots and use same password everywhere and so they feel safe nobody can prove it is them ho lost it.
In theory I agree. In practice I strongly disagree. As soon as I hit more than maybe 3 email addresses it became a burden to maintain and I totally regret it.
I could do <servicename>@example.com to make things easier but this is less secure than <random>@example.com
I find that <servicename> is actually adequate. Your primary adversaries are all automated and the technique is not so widely used to date as to be accounted for by the bots at large. I guess for that extra edge of security you could do it in pig latin.
Getting the mail isn't the problem. Sometimes I have to reply to those company and especially in a Mail client setup it becomes difficult to reply from <company-name>@mydomain.tld and I often end up replying from <my-first-name>@mydomain.tld and they have my main email as well. Unless of course I setup a "reply-from" for each of these <company-name> emails I used.