The problem is if someone figures it out and starts sending you spam to {random}@domain.tld. That's when you will need to sit down and start creating actual aliases for all those used email addresses and stop the catch-all forwarding:)
Also, another downside is that you will loose privacy by using your own domain.
And the lack of privacy makes targeted scam/phishing more likely, and targeted scam is the one we are most susceptible to.
All in all, I am not saying this is bad idea, in fact I am doing it myself, just pointing out this is not so black and white.
Using iCloud solves those problems, but puts you at risk of getting your account banned and loosing access to those emails, so there is that.
Probably best way to deal with it is to get dedicated email domain with a bunch of your friends, and hook it up with something like SimpleLogin. But that's gets complicated quickly ;)
I have run this for years with very little problems. And I can honestly say that have not found anyone writing to addresses I did not give them at their domain. Simple as this is, it is way to niche for companies to figure it out and exploit it. And if that really was a problem I'd just create a new subdomain.
If you are worried about privacy, get a domain just for this. Use domain privacy and dont host other things there.
Yes, some sites whitelist domains or dont allow subdomains. For those I'll use another account - or a firefox alias or something. But 9 out of 10 work fine.
I am not a fan of alias services since materializing names takes discipline. How many do you make? Maybe there is a limit of 50. When do you share them across services? My guess is many people just create 2 or 3 aliases they use for everything - which defeats the purpose. Sure, it masks your personal address, but once one gets compromised, you find it basically served as your personal address anyway.
I also dont really keep track of most of the names I use. Since most are one time things that I would never use again, like to sign a waiver or something. But I mostly stick to '{domain}@' for the names. So my nytimes account would just be nytimes@, which is predictable when I need to recover it. I used to use addy.io for this, but it was not as good since it had account limits and I had to manually manage every alias. Much easier for me to just create a mail filter to sinkhole an old name. Of course I have never really needed to do this anyway.
> I have run this for years with very little problems. And I can honestly say that have not found anyone writing to addresses I did not give them at their domain. Simple as this is, it is way to niche for companies to figure it out and exploit it.
Someone I knew did this. Spammers used lists of common names.
I've found using a subdomain helps with that, spammers will try everything@domain.tld but won't bother trying to brute force subdomains.
However be warned some surprisingly large websites don't support subdomains, for example eBay will silently send user@sub.domain.tld to user@domain.tld and you'll only figure it out by looking at your server logs for rejected mail.
In those cases I have to specifically alias that username@domain.tld to the subdomain.
With this new Apple privacy subdomain maybe eBay will finally fix this.
Because the world runs on incompetence, so it's ultimately unavoidable (best case, you don't know that something important that you're relying on is run incompetently).
WHOIS isn't a factor here. If an attacker knows or deduces that you're the only individual receiving mail at *@yourdomain.example [1], they can track you across different databases by just looking for your domain name.
The privacy preserving aspect of hide-my-email services is the fact that they have thousands of users using the same domain name.
[1]: This is trivial if you have a service's email database leak. You just find all domains that have exactly one user. If the service targets individuals (who would sign up with personal emails, not work emails) and is reasonably popular, you'll get a pretty good list of single-user domains.
> If an attacker knows or deduces that you're the only individual receiving mail at *@yourdomain.example [1], they can track you across different databases by just looking for your domain name.
How would that attacker gain access to such databases? Let's say HN is compromised and my email here, say hn@mydomain.com, is leaked. How does that help you track me elsewhere? If I start receiving spam at hn@mydomain.com because of the leak, I will simply revoke the alias and the spam will bounce.
> How would that attacker gain access to such databases?
Data breaches happen all the time.
Some services also expose emails, intentionally or unintentionally. Github is one example where your email might be exposed publicly.
> How does that help you track me elsewhere? If I start receiving spam at hn@mydomain.com because of the leak, I will simply revoke the alias, and the spam will bounce.
Because, as parent said, if someone deduces that you are the only user of mydomain.com, they can just search leaked or exposed records for @mydomain.com and infer that the accounts most likely belong to the same person.
That's the difference, with hide my email millions of unrelated people share the same domain, so you can't reliably link one email to another just based on the domain.
> The problem is if someone figures it out and starts sending you spam to {random}@domain.tld.
It's a non-issue. I've been using a catch all domain for at least a decade. I get a small amount of spam to random made up emails but not enough to care about plus it all gets caught and filtered.
Not really, this only works for other emails hosted by Gmail (including Workspaces) or if you supply SMPT that will send those emails. If you use simple email forwarding from your DNS provider, you don't have SMPT server to give to gmail:/
Google will happily send from smtp.gmail.com, after verifying that you own that email. You won’t get DKIM, but Google’s reputation is enough to make the mail land in people’s inboxes.
> (This is somehow fixed in 1.2 but it requires additional entry in the config for whatever reason. Can't it just work?)
"For whatever reason": because it requires modifying `ssh` and doing that by default is a really sketchy thing to do because it is a very security sensitive tool. No program (Ghostty included) should be mucking with that by default. We want users to be aware.
"Can't it just work?": No, because the entire mechanism is flawed, and I didn't invent the mechanism. It's like asking, "why must I drive to my destination, can't I just teleport?" The entire premise of the question is silly, and it's not the car's fault (Ghostty is the car in this example). For those who want to learn more about "the mechanism": read Ghostty's terminfo page, but also just do some light web searching on how terminfo works. Its a total nightmare.
I really wish that weren't the case, I really do. I promise its just as annoying to me as a user and more annoying to me as a maintainer to have to hear people complain about this repeatedly when I'm not doing anything wrong, personally. I'm playing by the rules. The rules are just bullshit.
We'll continue to make enhancements to improve this while we wait for Ghostty's terminfo to propagate to every machine in the world. It will, it'll just take... a long time. Next up we plan on introducing a `ghostty +ssh` command that you can drop-in replace most `ssh` usage with and it'll automagically just work.
Ouch, I did not expect my complaining would get a response from the author!
Just to be clear, I do think Ghostty is amazing piece of software and it's so fast that it's hard to believe, so thank you for the hard work.
> read Ghostty's terminfo page, but also just do some light web searching on how terminfo works. Its a total nightmare.
Oh, yea, I totally get that. I actually _did_ try to understand what the issue is, but gave up on that time-sink rabbit hole and decided I might give it another try once the xterm-ghostty is more popular.
Have you considered the fact it could be because Apple Watch itself is closed, walled garden and Apple has full control over its security (and therefore trust in it)?
Imagine a world where they allow Pebble to go through certification process for it to get jailbroken half a year down the road opening the gateway to iMessage for all the spammers in the world. What then? Should Apple now play whac-a-moll with the spammers forever, or block the access to all Pebble watches creating another scandal? And what if this happens to next 10 different watch makers down the road?
They own Apple Watch and if it gets jailbroken its their mess to deal with, but if they open it to the world then they have zero control over it.
If they block access to all Pebble watched AFTER it has been shown to be opening a dangerous gateway to spammers despite valiant attempts by all to engineer it to be safe, then that would be a lot less of a scandal.
If they further block it by default but allow Pebble users to bypass the block with some very scary warning message then My God there wouldn't be a scandal at all. People who know and accept the risks can use the thing they paid money for as they please then.
Free does not mean limitless. Where I live in EU its not uncommon to wait for over a year to see a doctor on „free” insurance and less than 24h when you pay out of your pocket.
People get free insurance but hospitals get fixed amounts of cash allowing them to admit fixed amount of patients
In this scenario the answer is yes, it loses some value. Still much better system than private care in US
There is a queuing theory thing here! People die in the queue.
However the US system. seems to create a lot if inefficiency. There is no free lunch. But a lunch where you don't throw out as much bread as you eat is more efficient.
For a several years now, all new cars sold in EU must have an S.O.S. button that will call emergency services. As a result each and every car has some sort of SIM card built-in and a cellular plan that works across entire Europe.
This SIM card must be free, but its a gateway to things like upselling (pay us $XX and get a wifi in your car) and also a way for the manufacturer to have always-on connection with the car.
Some manufacturers (KIA/Hyundai, Ford, Toyota) offer complimentary free app that you can use to check car location, open/close it, turn on AC (hybrid/ev) etc. with option for more paid features.
Edit: As for the speed limit, its also Europe regulation from this year - car must know the speed limit and beep if you exceed it. Different manufacturers do it differently, but since this has been optional feature for so many years in every car, all manufacturers had this ready - and its mostly based on built-in navigation + road sign recognition. It could use cellular but since this has been feature for so long I don't think this is how it works in majority cases.
Unfortunately, its not that simple. From the car company perspective, all they want is to sell new cars and they are perfectly happy with scrapping the 8-years old EV with damaged battery.
Also, people keep talking about converting batteries to home energy storage but its not that simple to do on your own - in fact its borderline dangerous to do so on your own due to hundreds tricky mistakes you can make that will end up with fire completely burning your home. This will only make sense at industrial scale but that also means it wont be too cheap anymore (not to mention those 8-years old cars which are in good condition, just missing battery that is more expensive than new car).
Also, I do think people are scared way too much by those dying batteries. Some of them will fails, sure, but there are so many gasoline cars with engines which have like 50% failire rate between 90k-180k miles driven. That's also pretty expensive to fix where often the only choice is to buy another engine from crashed car. I assume it might be similar here - 20-30% batteries will fail soon after the 8y warranty and will be replaced by batteries from crashed cars, the rest will work just fine for 15+y
I own Mach-E EV and I am scared. It's a great car, I love it but looking at what tesla is doing to the EV market - both new and used - I can't even fantom how it will look in a few years.
Its surprising how on one hand a huge effort is put into World of Warcraft running smoothly on macOS (they always implement all the new Metal features with every expansion and it was the first native Apple Silicon game) but completely abandoned macOS for new titles.
Of course they won’t drop a good chunk of their existing subscribers overnight; once the initial work is done, maintenance shouldn’t take a ton of resources, especially considering it’s still a cash cow. Likewise, they are sort of maintaining SC2 with these tiny balance patches, and it’s still working on macOS, but it’s clearly the last echo of the old company.
Well, yes its Apple thing, and they do have systems in place to prevent this, though I'd argue they are not very user friendly for non-tech savy people.
Also, another downside is that you will loose privacy by using your own domain.
And the lack of privacy makes targeted scam/phishing more likely, and targeted scam is the one we are most susceptible to.
All in all, I am not saying this is bad idea, in fact I am doing it myself, just pointing out this is not so black and white.
Using iCloud solves those problems, but puts you at risk of getting your account banned and loosing access to those emails, so there is that.
Probably best way to deal with it is to get dedicated email domain with a bunch of your friends, and hook it up with something like SimpleLogin. But that's gets complicated quickly ;)