this post was submitted on 09 Oct 2024
826 points (99.9% liked)

Technology

59378 readers
3143 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] sugar_in_your_tea@sh.itjust.works 34 points 1 month ago (3 children)

I recently went through most of my accounts and randomized the username, with the thought here being to limit the likelihood of one site being compromised leading to accounts at other sites being compromised. I don't have to remember them due to using a password manager, so it's really no skin off my nose.

I'll use this as a reminder to everyone to improve your security. Some ideas:

  • use a password manager and use random usernames and passwords
  • have multiple email accounts, and don't use your "main" email w/ random signups - I use a simple mnemonic, like "-@domain.com"; so "me-shopping@domain.com" or "me-games@domain.com" so it's easy for me to remember, but unlikely for a lazy hacker to pwn other accounts (a lot of these are automated); my real email is "me@different-domain.com"
  • use 2FA if offered, even if it's stupid SMS or email based; having any extra step can deter an attacker

Sucks that people are targeting IA, I hope there isn't any lasting damage and that this is a simple defacement/DOS.

[–] Pringles@lemm.ee 11 points 1 month ago (4 children)

For e-mails, you can just get firefox relay with your own subdomain and generate infinite e-mail masks for 1$ a month. I usually take "nameofshop@mysubdomain.mozmail.com" for example. It's pretty great because you just make the masks on the fly.

[–] xthexder@l.sw0.com 7 points 1 month ago (2 children)

I've been doing this for several years now (not specifically that service, since I have my own domains). It's really nice knowing exactly who sold your email to the spam bots, because it's right in the address. Super easy to block once that happens.

[–] helenslunch@feddit.nl 2 points 1 month ago

Yeah, I bought some Chinese batteries a while ago and they sold/leaked my info to a dozen other scam companies. None of which I was able to unsubscribe from. Just ticked a box to disable the email and that was the end of that. If I hadn't, they would have been blowing up my inbox for the rest of eternity with no way to stop it or know where it came from.

[–] VonReposti@feddit.dk 1 points 1 month ago* (last edited 1 month ago)

addy.io is another service which I'm using with my own domain. I know there exists a third, but I can't remember the name.

[–] sugar_in_your_tea@sh.itjust.works 4 points 1 month ago* (last edited 1 month ago)

Yup.

If you use the same email everywhere, they can try brute-forcing the password by using the email instead of your username. Give them less to go on. $1/month is absolutely worth it to prevent an important account from getting hacked.

[–] elfin8er@lemmy.world 2 points 1 month ago (2 children)

What about plus addressing which is supported by most major mail services for free? You can just use personaladdress+nameofshop@gmail.com for example.

[–] toynbee@lemmy.world 4 points 1 month ago (1 children)

For users of Gmail, I can confirm this works and you can even set it up so that address+nameofshop goes to a folder called "nameofshop."

You can also apparently add a dot anywhere before @gmail.com and still receive the email. I haven't tried this one, but the last time I mentioned this someone said it was part of the email standard, so presumably it works.

I don't know of tricks specifically of this vein for proton mail, but I do know you can setup a catch-all address so, for example, something addressed to invalidaddress@domain.com goes instead to spam@domain.com.

I've not tried SimpleLogin, but apparently it offers similar functionality.

[–] ben_dover@lemmy.ml 2 points 1 month ago

can confirm, foo@gmail.com works just the same as f.o.o@gmail.com

[–] Pringles@lemm.ee 3 points 1 month ago

I didn't know that actually. They can still deduce your actual email address from that, but for the identification of the culprit that would work as well.

[–] Blackmist@feddit.uk 1 points 1 month ago (1 children)

The email mask is free without a subdomain. I use it for the odd random signups where the only thing I'm really interested in is not having another nobhead add me to their spam lists.

[–] Pringles@lemm.ee 1 points 1 month ago

That's how I used it initially as well, but chose to get a subdomain to identify shops and services that had data breaches/leaks, pass on the email to other shops and services, etc.

And then I can just block that mask.

[–] Julien_catanese@lemmy.world 2 points 1 month ago (1 children)

I recently went through most of my accounts and randomized the username, with the thought here being to limit the likelihood of one site being compromised leading to accounts at other sites being compromised. I don’t have to remember them due to using a password manager, so it’s really no skin off my nose.

I’ll use this as a reminder to everyone to improve your security. Some ideas:

use a password manager and use random usernames and passwords
have multiple email accounts, and don’t use your “main” email w/ random signups - I use a simple mnemonic, like “<user>-<purpose>@domain.com”; so “me-shopping@domain.com” or “me-games@domain.com” so it’s easy for me to remember, but unlikely for a lazy hacker to pwn other accounts (a lot of these are automated); my real email is “me@different-domain.com”
use 2FA if offered, even if it’s stupid SMS or email based; having any extra step can deter an attacker

Sucks that people are targeting IA, I hope there isn’t any lasting damage and that this is a simple defacement/DOS.

thanks for the advices ! Would you recommend a particular password manager?

[–] sugar_in_your_tea@sh.itjust.works 7 points 1 month ago (1 children)

I like Bitwarden, largely because it's open source and audited by a reputable third party.

[–] Julien_catanese@lemmy.world 2 points 1 month ago
[–] AsudoxDev@programming.dev 2 points 1 month ago* (last edited 1 month ago)

Point 2... if you pay for a email aliasing service, you will be locked in. What I suggest is using plus addressing. e.g.

example+83hdo72@example.com

As long as you keep using randomized ones, this'll be as good as an alias against automated and manual login attempts. It just does not hide your base email, which would be

example@example.com

Many email services offer some free aliases. For example, I use one alias, along with my main email that is only used for important services. Other than that, I have an alias that is used for online accounts. This way, your main inbox is free of spammers. And even if your main address were to be the target of a spammer, the automatic spamming software most likely will not chop off the plus part, so you can easily block that email with the specific plus identifier. Not as good as external email aliasing services, but at least you won't be locked into the email aliasing service. Bitwarden has a generator for such things, really nice tbh.