• I hadn’t heard about this feature before and was curious how it worked. Basically its creating a random email alias for your mailbox that you can manage separately from your main address, so you can turn it off if whatever site you gave it to starts getting spammy. Use a password manager and the fact your account email is random shouldn’t matter much when logging into a website I guess.

    • artyom ( artyom@piefed.social ) 
      link
      fedilink
      English
      arrow-up
      8
      ·
      3 months ago

      It’s a common feature. Mozilla, addy.io, SimpleLogin, etc. all have it. However Apple is special in that they use the same domain as millions of other genuine users, so sites can’t really effectively block you from using it, as is the case with just about every other email aliasing service. Unfortunately they’re also abandoning that feature.

    • Yes, a password manager will help to generate account logins and track them easily for you. But also if your email provider supports it, set your username email address with a +prefix specific to the website/service so you make the account unique, have traceability and isolate your risk if your email or account is sold or leaked. E.g. name+website@example.com

      Not every website or service accepts email addresses with plus sign prefixes but this is handy for most.

    • XLE ( XLE@piefed.social ) 
      link
      fedilink
      English
      arrow-up
      2
      ·
      3 months ago

      There are several services that offer this to both free and paying users. As far as I know, though, none of them have a vulnerability as bad as this

    • No detail given outside of it was disclosed to Apple a year ago, and - despite repeated gentle, respectful prodding - the problem still hasn’t been fixed, so now the people who found it are revealing to the public that it exists, and the website reporter says they confirmed it. Coincidentally(?), Apple recently said they’re going to change the way spoofed emails work - of course, the change will make it obvious it’s a spoofed address so it’ll be easy to reject them.