Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
tjames7000
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
tjames7000
2mo ago
Here are some more details: https://easyoptouts.com/guides/apple-hide-my-email-was-leaki...
2.
▲
by
tjames7000
2mo ago
Here are some more details: https://easyoptouts.com/guides/apple-hide-my-email-was-leaki...
3.
▲
How Apple's Hide My Email exploit worked and why you're still at risk
(easyoptouts.com)
4 points
by
tjames7000
2mo ago
|
0 comments
4.
▲
by
tjames7000
2mo ago
We don't have full headers, unfortunately. I'm not very familiar with SMTP, but to test things out, we ended up running a minimal custom mail server with the nodejs 'net' module to have full control over responses. I thi
5.
▲
by
tjames7000
2mo ago
Okay, I see what you mean. We never paid attention to whether (1) was happening. I imagine Apple can tell based on the code that was running at the time. Even in case (1), isn't it possible that Hide My Email bounces happen differently
6.
▲
by
tjames7000
2mo ago
We saw the issue for a wide variety of hidden address domains. We use Mailgun to send emails so we were seeing Mailgun logs with things like this. I replaced the customer's real email username with "redactedForPrivacy". &
7.
▲
by
tjames7000
2mo ago
We'll publish more details soon. In short, emails that triggered 550 5.7.1 or 552 5.7.0 were what we saw the most. 550 5.1.1 was also a problem in the real world, but not possible to exploit. The error message contained the meant-to-be
8.
▲
by
tjames7000
3mo ago
We're hoping that by notifying people that there's a vulnerability, people can stop using Hide My Email if it matters to them. I don't think that disclosing the exploit method will get Apple to fix it faster at this point.
9.
▲
by
tjames7000
3mo ago
> > “It seems that ending new sales of Hide My Email until the problem is fixed would be an effective way to limit the number of customers at risk. Is that an option?” Murphy wrote back. > I can only hope that was a sardonic moment
10.
▲
by
tjames7000
3mo ago
I've been going back and forth with Apple about it for a year. We don't feel comfortable releasing the exploit details even though they're being slow. We think enough people rely on Hide My Email for personal safety that it w
11.
▲
by
tjames7000
3mo ago
We put up a timeline of the disclosure here: https://easyoptouts.com/guides/apple-hide-my-email-is-leakin...
12.
▲
by
tjames7000
2y ago
I co-founded easyoptouts.com a few years ago because all of the existing options were way too expensive. We focus on publicly-accessible people-search sites. Our customers are happy, and you can check out our privacy policy to see how we ha
13.
▲
by
tjames7000
2y ago
easyoptouts.com, which I work on, doesn't use manual labor - everything is automated! It's definitely important to avoid giving more people access to the data. edit: and as a result of automation, our prices are also way lower tha