Hacker Newsnew | past | comments | ask | show | jobs | submit | more groovecoder's commentslogin

(Relay tech lead)

Oops, thanks for catching that. We'll add a LICENSE file.


(Relay tech lead here)

Yeah, the all_urls add-ons are always concerning. We have an issue filed to move that to optional_permissions instead, but need to get the UX right:

https://github.com/mozilla/fx-private-relay/issues/252


(Relay tech lead here)

It's in the privacy policy (https://www.mozilla.org/en-US/privacy/firefox-relay/), but yes - the emails are sent thru Amazon SES in plaintext.

We have kicked around the idea of enabling + preserving E2EE emails thru Relay, but ... it's tricky.

https://github.com/mozilla/fx-private-relay/issues/360


Howdy. I'm the tech lead on Relay. We're working on replies right now:

https://github.com/mozilla/fx-private-relay/pull/770


While you're here, can you test the relay dashboard (where you can create aliases) on Firefox for Android 84.1.4 ? The scroll is incredibly sluggish, I don't know what scroll effect you added but please have a look. It's a bit unfortunate for a Mozilla service ^^ I can provide you a screen capture if needed.


Can you file that here so I don't forget?

https://github.com/mozilla/fx-private-relay


Note: we have an update coming that includes a "Limit to Designated Sites" feature in the base Multi-Account Containers extension: https://github.com/mozilla/multi-account-containers/pull/165...



That helps only for breaches involving specific email addresses. What the GP is hinting at is Facebook having your email address and you using the same email address on a site for a purchase. Sellers usually upload their customers' email addresses on to Facebook and other social media platforms so that they can target these users better. So if you use the same email address everywhere, then linking all your interactions and transactions is a certainty.


M-A-C dev here ...

We're actually pretty deep into the work of adding sync to M-A-C. https://github.com/mozilla/multi-account-containers/pull/161...

Predictably, synchronizing data is complicated, so it's taking a while and we're trying to do it in a way that doesn't destroy any existing data. So we'll be doing some heavy internal testing on it before we release it.

But it's definitely coming.


It's pretty verbose and lengthy, but I recently read the NIST "Trustworthy Email" publication and it did a great job explaining these technologies - Sender Policy Framework (SPF), DomainKeys Identified Mail (DKIM), and Domain Message Authentication, Reporting, and Conformance (DMARC) - that are used for modern email authentication.

https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.S... (PDF obv.)


Opinion article; is thinly-veiled content-marketing piece for an AI cybersecurity company.


I found the statements about PII uploaded by advertisers confusing. The authors say “PII uploaded by advertisers to target customers via custom audiences” was NOT found “being used for advertising” but the whole point of uploading PII into custom audiences is to target them for advertising.

You have to read the details later, where they uploaded 2 different pieces of PII for a customer - one already associated with a FB user, and therefore targetable. The other was brand new PII. Only the latter was not found to be targetable.

So yay - Facebook doesn’t use rainbow table lookups to extract plaintext PII from hashes that advertisers upload. Gold star for them.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: