Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That still tells the sender it’s a valid email address though?


You can literally ask any SMTP MX server if an email address is valid, and it'll tell you yes/no. Emails send to invalid addresses are in general not silently discarded.


> I've noticed that moving the goalposts is extremely prevalent on HN, which makes for pretty frustrating conversations (or just reading). And then sometimes it's a tag team[…]

<https://news.ycombinator.com/item?id=23117242>


Politicians are masters of this tactic of deflection. The nastier, the better they are at it.

Calling it out is the best one can do without getting trapped in a cycle of low-effort premises and high-effort responses.

Although, as usual in HN, the premises come from different accounts, so both are valid. And it probably reveals valid addresses when the image URL is unique for each email.


Definitely happens a lot on HN, but I think that's just the nature of a mix of different opinions. Better IMHO to just treat them as individual arguments and reply accordingly


> moving the goalposts

I'm really not (honestly!) trying to invalidate anyone's point or win any argument - my post is more of a question-in-disguise: the GP post I was replying to concerns message-read tracking; whereas my post invokes the entirely separate matter of external actors being able to determine the validity or existence of a gmail address.

I'm not moving the goalposts; you guys are talking about the NFL game's goalposts; I'm talking about the FIFA world cup game goalposts.


> I'm not moving the goalposts; you guys are talking about the NFL game's goalposts; I'm talking about the FIFA world cup game goalposts.

Analogously, the issue would be out of bounds then, as the issues are distinct, and so a failure mode that discloses the existence of an email account is not a failure you can lay at the feet of any particular provider of email accounts, but is partly an implementation detail of how different email providers respond to emails to nonexistent addresses. That particular failure (disclosure of the existence of an email address) and any potential solution is considered out of the scope of the problem in the thread (disclosure of the opening of an HTML email due to loading tracking pixels).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: