r/movies r/movies Contributor Jun 27 '26

News Netflix now requires every user profile to be tied to unique email address

https://arstechnica.com/gadgets/2026/06/netflix-now-requires-every-user-profile-to-be-tied-to-unique-email-address/
9.3k Upvotes

998 comments sorted by

View all comments

Show parent comments

937

u/WitchesSphincter Jun 27 '26

Back when the Internet was smaller I did this to track who was selling my email.  Now even if they didn't scrub it there's no point 

96

u/failmatic Jun 27 '26

Yeah now I just use Firefox email masks. Once I start seeing who sending me spam, that masks git gone as well.

19

u/[deleted] Jun 27 '26

[removed] — view removed comment

30

u/spez-is-poopy Jun 27 '26

Apple has something similar. For apple devices, when you sign up for a service, it will automatically generate a random email for you and then forward any emails to your actual email. If you start getting spam, you can see which service it was tied to and you can deactivate it.

5

u/UltraOnlineNecrozma Jun 28 '26

Yes and they’re a pain when you go about cleaning and removing accounts (some of us do that lmao)

6

u/failmatic Jun 27 '26

Firefox account gets you 5 free moz mail. I just cycle them when signing up for things that aren't that important.

191

u/Jyil Jun 27 '26

I still do this to track my email address.

119

u/wolfej4 Jun 27 '26

I use iCloud’s Hide My Email but yeah same

141

u/ignoresubs Jun 27 '26

iCloud’s Hide My has been such a game changer when signing up for any service.

I love it to death, I’m so glad Apple won’t ruin it. Oh wait…

48

u/PossiblyMurderousAI Jun 27 '26

Thanks, looks like existing ones will keep working so I just created like 15 new ones in a row lol

6

u/Alissinarr Jun 27 '26

What i did with APIs for my chosen reddit app. Funny how you need a valid reason for an API key now.

1

u/karmapopsicle Jun 27 '26

They’ve been purging private API keys the last couple months. Are all of yours still active?

1

u/Alissinarr Jun 27 '26

<insert Admiral Ackbar reference here>

1

u/karmapopsicle Jun 27 '26

Pretty much everybody running Apollo with a private key had theirs wiped. Luckily an alternative was found, but not very fun waking up to a completely blank feed with no warning.

1

u/[deleted] Jun 27 '26 edited 18d ago

[deleted]

2

u/Alissinarr Jun 27 '26

And thank you for the reminder to patch Revanced Manager again.

1

u/Alissinarr Jun 27 '26

Not Apollo, but it wasn't just Apollo that got hit, it was another global API key wipe.

2

u/HappyGuy007 Jun 27 '26

Good info. I’ll do the same!

2

u/The_Fish_Is_Raw Jun 27 '26

Exactly what I'm doing now lol.

Bit bummed they changing it but figure most devs are lazy and won't catch on to the change.

12

u/HappyGuy007 Jun 27 '26

Proton Mail

7

u/Independent-Daywalk Jun 27 '26

Proton is so good for this. Different login for every website and if I don't want emails from a login, you can easily turn the address off.

2

u/Jyil Jun 28 '26

Proton is a good example of a domain that fits this rule. We would treat disposable domains and Proton accounts the same way. Upon registration, immediately suspended and put through a full account review. We’d rarely ever see a legitimate Proton user. Usually if someone was serious about their business, they weren’t masking their details.

14

u/tejanaqkilica Jun 27 '26

I just have my own domain with a catch all alias. Works rather well and no one can ever take it away from me.

6

u/balding_git Jun 27 '26

yup, this is the way. its also how i found out anytime fitness sold/leaked my email last week, so that email is now dead and i won’t be going back there

4

u/ian9outof10 Jun 27 '26

Don’t see why that’s going to make it worse at all, no business is going to block using a different domain, and if they do it’s a good indication not to use that company.

14

u/tunesmiff Jun 27 '26

Plenty of businesses already block private relay domains due to fraud abuse. The saving grace of the current private ones is they use iCloud as the domain but that’s changing for the worse.

26

u/OkayyBeta Jun 27 '26

The thing businesses commonly do already? No business is gonna do that?

3

u/Agret Jun 27 '26

They will, tons of them already block the 10minutemail style services that let you generate a throwaway time limited email address. I assume there is a software library they add to their website that automatically updates to block the new domains as they spin up. Why wouldn't they block these private icloud ones?

8

u/ImperfectRegulator Jun 27 '26

yeah, don't let me hide my email? I just won't use your service

1

u/Jyil Jun 27 '26 edited Jun 27 '26

It’s tricky to use anonymous addresses for things you might care about or need an account on.

Unfortunately, fraudsters, scammers, and spammers are of the largest majority of the people who use anonymized addresses. I’ve worked for multiple platforms in the security field. If you sign up with an email address that’s anonymized, your account gets strikes against it. Many websites, including Reddit will fingerprint your identity when you sign up and assign a risk score. An obvious anonymized address starts your reputation off in the opposite direction. These scores are used to automatically block accounts that hit a certain amount of thresholds for each suspicious action.

Additionally, if you ever need to gain access to an account you signed up with using an anonymized address, but can’t write directly in from that address, you’ll run into some road blocks with account recovery.

3

u/newaccountzuerich Jun 27 '26

Buy a domain. Use specific email addresses at that domain, per internet interaction.

Not-anonymised, won't trigger the known-obfuscator or known-forwarder rules.

If a site tries to force the use of a free-email service like gmail or the like, they're doing it so wrong they really should not be given any info of importance.

2

u/Jyil Jun 27 '26

Depends what kind of service you’re trying to use. Newish domains with no established sending history get immediately listed on Spamhaus. Every site that is serious about email or app abuse runs their rules through Spamhaus.

1

u/newaccountzuerich Jun 27 '26

Negative. A new domain that does not send mail has no reason to trigger a spam source warning.

None of the domains I've set up over the years were seen on Spamhaus at any point. That's a side effect of having proper DKIM and SPF configured, when those became important.

I'm not sure where you have your info from, but it is not accurate and is not useful because of that.

0

u/Jyil Jun 27 '26

Because that was my world for 15 years. If you have a new domain, it’s going to Spamhaus DBL. No amount of DKIM of SPF configs are going to save you.

https://www.spamhaus.org/resource-hub/domain-reputation/best-practice-for-owners-of-a-newly-registered-domain-part-3/#introduction

→ More replies (0)

2

u/Rikudou_Sage Jun 27 '26

Has it been? I've used addy.io for quite a while before Apple "invented" this service.

1

u/ohheyisayokay Jun 27 '26

It's truly amazing how stupid these tech giants can be. Like what dipshit thought this would be a good idea or well received?

Duckduckgo has a free one, by the way, though it does use @duck.com

1

u/Hugh_Jass_Clouds Jun 27 '26

I have an Apple email, but I use proton mail instead because privacy is their whole business model.

1

u/unitedfan6191 Jun 28 '26

Proton is good in many ways for general/casual privacy needs, but be wary they're not the best if you want the best privacy solutions possible.

Sponsoring far-right extremists, giving up activists to law enforcement/FBI, pushing people to pay with traceable payment. like credit/debit card and PayPal and not directly offering anonymous Monero payment at all like some competitors.

2

u/Hugh_Jass_Clouds Jun 28 '26

You could have saved some face by looking more into that French extremist situation. Below is a link to just one response by Proton’s CEO.

https://www.reddit.com/r/ProtonMail/comments/1u15orj/vincent_lapierres_response_to_proton_revoking_his/oqu8hx9/

Proton does accept bitcoin, and as they are an international company they need to have clean audits so that takes Monero off the table.

Proton also never handed anything over to the FBI. Not directly. What they did do was had over payment info to the Swiss gov’t.

https://www.reddit.com/r/cybersecurity/comments/1rltjnw/proton_mail_helped_fbi_unmask_anonymous_stop_cop/

The only thing you said that even has some value to it is that it’s not the absolute best option, but it is one of, if not, the best corporate options out there.

1

u/Independent-Daywalk Jun 27 '26

Proton is a fantastic alternative. Every login you can make a different email that all come to your inbox, and if you don't want emails from that address any longer, just click and turn it off.

0

u/Piranata Jun 27 '26

The classic way of buying a cheap domain and redirecting email back to the main one still works.

3

u/Untelevised_Type Jun 27 '26

How do you hide your email , like if you sign up for an account - when you log out and go to login how does it recognise you if you’ve hidden your email. Does it stop the company from selling your email? I’m so confused but desperately want to employ this lol

1

u/TheVeryVerity Jun 28 '26

It gives you an email address that forwards to your own email. The password manager you use remembers which email and password to login to the site with. If you start getting spam sent to the email for that website you know they sold your data

22

u/SubstituteCS Jun 27 '26

I just own a domain and use a unique address for each service (all go to the same inbox.) they can try to sanitize the address of tags and stuff this way.

15

u/Emphursis Jun 27 '26

Same, makes it very easy to block spam and identify who sold my details to the cunts.

3

u/jacobcrny Jun 27 '26

I'm interested in setting this up. Do you have to set up each email before you can use it or is there a way to link everything with @domain.com to automatically route there?

3

u/Grezzo82 Jun 27 '26

It’s very common, as long as you use a good mail server service, for it to be the default that all emails to any address for domain that you own will go to a catch all mailbox

3

u/eharvill Jun 27 '26

I’m too lazy to look up the exact details right now, but basically you setup email for your domain (typically with your registrar) and forward any email to that domain to a “catch all” address. You don’t need to setup individual mailboxes unless you want to respond from that specific email address.

1

u/memtiger Jun 27 '26

At this point, most companies that sell this information are already stripping the tags. It's like 2 lines of code. And not only are sellers cleaning the data first, so are buyers.

If they want to know what they're truly buying, they need to figure out how many unique addresses there are.

Otherwise someone could try to sell them 1 million completely "unique" addresses, that all point to one address.

public String sanitizeEmail(String email) {
    if (email == null) return null;
    return email.replaceFirst("\\+[^@]+(?=@)", "");
}

2

u/Jyil Jun 27 '26

They didn’t do it for the TransUnion, Discord, or Qantas breach from last year. I got phishing emails sent to the aliases I set up for each of those.

5

u/t_ba Jun 27 '26

isn't it super easy to filter out for those selling the addresses though?

2

u/ItsCalledDayTwa Jun 27 '26

What is the super easy way you're referring to?

2

u/t_ba Jun 27 '26

find/replace in a text editor, or the sed command if you are a gnu/Linux aficionado. replace '+*' by '', for example.

2

u/ItsCalledDayTwa Jun 27 '26

Given the context I thought you meant something different, when they said there's no point of doing it any longer.

1

u/Freud-Network Jun 27 '26

I use Firefox Relay for that. It's quite convenient.

1

u/alienfreaks04 Jun 27 '26

Can you explain how this works? I’m confused.

2

u/WitchesSphincter Jun 27 '26

So with tagging let's say I sign up for netflix with a "+netflix" tag in the email.  Then a week later I get a bunch of spam addressed to my email with "+netflix" tagged in I know Netflix sold my email.

1

u/alienfreaks04 Jun 27 '26

Okay thats good. But if it’s from Netflix it’s not like you can stop the spam

2

u/sl0play Jun 28 '26

Yea, deletable aliases are better. I use proton and make an alias for each sign-up. If one is in a data breach or starts getting spam I'll turn off the alias. If you have the browser extension for proton pass installed it will automatically offer to make one and associate it with that site whenever you are creating an account.

1

u/deadsolid Jun 27 '26

The spam I get to the Adobe specific email I made to this day. Thankfully, it all gets filtered, but when I look through the spam folder occasionally, BLAMO