{"id":555088,"date":"2023-02-22T15:00:17","date_gmt":"2023-02-22T12:00:17","guid":{"rendered":"https:\/\/en.buradabiliyorum.com\/using-your-real-email-to-sign-in-your-privacy-is-at-risk\/"},"modified":"2023-02-22T15:00:17","modified_gmt":"2023-02-22T12:00:17","slug":"using-your-real-email-to-sign-in-your-privacy-is-at-risk","status":"publish","type":"post","link":"https:\/\/buradabiliyorum.com\/en\/using-your-real-email-to-sign-in-your-privacy-is-at-risk\/","title":{"rendered":"#Using Your Real Email to Sign In? Your Privacy Is at Risk"},"content":{"rendered":"<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_85 counter-hierarchy ez-toc-counter ez-toc-custom ez-toc-container-direction\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<label for=\"ez-toc-cssicon-toggle-item-6a408c6912712\" class=\"ez-toc-cssicon-toggle-label\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #dd3333;color:#dd3333\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #dd3333;color:#dd3333\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/label><input type=\"checkbox\"  id=\"ez-toc-cssicon-toggle-item-6a408c6912712\" checked aria-label=\"Toggle\" \/><nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-1'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/buradabiliyorum.com\/en\/using-your-real-email-to-sign-in-your-privacy-is-at-risk\/#%E2%80%9CUsing_Your_Real_Email_to_Sign_In_Your_Privacy_Is_at_Risk%E2%80%9D\" >&#8220;Using Your Real Email to Sign In? Your Privacy Is at Risk&#8221;<\/a><ul class='ez-toc-list-level-2' ><li class='ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/buradabiliyorum.com\/en\/using-your-real-email-to-sign-in-your-privacy-is-at-risk\/#Your_Email_Can_Be_Used_to_Identify_Which_Services_You_Use\" >Your Email Can Be Used to Identify Which Services You Use<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/buradabiliyorum.com\/en\/using-your-real-email-to-sign-in-your-privacy-is-at-risk\/#How_to_Avoid_Your_Email_Login_Becoming_a_Privacy_Nightmare\" >How to Avoid Your Email Login Becoming a Privacy Nightmare<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/buradabiliyorum.com\/en\/using-your-real-email-to-sign-in-your-privacy-is-at-risk\/#Bad_You_Use_Your_Personal_Email_for_Every_Login\" >Bad: You Use Your Personal Email for Every Login<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/buradabiliyorum.com\/en\/using-your-real-email-to-sign-in-your-privacy-is-at-risk\/#Better_You_Use_a_Throwaway_Email_for_Sensitive_Logins\" >Better: You Use a Throwaway Email for Sensitive Logins<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/buradabiliyorum.com\/en\/using-your-real-email-to-sign-in-your-privacy-is-at-risk\/#Best_You_Use_an_Email_Alias_Service_for_Every_Login\" >Best: You Use an Email Alias Service for Every Login<\/a><\/li><\/ul><\/li><\/ul><\/li><\/ul><\/nav><\/div>\n<h1><span class=\"ez-toc-section\" id=\"%E2%80%9CUsing_Your_Real_Email_to_Sign_In_Your_Privacy_Is_at_Risk%E2%80%9D\"><\/span>&#8220;Using Your Real Email to Sign In? Your Privacy Is at Risk&#8221;<span class=\"ez-toc-section-end\"><\/span><\/h1>\n<div>\n<figure style=\"width: 1920px\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" class=\"type:primaryImage wp-image-872924 size-full\" data-pagespeed-no-defer=\"\" src=\"https:\/\/www.howtogeek.com\/wp-content\/uploads\/2023\/02\/EmailPrivacy3.jpg?width=1198&amp;trim=1,1&amp;bg-color=000&amp;pad=1,1\" alt=\"A closeup view of a Forgot Password button on a website.\" width=\"1920\" height=\"1080\" data-credittext=\"Jason Fitzpatrick \/ How-To Geek\"\/><figcaption class=\"wp-caption-text\"><span class=\"type:primaryImage imagecredit\">Jason Fitzpatrick \/ How-To Geek<\/span><\/figcaption><\/figure>\n<p>Someone who knows your email address can use it to see if you have accounts with various online services. Email aliases provide a way to secure against this privacy risk.<\/p>\n<p>Many people use their primary email to sign in to practically everything. That\u2019s a privacy nightmare, and you might be shocked to see how easily someone can use it to effectively stalk you and violate your privacy.<\/p>\n<h2 role=\"heading\" aria-level=\"2\"><span class=\"ez-toc-section\" id=\"Your_Email_Can_Be_Used_to_Identify_Which_Services_You_Use\"><\/span>Your Email Can Be Used to Identify Which Services You Use<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Typically when people talk about serious privacy issues related to your email address or other kinds of logins, the focus is on data breaches, leaked information, and other high-profile problems.<\/p>\n<p>No doubt about it, having the account data for a service you use leaked is a privacy problem that reveals your personal information to strangers and anyone out there mining leaked data dumps. It would be less than ideal to have your readily identifiable firstname.lastname@gmail.com (or any email that can be easily linked to your real identity) <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/download-scripts-themes-apps\/\" data-internallinksmanager029f6b8e52c=\"9\" title=\"Download Scripts &amp; Themes &amp; Apps\" target=\"_blank\" rel=\"noopener\">app<\/a>ear in a file dump containing tens of thousands of emails.<\/p>\n<p>Especially if that dump is from a service you\u2019d prefer people didn\u2019t know you used\u2014whether that service was related to pornography, a support group for a mental health or medical issue you have, or anything else you wanted to keep private.<\/p>\n<p>But that\u2019s not the only way your email address can unmask information about you. Poorly designed login systems can reveal whether or not an email address is associated with an account. You know when you forget your password and use the Forgot Password link on a login portal? You put your email address in, you click submit, and you get some sort of feedback.<\/p>\n<p>The properly designed login portals provide no identifiable feedback. You might get a message like: \u201cIf that email address or login is associated with an account, you will receive an email with a password reset link.\u201d<\/p>\n<p>But poorly designed login portals will give identifiable feedback indicating that there is no email associated with the account or that the email is associated with an account. If someone manually uses the forgot password function, you\u2019ll receive a notice in your email inbox that they have done so.<\/p>\n<p>But more troubling, many of these login portals are exploitable, and the validity of an email can be checked without triggering a full password reset request (so there would be no email sent to alert you that someone is probing the account for information about you). Automated tools like <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/github.com\/megadose\/holehe\">Holehe OSINT<\/a> will probe hundreds of commons services for whatever username@domain.com you put in and return a list of results indicating whether the service has an account associated with that email.<\/p>\n<figure style=\"width: 1200px\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-872925 size-full\" data-pagespeed-lazy-src=\"https:\/\/www.howtogeek.com\/wp-content\/uploads\/2023\/02\/EmailPrivacy1.jpg?trim=1,1&amp;bg-color=000&amp;pad=1,1\" alt=\"an image of the Holehe security app.\" width=\"1200\" height=\"600\" data-credittext=\"Jason Fitzpatrick \/ How-To Geek\" src=\"\/pagespeed_static\/1.JiBnMqyl6S.gif\" onload=\"pagespeed.lazyLoadImages.loadIfVisibleAndMaybeBeacon(this);\" onerror=\"this.onerror=null;pagespeed.lazyLoadImages.loadIfVisibleAndMaybeBeacon(this);\"\/><figcaption class=\"wp-caption-text\">The Holehe app running through its domain list using a test email address. <span class=\"imagecredit\">Jason Fitzpatrick \/ How-To Geek<\/span><\/figcaption><\/figure>\n<p>The existence of the Holehe tool shouldn\u2019t unsettle you as much as the existence of the exploit it is taking advantage of. Because of poorly designed login portals, it\u2019s trivial for people to see if you have registered your email with a given service.<\/p>\n<h2 role=\"heading\" aria-level=\"2\"><span class=\"ez-toc-section\" id=\"How_to_Avoid_Your_Email_Login_Becoming_a_Privacy_Nightmare\"><\/span>How to Avoid Your Email Login Becoming a Privacy Nightmare<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>If you read over the previous section with an uneasy feeling and dislike the idea that somebody could piece together where you\u2019ve been on the internet in such a stealthy fashion just because they know your email address, we hardly blame you.<\/p>\n<p>Even though online privacy is an illusion in many ways, we all want to do as much as we can to maintain our privacy in whatever way we can. So let\u2019s look at how to handle dealing with this email privacy issue from a bad, better, and best practice perspective.<\/p>\n<p>While we\u2019re focused on the idea of email logins because they have much bigger privacy implications than other things, you can apply this <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/general\/\" data-internallinksmanager029f6b8e52c=\"3\" title=\"General\" target=\"_blank\" rel=\"noopener\">general<\/a> thinking to literally everything you use your email address for: <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/news\/\" data-internallinksmanager029f6b8e52c=\"2\" title=\"News\" target=\"_blank\" rel=\"noopener\">news<\/a>letters, store coupons, and so on.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Bad_You_Use_Your_Personal_Email_for_Every_Login\"><\/span>Bad: You Use Your Personal Email for Every Login<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Far too many people find themselves in this situation, and if you\u2019re reading this article and it\u2019s how you do it, then you\u2019re certainly in a large crowd.<\/p>\n<p>But using your personal email address as a login for everything you sign up for is a terrible practice. Even putting aside the privacy implications we outlined already here, it eventually leads to an inbox full of spam emails and difficulty controlling who or what has access to your email.<\/p>\n<p>If you take away nothing from this article, we hope you take away what a privacy-endangering practice this is (and hopefully, you adopt the practices we suggest in the next sections).<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Better_You_Use_a_Throwaway_Email_for_Sensitive_Logins\"><\/span>Better: You Use a Throwaway Email for Sensitive Logins<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>At the bare minimum, everyone should have a throwaway \u201cjunk\u201d email address (or ten!) that they use for services, subscriptions, forums, and other things they don\u2019t want to associate with their primary email address and identity.<\/p>\n<p>Do note that this isn\u2019t the same as using a temporary disposable email address to get a coupon code or some such thing. This is setting up a separate email you use for whatever purpose (adult content, participating in a forum focused on a medical issue you\u2019d like to keep private, etc.) and that purpose alone.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Best_You_Use_an_Email_Alias_Service_for_Every_Login\"><\/span>Best: You Use an Email Alias Service for Every Login<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Setting up a few junk email addresses to use in place of your real primary email address is a viable strategy, but it\u2019s not the best strategy. It\u2019s easy to end up using the same email addresses for so many services that what started as a \u201cjunk\u201d email address just for a few things becomes almost like a secondary and easily identifiable email that gets as much use as your primary email.<\/p>\n<p>The ideal solution is to use an email alias service. An email alias service allows you to create and manage unique email addresses you can use for different purposes. You can use a single alias for a single site or use it for a few sites as part of a particular hobby or niche interest.<\/p>\n<p>Instead of limiting yourself to either using your primary email or whatever \u201cjunk\u201d secondary email you\u2019ve set up, you can use many unique aliases for whatever service you wish, turning them on and off at will or deleting them entirely to \u201cmemory hole\u201d the entire identity built up around that particular email.<\/p>\n<p>Apple users can lean on Apple\u2019s Hide My Email relay service. You can also use DuckDuckGo\u2019s Email Protection service or <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/simplelogin.io\/\">ProtonMail\u2019s SimpleLogin email alias service<\/a>. If you\u2019re a 1Password user, you might also consider looking at <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.fastmail.com\/1password\/\">FastMail<\/a>. In 2021, 1Password partnered with FastMail to integrate the service directly into its password manager for seamless on-the-fly email aliases.<\/p>\n<p>Whatever service you use for email aliases, however, we strongly encourage you to start using it today. Whenever you sign up for a new service, use an alias. And whenever you log into an existing service that relies on your personal email address, consider switching it over to an alias. In short order, you\u2019ll have liberated your personal email address and put a wall of email aliases between you and the people who would chip away at your privacy.<\/p>\n<p>And while you\u2019re thinking about private communication and privacy in general, now\u2019s the perfect time to look at the best ways to send encrypted emails, the benefits of a secure email service like ProtonMail, and to consider incorporating a good VPN into your routine.<\/p>\n<\/div>\n<p><script>\n setTimeout(function(){\n  !function(f,b,e,v,n,t,s)\n  {if(f.fbq)return;n=f.fbq=function(){n.callMethod?\n  n.callMethod.apply(n,arguments):n.queue.push(arguments)};\n  if(!f._fbq)f._fbq=n;n.push=n;n.loaded=!0;n.version='2.0';\n  n.queue=[];t=b.createElement(e);t.async=!0;\n  t.src=v;s=b.getElementsByTagName(e)[0];\n  s.parentNode.insertBefore(t,s) } (window, document,'script',\n  'https:\/\/connect.facebook.net\/en_US\/fbevents.js');\n   fbq('init', '335401813750447');\n   fbq('track', 'PageView');\n  },3000);\n<\/script><\/p>\n<blockquote><p><strong><span style=\"color: #ff6600;\">If you liked the article, do not forget to share it with your friends. Follow us on\u00a0<span style=\"color: #ff0000;\"><a style=\"color: #ff0000;\" href=\"https:\/\/news.google.com\/publications\/CAAqBwgKMLG0nwswvr63Aw\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Google News<\/a><\/span>\u00a0too, click on the star and choose us from your favorites.<\/span><\/strong><\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\">For forums sites go to <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/forum.buradabiliyorum.com\/\" target=\"_blank\" rel=\"noopener\">Forum.BuradaBiliyorum.Com<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\"><strong>If you want to read more like this article, you can visit our <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/en.buradabiliyorum.com\/technology\/\" target=\"_blank\" rel=\"noopener\">Technology category.<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<p><span style=\"color: black;\"><a style=\"color: #ff9900;\" href=\"https:\/\/www.howtogeek.com\/872828\/using-your-real-email-to-sign-in-your-privacy-is-at-risk\/\" target=\"_blank\" rel=\"noopener\">Source<\/a><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8220;Using Your Real Email to Sign In? Your Privacy Is at Risk&#8221; Jason Fitzpatrick \/ How-To Geek Someone who knows your email address can use it to see if you have accounts with various online services. Email aliases provide a way to secure against this privacy risk. Many people use their primary email to sign&#8230;<\/p>\n","protected":false},"author":1,"featured_media":555089,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/www.howtogeek.com\/wp-content\/uploads\/2023\/02\/EmailPrivacy3.jpg?height=200p&trim=2,2,2,2","fifu_image_alt":"","footnotes":""},"categories":[18],"tags":[],"class_list":["post-555088","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology"],"_links":{"self":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/555088","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/comments?post=555088"}],"version-history":[{"count":0,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/555088\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media\/555089"}],"wp:attachment":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media?parent=555088"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/categories?post=555088"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/tags?post=555088"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}