this post was submitted on 30 Sep 2026
118 points (98.4% liked)

Firefox

7556 readers
125 users here now

A community for discussion about Mozilla Firefox.

founded 3 years ago
MODERATORS
 
you are viewing a single comment's thread
view the rest of the comments
[–] dgdft@lemmy.world 21 points 4 days ago (3 children)

In what world is a public email sensitive PII, mate? Sure, “never post anything on the internet ever” is the best OPSEC posture by default, but this user is a clearly-experienced self-hoster who understands the risks and consequences of what they’re doing.

It’s listed as their whois domain contact, and anyone with OSINT chops can find a long-term email tied to a custom domain with enumeration tools + breach data. Why hide it?

[–] Humanius@lemmy.world 16 points 4 days ago* (last edited 3 days ago) (2 children)

It can now pretty reasonably be assumed what OP's first name is, and that can be associated with his username.

Granted, his username might also be a derivative, but on its own there is a certain amount of plausible deniability there.

The more crumbs of identifiable information you leave around, the easier it becomes for malicious parties to gather them together and build a profile on you.

[–] dgdft@lemmy.world 7 points 4 days ago (1 children)

Right, but speaking for the dev crowd, plenty of us have public identities. Anyone can find my email trivially by scraping github. If you have a public online identity in the first place, it’s far preferable to treat your public-facing email as public information, rather than to rely on security by obscurity and assume no one will ever discover it.

The only glaring risk from an online attacker is credential stuffing, and falling victim to that one is a skill issue tied right back to assuming your email address won’t become public.

[–] CrimeIsLegalNow@ani.social 1 points 3 days ago

If Lemmy wasn't a collection of people fascists want to kill I'd agree

[–] daychilde@lemmy.world 3 points 3 days ago (1 children)

I'm the only daychilde on the internet. It's trivial to find my name and my wikipedia entry.

Nobody's murdered me yet.

[–] CrimeIsLegalNow@ani.social 0 points 3 days ago

I know you just didn't flag yourself that hard, you should have figured out by now these script writers are hacks.

[–] OrganicMustard@lemmy.world 5 points 4 days ago* (last edited 4 days ago) (1 children)

Email is an unique identifier, so whatever content and metadata goes along it is identified. For example now we know accounts lena and gregor use the same device and most probably belong to the same person.

[–] lena 4 points 4 days ago (1 children)

You could've also simply gone through my post history and seen that I switched accounts like two years ago. Both of my accounts were also admins of my instance at some point.

[–] OrganicMustard@lemmy.world 6 points 4 days ago

I meant it as an example. You decide what information you want to make public.

[–] TragicNotCute@lemmy.world 1 points 4 days ago (1 children)

I mean, I just sat through annual privacy training and was taught that email addresses are legally PII in many jurisdictions.

[–] dgdft@lemmy.world 5 points 4 days ago

Legally, of course it’s PII — but is it sensitive information if you treat it as public and distribute it yourself?

I’m speaking to the functional cybersecurity angle, not the semantics of PII.