Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This article brings up a question about protecting email addresses that I'm hoping a HN reader can answer.

I have a unique email address for PayPal--different from my normal email address--that I want to keep secret. The problem is that every time I make a purchase, the merchant gets this email address (in addition to the normal email address I gave to the merchant). I know that merchants get it because I get junk mail at my secret PayPal address from merchants I did business with.

Is there no way to make a PayPal payment without PayPal handing my email address over to the merchant?

As a related question, why do I have to trust the merchant to redirect me to PayPal's website to make the payment? There are many ways I can get fooled into entering my PayPal password directly into merchant's website (for example, the merchant opens the PayPal site in a frame or pop-up, so you can't verify that it's really PayPal). Isn't there a way I can open my own browser window, login to PayPal, and give some sort of invoice number to PayPal to direct payment to the merchant?



>(for example, the merchant opens the PayPal site in a frame or pop-up, so you can't verify that it's really PayPal) //

You can right-click the page in Firefox and choose "view page info", then on the security tab you can see if it's paypal, see the certificate, etc.. Someone could hijack right-click, it's going to be a bit of effort though. I think in FF shift+rightMouseClick overrides normal right-click to give you the browser menu, but probably that's capturable by the site too.

Ctrl+I is the shortcut, but I don't think it handles frames.


Interesting question. I have no idea. I suggest you shop it around as a new "Ask HN" question and as a question on security.stackexchange.com.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: