mozilla / fx-private-relay

Keep your email safe from hackers and trackers. Make an email alias with 1 click, and keep your address to yourself.
https://relay.firefox.com
Other
1.48k stars 177 forks source link

Domain Aliases can be created by sending mails from different and unrelated emails #1127

Open AOiegas opened 3 years ago

AOiegas commented 3 years ago

Build:

Affected Platforms:

Browsers tested on:

Prerequisites:

Steps to reproduce:

  1. From the second email address send a mail to a set Subdomain address (e.g. something@subdomain.mozmail.fxprivaterelay.nonprod.cloudops.mozgcp.net );
  2. Go to https://stage.fxprivaterelay.nonprod.cloudops.mozgcp.net/accounts/profile/ ;
  3. Observe the generated aliases list;

Expected result:

Actual result:

Notes:

groovecoder commented 3 years ago

This is actually by design - this enables the “offline” relay experience. E.g., you check in at hotel XYZ that wants an email address. You say “hotelXYZ@cratez.mozmail.com” and it starts working immediately - you don't have to create it before-hand.

We can consider some ways to mitigate abuses like you mention. E.g., we could limit domain aliases created by any particular sender, a sender only gets to create a single alias.