← Back to context

Comment by jorts

5 hours ago

Just adding plus signs and the vendor name in the address would do it.

isn’t this easy for a potential attacker to mitigate, i.e. dropping from the address everything after the plus? it’s a known trick for gmail so i would not be surprised if an attacker knew how to get to the “real” address by cleaning it up.