9 ms·
Mailbox.org – Privacy made in Germany
- galaktor 10y agoFull disclosure: I'm a new user of mailbox.org, but not otherwise affiliated. I find its approach to useable security features interesting, especially considering the entry-level price points. edit: typo
- sternenseemann 10y agoI really hate the kind of “Privacy made in Germany” way of marketing, especially since I am german. Mailbox.org seems decent from what I've heard but products advertised like this are mostly sheer bullshit. I don't know why transferring a “quality” label from (oldschool) engineering products to IT even works.
- sabertoothed 10y agoAlso German and I agree, too. When all other arguments fail, slap a stupid country-based label onto your product.
- nathancahill 10y agoI think they're referencing the fact that it's outside of the US, for privacy reasons. Not the quality of the software engineering.
- Sylos 10y agoRight, but at this point, German privacy laws are pretty horrible, too, and getting worse as we speak. The BND (German intelligence agency) also works closely with the NSA, and considering what's publicly known, it wouldn't surprise me, if the two exchange essentially all data behind closed doors.
- cJ0th 10y agoWhat's more Interior Minister de Maizière is pushing an anti-encryption agenda.
- allendoerfer 10y agoLast Interior Minister who tried something like that did not got away with it unharmed [0]. De Maizère is one of the (or the, nobody likes von der Leyen) last remaining big shots of the CDU, Merkel has not killed yet. She is a funny silent killer and does it by stating that "X has her fullest [sic] trust" ("hat mein vollstes Vertrauen") after which they resign [1]. The German government consists entirely of people who are no thread to her: her own team (consisting of uncharismatic men), old men, younger woman, experts nobody knows, people from the smaller CSU and politicians from the SPD, who destroyed itself so badly that Merkel can even reap the rewards for the liberal policies they introduce. Underwood could learn so much from her, she killed two political parties and a generation of politicians in her own, while herself surviving one (world-scale) crisis after another. [0] https://en.wikipedia.org/wiki/Stasi_2.0 https://en.wikipedia.org/wiki/Stasi_2.0 [1] http://hatmerkelschonihrvertrauenausgesprochen.de/ http://hatmerkelschonihrvertrauenausgesprochen.de/
- lima 10y agoThe biggest risk to your privacy is your provider getting hacked, not the NSA.
- cygned 10y agoThere's a German law forcing telcos and email providers with more than 10.000 customers to provide access for law enforcements. German wikipedia article about it: https://de.wikipedia.org/wiki/E-Mail-%C3%9Cberwachung https://de.wikipedia.org/wiki/E-Mail-%C3%9Cberwachung
- Bino 10y agoMakes sense for their point of view. Pro tip: if you don't want your government spy on you in the democracy you live in. Store your data in another less interested in you.
- e12e 10y agoJust a reminder that if you choose a friendly/allied country - they will spy on you (a foreigner without privacy rights) and share data with "your" intelligence services (those to whom you might be more interesting). If you choose a hostile country they might spy on you and "your" intelligence services will try to hack your provider because spying on hostile countries is one of the things they do...
- gurubert 10y agoNo, see here: https://posteo.de/blog/posteo-zur-m%C3%A4r-von-der-abh%C3%B6r-schnittstelle https://posteo.de/blog/posteo-zur-m%C3%A4r-von-der-abh%C3%B6... The same applies to mailbox.org
- allendoerfer 10y agoThe mark is so overused, one day it will actually do what it was intended to [0]. I think that is a tragedy. One of the best brands in the world gets destroyed, because it is not actually a brand. Free rider problem. [0] https://en.wikipedia.org/wiki/Made_in_Germany https://en.wikipedia.org/wiki/Made_in_Germany
- SyneRyder 10y agoIt resonates with me. I don't think it's just a reference to engineering quality, Germany is more privacy conscious than some other countries. Whether it's the cypherpunk & privacy-tech scene of Berlin, or the awareness of the consequences of surveillance resulting from the GDR days. Even in little things: like Germans using cash because they don't want to create an electronic credit card trail of where they were, or walking through Munich train station and seeing Snowden in all the news headlines (in 2013), while back home he was getting nowhere near as much news coverage (and certainly not the front page headline). I don't know if any of this applies to Mailbox.org, but as a marketing phrase it works for me. [I'm Australian, but an 'aspiring German'.]
- pluma 10y ago> like Germans using cash because they don't want to create an electronic credit card trail of where they were ... and then using their Payback loyalty cards at every opportunity. Don't get me wrong: many Germans hold out on loyalty cards and some people may indeed use cash to avoid a paper trail, but you make us Germans sound like mythical privacy-minded creatures which the vast majority of us is decidedly not.
- plumaisafotze 10y agoOh you not know the 'vast majority' of Germans but how they live. Awesome, tell my cousin Sven he... never mind, I'll mail him with this new service. Serious kid, stop talking out of your ass. Germans use cash to avoid a paper trail? Nothing to do with spending and saving? Because that's the first thing anyone would say. But a dishonest person who wants people to think of privacy as your having something to hid would say paper trail. Some other retard said something about nothing to worry about? Ok, you're 15 and don't remember the STASI but you should heard have heard something. Look at all the shills... You don't like the branding... and after that, let's talk about another service. This place is becoming Reddit.
- SyneRyder 10y agoIt's a relative thing - I know most Germans don't see themselves as privacy-minded, but the bar is so low everywhere else that the little things in Germany add up & make it stand out. One example is browsing Google Street View and seeing how many buildings & houses are blurred out in Germany due to people sending privacy requests. I don't think I've ever seen that in Australia, but I keep encountering it when planning my trips to Germany. 3% of Germans opted-out of their house being included in Street View - a low percentage of Germans, but still crazy high compared to the rest of the world: https://googlepolicyeurope.blogspot.com/2010/10/how-many-german-households-have-opted.html https://googlepolicyeurope.blogspot.com/2010/10/how-many-ger...
- limeyy 10y agoRight, the war efficiency and quality car production sure created this stereotypes. It is quite amusing when you see how poorly things are ran in Germany irl. Like road works taking 10 years. Or the Berlin Airport debacle, which can teach Italian Mafia a lesson or two: https://en.m.wikipedia.org/wiki/Berlin_Brandenburg_Airport https://en.m.wikipedia.org/wiki/Berlin_Brandenburg_Airport And also: http://www.bbc.com/news/world-europe-36185194 http://www.bbc.com/news/world-europe-36185194
- type0 10y agoIf you actually listen to the guy's talks (Heinlein) on youtube, you will see that he cares deeply about privacy. That's all it means, it doesn't mean that the whole German society cares more than others about privacy.
- paste0x78 10y agoDon't France and Germany want to put backdoors in encryption? > http://www.wsj.com/articles/france-germany-push-for-access-to-private-internet-messages-in-terror-probes-1471976815 http://www.wsj.com/articles/france-germany-push-for-access-t...
- secfirstmd 10y agoAnd Germany looked the other way for NSA surveillance for years...
- madez 10y agoFor decades.
- tedunangst 10y agoGerman police have a history of using spyware going back quite some time: http://www.spiegel.de/international/germany/trojan-trouble-the-shady-past-of-germany-s-spyware-a-792276.html http://www.spiegel.de/international/germany/trojan-trouble-t... But now the rules are different. Spyware can only be used "when lives are at risk". http://arstechnica.com/tech-policy/2016/02/german-police-can-now-use-spying-malware-to-monitor-suspects/ http://arstechnica.com/tech-policy/2016/02/german-police-can...
- 0XAFFE 10y agoA month or two ago I sent them an encrypted (gpg) mail to their support address but they replied in plaintext and even citing my original request in full.
- deleted 10y ago[deleted]
- mottosso 10y agoThanks for sharing that.
- kyledrake 10y ago"Privacy oriented" is something I strive for in my own dealings, but centralized service privacy is and always will be lip service. What does "privacy oriented" actually mean? It must be very clearly defined. Let me give an example. A government entity sends a subpoena to receive all data on an email account. If the service provider is legally mandated to respond with data or face prosecution, what happens? In this case, Google might actually be better for "privacy" because they at least have the economic capability to push back against Doe subpoenas. A small provider won't have the resources to defend against a frivolous subpoena and will hand over everything. Something to keep in mind when considering this stuff. I really think the only way to at least control the option to defend your privacy is to run your own servers.
- eridius 10y ago> In this case, Google might actually be better for "privacy" because they at least have the economic capability to push back against Doe subpoenas. I'm pretty sure Google complies with subpoenas for data all the time. Given their scale, they probably even have employees whose full-time job is dealing with government subpoenas for data.
- darkhorn 10y agoIf Turkey ask data from Gmail Google says that the USA has rights for free speach so we cannot give this guy's real IP (who sweared to Erdoğan). On the other hand Hotmail immediatly gives this kind of data to the Turkish prosecuters. Why? Because Government of Turkey is the customer of Microsoft but Google is not. So if you live in Turkey who you would trust? If you live in USA who you would trust? If you live in X who you would trust?
- ivanhoe 10y agoThe country where the company and servers are located makes all the difference IMHO. Many things that government can push in US under Homeland Security and similar acts, they can't in Germany. Their privacy laws are much more protective against mass and/or unsubstantiated surveillance, legal services are not that ridiculously expensive as in US, etc.
- hiq 10y agoHow is it any better than ProtonMail? [0] [0]: https://protonmail.com https://protonmail.com
- blunte 10y agoI've been using Protonmail for a year now, and I'm very happy with it. I have several domains on it. The mobile apps are decent (I have iOS and Android), and the web app is fine. It's not perfect, but given their limited resources compared to Google I'm quite impressed.
- galaktor 10y agoDoes ProtonMail have a feature similar to the "full inbox encryption" [1] mailbox has? Also, there are some nice features in mailbox, like only allowing to send email to other servers which support encryption [2]. I'm genuinely curious if ProtonMail has similar functionality on offer, especially since it appears to be free. [1] https://support-en.mailbox.org/knowledge-base/article/the-encrypted-mailbox https://support-en.mailbox.org/knowledge-base/article/the-en... [2] https://mailbox.org/en/ensuring-emails-are-sent-securely/ https://mailbox.org/en/ensuring-emails-are-sent-securely/ edit: links
- Veratyr 10y agoInfo on what ProtonMail encrypts is here: https://protonmail.com/support/knowledge-base/what-is-encrypted/ https://protonmail.com/support/knowledge-base/what-is-encryp... TL;DR: It encrypts just about everything in storage but "Subject lines and recipient/sender email addresses are encrypted, but not end-to-end encrypted.", which tells me they might have access to these things.
- tga 10y agoMailbox.org runs http://open-xchange.com/ http://open-xchange.com/, so besides email you also get a calendar and (rudimentary but functional) online word processor and spreadsheet, with team collaboration. You can try a demo of the software on the Open-Xchange site. I've also been a happy customer for about a year now.
- mxuribe 10y agoI think we need more of these types of companies, or at least more competitors in this realm. I've also heard so many good things about FastMail too. We need more mail providers who are: * trustworthy * secure * reasonably priced * etc. If running my own mail server was not so laborious and headache-inducing, i'd love to move away from google for apps/domain. I have no functional complaints of google; i am happy with their performance without a doubt. Its just that, as every day passes, I keep getting creeped out; its the "ick" factor. And for me it started well before the Snowden disclosures.
- eridius 10y agoIf you want to stop using Google for email, but want to keep the domain in Google Apps for whatever reason, you can set up a FastMail account and then configure Gmail to forward all of your email to FastMail. Yeah your email still goes through Google's servers so it's not completely ick-free, but at least you don't have to deal with using Google for email on a day-to-day basis anymore.
- msh 10y agoI have been using them for about a year and have been quite satisfied. They also support using your own domain at no extra cost.
- detaro 10y ago2 years here, nothing to complain. While the service is relatively new, the people behind it have been in the business way longer. Years ago I set up my first own mail server using their books ;)
- mk89 10y agoSome weeks ago, I was looking (again) for a privacy-oriented alternative email provider. I stumbled upon mailbox.org and some others (like protonmail, and startmail). I decided to go for mailbox because 1) I know that Germany at the moment has still one of the best regulations about data protection (although I fear this is going to change in the next few years), 2) it provides some features others don't (like protonmail, and startmail). It was worth a try at least, so I decided to use the 30 days trial account. It looked really good and promising: nice UI, clear documentation, cool domain name if you don't want to use your own. It provides also Office-like, calendar, and storage features. Therefore, I made up my mind, and I was determined to become one of their paying customers. So, I put 12 EUR(1 EUR/month) on the account. A few hours later I found out[0] that mailbox.org is offered by a politically motivated provider called JPBerlin [1]. I sent the cancellation request, and so far my account is still on hold - I could revoke the cancellation, though. An email received after the cancellation request says "please allow us a couple of days". Sure. It's just they took 1 EUR from the account, although I had the cancellation request sent like 10 days before the end of the trial period. In the end, I would like to say that as a service it looks promising. However, until they stop with their political involvement, I think, not many people will use it. [0]: http://www.emaildiscussions.com/showthread.php?t=68527 http://www.emaildiscussions.com/showthread.php?t=68527 [1]: https://www.jpberlin.de https://www.jpberlin.de
- madez 10y agoAre you sure you understand what they mean by saying they are a political provider?
- galaktor 10y agoMight be better to link to the "www" sub-domain [1] of your second URL; otherwise getting SSL cert issues. [1] https://www.jpberlin.de/ https://www.jpberlin.de/
- deleted 10y ago[deleted]
- cygned 10y ago
- terraforming 10y agoAfter the fastmail fiasco (they increased prices, and now old packages no longer have access to the newest features), I started looking for an alternative and came across mailbox.org... I've been trialing for a few days and they do seem interesting. I just wish we could use an unlimited number of aliases in our own domain, it doesn't make sense to me otherwise.. They do have some interesting features, such as mailbox encryption as well as calendar/contacts encryption. It's client-side encryption, though it's in the browser. An alternative to mailbox.org is mailfence.com.
- geekam 10y agoI was about to move from Google to Fastmail (been looking to move away from Google for a while) and then I read your comment. Now rethinking the decision.
- eridius 10y agoMake the move. FastMail is great. I didn't even know there was a fiasco (I knew they changed their pricing structure to make it much simpler, but it doesn't really affect me in the slightest as a normal user). I switched from Google to FastMail a while ago and I haven't had a single regret.
- tdurden 10y agoSeconded - the only hiccup I have seen with FastMail in the last 3 years was a recent DDoS attack [1] (and that was minimal). If you are willing to pay a small monthly fee, I think FastMail is an excellent alternative to Google. [1] https://blog.fastmail.com/2015/11/11/ddos-attack-may-lead-to-potential-service-disruption-this-week/ https://blog.fastmail.com/2015/11/11/ddos-attack-may-lead-to...
- eridius 10y agoI remember reading about that, though I don't remember if I even noticed it happening at the time. I just want to highlight something from that page that I think is awesome: > We do not respond to extortion attempts, and we will not pay these criminals under any circumstances.
- emanuelsaringan 10y ago> your data kept safe by systems compliant with German data protection law. If everyone you communicate to via email is using either Gmail or Yahoo Mail, then US has your data too right?
- binaryanomaly 10y agoI'm a mailbox.org user since a few months. I like the product it supports open standards, imap, caldav, carddav. If you want you can lock down pretty much everything with pgp. Data is in Germany/EU and the pricing is really fair stars with 1€/month with 3 mail aliases and 2 GB. The guys behind it seem to be IT people with Linux/open source mindset and good ethics as far as I can judge. I feel very comfortable with mailbox.org
- type0 10y agoI use them as well, they have custom domain and two factor authentification support. The only complain is that sharing in their online Office can be buggy, i hope Open-Xchange will fix that, but that's more of a side feature for me. At least their business model seems more honest than Proton Mail.
- nullcipher 10y agoI am not sure if having my data in mailbox.org is any more private that Microsoft or Google. My gmail doesn't even show any ads.
- type0 10y agoIf you use gmail and don't pay google for Apps account, you are not their customer, that's the difference. How much does Microsoft charge for its email service?
- hypercluster 10y agoI've been using mailbox for about two years and am now switching to fastmail. The UI is vastly better and works great on mobile. It's also the base for the mobile app which mailbox doesn't have (well, the OX one). And that's the other thing. Having a dedicated app with search integrated and push notifications on iOS is awesome.
- Bino 10y agoIf so, and german data protection laws apply, why isn't the TLD .de?
- pluma 10y agoBecause TLDs mean nothing? You don't see every US service use .us either. Plus .org has certain connotations (at least in Germany): non-commercial, activism, open source, etc. It's a bit ingenious considering this is a paid service, but they were probably proud they were able to get such a premium domain name. Also, at least to Germans .de generally implies it's primarily German language and/or limited to a German (speaking) audience.
- noinsight 10y agoActually, your choice of TLD has a huge impact on jurisdiction. The USoA asserts super-jurisdiction [1] over .com/.net/.org and will seize such domains at will [2], and therefore personally I will never use those TLD's as a non-US citizen. What legal recourse do non-Americans have in such a situation? They would probably have to fight it through US courts which significantly raises the bar for non-American entities. Another thing to consider is DNSSEC when it comes to TLD's. Domain records are signed top-down. The ccTLD's fall under the jurisdiction of their respective countries. I don't even know under what jurisdiction the other/new TLD's fall under, it's probably based on where the owning company is headquartered? [1] https://yro.slashdot.org/story/12/03/06/1720230/us-asserts-super-jurisdiction-over-dot-com-dot-net-and-dot-org-domains https://yro.slashdot.org/story/12/03/06/1720230/us-asserts-s... [2] https://en.wikipedia.org/wiki/Domain_name#Seizures https://en.wikipedia.org/wiki/Domain_name#Seizures
- gurubert 10y agoYou can use your own domain with mailbox.org and not be affected by any .org issues you may think exist.
- aibottle 10y agoWhat kind of argument is that? The TLD has nothing to do with privacy laws.
- civil534 10y agoPeople in this discussion are mentioning subpoenas and compliance with same. Are we talking civil as well or just criminal? If I'm sued in Nevada civil court for defamation or something does a German company give a shit?
- HugoDaniel 10y agoE-Mail privacy in a 14 eyes country ?
- DyslexicAtheist 10y agoOh, it's bullshit made in Germany again. >> When e-mails go unnoticed because of being redirected to a spam folder that you never check, you are in fact still legally liable for such e-mails – as you cannot disprove having knowledge of them. This is a danger that our users can safely ignore: We check for spam and viruses before the e-mails are accepted and reject anything that looks suspicious. This way, you always know exactly what e-mails you have received and read. How does that even work when they GPG encrypt content. Are they escrowing the private keys? what a timing of this post. Just as I was ranting about this old 30C3 talk[0] and pointing out what a scam "DE-Mail", "e-brief" and "Trusted-Cloud", etc. is, ... then this is trending on HN. Hilarious. [0] https://www.linkedin.com/hp/update/6175253192402563072 https://www.linkedin.com/hp/update/6175253192402563072 - or: [1] http://www.amara.org/en/videos/y1Gk3maFbvNQ/info/bullshit-made-in-germany/ http://www.amara.org/en/videos/y1Gk3maFbvNQ/info/bullshit-ma... (select English subs)
- gurubert 10y agoPlease show me an e-mail SPAM / Virus that is sent GPG-encrypted to you. I do not think that this will ever happen.
- caspianplover 10y agoI've been customer of mailbox.org for just over a year now. I can't assess the quality of their security, or the lengths they'd go to protect customer privacy, though they seem to know what they're doing. We had a Linux consultant from Heinlein Support at the last place I worked for, and he did his job very well. I'm also pretty happy with the Card+CalDav-offerings from mailbox.org. With their customer support, however, im rather disappointed: mailbox.org offers what they call "Familienaccounts" (non-commercial accounts, meant to share, among other things, calendars and contacts with one another [0]). Grouping existing accounts into "Familenaccounts" by means of contacting their support team used to be a feature that was offered (and advertised) by mailbox.org, and a feature that I've used for two of my family members in the past. For some technical reason or other, mailbox.org is unable to convert existing accounts into Familienaccounts any more. This wouldn't be that much of a problem (workaround was to backup data, cancel one account, get that account's credit refunded, ask them to remove that account from their list of blocked accounts, recreate that account as a "Familienaccount", pay for the new account and restore the backed up data). What rubbed me the wrong way was that it took a month of to and fro emailing with mailbox.org support just to get that information (while they still advertised being able to convert accounts on their website). When we decided to implement the workaround, it took another month from cancelling the old account to getting the new one working, with my wife unable to receive emails for some time inbetween. I will continue to use mailbox.org, but in my opinion they really need to improve their support. [0] https://support.mailbox.org/knowledge-base/article/familien-accounts-alle-fragen-antworten https://support.mailbox.org/knowledge-base/article/familien-...