7 ms·
More people are searching for an inbox that protects their privacy
- criddell 6y agoServices like Proton do a good job of keeping the body of the email private, but is there anything they can do about protecting the header information? Metadata can reveal a great deal.
- Drip33 6y agoThere's a lot they can do, but then it makes it impossible to search your inbox for old emails by subject, from, to etc fields. You can reduce what an adversary sees by not including anything useful in the subject line and the only thing you can't protect is who you're speaking to and when.
- gruez 6y agoThe third party doctrine[1] allows the government to access your call records (and other metadata) without a warrant, but I don't think anyone's fine with that. [1] https://en.wikipedia.org/wiki/Smith_v._Maryland https://en.wikipedia.org/wiki/Smith_v._Maryland
- GuB-42 6y agoSecurity / convenience tradeoff. Not being able to access the email body already makes full text search impossible, among other things. It is one tradeoff for using Protonmail instead of, say, Gmail. Encrypting header data would make most operations impossible unless you download your entire inbox first.
- upofadown 6y agoSTARTLS usage is over 90% these days. So the email server(s) get your metadata but passive network observers do not. So the providers can work to get that to 100% and mandatory to foil active attacks.
- avmich 6y agoUnfortunately it's rather hard to open an account on Proton Mail, probably for reasons of fighting spam, but it still doesn't help. They e.g. require already existing email, which defeats part of the purpose.
- tjpnz 6y ago>They e.g. require already existing email, which defeats part of the purpose. That's optional.
- notRobot 6y agoIt is optional now, but used to not be until very recently.
- searchableguy 6y agoOnly if you are using their vpn or other free ones. If not, you can create an account with captcha option. Seems fair to me.
- gruez 6y ago>They e.g. require already existing email, which defeats part of the purpose. purpose of what? being fully anonymous? If all you want is a mail provider that doesn't scan your emails for marketing purposes, it shouldn't make a difference. If you really want to be anonymous, you can always use a burner email (no, not the disposable kind) to sign up.
- pmoriarty 6y agoI don't trust Proton Mail. There's nothing stopping them from sending your browser Javascript that completely compromises your keys. They've admitted as much when I asked them about this years ago.
- bitdizzy 6y agoI use proton mail just for the privacy guarantees enforced by social pressure on their brand. They hold your PGP keys (you can't give them a subkey of your own private master key) so there's no reasonable security there. In general, I don't think PGP encrypted emails provide much security anyway. If I need to send a message securely, something like Signal provides better cryptographic properties like forward secrecy. All I know is, I would hear about it very quickly as soon as Proton Mail is discovered to violate my privacy, and that's all I can expect of email. To be honest, the fact that their API is not open sourced and I have to use their web client or mediocre IMAP bridge would make me seek alternatives if I were to reconsider email providers. It would have to be one that has as strong of a privacy-conscious brand, or self-hosting.
- upofadown 6y ago>... something like Signal provides better cryptographic properties like forward secrecy. Forward secrecy only works up to the point your end point gets compromised and only for messages you have not kept. So for the vast majority of people it provides very little value. It provides no protection against someone who breaks your encryption and something like the Signal Protocol's much greater complexity provides more opportunities to do that.
- bitdizzy 6y agoPGP isn't any better on the first point and on the second point, I would bet the money in my pocket that GPG (being the most dominant implementation of PGP) is far more complex and bug-ridden than Signal's cryptography or implementation are unsound.
- 6y ago
- ed25519FUUU 6y agoI see that Lavabit also reopened as an email service (they famously shut down rather than release the SSL keys for Snowden to US intelligence agencies[1]). https://en.wikipedia.org/wiki/Lavabit#Connection_to_Edward_Snowden https://en.wikipedia.org/wiki/Lavabit#Connection_to_Edward_S...
- ogre_codes 6y ago> The number of Google searches in all languages for privacy-focused Gmail alternatives The irony here. I wonder if the number of people searching for Google search alternatives on Google is up as well?
- jmnicolas 6y agoYes and even if Linux was a true alternative on phones you would still leak a lot to your ISP (they can triangulate your position using cell towers and unless you use a VPN they know every websites you connect to).
- hyperpl 6y agoReminds me of what I considered to be the only use of Internet Explorer on Windows 95 was to download Netscape!
- calvinmorrison 6y agoAt the core, google and other companies sell your data for advertisements, at best, at worst they're sending it all the NSA or some other black box. I recommend everyone BUY A DOMAIN. Then switch providers. you can always switch with your own domain. The select a provider based on thier offering be it protonmail, fastmail (shameless plug), or others
- beders 6y agoNo worries, the NSA will see it all anyways :) There's no privacy on the internet. That said: I'd love to run my own e-mail servers, but Yahoo does a pretty good job keeping spam away from me and offers enough convenience that I just stuck with it. Happy to consider alternatives I can run on a cheap instance somewhere.
- marban 6y agoYahoo, really? I get a lot of false positives w/ them.
- tjpnz 6y ago>At the core, google and other companies sell your data for advertisements, at best, at worst they're sending it all the NSA or some other black box. Post Cambridge Analytica I'm not sure which is worse.
- polote 6y ago> I recommend everyone BUY A DOMAIN. you will end up having most of your conversations with gmail or outlook users so that would not change anything
- vkou 6y agoThis is the only correct response to this problem, and it needs to be seen more prominently. E-mail in 2020 is not secure against a motivated attacker. It doesn't matter how secure and woke your provider is, when: 1. Everyone you talk on an e-mail thread gets a copy of the entire e-mail thread, to do whatever they want with. 2. You can't control the present and future security of other people's providers, or the present and future security of the computing devices they use to read the e-mail you send them. Now, if you want to LARP, you can try setting up a mailing list for your friends who only use secure providers (For whatever definition of secure you want to use), and only limit your use of a single e-mail address to that mailing list. Great. Go for it. Write a blog post about it, even. But that's not going to solve the fundamental problems of #1 and #2 for the rest of the world. Now, if you actually want security (as opposed to 'I want to LARP at security'), take a page from conspiracies in the financial sector, and don't use e-mail for any conversations that you'd like to remain secure. Securing e-mail is a waste of time. It can't be secured, because of 50 years of social expectations about how e-mail should behave. (Other people retain copies of your e-mails, and other people can choose which provider services their address.) You can spend that effort on trying to secure a different communication protocol, which does not have those 50 years of social expectations, and that will probably lose to e-mail (Because those two security holes provide users with value, and when it comes to value versus security, security will lose every time.)
- nostromo 6y agoOn a related note, DuckDuckGo's growth trajectory is amazing: https://duckduckgo.com/traffic https://duckduckgo.com/traffic Maybe a desire for privacy is driving this. Or maybe Google's increasing bias, or ad saturation, or AMP, or something else...
- aclelland 6y agoI use DDG on my mobile device now. I switched when Google started showing images in the omnibox as I typed in search terms. I found it useless and distracting but (of course) Google knew better and didn't offer any way to disable it. Generally I'm pretty happy with DDG results and don't feel the need to switch back to Google. I have seen a lot of scam ads on DDG which I've reported but never received a response to. The new Apple map integration seems to work pretty well even though I'm on Android.
- paul7986 6y agoI'd wish DDG would either provide their own email service or create a front-end for your choice of mail providers (i.e. iCloud, Protonmail, etc). I'd love to move away from everything Google (further support a company who is pro-consumer) to a company in which i trust and whose business model/ethos is privacy.
- gabruoy 6y agoI just want Duckduckgo browser on desktop. Obviously its just chromium with a "delete history" shortcut built in, but the way their mobile browser inverts the way you think about privacy really helps. It inverts your browsing experience from "We will save all your cookies, history and data unless you clear it" to "We will delete your cookies and history constantly all the time unless you specify the websites you want to have your stuff saved on."
- scandox 6y agoWhat is the real appetite for privacy? It's talked about a lot and I believe in it personally. Everyone I talk to says it is important to them but are totally uninterested even in modifying settings with existing providers let alone changing. There is a very strong disconnect between what people say and do on privacy.
- pier25 6y agoI think most people simply don't care, regardless of what they say. Convenience really rules the world.
- johnghanks 6y agono they aren't
- justanotheranon 6y agoanyone in a FVEYs, or 14EYs, or 22EYs country should use Yandex mail. hosted in Moscow. FBI cant issue an NSL to read every email you sent or received to construct your patterns of life to more easily parellel construct you or blackmail/coerce you into compliance. even NSA has to tread lightly, and cant just casually feed your emails into XKEYSCORE, because if they get caught, then Yandex with the assistance of FSB will kick out NSA and/or hack back or retaliate with active measures. so NSA would only risk blowing their Yandex collection for very high National Priority targets. not you. in a sense, the smartest surveillance evasion tactic is to hide in the fog of cyber war between the Nation States. if you're not Baghdadi or Carter Page, you wont have to worry as much. plus, Yandex mail is better than gmail. Yandex is what gmail was 10 years ago--simple UI, no bloat, no ads, no spam, no BS. Yandex has a mobile email app too. better, you can host your private DNS on Yandex, then use Yandex for your private domain's emails. and unlike Google, who is probably selling your info about you from your emails to an ecosystems of ad spammers and "database of ruin" analytics spy companies, Yandex is not. thanks to US sanctions on Russia, your data is effectively siloed off from the US market. finally, consider the Shadowbroker hacker used Yandex to leak the stolen NSA EQGRP files. has the Shadowbroker been caught? nope. Yandex security looks better than anyone else's. we live in interesting times, when Russia is now a safer place to store your data than the US. the world has gone mad.
- jpeeler 6y agoDo you know if Yandex mail has a friendly API? One of the things that keeps me on Gmail is that they have an API with many language bindings that I have used on occasion. Also, I see that they have their own browser?? https://browser.yandex.com/ https://browser.yandex.com/ I assume it's just a rebrand.
- justanotheranon 6y agoi highly recommend Yandex browser. it is a Chrome fork, but it appear to be heavily modified with extra security features added. Such as DNSSEC pointing to Yandex's own DNS servers. I presume everything that phones home to Google has been ripped out of Yandex browser, much like Ungoogled Chromium. I like Yandex browser mainly because it puts the URL bar at the bottom. Google removed that feature years ago. Yandex browser also integrates with all of Yandex's services, like Mail and Disk. and yes, Yandex has an API for everything. You don't need language bindings as long as your language speaks HTTPS.
- hankchinaski 6y agoeven if you use protonmail and your correspondence use google the “privacy” claim is pointless...
- timwis 6y agoUnfortunately with encrypted mail like ProtonMail you can't setup email filters that act on the contents of the email; only the headers. This makes it harder to keep organised and fight unwanted mail so I've gone with fastmail
- jakobdabo 6y agoThere is one rather ugly privacy threat that I seldom see discussed even on HN. The spam fighting services. First of all, I'm not sure whether they are being run locally on the mail servers or maybe the mail servers forward our emails body to a third party anti-spam service to get a "spam score". And secondly, after being assigned a "spam score" a part of your email may end up in the headers as "X-something" where the anti-spam service describes why it didn't like your email. And we know that many 3-letter agencies collect as much email metadata (e.g. headers) as they can sniff out. So, you should know that the first X bytes of your unencrypted emails are less private than the remaining part, because they can be part of the metadata.
- arghwhat 6y agoSpam detection is run locally on the receiving mail server, and adds the result information to the email as the "X-something" header fields you are referring to as part of the receive pipeline. See e.g. rspamd. Should you forward the email with these header fields intact, then all it does is reveal a bit about your mail providers' infrastructure, which is already entirely public information.
- jakobdabo 6y agoI've seen small parts of my email body in the "X-something" headers inserted there by the anti-spam service. I can try to find an example later when I get to my desktop.
- arghwhat 6y agoI don't have memory of such behavior, but even then, this is in your receive pipeline, reading plain-text, publicly readable email meant for you and appending something to its plain-text, publicly readable header meant for you, all in order for the server to present this information to you/your mail agent. I don't see why any of this would lead to any amount of concern, but feel free to present the header field you refer to.
- mcraiha 6y agoI am looking for a world where email does not exist.
- dvduval 6y agoI see people discussing different alternatives, but for me there are very few viable solutions that would be nearly as good as gmail. And actually I don't like it this way. I hate to use the m word here, but it's kind of monopolistic for me. And seriously, this is an email period it was invented how many decades ago? It should be easy to have something that works very well with offerings from multiple providers. As you dig deeper, there are a lot of little details that give Google the advantage. I'm not expert enough to describe all of them in detail, but certainly part of it is we have big players who are dominant on Android and Apple making it difficult for small players to catch up. We also have, as one person pointed out, blacklists and not being easy to get around that with other providers because Google is so dominant in this space too.
- jug 6y agoThis is really just an ad for Proton Mail.
- r29vzg2 6y agoMy problem with ProtonMail is their requirement to use their bridge software for 3rd party mail apps and their requirement to use only their mobile application. I get the limitation because of the encryption, but I wish I can just turn off the encryption for specific apps. I don’t need my mail encrypted in flight, I just don’t want it sitting on Google servers. For that ProtonMail is overkill.
- dataminded 6y agoIs someone at Firefox listening? This is a service you can monetize right now.
- michaelmrose 6y agoI wasted a good bit of time looking through their page to see if ProtonMail bridge would work with arbitrary tools like offlineimap and found it nowhere there so for anyone else with the same question. It appears it does. https://spaceandtim.es/code/protonmail_mutt/ https://spaceandtim.es/code/protonmail_mutt/
- jasonv 6y agoI barely use email anymore, and I don't really use any chat apps. I think about moving off Gmail, but 99% of my emails are from retailers I shop with. Newsletters are now RSS, email with humans.. doesn't happen much, etc etc. Business emails are not very interesting -- we use secure methods to share info when needed. Email is.. to me personally, not very important anymore. (I show up to my accountant's office to sign things.. I keep looking for something that I need to secure.)
- CryDeTaan 6y agoPerhaps a bit off topic, but I created a service that at least hides your real email address when signing up to services. Its not a new idea, but I wanted to build something mostly for myself. So it is rudimental, but works. https://mailphantom.com/ https://mailphantom.com/
- ryandrake 6y agoMine has been working out well for the past, I don't know, close to 10 years: exim4 + dovecot running on Debian. I'm the only one with access to the OS, software, and data, and TLS works, so I'm pretty confident that it's at least as or more private than any hosted solution. It feels weird that self-hosting is seen as such an outlier case these days, but it's not difficult to set up and maintain.