4 ms·
One serious problem is that email, apart from a means of communication, is also a means of authentication. Taking away a person's email address could easily mea
by aduitsis 6y ago
One serious problem is that email, apart from a means of communication, is also a means of authentication. Taking away a person's email address could easily mean that they will have to spend a tremendous amount of time changing it with various parties that have it in their records. At least those of them that can actually accept to talk to you (e.g. your bank or the IRS).
An non-optimal approach would be to actually own the domain name of one's email address and then use one of those providers listed there as the "backend" mailbox, by forwarding the "real" email address to the "backend" mail address. Most domain name providers will actually provide this kind of email forwarding for free. And it would be much much easier to switch between the backends. Or even use two of them simultaneously.
- jessaustin 6y agoProperly setting the MX DNS record is better than forwarding.
- aduitsis 6y agoI'm not sure this can work in general. You need some entity to forward and use the proper envelope headers for the mail to go through in the backend.
- jessaustin 6y agoAn SMTP server capable of responding to a forward would also be capable of responding to the original message, and would be accessible via the MX record. The only reason I see to introduce the additional server in the middle would be because the final destination is not always online or otherwise unreliable, and even then only if the forwarding server is more forgiving than typical mail senders.
- galago 6y agoI've owned a domain for 20 years and always had my mail hosted by one of the web hosting companies. I've used a couple hosting providers, but to be honest, I'm not certain how they've handled my mail in terms of privacy. It never seemed "non-optimal" to own the domain. I still think using gmail or other free services is a bad idea, but i don't generally say it out loud much anymore. People react negatively because they don't want to consider whether the services they depend on are misusing their personal information.
- aduitsis 6y agoThank you, I meant non-optimal in the sense that using a (possibly free) email provider as a "backend" might mean that the emails are eventually accessible by third parties. Having your own domain like that mostly shields from the provider locking you out of your email on a whim, but certainly doesn't help much with privacy.
- jabroni_salad 6y agoI have read some horror stories from people who have lost control of their domain. Now you have a hostile actor holding it for ransom and able to receive your mail. I really like having full control of my MX record but that's something I keep in the back of mind. Whenever I think of it I go and top off my registration up to 10 years so I don't have to worry about auto-renew failing.
- adtac 6y agocounter-intuitively, it's better if you didn't renew 10 years at once because you're much more likely to forget after 10 years
- busterarm 6y agoEmail on its own should NOT be used for authentication/validation and collectively we should push to move past it. Password reset emails are pretty terrible if not combined with something like TOTP. So push everyone to start using TOTP. For communication that matters, signing keys is better than nothing. I know PGP isn't that great, but for now we don't have better. Organizations that care about this are pushing on this, but for "general use" we'll probably never get there.
- aduitsis 6y agoIncidentally, many services are now requiring a cellphone to send some one time password via SMS. Your phone number is something that you actually pay for and can transfer between carriers as you see fit. So in that sense, it's much more predictably controllable and, more importantly, under the legal jurisdiction of your own country.
- quesera 6y agoOTP via SMS is not safe enough for any person/organization who might be targetted by a motivated attacker. TOTP gives you better control over risk (good hygiene is achievable), whereas depending on SMS is outsourcing your risk management to low-paid carrier employees.
- ClumsyPilot 6y agoHow does TOTP solve the reset email problem, what do you do if your phone is destroyed/lost/stolen and you don't have TOTP app any more?
- busterarm 6y agoThat's why you were supposed to backup recovery keys at the beginning and store them somewhere safe. Like on a piece of paper in a safe. An encrypted database works too.
- srockets 6y ago