6 ms·
The most popular open-source alternatives are SimpleLogin[1] and AnonAddy[2]. The former one was just acquired by ProtonMail[3]. [1] https://github.com/simple-
by up6w6 5y ago
The most popular open-source alternatives are SimpleLogin[1] and AnonAddy[2]. The former one was just acquired by ProtonMail[3].
[1] https://github.com/simple-login/app/ https://github.com/simple-login/app/
[2] https://github.com/anonaddy/anonaddy https://github.com/anonaddy/anonaddy
[3] https://protonmail.com/blog/proton-and-simplelogin-join-forces/ https://protonmail.com/blog/proton-and-simplelogin-join-forc...
- bertman 5y agoHuh, hadn't heard about Proton buying Simple Login. I'm not sure how to feel about that. I really like SimpleLogin, but Proton always felt kind of "icky" for lack of a better word. Guess we'll see.
- Vinnl 5y agoMozilla also has Firefox Relay: https://relay.firefox.com/ https://relay.firefox.com/ (Disclosure: I'm on the Relay team.)
- sinatra 5y agoIf relay gets popular, won’t some services simply start to block relay subdomain for registration to make it ineffective? Just like 10minutesemail etc are blocked in many places.
- m-p-3 5y agoYou can flag them to the Relay team and AFAIK they'll reach out to the domain that blacklisted them with the hope to make them change their mind. A service that doesn't accept an email proxy during registration is not going to respect my privacy, so IMO not worth of using.
- Vinnl 5y agoFor an example of that, see here: https://github.com/wesbos/burner-email-providers/pull/339 https://github.com/wesbos/burner-email-providers/pull/339 But yes, definitely a concern that is constantly on our radar.
- CryptoBanker 5y agoSites already have started blocking the mozmail.com domain name. I'm considering moving over to fastmail given that their domain is already established for email purposes. I would imagine the same is true for icloud emails
- skeletonjelly 5y agoI love Relay! Thank you!
- Vinnl 5y agoThat's always great to hear!
- withinboredom 5y agoI don't know how much I can trust Mozilla with my privacy. I know it's not Mozilla's fault, but 90% of my millions of DNS requests that leave my house go to Mozilla tracking services. It's kind of scary how much information Mozilla has on people, just based on what leaves my house (and no one uses Firefox). I have no idea if Mozilla does any aggregation on that data, but it's a bit worrying IMHO.
- 3np 5y agoAny thoughts on improving the situation on self-hosting? I've written about the situation for Firefox Accounts (FXA, a dependency of Relay if you don't want to use third-party hosted services) here before[0][1] and Relay looks kind of similar. When comparing Relay with the other two, I get the impression that SimpleLogin/AnonAddy actually interact with the community and understand that self-hosting is something people want to do and provide approachable documentation and support for that, whereas Firefox Relay seems built only with a single global prod deployment in mind and is more like "well theoretically you could but you're on your own and who would do that anyway?". Even if it's public and under an open license, the intended audience is Mozilla internal, e.g. [2] Like, if a user signs up for Relay today and in 2 years Mozilla sunsets it, the way things looks today I think it wouldn't be viable even for most seasoned self-hosters to migrate to their own deployment. I do appreciate the work you guys are doing and I think the engineers seem to have good intentions, so don't want to be overly critical. But mentioning it as open source alongside SimpleLogin and AnonAddy comes with some major caveats IMO, and I'd wish that some more priority is put on keeping docs complete and up to date and making the stack realistically approachable for outsiders. [0]: https://news.ycombinator.com/item?id=30727935 https://news.ycombinator.com/item?id=30727935 [1]: https://news.ycombinator.com/item?id=30315816 https://news.ycombinator.com/item?id=30315816 [2]: https://github.com/mozilla/fx-private-relay#optional-enable-premium-features https://github.com/mozilla/fx-private-relay#optional-enable-...
- Vinnl 5y agoI can only speak for myself, but my honest answer would be that indeed, self-hosting probably won't be easy to do any time soon. We're trying to get a less technical audience to benefit from privacy protections too, and I don't think there's a good approach to get them to self-host as well, so focusing our limited time on other things is probably more effective. But who knows, actual use and user research do influence our roadmap, so nothing's set in stone. But you're absolutely right, the caveat is indeed that the reason you care about open source does matter. If you want to self-host, you're probably better off with another product. If you want to be able to see what code is running, or even be in control of the running code yourself (even if it's running on someone else's servers), then Relay might be interesting too.
- smusamashah 5y agoI use mozmail and on the fly emails are great but so easy to exploit and spam. For example, my custom domain is foo.mozmail.com. I enter my on the fly email address bar@foo.mozmail.com on attackers website. Voila. Now they know my custom domain name "foo" and can use it to send email to all possible on the fly addresses. e.g. 1@foo.mozmail.com 2@foo.mozmail.com so on and so forth. Now my custom domain name as a whole is compromised but I can not change it anymore and lost all benefits of Firefox relay.
- aorth 5y agoYou don't have to use the custom @domain.mozmail.com address with Firefox Relay—you can use @mozmail.com with one of the auto-generated random aliases. Your complaint is similar to using RFC 822 "me+site.com@domain.com" style emails and then worrying that sites are going to learn that your real email is "me@domain.com" by stripping off the part after the plus sign. Call me optimistic or naive, but I don't think that sites are doing that... https://people.cs.rutgers.edu/~watrous/plus-signs-in-email-addresses.html https://people.cs.rutgers.edu/~watrous/plus-signs-in-email-a...
- Vinnl 5y agoYes, it is recommended to use a completely random email by default, and only use your custom domain as a fallback when you can't use the random one (e.g. when you have to give up your email somewhere in-person). We're looking into ways to make that clearer, because people's intuition tells them to use their custom subdomains by default.
- smusamashah 5y agoThat's right. Thanks for correction. I have been doing exactly that. Using custom domain email everywhere I needed. Will use generated emails from now.
- Rebelgecko 5y agoI'm a big fan of SpamGourmet, but I've noticed a few websites have started to blacklist it