5 ms·
> A lot of the optimisations for efficient client-server sync require the server to be able to read the message. If everything were encrypted, the server would
by doodlesdev 3y ago
> A lot of the optimisations for efficient client-server sync require the server to be able to read the message. If everything were encrypted, the server would basically be a dumb blob store. This is particularly bad for mobile, where you only want to sync partial information. Users expect to be able to search their whole archive, so either you need all the data in the client, or the server needs to have access to the data.
> JMAP is therefore not introducing any new measures to address end-to-end encryption. The best advice is probably to run your own "JMAP server" on trusted hardware; otherwise you need to sync the entire multi-gigabyte mail spool to all your devices. JMAP is also simple enough that you could run the server on multiple machines with an underlying replication protocol over encrypted links and have that do your smarts.
They lost a huge opportunity. Encryption at rest of emails and E2EE should've been how we built these protocols from the start, here we get a chance to try it and... no, just "self-host" instead.
I enjoy self-hosting stuff, but it's just not what normal people will be doing, and they deserve privacy too. Also, self-hosting email is possibly the most complicated self-hosting task you can think of due to deliverability issues.
My biggest pain point with mail providers that support encryption, such as Proton or Tutanota, is that I have to run a "bridge" application that hosts the IMAP server on my machine, since otherwise there's no way to get the encrypted payloads into my mail client. Otherwise, I will have to use their proprietary client (proprietary in the sense it implements their own protocols). This sucks, and it could be solved at the protocol level with JMAP. I expected this to be a top priority of the Fastmail team when developing this, but unfortunately it's not.
- danielheath 3y ago> They lost a huge opportunity. Encryption at rest of emails and E2EE To implement E2EE for email would involve replacing literally every part of the tech stack at literally every provider. You can't lose an opportunity you never had.
- drdaeman 3y agoI don't think so. I mean, I can't imagine what exactly needs to be replaced, and I'm not really getting what that GP quote is talking about, unless it's email metadata (encryption of which is impossible in practice) or full-text search (I always forget about it, as I don't really use it myself) First, at-rest encryption is perfectly doable with most typical software setups (Postfix/Exim/Dovecot/Cyrus/etc), and I think should be not so hard to achieve with proprietary systems as long as they a) capable of dealing with MIME messages (don't reprocess emails for storage) and b) have milter-like capabilities in their local delivery pipeline. You just throw in a milter that encrypts messages to a user-provided key (such as S/MIME or - hey, don't throw anything at me - PGP public key, or whatever MUA may support), and rely on the mail user agent (aka mail client) to be able to decrypt this mail. Second, I'm not sure how E2EE is even in the picture. It - by definition - should be all happening on the endpoints, so I'm not sure how providers (let alone protocols they use) even fit in the picture. And if anything, it's not on IMAP but on SMTP. But even then, SMTP/LMTP are delivering MIME-encapsulated data (that typically happens to be HTML or text pieces), and they don't really care about what sort of data is in there. This significantly hinders anti-spam capabilities, though.
- danielheath 3y ago> should be all happening on the endpoints Right - but Fastmail never had the opportunity to do that, which is what I read GP as asking for.
- Kalium 3y agoEncryption at rest is beyond the scope of any reasonable systems data interchange protocol. That's not a missed opportunity, it's a nonexistent one.
- chrismorgan 3y ago> This sucks, and it could be solved at the protocol level with JMAP. It couldn’t. You’ve failed to understand the reasoning summarised in the first paragraph. E2EE comes at a significant and fundamental cost, and not one most people want to pay. There’s a reason why your Proton Mail and the likes are crippled in ways like this: because that’s the best we know how to do with that kind of approach. There’s also the matter that first-party end-to-end encryption is snake oil: <https://hn.algolia.com/?query=chrismorgan+snake+oil&type=comment https://hn.algolia.com/?query=chrismorgan+snake+oil&type=com...>. See also Fastmail’s reasoning for not offering any of this kind of thing: <https://www.fastmail.com/blog/why-we-dont-offer-pgp/ https://www.fastmail.com/blog/why-we-dont-offer-pgp/>.
- userbinator 3y agoThere's already something called PGP.
- myself248 3y agoIn spirit, I would love to self-host, but I have neither the sysadmin skills to do it, nor the time to keep up on security patches, etc. I definitely don't want a "hosted" offering where my stuff lives on someone else's hardware and vanishes when they go out of business. What I would love is a "sysadmin contractor" who runs my stuff for me, on my hardware, on my bandwidth. I pay them not for the hosting, but for the admin skill. Probably a step up from fiverr, but not a full-time employee. This wouldn't scale very well if the contractor wanted to work for a hundred-plus people like me and learn all our individual tech stacks. But if I could pick from the contractor's menu of supported stuff, and configure it with a menu of supported connections, they should be able to automate a great deal of the administration across all their clients. Does anything like this exist? I'm aware of various host-it-yourself platforms and distros, but they all expect me to be my own admin, which is a dealbreaker.
- dv35z 3y agoI’ve been thinking the same thing - a mix of “CTO on-demand” / “Cloud IT / platform operator” / tech support. What would your ideal budget range for this role be? Maybe we can find a 5-star person, share out their time among 4-5 people here on HN…
- myself248 3y agoI would imagine such a person would heavily script a lot of things and be able to spread their time among hundreds of customers, and I'd get the cheap rates if I'm willing to pick off their menu of preferred software packages for each need, rather than picking my own specific one, for instance. I don't know if it's realistic, but I'd love something on the order of $20/mo for something simple like my own photo gallery (whatever package they recommend), maybe a peertube instance, a personal pastebin or etherpad. I'll provide the hardware and connectivity, I just want someone to help me set it up, log in periodically and apply patches, and manage backups and stuff. I'd expect to pay more if I had weird requests or high-maintenance stuff like email. Some time ago, I heard an interesting idea for "investing" in indie musicians -- buying their music actually buys stock, and if they become popular, your shares become more valuable. Similarly, if I'm picky about wanting my CTO-on-demand to support _this particular_ photo gallery software, and I pay extra for that special service initially, but later it becomes popular and many of their customers request it and they're able to service those requests because I paid them to develop the skill, maybe I get something in return? I dunno, that gets complicated, but it's worth thinking about how the incentives work.