I recommend everyone BUY A DOMAIN. Then switch providers. you can always switch with your own domain.
The select a provider based on thier offering be it protonmail, fastmail (shameless plug), or others
I recommend everyone BUY A DOMAIN. Then switch providers. you can always switch with your own domain.
The select a provider based on thier offering be it protonmail, fastmail (shameless plug), or others
Who is right? Is there a consensus in the security community?
[1] https://medium.com/@N/how-i-lost-my-50-000-twitter-username-...
> Who is right? Is there a consensus in the security community?
There might not be one best answer. There have been many other stories on HN of people loosing access to their Gmail accounts, and having no recourse with Google to regain access.
My gut feel is the best any of us can do is to set up our digital lives so that our accounts are "misaligned" to make it more difficult to use social engineering to pivot between them. For instance, in the story you linked, they key to an actual attack was a shared credit card number between Paypal and Godaddy that was used for verification. Ignoring the fact of how stupid it is to use just 4 digits for such a task, it would have made that path more difficult for the attacker if he'd used a dedicated card for Godaddy (given his domains were valuable enough to him that they could be used to extort a $50k twitter handle from him). Having different, secret, email addresses/domains attached to important accounts could also provide a stumbling block.
But it's also worth noting that much of the attacker's planned attack failed, and he only succeeded in the end through extortion.
you will end up having most of your conversations with gmail or outlook users so that would not change anything
E-mail in 2020 is not secure against a motivated attacker. It doesn't matter how secure and woke your provider is, when:
1. Everyone you talk on an e-mail thread gets a copy of the entire e-mail thread, to do whatever they want with.
2. You can't control the present and future security of other people's providers, or the present and future security of the computing devices they use to read the e-mail you send them.
Now, if you want to LARP, you can try setting up a mailing list for your friends who only use secure providers (For whatever definition of secure you want to use), and only limit your use of a single e-mail address to that mailing list. Great. Go for it. Write a blog post about it, even. But that's not going to solve the fundamental problems of #1 and #2 for the rest of the world.
Now, if you actually want security (as opposed to 'I want to LARP at security'), take a page from conspiracies in the financial sector, and don't use e-mail for any conversations that you'd like to remain secure.
Securing e-mail is a waste of time. It can't be secured, because of 50 years of social expectations about how e-mail should behave. (Other people retain copies of your e-mails, and other people can choose which provider services their address.) You can spend that effort on trying to secure a different communication protocol, which does not have those 50 years of social expectations, and that will probably lose to e-mail (Because those two security holes provide users with value, and when it comes to value versus security, security will lose every time.)
EDIT-after-parent-edit: That, too, regarding "and that'd be @gmail.com?".
It does raise an eyebrow or two when I tell someone my email is theirname@myname.domain
Not everyone is even contactable from my own domain. The IP address used to belong to some spammers several years ago and some blacklists are still there.
Also, my newsletter, even though it uses double opt-in, triggered some automatic mechanisms of Spamhaus. I ended up on a blacklist several times. Fortunately, I was able to argue my way out and after the last incident, they must have updated their lists.
But those were bad times, no one could literally post a link to my blog onto Twitter etc.
My company name was too long, so we registered a domain for our email that was just our initials and it was nicer to type, and really easy to set up.
Post Cambridge Analytica I'm not sure which is worse.
That said: I'd love to run my own e-mail servers, but Yahoo does a pretty good job keeping spam away from me and offers enough convenience that I just stuck with it.
Happy to consider alternatives I can run on a cheap instance somewhere.
Partner is a die-hard webmail user who detests native desktop clients. I'd like them to be able to use Fastmail webmail with my self-hosted calendar and contacts.
For CalDAV, many people use the Fastmail web interface with other calendars by syncing them (https://www.fastmail.com/help/calendar/sync.html?).
https://support.google.com/mail/answer/7190?hl=en
I'll try ninemail. Thanks.
Everyone has this. It's called IMAP.
As for the gmail web client, various services are providing similar interfaces on their email service.
(A great thing about HN is that you don't need to have an account in order to read articles. So I can bookmark it on my phone without worry.)
That said, I still 100% support getting off of the free email providers in order to wave a middle finger at surveillance capitalism.
But that's false. They're encrypted with TLS. It's just not end to end encrypted.
There is clearly some merit to Proton Mail's privacy claims. Even Google goes out of their way to try to scrape data from ProtonMail: https://old.reddit.com/r/ProtonMail/comments/9yl94k/never_co...
I have my own domains, POP mailboxes hosted by my domain providers which also provide SMTP servers (I don't feel like self hosting) but I know Google know most of what I write.
Until some time ago there used to be a prompt indicating that the page was translated. But haven't used chrome in a long time.