back

by calvinmorrison·6y ago·view on hn ↗
At the core, google and other companies sell your data for advertisements, at best, at worst they're sending it all the NSA or some other black box.

I recommend everyone BUY A DOMAIN. Then switch providers. you can always switch with your own domain.

The select a provider based on thier offering be it protonmail, fastmail (shameless plug), or others

13 comments
The trouble is that opens another attack vector. This story[1] (previously discussed on HN[2]) comes to the opposite conclusion.

Who is right? Is there a consensus in the security community?

[1] https://medium.com/@N/how-i-lost-my-50-000-twitter-username-...

[2] https://news.ycombinator.com/item?id=20927465

> The trouble is that opens another attack vector. This story[1] (previously discussed on HN[2]) comes to the opposite conclusion.

> Who is right? Is there a consensus in the security community?

There might not be one best answer. There have been many other stories on HN of people loosing access to their Gmail accounts, and having no recourse with Google to regain access.

My gut feel is the best any of us can do is to set up our digital lives so that our accounts are "misaligned" to make it more difficult to use social engineering to pivot between them. For instance, in the story you linked, they key to an actual attack was a shared credit card number between Paypal and Godaddy that was used for verification. Ignoring the fact of how stupid it is to use just 4 digits for such a task, it would have made that path more difficult for the attacker if he'd used a dedicated card for Godaddy (given his domains were valuable enough to him that they could be used to extort a $50k twitter handle from him). Having different, secret, email addresses/domains attached to important accounts could also provide a stumbling block.

But it's also worth noting that much of the attacker's planned attack failed, and he only succeeded in the end through extortion.

Unfortunately we rely on registrars for too many things nowadays, which is probably as bad as our enormous trust on commercial certificate authorities.
> I recommend everyone BUY A DOMAIN.

you will end up having most of your conversations with gmail or outlook users so that would not change anything

This is the only correct response to this problem, and it needs to be seen more prominently.

E-mail in 2020 is not secure against a motivated attacker. It doesn't matter how secure and woke your provider is, when:

1. Everyone you talk on an e-mail thread gets a copy of the entire e-mail thread, to do whatever they want with.

2. You can't control the present and future security of other people's providers, or the present and future security of the computing devices they use to read the e-mail you send them.

Now, if you want to LARP, you can try setting up a mailing list for your friends who only use secure providers (For whatever definition of secure you want to use), and only limit your use of a single e-mail address to that mailing list. Great. Go for it. Write a blog post about it, even. But that's not going to solve the fundamental problems of #1 and #2 for the rest of the world.

Now, if you actually want security (as opposed to 'I want to LARP at security'), take a page from conspiracies in the financial sector, and don't use e-mail for any conversations that you'd like to remain secure.

Securing e-mail is a waste of time. It can't be secured, because of 50 years of social expectations about how e-mail should behave. (Other people retain copies of your e-mails, and other people can choose which provider services their address.) You can spend that effort on trying to secure a different communication protocol, which does not have those 50 years of social expectations, and that will probably lose to e-mail (Because those two security holes provide users with value, and when it comes to value versus security, security will lose every time.)

This is basically it. If you trust an entity, great, if not, move and update your DNS maybe even host your own if you're up to the challenge.
The link may say that more people are looking for a private email inbox, but I don’t think most people are willing to pay the price of a domain and an external service. The latter is practically an oligopoly currently because of the lack of options; in terms of price, email services are a complete rip-off.
They're not willing to pay because they don't know that you can buy domains in the first place. Most of the time when I tell someone my first@lastname.com they're like ...and that'd be @gmail.com?
Yes, and it's even worse when you're using a "new" TLD like .family. Almost nobody (based on personal anecdotal evidence) outside of tech is even aware those are now valid domains.
When even a .co is considered a typo, I think we've a long way to go with this...
Anecdotally confirmed by the number of times people react with some level of amazement when I tell them my email address is myname@myname.com. "How did you get that?", etc.

EDIT-after-parent-edit: That, too, regarding "and that'd be @gmail.com?".

I run a service that lets you hand out burner addresses that you can make up on the fly.

It does raise an eyebrow or two when I tell someone my email is theirname@myname.domain

I personally love mine. firstname@pobox.com. it's really easy to say "P O box" over the phone and everyone just gets it.
I have a service with one customer (me) that lets people email me via my phone number. For example: 732-757-2923@telephonemail.com (this isn’t the actual domain I use).
Or they don't want the hassle and find it too difficult and/or daunting.
I have my own domain for blog, e-shop and e-mail.

Not everyone is even contactable from my own domain. The IP address used to belong to some spammers several years ago and some blacklists are still there.

Also, my newsletter, even though it uses double opt-in, triggered some automatic mechanisms of Spamhaus. I ended up on a blacklist several times. Fortunately, I was able to argue my way out and after the last incident, they must have updated their lists.

But those were bad times, no one could literally post a link to my blog onto Twitter etc.

Have you considered registering a brand new related email that doesn't have the negative association with it?

My company name was too long, so we registered a domain for our email that was just our initials and it was nicer to type, and really easy to set up.

The problem is that my blog already has some recognition. Surname dot net.
>At the core, google and other companies sell your data for advertisements, at best, at worst they're sending it all the NSA or some other black box.

Post Cambridge Analytica I'm not sure which is worse.

No worries, the NSA will see it all anyways :) There's no privacy on the internet.

That said: I'd love to run my own e-mail servers, but Yahoo does a pretty good job keeping spam away from me and offers enough convenience that I just stuck with it.

Happy to consider alternatives I can run on a cheap instance somewhere.

Yahoo, really? I get a lot of false positives w/ them.
Is it possible to configure Fastmail's web client to connect to an arbitrary CardDAV and CalDAV server?

Partner is a die-hard webmail user who detests native desktop clients. I'd like them to be able to use Fastmail webmail with my self-hosted calendar and contacts.

For CardDAV, there's options to do a regular one time import, but it's not setup to sync.

For CalDAV, many people use the Fastmail web interface with other calendars by syncing them (https://www.fastmail.com/help/calendar/sync.html?).

I've been incredibly happy with mailbox.org.
The only thing preventing me from leaving Gmail is that they have awesome clients (web, android, iphone). And all of them sync well. Does anyone else have this?
Awesome clients? For android try ninemail (if you are calling android default email client awsome you wont come to your breath for next 2 weeks ;). For web you have gazillion of them, from roundcube to horde and nextcloud plugin (anyway, its just a user interface, protocols are standardised (mostly IMAP beeing used for accessing mail and any client supporting it can read emails). But yep. It is for self hosted people. And I think that everyone in 2020 should be self hosted (I thought that in 2000 too but it is just getting worse, everyone locking himself into some vendor jail, one way or another).
Or K9 if you want an open source client to inspect the source code if you feel like it's necessary to ensure that the app works as intended.
The search abilities of gmail make it the killer app for me:

https://support.google.com/mail/answer/7190?hl=en

I'll try ninemail. Thanks.

>Does anyone else have this?

Everyone has this. It's called IMAP.

IMAP is not a cross-platform client. It's a protocol.
Yes. That's why everyone has it.
All email clients (non-web) do the same thing (including sync). And you can plug imap/smtp into almost every email client.

As for the gmail web client, various services are providing similar interfaces on their email service.

I don't know about Proton, but right now I cannot think of anything missing from FastMail that exist in Gmail -- they even support label now. The clients are better than Gmail, IMO.
What about search capabilities? the search power of gmail is awesome:

https://support.google.com/mail/answer/7190?hl=en

If you depend on Google suite, you might miss out on features provided by the online office tooling.
They lack automatic translation of emails. Not a big deal, but in gmail it's one click away and with fastmail you have to copy-paste.
If you are focused on privacy, you probably aren't using a client app. Browsers are the way to go, particularly on mobile devices. They allow you to more easily prevent data being stored on the device. The simple presence of an app evidences that you have an account with that service whereas a browser, absent bookmarks, reveals nothing. I don't hesitate to unlock my phone for airport checks. They aren't going to find anything, nor be able to say I have an account anywhere.

(A great thing about HN is that you don't need to have an account in order to read articles. So I can bookmark it on my phone without worry.)

Since the browsers are a spyware on their own, especially chrome, this is not really true. And fingerprinting, cdns, etc. doesnt really provide you privacy. And local storage, history, cookies, syncing bookmarks to google etc. doesnt help either. We could argue about ssh / rdp access but browser is surely not a way to go.
It's possible to value (incremental gains in) privacy without taking it to such extremes. I definitely wouldn't want to go to such lengths, and I'm probably somewhat more privacy-conscious than many.
This looks good -- but it looks like they host the mail server, correct?
Since SMTP transfers things unencrypted, you kind of have to assume that a bad actor with reach as wide as the NSA's is intercepting all your email regardless of who your provider is. There's really no solution there, since the company from which you order your suppositories isn't using end-to-end encryption to send you their order confirmations.

That said, I still 100% support getting off of the free email providers in order to wave a middle finger at surveillance capitalism.

Doesn't most server support STARTTLS by now?
>Since SMTP transfers things unencrypted

But that's false. They're encrypted with TLS. It's just not end to end encrypted.

Or get a custom domain to use with gmail, best of both worlds!
Or you could just ditch Gmail and all of Google's shady practices.

There is clearly some merit to Proton Mail's privacy claims. Even Google goes out of their way to try to scrape data from ProtonMail: https://old.reddit.com/r/ProtonMail/comments/9yl94k/never_co...

But what happens when half or more than your emails go to Gmail accounts? Google still see them.

I have my own domains, POP mailboxes hosted by my domain providers which also provide SMTP servers (I don't feel like self hosting) but I know Google know most of what I write.

Auto translate pages was quite a handy feature, you are probably complaining about it being enabled by default.

Until some time ago there used to be a prompt indicating that the page was translated. But haven't used chrome in a long time.

What Gmail data do you believe is used for advertising? What would convince you that it was not?