[1] https://creativecommons.org/licenses/by-nc-sa/4.0/ [2] https://github.com/skiff-org/skiff-apps/issues/94
Further, it looks like the email encryption provided by this system only works between users of Skiff. At that point, why use email at all? Why not use a real secure messenger? Instead of building an "encrypted email service", you could literally just build an email-flavored frontend to Matrix; either way, you're proxying to SMTP, not speaking it directly.
>From the white paper, it appears as if this system requires its users to trust the server. That's not end-to-end encryption. What do I have wrong here?
It doesn't. All data is encrypted client side across all apps - Skiff Mail, Drive, Pages, and Calendar. For sending external, the whitepaper is very clear how this case is handled in section 8.2 as securely as possible (without having PGP in place. Though this is something we are looking at based on community feedback).
>Further, it looks like the email encryption provided by this system only works between users of Skiff. At that point, why use email at all? Why not use a real secure messenger? Instead of building an "encrypted email service", you could literally just build an email-flavored frontend to Matrix; either way, you're proxying to SMTP, not speaking it directly.
Lots of folks are sick of getting sold their data sold based on their email. Even corporations are sick of largely giving more information about their customers to Google even notoriously Amazon that stopped sending purchase receipts via email.
So even if not end to end encrypted, we do encrypt the emails with the recipient's keys ensuring that only the recipient can access this data. This is a strong privacy guarantee not just backed by a flimsy privacy policy but actual cryptography.
Apparently, email may not their main e2ee usecase. The CEO at Skiff wrote this on PrivacyGuides forums:
Our solution for external sharing was not intended for email. It is much more powerful to share E2EE real-time collaborative docs/files with subpages, embedded E2EE files, and so much more.
Curiously, in the same thread, there's is a mention of Trail of Bits auditing their codebase twice.https://discuss.privacyguides.net/t/skiff-mail-email-provide...
ProtonMail does have import/export and the SMTP bridge (for paid users) and those things work but ProtonMail mangles emails: it removes plaintext body where there's a HTML body and it screws with headers.
Ultimately the best option I could come up with was self-hosting my email address. Incoming emails go directly to a box sitting in my office, with TLS enforced.
I put this off for years fearing deliverability issues but finally realised that incoming and outgoing email can be hosted in different places. So though the box in my office receives my email, I send email through either a Hetzner box or Mailgun (with retention disabled). Haven't encountered any issues with this so far.
wow, an e-mail service without smtp nor imap?? no thanks
More expensive than self hosting, but still quite cheap, and no weird vendor-specific lockin for the important parts.
> Unlimited pages
> Desktop, tablet, and mobile access
> IPFS support
> Full text search
Which seems to be all about the document service, but it also doesn’t mention how much storage I get. I assume it’s not unlimited despite saying “Unlimited pages.”
Also, I can see that Skiff has raised over $14M in VC funds[1], so as a privacy-focused product with a free-tier I think it’s fair to ask what they see as their path to profitability is without compromising either their privacy or their free offering.
1. https://www.crunchbase.com/organization/skiff-402f/company_f...
They seemed to have pivoted from web3? https://news.ycombinator.com/item?id=29797691
That would then actually be email rather than not-email-over-smtp.
Another service delegated to trust a 3rd party isn't.
..Personally, this looks promising. I am going to say it though- Skiff needs some sort of mechanism to use PGP if for nothing else, then to communicate with Protonmail email addresses specifically. I see they are taking the stance its's time to move to something beyond PGP- but given the extremely large userbase that is Protonmail- I think their target market would feel better being able to communicate with their protonmail contacts- using PGP.
Also, i'm having trouble seeing if Skiff has a way to 'send secure emails' to other external email providers, like Tutanota ,Mailbox, and Protonamil do for their users to securely contact people outside their ecosystems(like peeps with gmail). Solve those issues- and the pain/difficulty/unease of convenience will disappear for their market which likely already uses Protonmail/Tutanota, etc. And Skiff would be very attractive at that point, positioning itself as a successor to those two possibly.
Right now, you can use Skiff Pages for this. You can share public links that have E2EE using link fragments, add passwords, and collaborate in real-time.
Skiff's free tier also has a 'generous' free tier with 4 aliases, 10GB of drive (only? combined with email?) storage, and custom domain support (? !)
I'm curious if your emails go to spam more frequently, being a smaller player in an established hegemony.
You have a generous free tier which may attract spammers. How do you deal with IP reputation?
And now I'm seeing Skiff, which is great, it's clear that people want this. I just no longer know who the players in the space are.
I personally use mailfence with IMAP on Thunderbird (so its not full E2E encryption despite the marketing) but I much prefer the Belgian privacy law.
Though the mobile/destop apps looks very nice and overall kudos for what seems like a coherent ecosystem (something I miss from my patching of sync.com and mailfence). Also concerned by VC money in that space, hopefully you are profitable. Nobody wants to have to move their life (calendar, drive, emails) because they trusted a startup that ran out of money...
On that note: the passwort page for the registration form has terrible UX.
Paste is disabled for the 'Confirm password' field (Chrome, Android) but for not the first 'password' one. Rationale?
I use a decent-length generated password from KeePass.
Being forced to typing this out just plain sucks.
Edit: after reloading the page, paste works also on the 'Confirm password' field. Very strange. Account creation still fails with above error though.
Yet the web UI downloads remote images by default.
Granted, it hides your IP address by proxying the request. But it still leaks that the message was read. I used https://www.emailprivacytester.com to test this. No image was fetched until I clicked the email to read it.
Generally, how does Skiff allow the user to ensure that the message is being sent to their actual correspondent and not the Skiff server? Signal messenger for instance uses "Safety Numbers" for this purpose.
[1] https://skiff-org.github.io/whitepaper/Skiff_Whitepaper_2023...
I noticed on your home page near the bottom under the "Getting the Latest in Privacy" subheading your list of scrollables begins to duplicate entries if you keep clicking the right arrow after the "Brave Talk X Skiff" panel. From that point on, most of the entries are twinned until you reach the end of the list.
I'm a button clicker. It's a bad habit.
Besides, I want my backup email address to be a non-gmail service to avoid complete vendor lock in.
Bye.