this post was submitted on 25 Apr 2024
286 points (95.3% liked)

Technology

59421 readers
2852 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
top 50 comments
sorted by: hot top controversial new old
[–] [email protected] 89 points 6 months ago (8 children)

For anyone using a custom domain, or thinking about it, read this: https://dmarcly.com/blog/how-to-implement-dmarc-dkim-spf-to-stop-email-spoofing-phishing-the-definitive-guide

Without these records you're a lot more likely to go to spam, or get rejected outright. If you have questions about it, ask here or DM me and I'll be glad to help.

[–] [email protected] 63 points 6 months ago (6 children)

Recently I added a custom domain to my protonmail account and during the procedure it makes you do this steps (adding SPD, DKIM and DMARC) to pass all the steps. They tell you exactly what records you have to add, where to add them and what the content should be. These guys are great

[–] [email protected] 8 points 6 months ago

Yep, setup mine about a year ago now, since I'm trying to get rid of Google completely, and it walks you through all of this. It was really well done setup.

load more comments (5 replies)
[–] [email protected] 8 points 6 months ago

Doing the lords work

load more comments (6 replies)
[–] [email protected] 41 points 6 months ago (3 children)

I always worry that it will get bought out by some asshole company and we'll be even worse off than with Google (if that's even possible).

[–] [email protected] 107 points 6 months ago (2 children)

Hi, this is Andy here, the Founder/CEO of Proton. As former scientists, we don't do what we're doing to make the most money (otherwise we wouldn't have picked science as a profession). There's no price which we would sell Proton to Google or Facebook. We also don't need to because thanks to the strong support of the community, Proton has the resources to thrive and grow as an independent organization. Safeguarding this independence is how we ensure that over the long term, we can always put user interest above all else.

-Protonmail Founder, 2 years ago, for what it's worth.

[–] [email protected] 93 points 6 months ago (5 children)

Google's motto used to be "don't be evil"

Companies can change.

load more comments (5 replies)
[–] [email protected] 7 points 6 months ago

Trust, but verify.

I want to see some assurance. I don't know Switzerland's laws, but if there's a concept of a "social purpose company" or something with actual legal teeth, that would make me a bit more comfortable.

They're certainly better than Google, and I like that their products are audited, but words from their founder don't need much, especially if the founder decides to leave.

[–] [email protected] 29 points 6 months ago (7 children)

That’s the benefit of a custom domain, I suppose; you can always change he provider without changing your email.

[–] [email protected] 10 points 6 months ago (1 children)

Yup, I just signed up for Tuta with a custom domain. If they start sucking, I'll move to Proton or something else.

[–] [email protected] 7 points 6 months ago (2 children)

You should be aware Tuta won't let you use a third party client, automatically forward messages, or do a mass export of your email. It's not impossible to move but they deliberately make it difficult. So does Proton in their own away.

They'll say it's about maintaining the security of your emails and such, but it's just a vender lock in tactic.

[–] [email protected] 8 points 6 months ago (1 children)

Proton allows you to export as eml or mbox. Seems fine to me?

load more comments (1 replies)
[–] [email protected] 4 points 6 months ago

Dang.

Some good news though:

Automatic forwarding isn't an issue IMO since I can do that at the DNS level for custom domains. However, everyone on my plan at the same domain would need to switch at the same time.

But definitely something to take into account. Hopefully it's just the immaturity of the product and will get resolved with time. Proton also didn't have IMAP when it started, and it has a workable bridge now (so bulk export is an option that way). Proton also supports encrypted email forwarding now (encryption probably only applies to internal to Proton forwards), so hopefully Tuta follows suit.

Maybe I'll switch to Proton instead, IDK. My emails aren't that valuable to me long term, so I'd be fine downloading/forwarding the few I care about manually. My primary goal here is to get off Google, and I'm willing to jump through a few hoops to do so (and Tuta is pretty good and pretty inexpensive). But that may not be true for others.

load more comments (6 replies)
[–] [email protected] 8 points 6 months ago

It’s unlikely but not impossible. I’ve been using PM with a custom domain for about five years now, and never thought too hard about leaving.

In an ideal world, a company like ProtonMail would be cooperatively owned by the workers and paying users, sort of like a credit union.

Pragmatically, they’ve done fine stewardship of the service for the last decade or so they’ve been around. A big part of it is that their value proposition depends on stability and trust. But it could be better.

[–] [email protected] 33 points 6 months ago* (last edited 6 months ago) (12 children)

Obligatory video from one of the greatest channels youtube has ever seen: By Default - There is no private email

load more comments (12 replies)
[–] [email protected] 31 points 6 months ago (1 children)

I value my privacy and have an extra $7 to blow every month.

Bleep boop, this summary has saved you 99.9%… just kidding i’m not a bot and have no idea what the article says ;-)

[–] [email protected] 6 points 6 months ago (1 children)

You're pretty close, the thing you missed is, "Google is creepy."

load more comments (1 replies)
[–] [email protected] 19 points 6 months ago (2 children)

I think it is important to understand that email never will be very secure because the standard wasn't made with modern threat models in mind, if you want to communicate privately and anonymously, you need modern protocols like signal, i also use proton but only because I hate Google, i don't expect my emails are any more private than they have ever been. I use email only when it is required, I use signal for private communication, overlap is impossible

[–] [email protected] 16 points 6 months ago (5 children)

Your emails are.more private in the same sense that if you have a letter with something on it, turning it over means someone can't read it over your shoulder, but they could have read it before it got to you.

Google has access to the contents of your inbox, Proton mail does not. But the protocols are unchanged and unencrypted email is accessible in transit.

So moving to Proton is a definite improvement, particularly as email remains a basic means of communication. But as you say if you wand secure communication then it is very flawed.

load more comments (5 replies)
load more comments (1 replies)
[–] [email protected] 12 points 6 months ago (1 children)

I recently migrated my email hosting away from proton. I paid for unlimited for almost a year, but I just couldn't take the missing features anymore. Maybe some of the missing features can be justified by security reasons, but some is just laughable.

If you want to use a proper email client, you need to host proton bridge in your local computer. You can only host imap and SMTP on localhost. Headless is not really supported, so good luck if you want your server to email you logs. Use VMs or docker containers? Fuck you.

On android, the only option is using their crappy mail client. For example, this client has not functionality to select all Mail from a folder if you want to archive it or mark as read. You have to select every single Mail one at a time.

Proton drive can only be used over the Webinterface or with some windows (gui) client. No automating your backups to be pushed there.

I switched to mailbox.org, which has weird 2fa but besides that makes my happy by just working with the damn standards. Not like email transfer is unencrypted when using STARTLS. Security is important, but for me personally, usuability has to be at least good enough.

load more comments (1 replies)
[–] [email protected] 11 points 6 months ago (4 children)

I have been exploring self hosting my email.

Docker mail server for backend. Roundcube for web ui

Still keeping accounts at mainstream providers though as backup, especially for outgoing mail.

[–] [email protected] 15 points 6 months ago (2 children)

You can just use a custom domain at Tuta, Proton, or any of the other email providers until you decide to self-host. Honestly, I don't think self-hosting is worth it, I value the spam filtering and uptime that major providers offer.

load more comments (2 replies)
[–] [email protected] 10 points 6 months ago

Register a domain, Postfix, spamassassin, freebsd jails... Do it like we did in the early 2000s, it never got better

[–] [email protected] 6 points 6 months ago

Don’t.

Not only is it not worth the hassle most home ISPs block port 25 to avoid compromised computers sending out spam.

[–] [email protected] 4 points 6 months ago

Friends don't let friends selfhost email.

[–] [email protected] 8 points 6 months ago

Some services don't send verification letters to Proton and it's site banned by the address in fucked-up authoritarian countries, both for having less control over what it is and easy registration. I want them to explore some multi-site hydra approach so they can't get put out of the game that easily. Moving your emails here means you can't rely on a hope it would work tomorrow.

[–] [email protected] 8 points 6 months ago* (last edited 6 months ago) (1 children)

Didn’t know google did shady things with our mail, but yea I shouldn’t be surprised

[–] [email protected] 5 points 6 months ago (1 children)
load more comments (1 replies)
[–] [email protected] 8 points 6 months ago (5 children)

Moving email seems like such a PITA, I don't think I would move unless to self hosting.

[–] [email protected] 32 points 6 months ago (2 children)

Self hosting email is even more of a pain.

[–] [email protected] 6 points 6 months ago

Good lord yes

load more comments (1 replies)
[–] [email protected] 12 points 6 months ago (3 children)

Move it to a custom domain and host it at Proton or Tuta. That way it's a pain once, and then you don't have to switch email addresses ever again.

load more comments (3 replies)
[–] [email protected] 6 points 6 months ago* (last edited 6 months ago) (1 children)

Yes, a royal pain in the ass. However. I did it recently but the way I did it means any future moves, of all my 300+ websites that I have logins for, is now done in seconds.

I signed up for SimpleLogin and a custom domain. I then went around creating aliases for all these sites. Changing the sites is indeed the worst part. Still, this is the last time I will ever do it. All my aliases were pointing to my Gmail account. Once I'd finished I settled on Proton. I just moved all my aliases to my Proton email address.

No one knows my Proton email address other than SimpleLogin.

I haven't yet, but I can now ditch Gmail. I still keep the account for a number of reasons but none are for emails.

I've also been testing Tutamail. I can get aliases to go to multiple mailboxes. I have the ability to respond to the emails from either Tuta or Proton and the recipient is none the wiser of where my mailbox resides.

load more comments (1 replies)
[–] [email protected] 5 points 6 months ago (1 children)

It certainly can be a bit involved. When I moved from Gmail address to my own personal domain I did it slowly over a few months.

I set my Gmail address to automatically forward to my new email address. Then I setup a quick filter which added a label on everything that had been forwarded. Once a week or so I would look at all the emails that had been forwarded and update them to my new email (or delete them if unwanted).

load more comments (1 replies)
load more comments (1 replies)
load more comments
view more: next ›