Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Right, so now all of my email can go through some third party's systems. That's exactly what we need in a post-Snowden world.


Not only that, but one of the partners here (Dropbox) has, calling the shots on their board, a notorious war criminal and warrantless wiretapping apologist, one Condoleeza Rice.

If you use this service, and if you don't think your mails are winding up in plain text in an NSA datacenter somewhere, you're a damn fool.


It's on GitHub, you can self-host it if you wanted to. It's not a service yet.


Self-hosting your e-mail is really not much better, from a security point of view, than letting gmail have your e-mail. Google has some of the best security people in the world, if your mail is safe anywhere, it's safe with Google. The problem, of course, is that Google is definitely going to try to read your mail, use and retain your private data indefinitely.

The problem is that if you host your own e-mail server, you dramatically increase the chances of some unpatched flaw or tiny messed up configuration file causing the Russian mafia to get access to everything on your e-mail server. You probably don't even particularly decrease the risk of the NSA getting your e-mails.

This is a problem that could be fixed by new models for e-mail that utilize encryption so that you inherently don't need to trust third parties in order to make use of their services. Avoiding third parties entirely is very likely impractical and unwise.


I've seen this argument before, and, while it's true to some extent, it seems like FUD to me. The same exact argument could be used for every single server you host yourself. But how many people here have an AWS machine running HTTP and SSH?

How many of them have been compromised by the Russian mafia?

People are so scared of email, and I just don't understand it.


Depends on the threat. If you host your own email, there is a whole class of legal intrusion (persuasive cops, warrants, national security letters) that you get to hear about if they want your archives or stuff that's encrypted on the wire. The same applies to corrupting employees; I'm going to know if somebody bribes my sysadmin for access, because that's me.

There's also some benefit in avoiding being part of a monoculture. Big mail providers are an enormously interesting target for both spies and criminals. Breaking into random quirky personal servers, though, has a very different cost/benefit ratio.


I heartily agree about avoiding being part of a monoculture, there are definite tradeoffs. The weirder your setup, the less likely you are to be swept up in anything bulk, but the more vulnerable you are to anything targeted. Unfortunately, it's pretty common for some quirky little open-source project to start out relying on obscurity, then become widely adopted, putting you in the absolute worst case scenario, since suddenly you're running high profile software that's never been "battle tested".


I disagree. Google has no protection against NSLs.

Check out sovereign on github: https://github.com/al3x/sovereign


Correct that Google has no protection against NSLs, but that's like saying that you should always drive your car because planes are common targets for terrorism. I'm deeply troubled by the activities of the NSA et al, but realistically you are far, far more likely to be targeted for actual harm by malicious hackers than by the NSA. Even if you are targeted by the NSA, there's a better than average chance that they'll be able to get the data you care about anyway - consider how often you send an e-mail to something that doesn't end up on a server that's vulnerable to NSLs - they can compromise you on either end of the conversation, and that's not even considering the fact that governments are out there buying zero day exploits on the open market.

My point is that taking an inherently insecure (at least with respect to data privacy) protocol like the ones we use for e-mail now and putting it on your own server (and thus taking responsibility for patching, avoiding zero days, etc) is not an answer to the problem of data privacy. The way forward in my opinion is the development of communication protocols which by their very nature are trustless. If you're just interested in protecting content, then if you're using end-to-end encryption, you could use LegitimateBankSiteNumberOne.ru as your e-mail provider and it wouldn't matter. The protocols for doing this are already well-known, it's just a matter of adopting them.


I believe he was looking from the view point of an end user, not the developer integrating with Inbox. To be honest his reaction was exactly the same as mine - I wouldn't really want to use any service that uses Inbox, because now all my email has been synchronized to some other third-party service.


Because self-hosting a mail service is totally something my mom can do...

(As the sibling comment notes, I'm talking from the perspective of the end user, not that of a technologist. We need to remember who we're ultimately building these things for...)


So your theoretical (straw man) user cares enough to not want their email in the hands of a third party service provider, but is unwilling to run their own service? Maybe this user should deliver their messages by hand directly to the recipient, because their demands are unrealistic.

Self-hosted services are a significant step forward from the corporate trap of the 2000s. Offering paid hosting plans is the most logical, sustainable revenue source for the companies writing this software.


You consider both third party hosting and self hosting to unacceptable?


No, I consider anything where step N involves "go to Github..." a non-starter for anyone who's not already a technologist. Self-hosted is great — in the world Snowden has demonstrated we live in, it's probably the best solution — but it needs to be turn-key, "plug it in and enter a username/password and you're done" level of effort, or it will never become widely used.


It's open source, so someone could easily build a simple installer.


I imagine statements like yours are why Google has the user base it does.

[Sscene. PM_Tech has phoned his truck driver father]

"*Yes Dad; just build a simple installer to get an email address. An email address...it's like a phone number but letters instead. You know...so the cable company can message you. Well I suppose you could just call them...I don't know, it might take a while to build. You will have to learn programming for a start. I know you are 56. Yes, it will cut into your time for watching sports. I know I am "good" at that "computer stuff" but some guy on HN said this is how you should get an email because he knows how to do it...OK. I will be round for the game. Love to mum."

FYI Any service I have to use that starts with going to GitHUb will be ignored unless

[a] I am trying to learn something from it [b] It is 2048.


I guess the only other option is second-party hosting.


Your mum likely doesn't have the need to connect multiple email endpoints through a single API either , your mum is not the intended audience of this product as it stands.


Excuse my ignorance - how is your email not going through a third party system the minute you email someone?

Are you emailing yourself on a self hosted, air-gapped system?

If you email me for instance, Google has your email shrug.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: