← Back to context

Comment by jorvi

16 hours ago

As Fastmail themselves have pointed out many times, e-mail is inherently a multi-party activity with both parties holding a copy of the e-mails. Aside from the microscopic amount of people GPGing their e-mail and sending it over good servers, your e-mail is as private as the other party treats it. Which isn't very much. And you can't do anything about that.

You want private and / or anonymous communications? Don't use e-mail.

I want some sort of hybrid paid for by my fastmail sub. Something like a first party gpg on the happy path for anyone who uses fastmail and a wasm/whatever (if possible) web app link for keen buy not willing to pay email recipients.

I.e. my friends who are willing to share keys now and then but not actually pay for the service.

Otherwise I'm stuck with signal asking for donations forever / waiting for something to actually replace email.

Fair point, but my desire is for "good enough" rather than perfect. I know my emails go into other systems, it's more about feeling that my inbox is hosted by a company solely based in a jurisdiction where it can't be compelled to do anything by the US government. It's also a matter of principle - I want to move as much of my infrastructure as I can away from US-based services because I don't trust things not to get worse there.

The bigger issue isn't a privacy one, it's a security one. For many people, if you can get access to their email box, you can account-reset your way into any other account they own. So if an authoritarian state compromises your account (because they control the servers), there goes your everything

  • A lot of people seem to ignore this point when it comes to Proton’s E2EE of emails at rest. It wasn’t even a year ago when the US government subpoenaed a Pennsylvania man’s entire Gmail inbox because he wrote a letter to a DHS attorney. This wouldn’t happen with Proton. It would definitely happen with Fastmail.

    • wow, hadn't heard about this until now. article: https://archive.is/J9Ant

      correction that it says:

      > The investigators who questioned Jon told him Homeland Security couldn’t obtain his emails, documents, photos or other content with an administrative subpoena, he said, but the breadth of what federal investigators did ask for shook him.

      > Among their demands, which they wanted dating back to Sept. 1: the day, time and duration of all his online sessions; every associated IP and physical address; a list of each service he used; any alternate usernames and email addresses; the date he opened his account; his credit card, driver’s license and Social Security numbers.

      However, what information the US government can or can't get from tech companies seems like a moving target.

      1 reply →