Live data from Hacker News

After self-hosting my email for twenty-three years I have thrown in the towel

cfenollosa.com

581–590 of 744 posts

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#581
I self-hosted my email during some years. My IP was banned in certain providers a few times, I guess due to neighbors. I also found quite complex to manage the service using dovecot at that time, but I guess today we have simpler servers.

However, I ended up moving away. Sadly, dealing with deny-lists and the management overhead was not worth for me. Fortunately, there are alternatives that doesn't require you to go to big providers :)

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#582

Earlier quoted context omitted.

This is pure victim-blaming. The problem is that bulletproof hosting exists, not that people are sick of spam.

I don't follow. I am pointing out that using the same kinds of lists that the big providers use will result in smaller providers being arbitrarily blocked with little recourse. Do you disagree with that assessment?

First, yes. They (the small providers) have recourse, it’s just annoying. They voluntarily signed up for that annoyance because of their ideology.

But much more importantly, that question is orthogonal to my argument. Using blocklists is a good way to cut down on spam, the fact that it might block some trivial percentage of people who for ideological reasons might or might not be on those lists isn’t the receivers problem.

You want this to not be the case? Contribute meaningfully to solving the problem in a more effective way. Don’t blame the people who just don’t want the spam.

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#583
Are the big tech email servers truly not used for spam at all? Because if they are, shouldn't they be permabanning each other as hard as they ban the little guy?

Clearly they're using different rules against each other than against small email servers, and I think that's all the evidence you need to get the EU to take action here.

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#584

Earlier quoted context omitted.

Gmail wouldn’t care at all, they know the pressure would go the other way. Racketeering doesn’t mean what you think it means.

Racketeering is when the only solution offered to you out of a problem someone created for you is to pay the person who created the problem. In the context of email: "you have to pay us to send your email because we have created a system in which only we can send email." Seems pretty close to racketeering. Anyway, telling someone they don't understand what something means is almost never a good way to start a convers…

That’s not what racketeering is. In order to be racketeering it must be extortative, fraudulent, or otherwise illegal. Your definition would make PG&E guilty of racketeering, which they are not. Selling fire insurance is also not racketeering.

When someone is using a word incorrectly making them aware of that fact is important. They’re welcome to google it.

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#585
post #536
post #485

Earlier quoted context omitted.

> The address 929@homeaffairs.gov.au, which must be used by Australian permanent residents to update their personal details You update personal details with the government via email? That's interesting. I would have assumed they would use at least a secure web form.

929 is the form. The email address is for completed copies of the form. Permanent residents are a class of non citizens who have the right to permanently reside in Australia. Most cannot vote. All of it can be done online through their portal. The Australian government spies on everyone anyway so using the portal presents no increased attack surface for anyone who would care. Really it's there as a legacy technology.…

If you used an immigration lawyer to apply for permanent residency, you can't use the portal to make those updates, because the original visa is not associated to your portal account.

So your only other option besides emailing the form, is to print it and bring it in person to an office.

I know this, because this was my situation until recently.

A few months ago I changed my PR subclass and the new application was done using the portal. Which means that I can finally use the portal to update my details.

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#586
post #225

Earlier quoted context omitted.

Unless you're doing something special, there is a big difference between sending your mail to the recipient's smtp server and relaying it through you ISP's smtp server. The difference is that if you send it direct the ISP can't read it, because it's encrypted. If you relay it, the ISP can read your mail, and even tamper with it, unless the message itself has been encrypted with something like pgp.

Your ISP can log and analyze all SMTP traffic if they want to, whether it's being processed by their mail relays or not.

I believe most SMTP servers talk SSL/TLS, so, yes, sending mail directly to an SMTP server that doesn't belong to the ISP prevent the ISP from reading the mail.

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#587
I already wrote this also in another thread. Which was not also only was suggested by me:

* implement and publish policies which emails you accept (regex/strings on domains, emails, headers, signatures and so on)

* found a association where all use this strict (which shall potentially be stricter than gmail and so on) settings and if gmail does not accept these emails, sue them for discrimination.

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#588
> We are all experiencing what happened when politicians regulated the web. I hope you are enjoying your cookie modals; browsing the web in 2022 is an absolute hell.

What would they do with email?

To be honest, I kinda like seeing a lot of cookie modals out there. Yeah, the experience can be hellish, but it highlights how many sites are actually collecting data from their users.

With that said, I wonder what alternative regulations are feasible if we don’t rely on politician-mandated regulations.

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#589
> The industry must self-establish clear rules which are harsh on spammers but give everybody a fair chance.

The author is dreaming, sadly. Why would the big email providers (corporations) change rules or do anything, when the failing system drives more people (such as the author) into their arms?

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#590

I tried to operate my own email server as well on a VPS, and I have been thinking that the way to solve these problems is to solve the problem of spam itself. Detecting spam puts the costs on the email providers... when the costs should be born by spammers. Perhaps some sort of digital stamp (digital signatures similar to stamps on physical envelopes) for each email sent paid for with micropayments in a cryptocurrenc…

Paper mail, phone calls, and text messages all cost money, and yet you get massive amounts of spam from each of those. No, putting a price on those does NOT help. What will happen is that one source of low-quality spam that will be priced out of existence will subside, and now companies with more money will be priced into the game, because they will decide that sending spam is competitive again, as there's so much less of it nowadays. So then those companies are sending you spam and there's no escape from that. What's the next step? How do you fix that? The "digital stamp" thing hasn't been thought out too far into the future.

Those are the equivalent of your banner ads and pre-roll ads. The next step is ad blocking. Since there's not a lot of companies that actually want to pay for this stuff now, there's actually not so many of them, and you can enumerate them. They'll try to randomize the text using auto-gen and eventually things like GPT-3. This might be successful. How do you protect against that?

Let's say you protected against that. The next step is ad integration. The kind of stuff SponsorBlock removes from YouTube videos. Small mentions of ads and sponsors, integrated into the content. Interaction reminders. Donation begging. SponsorBlock works well because all that stuff is public, but that might not work well for email. Are you willing to let an equivalent of SponsorBlock read your email? Would you trust it? It would require a completely new paradigm for such blocking addons, where we're sure - by means of technological assurances - that such a blocking program cannot spy on us by leaking emails back to the mothership. That's a tough one, and I have a feeling in the current browser-centric environment the effort is just so large, and the required approaches are so far from what's being done nowadays, and the payoff of satisfying a fringe mail-midroll-ad-blocking need is so small, that it simply won't be done.

What's next after that? SponsorBlock hasn't caught up widely enough to cause people to find workarounds. I don't know, but I'm sure it'll come.

Post reply on HN