Earlier quoted context omitted.
> A “friend request” mechanism is one way of achieving this. But then you’re left dealing with spam “friend requests”, which is still something I have to take action on, filter out, or ignore — same as spam email.
Having a trustworthy inbox that contains only legitimate email and a separate friend request queue where you can decide “do I know this person / organisation?” is far better than having a single inbox that’s a vast ocean of emails of unknown provenance you have to make a trust decision for for every single email.
The Future of Email
151–160 of 217 posts
Re: The Future of Email
#152In 1993, a friend of mine was working at Apple. I wanted to send him a funny message with a spoofed sender. I just typed "telnet apple.com 25" and then typed in the required commands. Apple.com accepted it and delivered it to my friend with a fake sender. Those were the days, lol!
Re: The Future of Email
#153I don't quite buy this in either direction (although they are both couched as possibilities, which makes it a pretty safe statement). Humans might notice, but years of annual mandated phishing trainings has led me to believe that humans as a whole are generally not great at noticing.
AI agents OTOH mostly do as they are prompted. If the human prompting them tells them to check these things, they will likely check much more consistently than any human. If the prompt doesn't say to check, the agent won't. But that again falls back to what the human might or might not think about.
Re: The Future of Email
#154Earlier quoted context omitted.
I like per recipient emails, but I worried how I would know I authorized that sender to send to lonely chicken. The original site could have been compromised. That's why I bought my email domain and use @hnrobert42.com. It helps to use a password manager. I get a lot of convincing emails to linkedin@hnrobert42.com. As well as zynga, wework, etc.
> That's why I bought my email domain and use @hnrobert42.com. It helps to use a password manager. Whenever there’s this discussion on HN, someone usually points out that can sometimes be a bother, especially when giving out the email in person, because people don’t really understand how email addresses works and ask “how did you get that email” or think you’re impersonating the service, or something similar. I guess…
It also makes it easier to pass off a fake realname! Hi I'm John Smith, jsmith@oneofmydomains-nottooobvious.com...
You can even pick a domain sound like a legitimate mail service or company, e.g. jsmith@jgs-consulting.com.or jsmith@liberty-mail.io
All domains and addresses in this comment are fictitious - overlap with real domains is coincidental.
Re: The Future of Email
#155Earlier quoted context omitted.
Of course it is possible to have E2E encryption on emails. You can have E2E encryption on everything. Just use `age` and encrypt your message with sender public key. Easy.
> Easy vbezhenar, this is your grandmother. I just got an email from you with a bunch of gobbledygook and I can't read it. /s If it were that easy, everyone would be doing it.
But even then, the sheer amount of people who'd complain and wonder what the block of base64 data was at the bottom of the e-mail, or the strange attachments I'd have (including signing other attachments) was too much to have to deal with. For the once in a million people who ever looked at key signing...
Re: The Future of Email
#156seems like pgp inside emails would solve alot of the issues around auth and confidentiality i think email is fine the way it is i dont need any more solutions that make it harder to host your own servers email is meant to be self hosted. i feel like commercial email services have their usecases but we should avoid having service providers playing with standards, as their motives might be self serving. we should keep…
Re: The Future of Email
#157Earlier quoted context omitted.
> They're widely understood I'll tell you right now, I've had multiple cases where I've had to quote parts of the RFCs to large companies because they were handling email authentication incorrectly. They are wildly misunderstood. The moment I see "add this include: directive to your SPF record" in some marketing platform's integration documentation I know they're going to fuck something up. To add-on, the really pro…
I wouldn't recommend for your own mental stability to look at /r/sysadmin when it comes to any sort of DNS or E-Mail issues. It really shows just how many bad systems administrators there are out there, who do not have a basic understanding of the systems they're using.
You'd think companies generating as much email as Atlassian would know what they're doing.
Re: The Future of Email
#158It's insane that in 2026 signing and encryption of emails still isn't the norm, but as long as the business model of the largest email vendors rely on us not having it, I guess we never will.
The model literally can't function if emails are encrypted. They have to be unencrypted for all the ML to run for the inbox to actually be useable.
Re: The Future of Email
#159That is the most evil part. Finally we will have bots talking to bots, no human in the loop.
All email problems can be solved with GPG, but that ruins Fastmail and other email services business, as they won't be able to read and analyze their users' emails. No ads, no selling user profiles to ad companies, not even teaching AI on user data. This is the kind of future of email I would like to see. Sadly, noone uses GPG and it's quite hard to teach people to do it.
Re: The Future of Email
#160I read this article and was surprised when I reached the end because the whole thing felt like it was setting the stage for some announcement or new thing. But nothing came..? Forgive me if I'm being thick but what was the takeaway?
The future of email is… the present of email!