Live data from Hacker News

A Hacker's Replacement for Gmail

dbpmail.net

161–170 of 218 posts

Re: A Hacker's Replacement for Gmail

#161

Earlier quoted context omitted.

FYI, last I remember, Pidgin stored your passwords in plaintext in an ASCII file on disk, unless you jumped through some hoops to integrate it with your desktop environment's keyring. They even have a article up on their site explaining why it's necessary to do this.

You can disable storing passwords. If you don’t want to have to enter a ‘master password’ when Pidgin starts up, there is no way they can store the passwords more securely than plaintext. Get full disk encryption and be happy.

That's simply not true. For example, on Windows, they can use CryptProtectData. Mac OS has a keychain function too. Pidgin devs are being disingenuous by suggesting that accessible to current user is identical to storing plaintext on disk.

Full disk encryption and per-user encryption are good steps. But an accidental backup of Pidgin will still reveal passwords that would be safe if they bothered to use platform specific APIs for such storage.

Re: A Hacker's Replacement for Gmail

#162

I'm not sure why you can't do those things on FastMail. (disclaimer: I work for FastMail) Sure we have folders rather than tags, which means you can't add multiple of them to the same message. Probably the biggest lack is that you can't manage IMAP flags via the web interface. Otherwise, our search is now very powerful (since about March this year) and allows you to build filters that show messages from multiple fold…

Happy paying FastMail customer here. Would love to see CalDav support (public and private), so I can ditch Google once and for all.

Seconded, especially with Calendar sharing with specific other people.

Re: A Hacker's Replacement for Gmail

#163
post #153

I'm not sure why you can't do those things on FastMail. (disclaimer: I work for FastMail) Sure we have folders rather than tags, which means you can't add multiple of them to the same message. Probably the biggest lack is that you can't manage IMAP flags via the web interface. Otherwise, our search is now very powerful (since about March this year) and allows you to build filters that show messages from multiple fold…

I've been using FastMail for a while and I like it a lot. Actually I love the fact that it uses folders instead of tags. The only problem I have with FastMail is that I've been receiving an increased amount of spam in my inbox.

Did you set up the advanced spam filtering and then train it on all of your folders? I also set the super-advanced options and changed the thresholds to around 3.0 (instead of the default, which was I think 5.0), which really helped. It's better than when I hosted on gmail, but I'd say 5-10 per day still get through and have to be reported, after about a month on fastmail. That's only a couple of percent, though (scanning my spam folder, I get something like 10-12 per hour, but this is an e-mail address I've had and not hidden at all since 1997).

Re: A Hacker's Replacement for Gmail

#164
I had a similar setup a couple of years ago. The main problem I had was the maintenance required. If you have any machine publicly accessible you have to be on top of security updates and proper system hardening. I gave up after my exim4 Debian system got 0-day rooted.

If doing it again I would avoid a Debian based distro. I'd probably use openbsd. And the less ports open the better.

Re: A Hacker's Replacement for Gmail

#165

Earlier quoted context omitted.

> Setting up a server in any hosting environment at this point comes with the assumption that its contents can be read at any time by the operators and whoever they let in without you ever knowing about it. Indeed. If you want to be secure, you need to keep your email server at home, or in some other location you trust, and make sure all communication on the net is encrypted. That way, if an adversary wants your secr…

There is a very good chance that an email server running on a "home" IP address block of any of the major ISPs will be blacklisted.

True. If your ISP won't remove your IP from the blacklist, you could probably use a commercial service (a la Amazon's SES) for outbound SMTP while running your MX and mailstore at home. That would have somewhat different privacy tradeoffs, but it's not that different if you expect most of your email recipients to be hosted elsewhere... I may try this.

Re: A Hacker's Replacement for Gmail

#166
post #122

Earlier quoted context omitted.

I've been looking at Kolab. They have a nice page listing their dependencies: http://www.kolab.org/community/upstream-communities All of these look fine - I already deploy all the server items - except Round Cube: does anyone know anything about them?

I've used roundcube before, both on a shared hoster and on my own server later on. It's okay, I wasn't impressed with the user interface at the time though that seems to have changed judging from their website. The software is a bunch of php and shell scripts and uses a MySQL, PostgreSQL or SQLite database.

Thanks. It doesn't sound hugely convincing. I guess people do harden PHP+shell scripts, but it sounds like work to me. eitland thinks Kolab can be run without it, at the expense of not having a webmail interface, which would be OK.

Re: A Hacker's Replacement for Gmail

#167
awesome... its time move away from proprietary, snooping services such as gmail. Hopefully setting up such a service should become easier ( may be less than 5 steps ) with better cloud VMs. Then even non-tech savvy people can have their emails away from snooping.

Re: A Hacker's Replacement for Gmail

#168
post #155
post #58

Earlier quoted context omitted.

That's a great point. Reminds of the time I taught my friend to use PGP and sent him an encrypted email. Every single time, he would reply in plain-text, thus exposing my older conversation. When asked why, he told me it's too much of a pain to do it. So my being careful about my privacy doesn't help if other people don't play along.

Can such kind of reply put your secret key in the risk? For example, it gives attacker enough information to deduce the key within reasonable time?

I don't believe so. I think the parent comment was more concerned about the message itself being sent in the clear.

Re: A Hacker's Replacement for Gmail

#169

Earlier quoted context omitted.

That's why they take memory snapshot first, which is trivial with VPS and then pick encryption keys from it to access encrypted volumes. This is well known method and works with pure hardware machines too with physical access. It's great question when you get to server, to shut it down or leave on. If on, it could destroy data, if turned off encryption keys are gone. I think it would require some individual case anal…

Isn't the pure hardware method for memory snapshots some ridiculously complex mechanism with freezing the memory and quickly transferring it to a reading device? If you're going to pull this, you need to know in advance that it's necessary, that's not some minor thing that everyone is going to just do automatically, it's an extra, complicated step it's easy to screw up. That said, I acknowledge the possibility of com…

"ridiculously complex mechanism" ... Not really. Anyone with the ability to stick a USB stick in a USB port and hit a power reset button can pull off this attack:

http://www.mcgrewsecurity.com/tools/msramdmp/

Re: A Hacker's Replacement for Gmail

#170
I did this for a long time, but it's really annoying:

1. If your provider goes down, you lose mail.

2. If you are conversing with people who are using an insecure mailer, such as gmail, Yahoo, etc (which is probably > 99.9% of all e-mail users), your e-mail is still accessible to the NSA, or to some Fortune 100 advertising company.

3. It's only a matter of time before the "big dogs" in email abuse the position and decide who is and isn't allowed to send/receive email outside of their little oligarchy, either on their own or at the behest of governments.

Like so much else that has been corrupted, we need to scratch the current architecture as too insecure, and build something truly secure for the future. This isn't in the interests of the Googles of the world, and it's actively in the worst interests of the NSA/FBI/CIA, so it's probably the right thing to do.

Post reply on HN