Live data from Hacker News

The Future of Email

fastmail.com

101–110 of 217 posts

Re: The Future of Email

#101

I find it hard to judge how much, if at all, this will help, but I'm all for email being more secure, to the point that organizations (banks, governments, insurance companies) stop creating walled-email alternatives: please log in to our secure message center, where you can only see our messages poorly formatted, and for a short time, until we permanently delete them . I like that my Inbox is a somewhat-searchable, h…

Those "message centers" aren't just about security, they're also about compliance. For example, insurance companies need to be HIPAA-compliant which requires that they can only send health-related info to other HIPAA-compliant systems, which means signing a BAA (a contract) with those other systems. There's no way to do that with email (your insurance company can't sign a contract with every potential email host in t…

Somehow they mail letters with info.

Encrypted email wouldn’t require a BAA.

Re: The Future of Email

#102
post #34

Earlier quoted context omitted.

> Basically you should pre-authorize the senders This is kinda what 'masked email' services like Fastmail's – of which I am a delighted customer – do. Until you've known the comfort of creating an address; giving it to a service; deciding that you want to end your relationship with them; just deleting that address, without changing your mailbox or infrastructure or archives or anything else … it's kinda life changing…

I like per recipient emails, but I worried how I would know I authorized that sender to send to lonely chicken. The original site could have been compromised. That's why I bought my email domain and use @hnrobert42.com. It helps to use a password manager. I get a lot of convincing emails to linkedin@hnrobert42.com. As well as zynga, wework, etc.

I do something similar with prepend.com and find it helpful for sorting. Also fun to see which domains sell my email and which dont (blacksocks.com hasn’t show up from anyone else in 20 years).

Re: The Future of Email

#103

It's insane that in 2026 signing and encryption of emails still isn't the norm, but as long as the business model of the largest email vendors rely on us not having it, I guess we never will.

None of the big providers want that. Otherwise Microsoft had more difficult to share the Outlook data for 1000 partners.

Re: The Future of Email

#104
post #34

Earlier quoted context omitted.

> Basically you should pre-authorize the senders This is kinda what 'masked email' services like Fastmail's – of which I am a delighted customer – do. Until you've known the comfort of creating an address; giving it to a service; deciding that you want to end your relationship with them; just deleting that address, without changing your mailbox or infrastructure or archives or anything else … it's kinda life changing…

Apple’s Hide My Email does the same thing and it’s just phenomenal.

Apple is a problematic email service provider. They don't even send DMARC reports.

Re: The Future of Email

#105
post #79

Earlier quoted context omitted.

I like per recipient emails, but I worried how I would know I authorized that sender to send to lonely chicken. The original site could have been compromised. That's why I bought my email domain and use @hnrobert42.com. It helps to use a password manager. I get a lot of convincing emails to linkedin@hnrobert42.com. As well as zynga, wework, etc.

> That's why I bought my email domain and use @hnrobert42.com. It helps to use a password manager. Whenever there’s this discussion on HN, someone usually points out that can sometimes be a bother, especially when giving out the email in person, because people don’t really understand how email addresses works and ask “how did you get that email” or think you’re impersonating the service, or something similar. I guess…

And some sites seem to have it not work. I suspect there’s lazy programmers with hardcoded test cases.

But that’s like 1:100 or so. And usually I’m entering my address to a robot so it’s not an issue.

Re: The Future of Email

#106
post #73

I love fastmail, I switched from Proton a couple years ago after deciding the trade offs to have encrypted email were not worth it, since even if I fully trust Proton, most emails come from or go to AWS, Outlook, or Gmail anyway. I have been extremely happy with the service. Fairly priced, very fast even with a huge inbox, and they don’t add unnecessary features or bloat. I thought I would use my OS’s mail apps but t…

What were the tradeoffs with Proton?

For me it was search. The proton apps are the only way to access email on mobile, and on them and on their webapp the search barely functioned, even with full text search downloaded. The only way to reliably search my email was with Proton Mail Bridge on desktop, but for some reason it continuously was using CPU on my laptop and of course didn’t work on mobile. If they made a server version that I could put in a docker container on my server it would probably solve most of my problems with Proton, because then I could access it from the Mail app on my phone over IMAP.

Re: The Future of Email

#107

I find it hard to judge how much, if at all, this will help, but I'm all for email being more secure, to the point that organizations (banks, governments, insurance companies) stop creating walled-email alternatives: please log in to our secure message center, where you can only see our messages poorly formatted, and for a short time, until we permanently delete them . I like that my Inbox is a somewhat-searchable, h…

Those "message centers" aren't just about security, they're also about compliance. For example, insurance companies need to be HIPAA-compliant which requires that they can only send health-related info to other HIPAA-compliant systems, which means signing a BAA (a contract) with those other systems. There's no way to do that with email (your insurance company can't sign a contract with every potential email host in t…

I think a lot of the HIPAA compliance can be signed away when you authorize them to send your medical information over email/voicemail/sms, but I'm not a lawyer, and my doctor doesn't email me anything but a link to log in to their EPIC portal.

Re: The Future of Email

#109
post #33

Earlier quoted context omitted.

The gp isn't talking about spam using "secure message" as bait to open unwanted email. Instead, legitimate companies like banks, healthcare, etc tell users to click on a url link to their "Secure Message Center" to read or submit some critical information. It's often the only way to get the info the users need. E.g. if I open a payment dispute with the bank, the workflow they use is the Secure Message area. I can't j…

> The gp isn't talking about spam using "secure message" as bait to open unwanted email. No, this includes all messages from my doctor/healthcare. It's not mass spam. Theoretically I could want to know what's in the message, but not enough to visit a website I've been logged out of again, perform multi-factor authentication, navigate to the message center and find the message and then back it up manually.

> No, this includes all messages from my doctor/healthcare

Then IMO they accept the responsibility of me seeing the message potentially much later than if they had stated the concern up front in e-mail.

Re: The Future of Email

#110

Earlier quoted context omitted.

Those "message centers" aren't just about security, they're also about compliance. For example, insurance companies need to be HIPAA-compliant which requires that they can only send health-related info to other HIPAA-compliant systems, which means signing a BAA (a contract) with those other systems. There's no way to do that with email (your insurance company can't sign a contract with every potential email host in t…

Somehow they mail letters with info. Encrypted email wouldn’t require a BAA.

Dollar bills are essentially untracked, good everywhere, secure, work no matter what. Same goes for normal mail, and it's a federal offense to tamper with it.

Nothing electronic will ever be secure, unless it is never, ever networked. Networking changes "touch physical thing" into "everyone on the planet plus their bots" can touch it.

Even if you pass harsh laws, you need to geogate network connections to only within that legal jurisdiction. Otherwise, it's pointless.

The real, true problem is anonymousness. I used to advocate for, now I'm done. The problems anonymity solve, are a gnat compared to the ones it creates.

I'm all for ipv8, but with a unique ID in the packet identifying the person directly.

I can't drive a car, own a gun, drive a boat, buy explosives, ply many trades, and 100 other things without a license. Maybe unrestricted internet access is in that category, and bad behaviour means it is revoked.

The Internet was a toy for a long time. Now it's the backbone of all commerce, industry, personal communication, with life threatening implications at times.

Play time is over.

Post reply on HN