Live data from Hacker News

The only safe email is text-only email

theconversation.com

111–120 of 123 posts

Re: The only safe email is text-only email

#111
post #100

Earlier quoted context omitted.

How much work would you propose is sufficient that grandma doesn't mind but spammers will be severely hampered in their sending and in a manner that doesn't require the receiver to store too much state?

Only a small amount is necessary. There is a protocol called hashcash (used by Bitcoin but generally applicable) that can be easily used with email [1]. You basically get a header like this: X-Hashcash: 0:030626:adam@cypherspace.org:6470e06d773e05a8 You can choose how much work you want to do and the recepient can specify thresholds for minimum work required. This header is all they have to store, and it's easily sto…

That does not sound terrible useful.

For one, it'll only work if both sender and receiver use it. Which means for 99.99% of mail traffic right now, it is utterly meaningless.

edit: Plus you also literally wasted everyone's time and energy.

I'd rather favor some kind of mechanism like grey-lists that don't require sender opt-in otherwise it'll be a dead technology just like GPG. (You can probably count the number of GPG emails within 1000 average mails on one hand)

Re: The only safe email is text-only email

#112
post #111

Earlier quoted context omitted.

Only a small amount is necessary. There is a protocol called hashcash (used by Bitcoin but generally applicable) that can be easily used with email [1]. You basically get a header like this: X-Hashcash: 0:030626:adam@cypherspace.org:6470e06d773e05a8 You can choose how much work you want to do and the recepient can specify thresholds for minimum work required. This header is all they have to store, and it's easily sto…

That does not sound terrible useful. For one, it'll only work if both sender and receiver use it. Which means for 99.99% of mail traffic right now, it is utterly meaningless. edit: Plus you also literally wasted everyone's time and energy. I'd rather favor some kind of mechanism like grey-lists that don't require sender opt-in otherwise it'll be a dead technology just like GPG. (You can probably count the number of G…

We make incremental change. Adoption starts slow, then some middle players pick it up, one big player grabs it and then it proliferates. I've been working on a mail client for some time and I have plans to write a mail server, and both will have first class, opt-out support for hashcash.

Re: The only safe email is text-only email

#113
post #111

Earlier quoted context omitted.

That does not sound terrible useful. For one, it'll only work if both sender and receiver use it. Which means for 99.99% of mail traffic right now, it is utterly meaningless. edit: Plus you also literally wasted everyone's time and energy. I'd rather favor some kind of mechanism like grey-lists that don't require sender opt-in otherwise it'll be a dead technology just like GPG. (You can probably count the number of G…

We make incremental change. Adoption starts slow, then some middle players pick it up, one big player grabs it and then it proliferates. I've been working on a mail client for some time and I have plans to write a mail server, and both will have first class, opt-out support for hashcash.

That sounds like a lovely pipe-dream.

I severely doubt any big player picks it up on grounds of it being cheaper and less energy intensive to simply greylist or blacklist.

Re: The only safe email is text-only email

#114
post #95

Earlier quoted context omitted.

The threat model here is phishing, not drive-by downloads. Browsers have a much greater ability to mitigate those. Also, a drive-by download email doesn't have to impersonate any particular sender, it just has to look like something that a user might want to click on.

> The threat model here is phishing, not drive-by downloads. I think you missed my point. What if it isn't a phishing attack? Or even, what if it isn't just a phishing attack? Your suggestion leaves users vulnerable by encouraging them to open suspicious looking links on the off chance it is, at most, a phishing attack. > Browsers have a much greater ability to mitigate those. Except when they don't. For what it's wo…

I don't know what you mean by "encouraging". I am taking it as a given that users cannot be reliably prevented from clicking on links in emails. The security benefit of forcing the URL to be displayed before the click is extremely minimal.

Re: The only safe email is text-only email

#115
post #62
post #56

Earlier quoted context omitted.

I feel like I'm making this comment once a week on HN but I host my own email and I haven't had any major issue so far with "big email". The main caveat is that you will have a very hard time getting your email accepted if it comes from a home connection IP range instead of some host provider but if you do have a dedicated server and follow the guidelines (SMTPS, DKIM, SPF etc...) it just works, at least in my experi…

Hosting one's own e-mail server is a totally opaque random crapshot. You may not have any trouble, but some other dude or gal will get their e-mail marked as spam without any way to tell what exactly is wrong and what to change.

If I ran an evil email monopoly, I would systematically drop all email from say _half_ of the email servers out there. This way, nobody would be able to make a case that we're abusing our monopoly position, but at the same time running an email server is hard and the internet is filled with wildly varying experience reports (which is the best FUD there is).

This way, fewer people start email servers and, therefore, fewer potential competitors grow up.

Obviously I have no way to tell whether Google really does this, but if they would, the result would look exactly like this HN thread.

I'm probably totally wrong here, but note that there is absolutely no incentive for the large email providers to try to fix this mess and make email the free distributed network it once was.

Re: The only safe email is text-only email

#116
post #77
post #72

Earlier quoted context omitted.

Many (most?) emails can be read in plain-text format even if they were written in HTML. The email often comes encoded with an "alternative" plain text version; of course you need a client that will show you that version instead. In my experience most personal email (i.e. not automated/form mails) I receive has a plain text alternative version that works fine. For emails sent by an evil client that doesn't provide a p…

> For emails sent by an evil client that doesn't provide a plain text version, you can consider a tool that attempts to convert HTML to plain text (though I don't have a suggestion for this yet). I use emacs to read my email, and w3m to render HTML email as text. It does a good job. Newer emacs includes its own web browser (eww) but I have not tried it for HTML email rendering since I'm happy with w3m. Replies always…

Mutt + Lynx does it well, too

Re: The only safe email is text-only email

#117
post #75

Earlier quoted context omitted.

First step when getting an ip for a server that will be a mail server is to check if the ip is not already blacklisted. You can always get it unlisted. After that don't start to send hundred of email by day. You need to build a reputation for your domain and ip. As the parent comment says, set up directly spf, dkim and dmarc (also arc if you can). Rspamd can help you do that. I've been running a personal mail server…

I've been running a personal mail server for twice as long with simply following those rules and my e-mail is still tagged as spam in Gmail when it's me who initiates contact (once the other party sends me an e-mail, reply or otherwise, I no longer get tagged as spam). As I said, it's totally opaque crapshot.

I'm in a similar boat. I've moved ISPs a few times throughout the years, and each move it takes a few months to finally get things settled. I'm in the US, and had the best luck for deliverability when I was on a Comcast Business account.

My current ISP, a local fiber provider, was not great getting going. Most of the IPs that they have are in at least 1 spam database, and it took a while for the ISP to reach out to the database maintainers themselves. Even then, since they're a small ISP, the IPs are still blacklisted. The ISP wasn't even a company when the IPs were added to these blacklists.

After a few months they were able to assign me an IP that wasn't in a blacklist somewhere. I still randomly have issues with the big providers though - gmail is probably the most annoying. Like dozzie, my SPF, DKIM, and DMARC setups are all valid.

Overall, I really enjoying running my own mail server. Every now and then there are a few annoyances, but it's worth it in the long run.

Re: The only safe email is text-only email

#118
post #111

Earlier quoted context omitted.

Only a small amount is necessary. There is a protocol called hashcash (used by Bitcoin but generally applicable) that can be easily used with email [1]. You basically get a header like this: X-Hashcash: 0:030626:adam@cypherspace.org:6470e06d773e05a8 You can choose how much work you want to do and the recepient can specify thresholds for minimum work required. This header is all they have to store, and it's easily sto…

That does not sound terrible useful. For one, it'll only work if both sender and receiver use it. Which means for 99.99% of mail traffic right now, it is utterly meaningless. edit: Plus you also literally wasted everyone's time and energy. I'd rather favor some kind of mechanism like grey-lists that don't require sender opt-in otherwise it'll be a dead technology just like GPG. (You can probably count the number of G…

How about sending (by email) a link to a proof-of-work-website, so the hash function can be computed in javascript/wasm in a browser?

Anyway, I agree on the waste of time+energy.

Re: The only safe email is text-only email

#119

Earlier quoted context omitted.

Over 99.5% of the email I receive is either plaintext or renders perfectly legible in plain. This suggests that a large fraction of newsletters are already plaintext. The mail client is primarily a program to display and send email. The web browser is a web browser. If the user wants safety, switching to plaintext is a very wide step forward.

> Over 99.5% of the email I receive is either plaintext or renders perfectly legible in plain. Is that representative? Where do you get email from? Did you change preferences on things like mailing lists in order to get to that percentage? Also: what kind of client do you use? iOS mail does send plain text emails as text/plain (which is fantastic) but if you look at e.g. inbox (gmail) it doesn't even allow sending pl…

I run two email addresses: one business, one personal. As you may imagine, the emails I get between the two are quite different. I'm using Thunderbird and always, when given the choice, opt for plain text email. I find Thunderbird does a very good job of rendering HTML email legible (easy to read) and functional (links work, etc).

Perhaps once a month, maybe less, I have to use the toolbar button "Show HTML Temp" to do a one-off rendering of an email as basic HTML. Almost always the same offenders.

I find it such a success that I recommend it to my customers - none of which are computer experts, and most are not what I'd call "computer savvy". A process has to meet a high bar for me to recommend something like this to my customers.

Shame that when I explain how it can help in improving one's security that a vanishingly-small number of customers take me up on the offer!

Re: The only safe email is text-only email

#120

Earlier quoted context omitted.

> Over 99.5% of the email I receive is either plaintext or renders perfectly legible in plain. Is that representative? Where do you get email from? Did you change preferences on things like mailing lists in order to get to that percentage? Also: what kind of client do you use? iOS mail does send plain text emails as text/plain (which is fantastic) but if you look at e.g. inbox (gmail) it doesn't even allow sending pl…

Emails can send in both formats for a single message, so it's possible and even likely that most mailing lists, etc. he receives send in both formats. In my experience, even most marketing e-mails are at least somewhat good about this. I'm 99% sure that Gmail will still send a plaintext e-mail inferred from your HTML content whenever you send, so it's not quite accurate to say it doesn't send in plaintext.

...and if you're PayPal or eBay, you offer the customer a choice of receiving plain text emails. Then you send them multipart emails with a blank text/plain part.

Not that this surprises me in the least :-)

Post reply on HN