Live data from Hacker News

The Future of Email

fastmail.com

141–150 of 217 posts

Re: The Future of Email

#141
Counter Point: Until people can migrate their inboxes and steer them to any provider, none of this authentication business seems to hold up actual value at scale.

If anyone can port their phone number, they should be in theory, allowed to port their email addresses as well.

None of the authentication systems here are helpful enough to allow this. You need a valid way to authenticate people irrespective of whatever provider they are on (not their email domain name)

That means that a standard needs to evolve that allows you sign on the behalf of the hosting provider itself.

Re: The Future of Email

#142

Earlier quoted context omitted.

Somehow they mail letters with info. Encrypted email wouldn’t require a BAA.

I'm not a lawyer, but I'm currently working on getting my company HIPAA-compliant, so I know more than the average person about this. My understanding is that there's a thing called the "conduit exception" which basically says that if data is transiently passing through a channel and it's not being looked at, it's ok. But wherever the data lands must be HIPAA-compliant. This seems crazy to me, but that's how it works…

> My understanding is that there's a thing called the "conduit exception" which basically says that if data is transiently passing through a channel and it's not being looked at, it's ok. But wherever the data lands must be HIPAA-compliant.

Sounds like they needed fax to be compliant, and came up with some moon logic to make that happen.

Re: The Future of Email

#143
post #113

I read this article and was surprised when I reached the end because the whole thing felt like it was setting the stage for some announcement or new thing. But nothing came..? Forgive me if I'm being thick but what was the takeaway?

Agree. I was waiting for the other foot to drop and then..."email's not going away."

Genuinely curious. Why is it posted and being upvoted here?

Re: The Future of Email

#144
post #117

What's the point of this article? The most I got was "email is here to stay," followed by some discussion of an MCP server for their proprietary mail platform. I particularly don't understand the constant fanfare around discussions of SPF/DKIM/DMARC. They're widely understood, published RFCs that have been around for at least 10-15 years, some of them longer. They're not obscure folk wisdom passed down through genera…

> They're widely understood I'll tell you right now, I've had multiple cases where I've had to quote parts of the RFCs to large companies because they were handling email authentication incorrectly. They are wildly misunderstood. The moment I see "add this include: directive to your SPF record" in some marketing platform's integration documentation I know they're going to fuck something up. To add-on, the really pro…

I wouldn't recommend for your own mental stability to look at /r/sysadmin when it comes to any sort of DNS or E-Mail issues. It really shows just how many bad systems administrators there are out there, who do not have a basic understanding of the systems they're using.

Re: The Future of Email

#145

Earlier quoted context omitted.

Those "message centers" aren't just about security, they're also about compliance. For example, insurance companies need to be HIPAA-compliant which requires that they can only send health-related info to other HIPAA-compliant systems, which means signing a BAA (a contract) with those other systems. There's no way to do that with email (your insurance company can't sign a contract with every potential email host in t…

Somehow they mail letters with info. Encrypted email wouldn’t require a BAA.

The post office is heavily regulated not to open your letters with severe criminal penalties if they do. An attacker also can't quietly X-ray your letter in transit to get a sneaky copy.

Re: The Future of Email

#146

What's the point of this article? The most I got was "email is here to stay," followed by some discussion of an MCP server for their proprietary mail platform. I particularly don't understand the constant fanfare around discussions of SPF/DKIM/DMARC. They're widely understood, published RFCs that have been around for at least 10-15 years, some of them longer. They're not obscure folk wisdom passed down through genera…

I was going to say the same thing. I only saw two things that are sort of about the future and not the past: - BIMI (I hadn't heard of that before) which seems like a very minor thing to be calling "the future of email" - AI might be easier to trick that humans On that second point, here's the exact text: > A person reading a suspicious email might notice that the sender’s domain has an extra character, or that somet…

Lookalike domains are a problem but in my opinion the bigger problem is when attackers figure out how to hijack a real domain.

For example, making a company named "there's a problem with your account call this number" on a site like PayPal and getting it to generate emails. They'll be from actual paypal.com and pass all authentication.

The other issue I'll often see is subdomain takeovers. Company makes a subdomain a CNAME to some other, external domain. Usually with the intention of hosting a webpage externally or whatever.

That other domain expires, but the CNAME doesn't. Somebody buys up the external domain, now they can publish SPF records and pass DMARC relaxed alignment on the organizational domain.

Now you can send all the emails you want with literally anything you'd like and the providers will say "yep, this passed DMARC."

Re: The Future of Email

#147
post #110

Earlier quoted context omitted.

Somehow they mail letters with info. Encrypted email wouldn’t require a BAA.

Dollar bills are essentially untracked, good everywhere, secure, work no matter what. Same goes for normal mail, and it's a federal offense to tamper with it. Nothing electronic will ever be secure, unless it is never, ever networked. Networking changes "touch physical thing" into "everyone on the planet plus their bots" can touch it. Even if you pass harsh laws, you need to geogate network connections to only within…

Botnet operator says "Hey I'll pay you $1000 to use your connection for a month."

Re: The Future of Email

#148
As a Fastmail user for both personal use, as well as for my business, the best thing I can say about them is that I haven't thought about them in...a decade?

We built a Discord integration so that new emails to our support address would ping us in a Discord channel using the JMAP API. It's only failed to work once that I can recall - and that ultimately ending up being on Discord - not Fastmail.

Just rock solid service all around with no bullshit.

Re: The Future of Email

#149

Earlier quoted context omitted.

Those "message centers" aren't just about security, they're also about compliance. For example, insurance companies need to be HIPAA-compliant which requires that they can only send health-related info to other HIPAA-compliant systems, which means signing a BAA (a contract) with those other systems. There's no way to do that with email (your insurance company can't sign a contract with every potential email host in t…

Somehow they mail letters with info. Encrypted email wouldn’t require a BAA.

They also send faxes to providers as well. It's kind of ridiculous when you think of it.

Re: The Future of Email

#150

Earlier quoted context omitted.

I'm not a lawyer, but I'm currently working on getting my company HIPAA-compliant, so I know more than the average person about this. My understanding is that there's a thing called the "conduit exception" which basically says that if data is transiently passing through a channel and it's not being looked at, it's ok. But wherever the data lands must be HIPAA-compliant. This seems crazy to me, but that's how it works…

Honestly, I think it's just because it's a crime to open someone else's mail. For whatever reason that sort of policy isn't extended to encrypted data in the cloud. It was a law written in the 90s, it should be updated and modernized.

Same goes for phones (and by extention, fax). Since wire tapping is already illegal, it doesn't need to be secure (at least going by the law).

I agree the laws need an update. I'd imagine a general 'common communication channels' or whatever would work, rather than specifing every single one that's allowed to be used. That way, it's still illegal to snoop on your communications, regardless of whether they happen by post, phone, email, SMS, Whatsapp, or whatever else we end up using in 20 years.

Post reply on HN