Live data from Hacker News

Modern email can be built from borrowed parts

en.andros.dev

141–150 of 165 posts

Re: Modern email can be built from borrowed parts

#141
post #117

Earlier quoted context omitted.

Tightly coupling identity to cryptosystems should be entirely dismissed for anything that is supposed to have broad adoption. First off, these systems always require indefinitely-lived secrets. To rotate keys (or the whole cryptosystem—think future possible quantum computers) is to change identity. Therefore, to change keys is to break the previous identity. Anything that requires users to think about long-term secre…

We need more and more varied DNS zones so there's competition between them. And not gTLDs which are just extensions of .us, but zones with genuinely independent administration.

Agreed. DNS is, afaik, the very best naming system we've got. But there's plenty left to do to make it better for human beings. Legally encoded rights to DNS names paired with easy-to-use GUIs for non-technical users would be near the top of my list.

And greater zone diversity like you say too. Kinda related to that, something like increased pinning of non-root DNSSEC keys so that the root isn't so all-powerful.

Re: Modern email can be built from borrowed parts

#142
post #141

Earlier quoted context omitted.

We need more and more varied DNS zones so there's competition between them. And not gTLDs which are just extensions of .us, but zones with genuinely independent administration.

Agreed. DNS is, afaik, the very best naming system we've got. But there's plenty left to do to make it better for human beings. Legally encoded rights to DNS names paired with easy-to-use GUIs for non-technical users would be near the top of my list. And greater zone diversity like you say too. Kinda related to that, something like increased pinning of non-root DNSSEC keys so that the root isn't so all-powerful.

[deleted]

Re: Modern email can be built from borrowed parts

#143
post #117

Here is another, not so new, idea: Username is your public key, password is your private key. So we get end to end encryption and account ownership out of the box. Something similar to how .onion addresses work. Needing easy to remember addresses? Build aliases on top of that. Needing server-side automation? Handle trusted server your private key. Also, almost everyone carry a 24/7 powered and Internet connected devi…

Tightly coupling identity to cryptosystems should be entirely dismissed for anything that is supposed to have broad adoption. First off, these systems always require indefinitely-lived secrets. To rotate keys (or the whole cryptosystem—think future possible quantum computers) is to change identity. Therefore, to change keys is to break the previous identity. Anything that requires users to think about long-term secre…

Edit: s/economics/ergonomics/

Re: Modern email can be built from borrowed parts

#144

Earlier quoted context omitted.

Yes, but I want the rate to be variable depending on volume. I want it to be $0.0001 for a simple personal email. But if you send 10,000 emails today, I want it to cost you $100 (or more). Many schemes to do this. Things like: The first 10 emails is $0.0001 each. The next 10 will be $0.001 each. And so on. You can always fiddle with the thresholds and costs.

I'm 10000 people sending 1 message each, to get the cheap cost for every message.

You're forgetting the 5 cent charge per recipient who hasn't put you in their approved list.

Re: Modern email can be built from borrowed parts

#145
post #138

Earlier quoted context omitted.

That was on mobile. If that's intent, the result is highly aggravating.

I think you're focusing too much on your best practices paradigm and not enough on my design vision.

Or perhaps the opposite is true.

The content is solid. The presentation very much Gets In The Way.

Re: Modern email can be built from borrowed parts

#146

Earlier quoted context omitted.

Email currently uses an HTTP request to https://mta-sts. /.well-known/mta-sts.txt, per RFC 8461. Depending on HTTPS/TLS instead of DNSSEC is one major reason you see this approach gaining popularity.

To be fair, it’s used by only those who choose to use horrendous “mta-sts” instead of DNS-based Authentication of Named Entities (DANE). I might add that if you want to enforce SMTP TLS, you can do just that without mta-sts or DANE.

Typically you don't want to require authenticated encryption for all outgoing email as many mail servers use certificates that are self-signed or otherwise appear invalid. It isn't as simple as it seems and isn't generally recommended.

What concerns do you have with MTA-STS?

Re: Modern email can be built from borrowed parts

#147

Earlier quoted context omitted.

To be fair, it’s used by only those who choose to use horrendous “mta-sts” instead of DNS-based Authentication of Named Entities (DANE). I might add that if you want to enforce SMTP TLS, you can do just that without mta-sts or DANE.

So, basically everybody? DANE has virtually no uptake. I think it might literally just be Microsoft at this point?

When I checked in 2024 (https://alexsci.com/blog/is-email-confidential-in-transit-ye...), Cloudflare had more domains using DANE than Microsoft. But you're right, DANE is not widely adopted. Lack of support by Google is most notable due to the large number of domains using their service.

Re: Modern email can be built from borrowed parts

#148

Self-ejecting panels on three sides of the website are a horrible user experience. Other than that... The most important thing is not the protocol, it's the gui. At the moment email's gui is horrible on all platforms without exception. If/when a decent gui appears, protocols will follow. Also, JMAP did reading can probably be just WebDAV?

Can you provide more feedback? What do you hate so much about current GUIs? (Working in this exact space)

None of them have good (or any) support for managesieve.

Without managesieve (or some other autotagging mechanism), email is just a big pile of junk.

Even Gmail doesn't support editing filters on the mobile app. It's ludicrous in 2026. And their filters are strictly weaker than Sieve.

None of them have a feature to "quickly generate a filter rule from a message".

None of them have a way to generate a forum-like interface from a mailing list more or less automatically.

None of them (except deltachat, I think), support displaying messages linearly, one below another, rather than one at a time.

One at a time is also important. When I'm writing to my boss, I am writing a message as if it is a document. But when I'm writing to my girlfriend, I often want it to a be a one-line response.

Overquotting is badly managed. Gmail hides the previous message under a button, which is super slow, but most of the time overquotting is not even needed. There should be a button to "not quote" and "strip quotes automatically".

Re: Modern email can be built from borrowed parts

#149

Self-ejecting panels on three sides of the website are a horrible user experience. Other than that... The most important thing is not the protocol, it's the gui. At the moment email's gui is horrible on all platforms without exception. If/when a decent gui appears, protocols will follow. Also, JMAP did reading can probably be just WebDAV?

> At the moment email's gui is horrible on all platforms without exception. This is obviously a matter of opinion. Of course there are endless different email GUIs, on all the platforms; if you don't like one, there are many alternatives. I cannot imagine that a "decent GUI" by modern web-development standards could be anything I'd prefer to what already exists. Email works and generally doesn't let designer ego get…

Which email gui supports managesieve?

Re: Modern email can be built from borrowed parts

#150
post #21

Self-ejecting panels on three sides of the website are a horrible user experience. Other than that... The most important thing is not the protocol, it's the gui. At the moment email's gui is horrible on all platforms without exception. If/when a decent gui appears, protocols will follow. Also, JMAP did reading can probably be just WebDAV?

Why do you find the panel experience so bad?

They flicker in front of my eyes, distract me from reading, and are easy to misclick.

Generally, there is zero reasons to add moving elements to a page.

Post reply on HN