Live data from Hacker News

The Hostile Email Landscape

liminality.xyz

61–70 of 251 posts

Re: The Hostile Email Landscape

#61
It is simple: the more fear uncertainty and doubt the "big email providers" can cast on no using one of the big email providers the more they chase everyone into their business (when they can read it). You can go on and on how it is "technically hard to fix email" but that is a second order effect to not even trying.

Re: The Hostile Email Landscape

#62

Surprised he didn't mention third party reputation providers such at Return Path.

I'm surprised as well, since these services reinforce his point even more. In other words, good reputation = $$$.

Also, I currently use mailgun (and dabbling with mandrill on some new projects) but I'm intrigued by postmarkapp.com take on dedicated IP addresses. Apparently they won't sell dedicated IP addresses because of the time needed to warm them up, so you get a shared IP and their TOS is stricter anti-spam than other ESP's: http://blog.postmarkapp.com/post/14127210172/the-false-promi...

Re: The Hostile Email Landscape

#63
post #15

Earlier quoted context omitted.

Crossdomain web hosts are also a thing, and HTTPS works fine. (Sometimes with particularly hilarious definitions of "fine", like CloudFlare's former practice of putting dozens of customers' websites in the same certificate, via subject alternative names.) If you're worried about the fact that your mail host and web host can now impersonate each other, we can just define a new X.509 extension for "I can only be used f…

SMTP can use TLS, though, right? It doesn't _have_ to use STARTTLS? You _could_ use SNI. My concern is that it doesn't get you anywhere. phishing sites can and do get TLS/SSL certificates. The process isn't particularly difficult or labour intensive if you own the domain. As far as spam goes, so what? This only proves I'm talking to the server I intended to, not that it's a reputable and upstanding member of the serv…

What about EV itself? Currently there's no EV equivalent for individuals, but it would be a step forward.

Re: The Hostile Email Landscape

#64

Create an email network where is would cost a penny to send email. It would be payed into bitcoin wallet of folks maintaining infrastructure. Every email would be digitally signed and encrypted. Certificate with keys would connected to email address (and bitcoin wallet). Spam would die. Go build it please.

The minute you say bitcoin is the moment you cut out 99% of the population; unless it is in the background and one does not have to interact with it directly.

Other than that, I agree paying to send will reduce spam.

But also look at your postal mail box. There is arguably more spam there than in your digital inbox, and that one costs (stamps).

Re: The Hostile Email Landscape

#65
post #37
post #26

Earlier quoted context omitted.

The thing is while the Internet is all excited about bitcoin, everyone else has (kind of) stopped using e-mail for communication. It's all phone based now. E-mail is just for the things that doesn't have an app. And maybe resetting your password. Unfortunately, the "geek" age is out in favor of the startup age.

That may be the case for personal communications (well, not me, I am old school) but I don't think it the case at all for professional communications.

True, although now shared with cloud tools, at least intra-company. In some markets, like China, they use messaging for business. It's better in some ways e.g. you get a response faster.

Re: The Hostile Email Landscape

#66

Create an email network where is would cost a penny to send email. It would be payed into bitcoin wallet of folks maintaining infrastructure. Every email would be digitally signed and encrypted. Certificate with keys would connected to email address (and bitcoin wallet). Spam would die. Go build it please.

As adamrt said, this won't kill off spam. It might reduce it a bit, though.

I keep thinking instead about something that works more like a refundable bond:

To send a message to you, I have to include some amount. (I don't know how much. Not a penny, though. Maybe $10 or $100.) If you want to keep receiving messages from me afterward, you return the bond. If not, you keep the money.

And after a couple of minutes of Googling, I just found a name for schemes like this: Attention Bonds.

Re: The Hostile Email Landscape

#67
post #7

The problem is not so much the attitude of the big guys. It is that smtp is fundamentally broken. we need a better mail protocol that ensures: 1. Traffic always encrypted and content always signed 2. Guarantee that the sender is who it claims he is 3. Decorrelating the email from the domain, a lot of users are prisoners of their current provider just because the address they gave everyone ends with the provider's dom…

> Decorrelating the email from the domain, a lot of users are prisoners of their current provider just because the address they gave everyone ends with the provider's domain name, very much like it is very hard to switch bank accounts This one seems completely uninteresting in a world in which $15/year can get you your own domain name, complete with reliable email servers, IMAP, and as many email aliases as you like…

Each individual using a GUID as domain name and another GUID as username for each correspondant is probably the solution. I am not suggesting it will require some fundamental changes. But the one thing that would never work is having to ask users to mess with MX entries themselves. So it take some infrastructure change somehow.

That being said my suggestion doesn't work from a privacy point of view as the domain GUID would become a tatoo and it wouldn't take long for directories mapping GUID to real identities to appear.

Re: The Hostile Email Landscape

#68

Earlier quoted context omitted.

The email deliverability issues we have had as a legitimate business are insane. Moving to an ESP years ago has helped, but it's far from perfect. I've wondered how a small business without the tech resources could manage this. For instance, several months back some of our account holders suddenly stopped receiving important account info as well as newsletters from us. Tracked it down to a third party filtering servi…

In fairness, I've worked with a number of generally legitimate shops who've had exceptionally poor email hygiene. Sending messages in the millions to domains which have been inactive and unregistered for over a decade , for example, suggests a certain lack of diligence in bounce-tracking or list-cleaning. The emails had been initially legitimately added, but clients and/or email providers had long since gone out of b…

We're clean.

For instance, our ESP detects hard bounces and auto removes them from our lists. We also use Webhooks to update internally on unsubscribes, etc.

For transactional emails, our ESP auto-adds bounces to an outbound block list, so any future attempts to send fail. We only send those to accounts with recent activity anyway, but either way, one bounce stops future sends.

Re: The Hostile Email Landscape

#69
post #7

The problem is not so much the attitude of the big guys. It is that smtp is fundamentally broken. we need a better mail protocol that ensures: 1. Traffic always encrypted and content always signed 2. Guarantee that the sender is who it claims he is 3. Decorrelating the email from the domain, a lot of users are prisoners of their current provider just because the address they gave everyone ends with the provider's dom…

> Decorrelating the email from the domain, a lot of users are prisoners of their current provider just because the address they gave everyone ends with the provider's domain name, very much like it is very hard to switch bank accounts This one seems completely uninteresting in a world in which $15/year can get you your own domain name, complete with reliable email servers, IMAP, and as many email aliases as you like…

Anyone can sign up with a provider and become "prisoner" but not everyone knows how to get out of it. How can you even compare the complexity of someone signing up for Internet service and getting foobar@att.net for free, and then later having to somehow figure out to pay $15 to set up another domain with E-mail to replace it?

Re: The Hostile Email Landscape

#70
Just goes to show reputation isn't the end all, be all, solution to everything. It's so often championed by the Linux kernel team as a reason why the distributed model works, and it's evident that in that case it certainly does. Here though, much outcry about how you can't setup a box and instantly be as respected as established boxes that have earned rep over time. This post just comes off way too butt hurt for my taste.
Post reply on HN