Show HN: OpenBSD Email Service – A free-email alternative
github.com
github.com
I'm surprised how easy it is, and having fun with sieve scripts :)
Good luck with your endeavour, it is if nothing else a learning experience. But it's important to keep in mind that if email is a critical tool for you (it is for many people, ymmv), toying with it may not be the best idea.
Or whatever. I remember the feeling, not the mistake that caused it.
But, that's a guess, and I obviously can speak on GPs behalf.
Also, you should be using your own domain with Gmail (or any other provider) so you aren't tied to anyone, anyway.
Extraordinary claims require extraordinary evidence. Please provide just a single reference to this claim.
So, without any means to control it myself I'm now in the mercy of fastmail support unless I set up my own postfix/dovecot in the meantime. I guess it goes both ways.
I get the best of both worlds; I don't have to worry about being blocked when I send things, and if I ever have issue with gmail, I can stop using them without losing my email address.
I do something similar, but when I send an email to a person for the first time, it always ends up in the spam folder by GMail.
Taken from my smtpd.conf:
table secrets { mylogin = [email]@ziggo.nl:[pass] }
accept tagged DKIM for any relay via tls+auth://mylogin@smtp.ziggo.nl:587 auth <secrets>It kind of defeats the purpose, since now the third-party will be able to read all my outgoing emails, and have control over them.
Relaying via the ISP's mail server though (even with TLS) seems like it would disclose the message contents.
By the way, give a look at mail-in-a-box, another cool project that implements a ready to use mail server with great functionalities.
Once that single server goes down it’s suddenly the biggest issue currently keeping us from doing anything. Whether it’s because of something I did or an upstream outage doesn’t matter, I’ve still got to troubleshoot it and try to work around it.
For $5/m you could have FastMail do it for you, or for free you could have Google do it. Yes there are trade offs, but they also have more infrastructure than you do for the same price.
Email is just one of those things I would rather outsource.
However I would advise using dedicated hardware for the server instead for improved privacy. There are two possible routes:
1) Rent a cheap dedicated server such as the Kimsufi line by OVH or the Personal line by Online.net. These cost below 10€ a month.
2) Run the email service on your box at home and use the cheapest VPS you can find just to tunnel a non-dialup IP address to that box using OpenVPN. The cheap VPS usually costs less than $10 per year.
For privacy, I think user encrypted email messages provide the best option.
At home self-hosting through VPN is a good idea. It would involve maintaining hardware, which I traded for low cost VPS. With a replica backup MX, I am not married to any hosting provider, and can hop without downtime.
There's a rule in security that anyone in physical possession of your device should be assumed to have access to it. The host has the server whether physical or virtual. You're not safe from them. Trusting them is the tradeoff made for the cheap, hosted server.
" I look at dedicated box more as an upgrade from VPS."
Multiple VPS's share a physical box. A malicious VPS can look for secrets in another VPS using side channels. This isn't possible on bare metal: they have to compromise an app or get a shell first. The next concern would be endpoint security. OpenBSD covers that well. Then, there's host or peripheral firmware which is almost always a risk if a 3rd party is hosting things. Your attack surface does go down, though, when you're not sharing a box with an attacker. There's also the performance benefits.
Virtual machine are secured by the shared host. I don't really expect top security from this end. A replica backup MX enables me to safely change hosts, if they behave badly.
OpenBSD defaults are what I base my endpoint security on, and keeping this updated is super easy.
Virtual machines are not secure in mainstream implementations. The tech they use has had a lot of vulnerabilities in the past. Google and Amazon even have their own custom versions for improving security. There's also no covert/side channel analysis done on those to even know what information leaks will be found in the future. Finally, hardware-level attacks are possible if you have malicious code running that bypass VM protection. Most popular recently is Meltdown/Spectre.
There's only been a few VMM's designed for security (two examples below). Most of them probably cost five to six digits to license. The FOSS ones are alpha or beta quality without the tools a big host would want for management. The VMM's focused on rapid development of features in unsafe languages don't look anything like the ones that passed pentesting. They also have highest marketshare due to those features. So, your host serving cheap VPS's is almost certainly not using a secure VMM: they're saving money using an insecure one on insecure hardware that they're patching as vulnerabilities are publicized. Like almost everyone does with their OS's for their beneficial features. ;)
http://www.cse.psu.edu/~trj1/papers/ieee-sp-vaxvmm.pdf
https://ghs.com/products/safety_critical/integrity-do-178b.h...
For example, Vultr offers $2.5/mo servers from two locations and they are proven, to be trusted hosting company. In case your IP has a bad reputation (you can test it right after spinning an Instance), you can just shut the server down and create a new one with fresh IP.
Problem with both Kimsufi and Online.net is that if you will get a bad reputation IP it is quite hard to get a new one. I have dealt with OVH and a blacklisted IP I have got on a new server and they were expecting me to contact blacklist providers and request whitelisting, which took time and resources.
PTR records are updated from the VPS provider web interface, it takes a few seconds to activate.
https://encrypted.google.com/search?hl=en&q=how%20to%20check...
But some VPS providers allow you to have a reserved IP that you can use as your SMTP IP, keeping it independent of your server instance. I'm about to switch to vultr.com for this feature, which means cleaning another IP but hopefully the last one for a long time.
I know that for many people here DSL does not provide sufficient bandwidth to suffice as the primary home internet connection, and $60/month is pricey if you only plan on using the connection for email, especially compared to a VPS. It is much less expensive than paying for a business account with any of the other ISPs, though.
Until I did this, my deliverability, especially to GMail, was awful.
ezmlm, for example, will not let you subscribe/unsubscribe
I've been administering mail servers going back over 20 years and I wouldn't recommend it to anyone. The last 4 years or so, things have gotten a lot worse. Google and Microsoft are actively and deliberately making it harder for people to run their own mail servers.
Sure, setting up DKIM and SPF and whatnot isn't hard. But blackholing legitimate mail without any reason, without any form of notification or any possible appeal, well that's just appalling. And sure, Google & MS have tools to debug a subset of mail issues, but those don't even work unless your MTA is sending boatloads of mail to their servers.
People at Google might be the smartest under the sun, but they don’t understand email: It’s primarily a way for people to communicate with each other. In Google’s eyes it’s only a way to deliver advertising to end users.
Edited for typo
Oh no, they understand email very well. They're just arseholes who want to force "regular joe" and small business to use their services. This isn't some kind of accidental incompetence. There's no "whoops, sorry your mail isn't getting delivered, our bad!"-type situation going on. This is a deliberate strategy of making it as hard as possible for people to run their own mail servers.
Of course they hide behind the excuse that you might be a spammer. But given Google's massive resources, there's no way in hell they can't tell ham from spam.
I set up my mailserver, sent a testmail to Google, no spam or other stuff. I don't know if SPF or DKIM was even configured. (It now is of course)
And of course, not hosted at home.
If people want to create their own mail service, more power to them - this is supposed to be HACKER news!
Of course, it's more work than having Google or Fastmail do it, but so what? I'm sure a significant majority of HN readers already have a VPS and domain name of some kind. Setting aside a few hours to set up a mail server on it isn't the indentured servitude many of y'all make it out to be.
Remember that the spam filters are aiming for "deliver no spam" rather than "deliver all legitimate email, but no spam" so your new server's messages being delivered helps the bonus prospects of nobody at Google.
Sure, my grandmother isn't likely to build her own mail-server, but anyone with a spare computer, and a spare afternoon can.
If you're worried about monitoring it for operation, make sure there is at least one automated email that passes in each direction once daily. Use pingdom free to check for basic up/down. That should suffice for a personal email system. Email senders will retry for days before giving up.
I say this as someone who has been hosting his own email on his own hardware on his own ISP connection (on OpenBSD no less!) for over a decade, and have never had a delivery issue
Only if you limit your email messages to parties that also use your personal email service.
I mean, I must not know what I'm talking about, having run personal and corporate mail systems for 15 years. Must be pretty easy to get the DNS extensions which aren't used uniformly across major mail carriers right. And hey, if your ISP gets blackholed it should be pretty easy to fix, right? And you just have to set up a separate system with automated tests to alert you when your service is down so you can get it back up in a few days before the bounces start going out. And certainly maintaining your own spam filters has never been difficult, to say nothing of software upgrades, maintenance outages, security patches, offsite backups, certificate renewals, and moving hosting providers.
But, yeah. Easy.
I've never had a reputation problem, but I've been sure to test for open relay on my servers as step zero. Maybe I've been lucky over the 4 ISPs I've had, but I've always ended up with clean IPs. In any case, that would be something you'd catch during initial setup and have to deal with before sending out your first email. This may be super painful to deal with, but I don't have any experience (fortunately).
I update my server OS (openbsd) once every 6 months and use long-lived self-signed certs for STARTTLS mail delivery. Combined with DNSSEC and DANE it makes for a trustworthy setup. Certbot for any certs that are more important to have a chain of trust for.
I set up DNSSEC/DANE/DKIM/SPF once over a couple of days and have never had a problem. I don't even have any spam to filter out after having domains for decades and lots of friends and family members using it. Google sends regular reports verifying that no one is using my domains for spam campaigns (at least to gmail addresses).
There are free online services to help generate configs for, and test for the correct configuration of each part of these setups.
Removable hard drives and fsarchiver make for simple offsite backups (just store them at work). But if you don't have a good backup plan, whether you're running your own email system or not, you've got bigger problems.
I'm sure you're dealing with bigger and more sophisticated setups than my vanity domains, but I'm not talking about those. I sometimes don't touch the email side of my system for years. Once set up it just works.
And this is precisely why walled gardens are attractive. Because when you realize the work that you have to put in to make federation work you give up and go running back into your walled garden.
But please, don't get me wrong. We need more decentralized email again. But what we need even more than that is less hotmail and less gmail. I feel much better telling someone to pay some $company a small fee for email hosting than I would telling them to suck it up and embrace the pain.
OpenBSD is a fascinating project, but it is _decades_ behind the state of the art in security.
As a concrete example: my personal mail server (on a modern operating system) has its SMTP handling in a separate process from mailbox serving. If the SMTP process is compromised, and the attacker reaches uid=0, it doesn't matter -- no data from the mailboxes can be exfiltrated.
Only SMTP is broken, because mandatory access control prevents the SMTP "root" from doing anything the SMTP daemon would not ordinarily be permitted to do. The SMTP daemon is not empowered to read mailboxes, even if its uid is 0.
https://www.cvedetails.com/cve/CVE-2015-7687/
Then you compare its record to Sendmail...
OpenBSD robs you of one of the layers that is standard on every other operating system in the world: Linux, FreeBSD, Solaris, even Windows.
We use SELinux in my current place and while it's fine, things break/fail in odd ways and we're always tweaking it.
In the 6-7 years I did Windows administration, I trained a couple hundred people on ACLs and specifically how the SubInACL tool should be used -- for all but about a dozen of them who truly grokked it, that training was an ongoing process over the course of those years...
OpenBSD's advantage is in its simplicity, which ultimately is the best security. If you have a system that you can clearly reason about and design for where it might fail, you are better prepared for "when" shit happens -- because it's not "if". If your entire system is properly architected, this isn't actually an issue.
It doesn't matter that you have uid=0, you do not have the granted capabilities to do new things.
http://niels.xtdnet.nl/papers/privsep.pdf
http://www.citi.umich.edu/u/provos/ssh/privsep.html
I would have much greater confidence in an OpenBSD project that included lomac or capsicum.