If your Gmail account is lost or compromised, good luck getting any help from Google; while G Suite support is decent, free Gmail account users are basically on their own.
Ask HN: Lost $400k USD in a deleted email, how contact a Gmail engineer? https://news.ycombinator.com/item?id=14452969
Ask HN: What to do about a wrongly shut down GMail account? https://news.ycombinator.com/item?id=2033474
Another account lost in the Google void – how many are there? https://news.ycombinator.com/item?id=17745761
Professor who refused to use other genders pronouns, was banned by Google https://news.ycombinator.com/item?id=14905384
In the Etherium case, he deleted the email and wanted to get it back 2 full years later. The only way he would have recovered from this would have been to take meticulous backups (and test them regularly). I would expect any 3rd party provider to honor my wish to delete data, especially 2 years down the line (and, in fact, they are probably legally required to do so).
In the "lost in the Google void" situation, the user set up 2fa but lost all access to their 2nd factors. I don't see any reasonable recourse to this, as any "solution" Google implements would undermine the entire purpose of 2fa.
The remaining two are obvious issues with Google's service. The "gender pronoun" one is a bit odd because gender pronouns don't seem to have anything to do with the account closure (there's speculation that he was mass-reported to exploit their abuse response systems).
Not sure if it's simple but how do you intend to protect against DNS record hacks?
"How?" is not the unanswerable question for them and for that domain, that it is for you & me and you&me.com
If security is your concern and long-term search isn't, consider giving them a go. Great mobile app, too.
I mean, of course the actual transit of the email from the sender to your inbox is out of their control, but after that client-side decryption is entirely feasible.
And what is wrong with hosting in Switzerland? Switzerland has very strong privacy laws.
As you can't verify their claims, all you can do is trust. If you want end-to-end encryption you should be gpg encrypting every mail, not relying on the unverifiable word on a provider. Any provider worth its salt will know that, thus wouldn't actually advertise an insecure (as verify can't be done) system as a secure one.
- https://protonmail.com/blog/protonmail-open-source-crytograp...
- https://protonmail.com/blog/protonmail-secure-email-open-sou...
You don't have to trust any of their server code - you only have to trust that the JavaScript blob they send you is actually the same as the open source version. This is the same threat model as trusting Signal from the App store instead of side-loading it yourself.
I feel like the hate is a case of people thinking not being perfect is worse than being average or bad.
I’m not really sure if Google is more likely to fuck me over than any external actor, but it doesn’t feel right.