Google launches AMP for email
techcrunch.com
techcrunch.com
Back when it was announced, several people brought concerns up with the supposedly open AMP project, and they were closed or locked, and the head of AMP blocked us. During that time, we found out that while AMP was supposedly "open", Google teams such as Gmail and Search would implement it however they wanted, and that no open governance would impact them at all. In essence, the idea that it was open was only so far as Google would also like you to implement whatever Google was already doing.
Your team has repeatedly refused to address criticisms of AMP from users and the community at large, and continued forward with a program that nobody wants[1]. There's still no way for someone to opt out of AMP as a whole except to use a search engine that doesn't support it, and Gmail seems to lack an AMP switch in settings, so I'm guessing you currently have no plans to let Gmail users escape it either.
[1] https://twitter.com/googleampsucks - Endless retweets of people's thoughts on AMP.
... Microsoft and Yahoo think it's a good idea and want to support it. There's no particular reason email needs to sit around in the gutter while the rest of the web gets more multimedia and more performant.
Email is not part of the web, and more multimedia and more round trips is not more performant, it's the opposite.
Content-Type: text/html seems to disagree with your assertion.
The output from man -H is not part of the web, no matter what its mime type is.
HTML is not the same as the web.
Tables are pretty much the only cross-platform/client way to format email.
But then email is one large unsanitized input that has so many rules to be applied, what could go wrong.
That's why email attachments alone are an utter MIME-field when it comes to security.
> That's why email attachments alone are an utter MIME-field when it comes to security.
And yes, remember the 35C3 talk on e2e email security.
Not seen that, watching now (about half way thru) and nice to retouch upon a feild I've not working in for many years and seeing how not much has changed. Equally a little depressing, to see the same types of problems 10 years on.
That ship sailed the moment it got named email, leading people to think of it as an electronic form of mail, and so to expect that eventually it could be used for any documents you would send by mail.
With mail, I can send anything I can print or handwrite on paper, which includes text in multiple fonts, graphics, charts, tables, in a variety of colors. I can also include anything that fits in the envelope, so I can include files on floppy or disc or memory card or a thin thumb drive.
Sure, earlier email systems could not handle anything more than plain text, but because it was called email many people assumed that was just because common computers and displays didn't have the capability to handle more.
Once the GUI became prevalent for home and office computers, rich email was inevitable.
In retrospect, if the people who designed the earlier email systems had wanted the restriction to plain text to be a design goal, rather than just a consequence of the technology of the day, they should have named it etelegram to make it clear.
I'd go so far as to argue that the parent's reaction -- "email should be plain-text" -- is exactly why the horrors of HTML are what we have today. No one adopted any of the better alternatives out there and then Netscape -- a web browser, after all -- hacked in HTML mail, and "worse is better" won the day yet again.
The web is not just what happens in a web browser:
> An information object is "on the web" if it has a URI.
— Tim Berners-Lee, Axioms of Web Architecture, https://www.w3.org/DesignIssues/Axioms.html
Serving public URIs for messages must be done by separate web servers like a webmail client, or a mail archiving tool such as Pipermail.
Note that there's no requirement for something to be an HTTP URI specifically. Any URI will do.
> Email is not part of the web
That's "email", not "emails". I understood that to mean email the concept / technology, not "emails" as in individual email resources.
By that reading, yes, email is on the web. You can link to a mailbox with the mailto: URI scheme.
If you read it as "Individual emails are not on the web" instead, then webmail seems to cover that.
If I reside in "urn:oid:2.16.840" and I read "https://news.ycombinator.com", is that what they call the inner-platform effect?
The web is an abstract information space that can contain arbitrary links between objects. The web isn't something you load in a browser, it's a way of organising links between things. So, yes, you can link to books, movies, etc. Anything with a URI.
You might be interested in this early document about the World-Wide Web:
https://www.w3.org/People/Berners-Lee/1996/ppf.html
It describes what I'm saying in more detail, including explicitly mentioning books as something that can be addressed in URI space.
More seriously, I think that -- if pressed -- I'd say that the identifiers are on the web, but the things are not. Other than that, I believe we would agree???
That said, the origin of this discussion is in relation to Google's launching of AMP for e-mail. The justification was that e-mails are on the web, so it's OK to use AMP to push them forward. A better viewpoint, though one I disagree with, relates AMP to being a better mode of HTML. (As opposed to one of the Web.)
I think that TBL is very incorrect here. If that statement is accurate, then most of the non-web internet would have to be considered "the web".
You think Tim Berners-Lee, inventor of the World-Wide Web, is very incorrect about what makes up the World-Wide Web?
I (sincerely) appreciate reminders like this of just how much online opinions and experiences vary.
My sense of the last few years of web changes is that performance is mostly a product of script-blocking or AMP-degraded functionality, and new multimedia is mostly a user-hostile attempt to boost revenue. Whether it's five-point stories broken across five page loads, Reddit's "use our app" links breaking in AMP, or Techcrunch's insane scroll-down-to-redirect-to-homepage layout, the last ~3 years of web development are full of changes I find actively negative.
I understand the fight over something like AMP for email much better when I remember how far from universal that is. It's not really a surprise there's so much disagreement over what to do next when there's this much divide over what's working well at present.
More performant then text? What are you comparing it to smoke signals FFS? And let me see if I understand you correctly, you _WANT_ multimedia in your emails?
What is the point? To send miniature versions of web-pages?!?
None of those "Advantages" were advantageous to the end user. This only benefits Google or other corporations, and anything that benefits them harms me.AMP in email could, hypothetically, allow me to hit the "checkin to my flight" button for a Southwest flight directly from my confirmation email without having to bump over to their website. That's cool, convenient, and simplifies my life. It also benefits the corporation (their resource allocation is easier if they have a firm count of flyers) and it benefits Google (I'm more likely to use an email client that facilitates this).
The business world is full of win-wins, and this has the potential to be one of them.
You can do that in HTML email too. Newsletter have an "unsubscribe" button, calendar invites have a yes/no/maybe button.
https://developers.google.com/gmail/markup/actions/actions-o...
So now we just have to lie back and think of profits?
You’ve perfectly summed up AMP for email with a use case that’s already been solved by a simpler technology that nobody has complained about.
As their users spend more time with voice assistants and less with search result pages, Google needs to make up for those losses somewhere else. If they don’t, their revenue growth will end or invert, the stock price will drop, and the amount of money they can pay all of their employees will significantly decline.
For all of the messaging platforms Google tried to build and messed up, it is a real possiblilty that Google could end up killing Gmail through management screw ups.
I am unapologetic about blocking ads, beacons, cookies, trackers of all kinds. My computer, my rules. Just as I'm not required to look at roadside ads, and I don't, I refuse to allow my network to become compromised to give someone else another BMW. Running a website is the cost of doing business. If you cannot afford the domain name, bandwidth, etc., choose another business model. Ads were and are a horrible business model. I haven't seen an ad in literally years. I plan on keeping it this way.
There are some very smart people in the blocking arena. Since most of this stuff is delivered via JS, it's fairly trivial, at least at the moment, to handle same-domain ads. The game may change in future, but the adblock people usually prevail.
One idea I have if the sites start outright blocking blocking users, is to sort out how to write the ads to a form of /dev/null while making the site think they've been shown. I used to do this with Flash cookies/LSOs. I wrote them to /dev/null so I could take advantage of Flash back when it was a thing, yet have no LSOs on my machine to track me. Coupled with referer blocking, history blocking, no fingerprinting, and other settings, it worked a treat.
I'm willing to bet that if we cannot "block" them as part of the domain, we can sort out a way to block the element, shunt the ads into the bit bucket and continue on our merry.
I think several dns-based ad blocking programs can do this today, but so far I have not had a problem with returning NULL address (0.0.0.0). Pihole talks about the pros and cons of common approaches: https://docs.pi-hole.net/ftldns/blockingmode/. One downside is you have to run a webserver to catch the redirect and all the overhead that comes with it.
In my view, that's not "email sitting around in the gutter", that's "email retaining things that make it valuable".
Also, email is not, and should not be, the web -- so "the rest of the web" is a bit of a nonsequitor.
imap is so insane that every email provider reinvented it to have a sane api for their web client and app. Fastmail also created JMAP to have a standard json api for email.
"The rest of the web" is the ad-laden, tracker-infested, bloated gutter of the internet. Email is (was?) a little morsel of the old open internet (along with RSS/podcasts) that has not yet drowned in the morass.
How long until the sender’s ad targeting subcontractors know you read it?
How long until they can act on that information to manipulate you into sending cash, voting to sabotage the government, or otherwise act against your own interests?
With static email, all of these latencies are in the days, or at least hours. With amp email, it can be accomplished in 100’s of milliseconds.
No technology has angered me more in the last few years than AMP. I have literally switched my main search engine just so I don't have to deal with AMP.
At no point have I ever appreciated AMP. It has only been a disadvantage.
Don't presume to speak so for others.
This effort destroys half of what makes email useful. I know that moving forward, I won't accept amp emails. If anyone sends me one, I'll just have to tell them to please send me a plain-text copy if they really want me to see it.
On the plus side, this could make spam much easier to detect: if it's amp-based, then it's most likely to be spam.
I can choose to send mails as Plain Text but disable rendering of HTML mails? Where do I set that up?
I filter those and sent them straight to my trash unread.
And I do mean empty, not absent, so MUAs don't even try to convert the HTML to plaintext.
Or sometimes, the plaintext version is buggy, eg. because the mailer forgot to remplace {{template variables}}. Or because it sent a boilerplate text. Or the content of a mailing that was sent years ago. (All of these are true stories, I got emails like these.)
The conclusion being that if some format (AMP, HTML, ...) becomes prevalent, developers will stop caring about other formats.
Which is particularly funny because amp URLs have also become a major tell for spam. Want your sketchy sign-in page to come from a legitimate-looking domain? Just set it up with AMP and all the "check the pre-.com URL" rules people know will completely fail them!
I wonder if AMP for email will produce the same hell of broken redirects that it's created for webpages?
I get the impression most industries are moving this way (by outsourcing everything they possibly can to *aaS).
I don’t understand why it has to be https://company.subcontractor.com, and not https://subcontractor.company.com
There’s probably a depressingly large and profitable industry waiting to be invented by the person that solves that problem.
From what I can tell, AMP email is a step in the other direction: run JS and active content as the email loads, presumably from an unauthenticated sender, and no https padlock that users already understand.
If so, you'll have no choice but accept the AMP crud, or cut off many of your contacts.
Will email go the way of xmpp?
I'd love to see email go away and more modern messaging platforms take its place. Having worked on apps and platforms that work with and parse email, email is not the future.
I'll also add that I think if something were to replace email, hopefully it would incorporate the slow response expectation of it. IM etc usually implies an expectation of an immediate answer; the length and expectation of not receiving an immediate reply afforded by email is immensely valuable.
I think the single worst thing to happen to email is the consolidation to so few vendors, ironically. This move is not changing my view. Does make me think heavily of ditching Gmail as a client. I was using emacs, but can't with advanced protection turned on. :(
Like IRC mostly got replaced by Slack and Discord.
As opposed to web browsers which all perform identically?
/s
Agreed. Can’t wait for Google Wave to replace email!
It's old, certainly, but that doesn't mean it's bad. I haven't seen anything out there that can adequately replace it.
Look at HTML5 for an example, with Edge now running on top of Chromium.
It introduces new ways for senders to revise history after an email has been sent. Sent an ad claiming that you had a given price for a full week, and then decided you didn't want to sell it for that anymore two days later? Handy that you can remove all evidence of your advertisement after you sent it.
It also introduces an entirely new playground for phishing scams, which I think you'll see using an abundance of new tricks, after Google has extremely unwisely made users comfortable entering data into emails they receive.
The head of the AMP project threatened to "enforce the CoC" on people who brought up these valid concerns.
How is that different from - I saw a price for a flight on the website, but now its gone. If it was going to change, why did they show it to me?
AMP for email makes json requests proxied by the email client. Your client can decide to only make these requests once and then keep them stable or to show you a version history of the state of your email upon every time you opened it.
I think this is not comparable. If an email links to an external image, the external image is not the email, it's a link and behaves as everyone expects a link to behave. The email itself is immutable.
This may seem to you like hair-splitting, but I don't think it is, since blocking external images is a common thing for people to do anyway. Doing so doesn't make email useless.
Why can't you just set your email client to archive every version of the message that you see? It wouldn't even take up much extra space, since it would just have to store the JSON responses.
> The email client strips out the text/x-amp-html part of the MIME tree when a user replies to or forwards an AMP email message. This is why it is important that an email provide alternative content in the HTML part.
I also can't imagine that companies are going to be thrilled about adopting this if it's going to potentially 10x the cost of lawsuits.
For that matter, why have human-readable addresses? That only leads to abuse. If you want to share an address you already know, you can copypaste it, use a QR code and so on. If you REALLY want to say it verbally, then simply list it on a search engine of your choice. DNS is a glorified search engine.
Advertisers will put the advertised price in a hotlinked image served from a server, and they will both (1) use the image being fetched as a proxy for the email being downloaded/opened/read, and (2) change the contents of the served image after-the-fact. ("Save this email and open it every day this week for a new deal" and other horrors.)
Alphabet's Code of Conduct can be found at https://abc.xyz/investor/other/google-code-of-conduct/ . I'm pretty sure "all our users" is intended to include advertisers and rightsholders (like music labels, movie companies).
I don't have any inherently issue with CoCs, though I find it irritating when threat of "enforcing the CoC" is used as a method to silence legitimate, reasoned criticisms.
The "What We Believe" section certainly has lots of open-ended language; it's quite easy to declare any unwelcome criticism 'unconstructive', or any dissenting views 'tactless'. But the "Don't" section is quite a bit more concrete, and mostly wouldn't apply. Was the implication that "this is a fundamentally bad idea" counts as "derailing" or "unstructured critique"?
https://github.com/ampproject/amphtml/issues/13457
https://github.com/ampproject/amphtml/issues/13597
and the resulting(check the timestamps): https://github.com/ampproject/amphtml/issues/13603
A response like this shows that they really were in a bit of a blinder there for a sec :)
And that's exactly how any open standard works, isn't it?
Or were you expecting that some standard board would have power over Google (or any other company) and be able to dictate how Google (or any other company) can implement the standard or not?
https://verizon-postmaster.tumblr.com/post/183699380323/amp-...
https://techcommunity.microsoft.com/t5/Outlook-Blog/Support-...
such as:
* Further development must be open for anyone to participate in
* Further development must be open for anyone to view
* Technologically mature standards must be implemented by multiple vendors or an open reference implementation
Is it perhaps possible that "further development" in this context refers to development of the standard, and does not come with any notion of open governance of implementation?
In the end, it's about market acceptance. If few people use it, it's likely that Google will eventually cancel it.
People are forced to use it, whether they like it or not.
Much like “we won’t ever use AMP to rig search results”.
And yes, users are forced to use AMP through their search, for example.
1. Setting Gmail to not automatically load external images will also ensure Dynamic Email (AMP for Email) is disabled by default as well.
2. The specific Dynamic Email setting should be "rolled out to all users over the next few weeks".
And through the monopoly users are forced to use AMP.
Ads, however...
I think the GP misspoke. It's more accurate to say that people are forced to use Google products. Even if you use DDG and Fastmail there's no escaping reCaptcha, AMP, and Google Analytics - unless you want to limit yourself to only a few websites.
Absent any other name I'd suggest calling it a Jurassic Park problem, after the famous scene.
Could you clarify without a broken link?
Standard for anything google makes open.
Which is why being "open source" is not enough.
Reminds me of the doc/xls formats with the difference that those were proprietary and become (controversially) open as a response to the standardization of the odt/ods formats
Trying to centralise as much of the internet and how people interact with it under their control is dangerous and open to widespread abuse - and this is already happening.
See:
YouTube demonetisation
YouTube content ID abuse
Chrome extension changes
Gmail is already completely broken on IMAP unless clients throw in google specific workarounds, and now they’re moving on to break the next layer of email too.
Joy.
- the largest browser people use to view pages (Chrome)
- the largest platform people use to run that browser (Android)
- the largest way people discover content online (Google Search)
- the largest way people advertise online (Google Ads)
- the largest way people share video online (YouTube)
- the largest email provider (Gmail)
This is way too much power over the internet in one corporate entity.
It’s way beyond what MS ever accomplished at their height, and it’s way beyond anything Apple ever accomplished either.
The power Google have over the internet at large and the content people consume at this point frankly terrifies me.
Google wields too much control and is forcing the evolution of technology to further their grasp. They reach into every sector of technology, and every play they make deepens their moat.
Look at how fast they spin up new products to see if they can claw into a new space. They move mountains if they sense they can grapple something new, and if it doesn't work out they tear it down without considering the users. It isn't about the individual - they want total control.
Google is 90's Microsoft's Embrace/Extend/Extinguish executed to perfection.
(See my thread from yesterday [1] where I argue these points as they pertain to the app store.)
I'm going to talk with my local lawmakers. I don't know what leverage I have, but I'll be damned if I sit on the sidelines.
Truly independent governance of separate projects within Google at the very least, but ideally totally separate legal entities that are carefully regulated and monitored to ensure they're not giving each other preferential treatment.
For better or worse, this is how it has to be for the market economy to function well in a society. A company can be successful up to a point - they cannot be allowed to win. The victory every for-profit entity seeks - permanent domination and monopolization of their market - is something potentially disastrous to society at large.
OTOH it's like a standard that you can build upon if it's foundational communication infrastructure (channels, touch points).
This means that stability on lower levels facilitates competition on higher levels. As long as nobody is excluded it's not problematic. It shouldn't be allowed to scrap services users depend on though, this would be a good organic regulator.
The problem with amp4email isn't that it makes everyone part of Google (though I'm willing to bet it'll ultimately imply all MUAs will end up having to embed Chrome engine). The problem is with Google using its near-monopoly position to push a "standard" that makes e-mail serve its users less, and serve companies seeking to exploit those users more.
I disagree. At some point, such a company effectively becomes the same as a government. I think that's hugely problematic.
I don't hear many people talking about punishing companies for their success. I hear a lot of people talking about punishing people for their abuse, though.
The network effect "free" user generated content platforms (YouTube, Facebook, etc) are the low hanging fruit here. The reason they have sustainable monopolies is because they have exclusive use of the user generated content on their platform. This is really easy to fix. Require that companies beyond a certain scale (1 million users perhaps?) that make user generated content freely available default to free use + attribution licenses for that content, unless users specifically opt-out on a per piece basis. And furthermore mandate that companies provide a means of easily accessing said free use content, such as through an API. Also require that users be able to 'remotely publish' content to the site again, through something such as an API. And finally prohibit companies from censoring discussion of competing sites except in obvious cases of abuse such as e.g. automated spam.
There - problem solved. Now you can create an e.g. Facebook competitor where people can keep their exact same friends (and even talk to the ones still on Facebook) except gain whatever benefits the new platform has to offer. Similarly for something such as a YouTube competitor where now you'd be able to seed yourself with what would likely be the vast majority of the user generated content from YouTube. You might also want to add a rule that sites cannot clone content from sites smaller than they are. Again the idea is to create unique incentives for users to try new sites. You'd get access to most of the content you already have from big site + whatever unique content the smaller site offers. And, just like that, you now have created massive competition with minimal direct 'punishment' of the existing behemoths.
- the way people get news (Google News)
- the way people learn about their website (Google Analytics)
- the way people fight spam (reCaptcha)
- a major way of embedding web fonts (Google Fonts)
- a hugely successful cloud document suite (Google Docs)
- a safe browsing service, making them effective gatekeepers of what can load in Chrome (Google Safe Browsing)
- an ever growing system for schools to manage assignments (Google Classroom) - this one particularly concerns me because paired with Chromebooks, it brings kids into an entirely closed Google ecosystem very young
> this one particularly concerns me because paired with Chromebooks, it brings kids into an entirely closed Google ecosystem very young
I'm not too concerned as many other big corporations (Apple, Microsoft) are fighting this ;)
The other corporations are only fighting small battles, but you can't compete with free, which is how Google gains its foothold.
"Each site you visit is checked against the Safe Browsing list on your system. If there's a match, your browser sends Google a hashed, partial copy of the site’s URL so that Google can send more information to your browser. Google cannot determine the real URL from this information." -- https://www.google.com/intl/en/chrome/privacy/#safe-browsing...
There's no way Firefox would be ok with sending all their user's visited URLs to Google.
(Disclosure: I work at Google)
How do I disable this in Firefox? Is this the section about "Content Blocking"?
- One of the most popular ways for running surveys / forms (Google Forms)
My knowledge is a year or two out of date (haven't hosted forms in popular websites anymore), but it doesn't seem like this could have changed that rapidly. Bots don't suddenly understand English, and neural nets aren't much better or worse at word CAPTCHAs than picture CAPTCHAs. It's just that Google didn't need books anymore.
I do still host a bug report form on a smaller site, and that just filters <a href, and more recently, http://. If someone enters that, the site gives the helpful message that http is not allowed for spam reasons and they should use hxxp:// instead and that I'll understand what they meant. Haven't gotten any spam since I started including that.
The cases where reCAPTCHA is a good idea are really rare. Logins can be solved with exponential back-off, forms can use spam filters similar to email and a simple CAPTCHA to catch the vast majority. With reCAPTCHA, I often spend minutes solving the because Google has no other markers to go on (deleting cookies, localstorage). I used to not mind them when other people were all complaining about those word CAPTCHAs (I found them easy) but now reCAPTCHA just take your time instead of your reading skills and they're absolutely awful. It rewards not using privacy technologies in your browser and so a lot of laymen don't experience the issues. Please don't use reCAPTCHA if at all possible...
Akismet is a third party service that works really well. You send data there with a HTTP POST and it will reply with a yes or no, it is spam or not spam. It is not that hard to implement. You do have to be aware that you are sending user data to that service, which you have to mention in your privacy policy.
Stop Forum Spam is a similar third party service. You send it an ip address and an email address. It will reply on both items if it is spam, together with a confidence level. Quite interesting way to reply :) It is originally intended to fight registration spam, but you can use it for comment spam or contact forms as well.
JavaScript spamfilters can be very usefull. Most spambots do a HTTP GET for a page with a form. They fill in all the fields and submit it with a HTTP POST. They don't run any JavaScript on that page. You can have honeypot and timeout fields on a form that get manipulated by JavaScript, and spambots will not validate. Works really well, and all transparent to the user. The only "risk" is that in the future spammers might start using more sophisticated spambots, like using Electron or Chromium. I implemented spamfilters like this in a WordPress plugin and it works really well for me: https://wordpress.org/plugins/la-sentinelle-antispam/
With power comes responsibility. Google has earned our trust with every new product they develop. If they misstep, they will hear it. In fact, they have to keep listen to keep being at top.
This made me laugh out loud. Thank you.
See also [2].
[1] https://groups.google.com/forum/?fromgroups=#!searchin/alt.r...
*I later also sought out a Google+ Beta invite. That one is harder to justify with just naïveté.
It might be a pain to move, but it is certainly possible, and it's certainly worth the effort.
They've gone out of their way to become impossible to reasonably avoid.
Regulatory action is the only thing that will stop them from completely destroying the concept of decentralization on the internet.
I mean, I have noticed those harder captures too since I switched to Firefox, but I didn't realize it was due to the different browser. I thought it was just a newer version.
If you have their tracking cookies, if you don't use a VPN, and if you block ads (which would have more tracking cookies), Google's certainty of who you are is higher, increasing the chance that you are a human.
Firefox's default settings, especially with the new Content Blocking features, are enough for reCAPTCHA to be less sure you're a human, and try to make you prove it more often.
So Google manages to sell a product (reCAPTCHA), show good intentions (bot-prevention), increase usage of Chrome (because it's a smoother experience through reCAPTCHA), and get more information on everyone.
Win x4
I sometimes use Random User-Agent as well to resist fingerprinting; this makes ReCAPTCHA not just extremely tedious (up to about 10 rounds of sl-o-o-o-wly fading pictures) but literally impossible (it never ends).
1. Do they reduce complexity of the (already insanely complicated) web/internet infrastructure?
2. Do they reduce barriers of entry for new companies?
If you look at thing Google consistently pushes forward, the answers are almost always in the negative.
One strategy for explaining the problem to non-technical people is by comparing regular email to the walled-garden email used by some banks, phone companies, and the like--where you have to log into their website to see your 'inbox' and use a web form to send messages. It's super annoying and the other party has complete control of the communication channel.
"Dynamic email" could be implemented to inject this kludge into your email client, giving the AMP sender (who likely has more power than the user) the same level of control over the channel. Imagine opening your email client and finding a message which asks for two security questions and a captcha, then lands you in a messaging interface which limits you to 200 characters and denies basic affordances of email like archiving and forwarding.
I find the arguments that email is already mutable because images are externally-loaded unpersuasive. In 2013 Google started caching images in gmail "to protect you from unknown senders who might try to use images to compromise the security of your computer." [1] Email marketers were upset at losing engagement metrics. Now a practice that used to be considered abuse is being rolled out as a feature.
[1] https://gmail.googleblog.com/2013/12/images-now-showing.html
After reading GMail's announcement about dynamic email and your position statement on AMP, I am thankful to have switched to FastMail and looking forward to remaining your customer. I'm writing to ask you not to implement AMP dynamic email. Even though you don't have a huge slice of the email market, your customers are probably disproportionately privileged and informed (they choose to pay for email...), which positions you to resist these erosions to privacy and democracy in ways that individuals can't.
More pragmatically, I see your non-support of AMP as a big feature. If you don't support AMP, companies can't as easily put pressure on me to use a communication channel where they have all the control.
Thanks!
However, if FastMail does add AMP for Email support, I expect them to do much more to ensure I can see the historical record of AMP data, and for them to take significant measures to ensure that user privacy is protected. And of course, that we can just shut it off.
I've just about completed the move (to runbox) without forwarding and it wasn't that big of deal. Just set aside a bit of time every once in a while to update all the accounts that are still sending to my gmail account.
Eventually I'll set up a permanent auto-reply saying "this account is no longer monitored, please contact me at xxxxxxx@runbox.com".
People point out that the email is read by an automated system, but that doesn't change the fact that Google is building a profile of me and selling it to advertisers.
With Fastmail there's a business model I can understand. I pay them money and they provide me a service.
The really dark side of all this is that we're quickly moving towards a world where you only get privacy if you can afford it.
Neither G Suite Gmail nor regular Gmail have been used and/or scanned for ads personalisation since back in 2017: https://blog.google/products/gmail/g-suite-gains-traction-in...
Personally, I just feel more comfortable paying 4 bucks a month to a company that isn't trying to monetize me.
Even simple tools like spam assassin read the body, and you can bet that almost any public provider is doing more than spam assassin.
Not to mention all kinds of actually free services. Think colab.
If you’re in China or occupied Tibet it may be not only advertisers but also an oppressive and adversarial government. Maybe not today but next year.
And, if available in one place, eventually available elsewhere.
That's why everyone should use e-mail with their own domain name. It gives you freedom to change e-mail provider whenever you want, without having to notify anyone about it.
I just switched the MX records over, hopefully I can keep my grandfathered free G-suite account as a searchable archive for the time being (I should also back-up all the mail in there but haven't had time to). It wasn't quite organised enough for me to want to bring it over.
I'm using DuckDuckGo for search now on my home laptop and phone, Safari on my Mac and Firefox on Windows machines instead of Chrome, Apple Maps on my phone. The one thing I can't see moving off at this point though is YouTube since so much of the content I watch is only there.
These companies desperately need to be chopped up and have severe data sharing restrictions put on them. They're much more invasive than Microsoft ever was in the 90s.
In order for your link-click to be resolved your computer has to send some packets and tell somebody that you want a piece of content. Somebody has to give you that content. Unless you're using tor (really, even if you're using tor), these are actions with physical manifestations which can be tracked.
In the fullness of time, email will fail as a communication medium because of these situations. I don't think that Google will mind terribly when it does.
Forwarding mail to Gmail accounts is perilous. My outbound queue is constantly full of mail to an established Gmail account that Google is throttling for some reason or another. I finally parted ways with a user over this specifically, since they had a number of mail accounts that were all forwarded to their Gmail account. For a company with so many smart employees, their handling on this is really dumb.
Receiving mail from Gmail accounts isn't much better. Spammers have discovered that they can cheaply spin up new Gmail accounts and spam the world for a good while before Google detects it. Since so many people use Gmail, on the receiving side I can't use any of the network reputation tricks to catch the spam. So, these days, an appreciable percentage of the spam landing in my users' mail accounts is coming from Google.
If it were just me, I'm pretty sure I'd just block anything to or from Gmail altogether and have one less recurring headache.
...which is really a shame, because I remember the excitement and wonder when Gmail debuted and how amazing it was at the time.
I don't refuse to relay messages to/from gmail addresses, but I do avoid interacting with gmail addresses as much as possible. The less I'm touching Google servers, the better.
Fortunately, most of the people I exchange email with don't use gmail.
Presumably people aren't sending e-mails to domains that belong to trackers/ads? Otherwise I don't see what the problem would be.
Every click is short-url'ed through the service, and every image is served through them. If you have images turned on by default, you'll also get tracking bugs as soon as you open the email.
This is so contrary to how anything else on the web works that I feel I must have missed something. Their "standard" is not available to individual developers. Only those who are already sending lots of mail may play. This is far worse than how web sites have slowly become more opaque so that it's now harder to learn how to develop them. It's simply not possible to play around with this new medium.
The open web is no more.
If this is true, then I celebrate it! It means that I can have my mailserver simply discard all AMP emails and be confident that I'm not missing anything aside from spam.
I researched this a bit. Here's the scoop: right now, GMail is trialling AMP emails and are limiting that trial to entities that send out lots of emails. Post-trial, the intention is to allow anyone to send AMP emails.
However, other major email services that have hopped onto this bandwagon are not limiting the use of AMP emails this way.
So it's not true that there's no way for individuals to send AMP emails. It's true for GMail specifically, but even there, that's a temporary limitation.
The standard is "open like in openxml" - there's a technical commitee, but your input will not be heard.
What makes you think input won't be heard?
Additionally, I think with AMP, you might be able to get your input heard, but only if you run a mail service with millions of users.
Major features an email have:
- it does not change (except for external resources, which are blocked by default anyway),
- works offline,
- can be read in ten years just fine.
I want my mails to remain static and available and I don't think I'm okay with them running some uncontrolled code.
https://postmaster.mail.ru/amp/playground.html
How they forget there's <style media="..."> and came up with this html non-conformant markup?
`<style amp4email-boilerplate>body{visibility:hidden}</style>`
New templating standard directly in html? They decided not to use DOM or components but just text, damaging the ability to transform the page in runtime and requiring backend processing?
` {{#cart_items}} {{/cart_items}}
{{^cart_items}} {{/cart_items}} `
And amp4email starts with `<html 4email>`, with the emoji? seriously? [I cannot even insert this emoji here at HN]
And regarding the tools... AMP-viewer... Can you actually check if there is anything implemented? i'm perplexed with https://github.com/ampproject/amp-viewer/tree/master/mobile-... - its only 4 source files with no logic inside, last commit 6 months ago... and all its supposedly do is generate iframe with mangled url pointing to amp-project website "https://www-ampproject-org.cdn.ampproject.org/v/s/www.amppro... ? So all the AMP processing is walled out in a propietary service?
And the other amp-viewer mentioned at https://www.ampproject.org/docs/integration/integrate-amphtm... redirects to google corp portal?
https://g3doc.corp.google.com/java/com/google/gws/plugins/am...
AMP documents display on its own. No need for AMP Viewer. (Example - https://amp.cnn.com/cnn/us/live-news/jussie-smollett-charges...)
I think I know why they're doing this, actually. It's a clever way of ensuring that any services that send, receive, or interact with AMP mail are Unicode-safe. If they can't include a U+26A1 ("HIGH VOLTAGE SIGN") character in the AMP markup, they'll probably mangle any other non-Latin text too.
You can see what the spec accepts here: https://validator.ampproject.org/#htmlFormat=AMP4EMAIL
It was kept in because it is fun, apparently.
Which is a showstopper.
... sigh AMP is the one thing I really, really, despise from Google and it just continues to spread.
They wave the banana to distract, but the gorilla comes with it.
Reminds me of QUIC/HTTP3. Seems like the way things work at Google nowadays.
Mutt, for instance, discards "html" and renders just the "plaintext" version. AMP emails would just be another part of the same email. Nothing would stop working.
AMP for email has support by Outlook, Yahoo, and Mail.ru, so it very much isn't under Google's control.
https://github.com/ampproject/meta-tsc
I would hardly consider Yahoo to be a leader in anything at this point, not sure about mail.ru. From an outsider's perspective AMP looks Google controlled.
It looks like from your comment history you are part of Google's AMP team. It would be nice to disclose that.
The TSC requires majority consensus. Google does not have a majority.
I remember you talking about how transparent the process is, but, alas, you never described it. And to quote another member of the discussions back then, anyone raising concerns:
> were closed or locked, and the head of AMP blocked us.
You being the head of AMP, of course.
mail.ru is owned by the same mafia group, that controls majority of Russian internet. They are either very stupid or want the same thing as Google (to destroy email as we know it). It is probably both.
Participation of mail.ru implies, that Russian mail providers won't ban Google in retaliation for this crap (neither on SMTP level nor via country-wide firewall).
Suggesting any part of AMP is open still feels very disingenuous when you recognize the monopoly position of the company spearheading it.
...which means nearly nothing.
Open in what sense? For example, there's no open standard (to the best of my knowledge) for the HTML used in emails right now and different email clients render HTML in emails differently.
On the other hand, the protocol itself is standardized, but AMP is not working on protocol level.
Is people or the communication what stops working, and then the involved system, not a piece of software by itself.
Not often enough. These days, people who are rude enough to send HTML emails are also rude enough not to include a plain-text version of the email.
I don't expect AMP to be any different.
"Please view the HTML version of the e-mail"
Which is annoying, because I have a preference set for plain text if it is included. If a sender doesn't have a plaintext alternative, they should not include any of this garbage plaintext, that just confuses the preference logic in MUA.
Anyway, it shows that we may start seeing:
<p>You need AMP supporting MUA.</p>
as a html "alternative".
They're going to bring the entire web under their control, more or less.
If there was ever a time to abandon every Google product you use, now is the time.
EDIT, to be clear: for Google search results.
It's great when I'm on the light rail going through areas with patchy cell signal, but when an article's share buttons are broken because it's the AMP version it's a pain to figure out how to navigate to the non-AMP version of the article.
A couple news sources (usually technical ones) thankfully put a link to the non-AMP version somewhere on the page, but IMHO this should be automatically done for every AMP link opened.
That is available in the standard markup, so it should maybe just be added to the UI (in the ellipsis menu probably).
Where will we see the setting, and is it still rolling out? I can see in my old Gmail account where I have "Ask before displaying external images" selected, so I'm presumably protected from AMP for now, but I would've expected to see the setting for AMP alongside it.
If the statement was, "I think AMP for Email is perfectly fine as is and doesn't need an option to disable." that might be something to call for disclosure.
To their credit, the Google Cloud product team does this religiously.
(toomuchtodo is indeed accurate that the Google Cloud team are top notch on disclosures.)
That's not actually sufficient. It needs to be opt-in, so I can search without signing in.
You can see the same mechanism here : https://news.ycombinator.com/item?id=19490573
Puke.
I have been strongly considering migrating off of G Suite for my domains, files, and emails. Maybe it’s time I bite the bullet rather than keep using a product I have to actively fight to use.
Then, when I changed the redirect to point to a new service (FastMail), most of my email came with immediately. There's some secondary advantages to this. Not only can you switch providers at the drop of a hat, but you can control your address even if you get banned or blocked by the email provider.
If you have, say, a gmail.com address, and your Gmail account gets terminated, you may lose access to all of your other accounts across the Internet as well, since you won't be able to access the email they're connected to. But if you own the domain, and it's forwarded to gmail.com, you can redirect the domain to another email provider, and send a new reset email to regain access to your other accounts.
Oh god no, please don't turn email into a "surface."
> That means you’ll be able to do [x, y, z] right from the message, all without leaving your web-based email client.
Quit. Gmail.
Why are so many technical users still on this gross platform that is turning the earliest, most successful decentralized internet protocol into a walled surveillance advertiser garden?
If you use gmail, go register a domain and point your MX records at an honest mail provider like Fastmail, Posteo, or Kolabnow. Or run your own mail server. This way your mail provider is hidden behind your domain and you can change it in the future if desired.
Seriously, stop reading hacker news for a second and make today the day you start migrating away from Google.
Simpler. Use outlook.com or icloud.com or tens of other email providers that are not an advertising company.
The Basic HTML version is the best and snappiest version, by far. Still exists. Even on Google's own Fiber service I have plenty of time when trying to load any other version to click the "slow? try basic HTML" link in the bottom right, and then you can set it as your default.
I'll be leaving anyway with this Amp crap, but there's still work email. Basic HTML is the way to go.
This needs to be explained to people, as most still think that Gmail just displays all of your private E-mail with a nice interface, FOR FREE!
The "FOR FREE" part is really the killer, I found that people are amazingly resistant to the idea of paying anything for E-mail, even if compared to their other utilities (power, water, internet, TV?) it is extremely cheap.
Google still saves and parses every email it gets and likely uses that data for a number of purposes. No longer directly targeting Gmail ads with it really doesn't do much for people who are concerned about Google and privacy issues.
Sure, but so does literally every email provider. Storing your email and spam classification are pretty much the two biggest features an email provider can provide.
This is like objections to "algorithms" or "chemicals".
There are some ingrained expectations in people when it comes to e-mail that will now be violated, so there's a great opportunity to abuse this.
By default, most email clients hide the header information needed to determine whether or not an email came from the address it claims to, including Gmail. I suspect we're going to see a lot of phishing emails that ask you to input sensitive data right into your email.
These AMP emails sound like a they are going to be a huge headache. "RSVP straight from the email!!" Yeah, and when that doesn't work am I stuck?
It’s amazing how reality is completely the opposite of what they are saying. I can still read a text email sent in 1999. No way an interactive AMP email will still work in 20 years.
Not all email providers support HTML in the same way. Some examples:
* At one point Gmail did not support style tags and all styles had to be inline. * Outlook for years used the Word HTML processor which had all sorts of limitations. Hell to get a button you had to create it in VML and put a conditional "if Microsoft do this" on it. * Some (up until a few years ago) versions of Outlook ignore either padding/margin on CSS (forget which one) * In order to layout your email so that it works across all clients, forget about using anything remotely modern. You have to use tables everywhere like it's 2000 all over again.
I'm probably forgetting a bunch, it's been a couple years since I had to deal with it.
With all these issues, adding yet another thing onto it is just asking for pain.
Excellent. Let's introduce one more standard.
That's a feature, not a bug. If it discourages people from using HTML in emails even a little, that's a good thing.
> Not all email providers support HTML in the same way.
What will make AMP support different?
(I used these a bit to coordinate small stuff in a project I was working on, mostly for the novelty value).
The company was soon acquired by some other bigger company, and the Zaplet concept was shelved for good.
https://gsuiteupdates.googleblog.com/2019/03/dynamic-email-i...
Email would be less of a hassle if I could just unsubscribe from many things in a standardized way within the email client itself.
Before I pull the trigger, anyone have a better service than Fastmail to recommend?
Emails already support updating by including external image references inside the email. Allowing this is a choice of the client.
AMP for email makes JSON requests proxied by the email client. Your client can decide to only make these requests once and then keep them stable or to show you a version history of the state of your email upon every time you opened it.
That is crazy, man.
NB: Not blaming you, just shocked.
E.g. when you open a notification email from GitHub, the email can tell you that since it was sent, there are now additional comments to consider.
Clients can (and do) use trust scoring to activate AMP in emails. Right now they use the same model that would allow loading images by default.
AMP: https://techcrunch.com/wp-content/uploads/2019/03/Dynamic-Ma...
Wave: https://www.youtube.com/watch?v=xBzuuWZPaXc&feature=youtu.be...
That said, the problem is not email. Email is just fine. The problem is people using email to solve problems that email was not designed to solve, namely marketing. With this move, Google is adding a considerable amount of fuel to the fire. Can’t say that I’m a fan of this, as cool as the features may sound on a surface level.
https://www.forbes.com/forbes/2000/0612/6514218a.html#58b1f3...
Interactive emails, powered by HTML/Javascript, in 2000! What could possibly go wrong?
Always a shame to have to go full HTML email, just for some light formatting.
There can be no doubt what they want now, and that Gmail as a platform is harmful to the internet at large.
If you haven’t already, migrate today. There’s plenty of good options out there.
Is it unpopular? Or are most users ambivalent? And if it is unpopular why does Google continually try and push it?
Edit: grammatical mistakes
I understand your concerns but think about it: In 5 years time would you rather have emails that are as broken as today's web pages or emails that are as broken as today's web pages AND controlled by Google?
precisely :)
work! work! work! work! work! work...
AMP is the Jason Bourne of the web developer world... it could be the end of us all.
It's at the stage that you meet people who love to hate it without even knowing why that hate it, that it is almost fashionable to hate it. Then those that do have a reason to hate it, always have their own reason. With no consensus reason for hating it. Though I'm noticing an increase of "Google" being the reason they give.
But then people love to hate, back when IBM was top dog - people loved to hate them, then Microsoft, and today, well today Google seems to get more hate than Microsoft these days. That's not saying Google did anything wrong, or Microsoft did anything right. If anything, people love to hate whoever is sitting at the top and today in the public's eye - that's Google. Not saying they are right, or wrong.
But clearly - the people's level of hate does seem to correlate with any large company attaining a overly dominant position. Just kinda fascinating to see the same patterns play out over time.
I don't love to hate it. I just hate it, and I can tell you why -- it's a one-two punch of AMP pages being generally inferior to the real pages, and Google interposing itself between me and the website.
So with that said, I totally respect your irrational burning hatred for AMP.
Any company not in a dominant position would go extinct by the mere thought of it.
But then, does the business or more so - shareholders drive these types of directions. As it is a trend we see play out over and over again.
takes off the mask to reveal Google Buzz
That being said I can't imagine a scenario where AMP in email is anything but annoying.
Google's record is one of infect and close.
It might seem unrelated, but disabling JS is the real fix.
No it's not. Slack and Messenger are replacing IRC.
Ever tried writing an actual letter to someone? If you forgot what those are, think a longform article, but with the intended audience of 1.
No messenger handles long passages of text well, because they are not designed to do that. And things like online status visibility are anti-features when it comes to letters.
If you want an exchange channel that's optimized for exchanging long messages, with no expectation of immediacy in response, with ridiculously accessible archival tools (ever heard of email clients?) there isn't anything that comes close to email.
Yeah, but if most people you know don't have active email accounts, that doesn't matter, and it's the direction that we're headed.
You and I are living in very different worlds if that's the case.
A lot of my friends are not using Messenger or anything FB-owned. Nobody I know actively uses Slack off-work.
Everyone has an email. For quite a few of my friends, that's the primary way of reaching them.
I think some evidence is required to support this claim.
Not as far as I can tell. But even if it is, this sounds more like a killing blow than something that would keep it alive.