Thunderbird’s New Home
blog.thunderbird.net
blog.thunderbird.net
I'm really happy Thunderbird hasn't gone the way of the dodo.
Okay, that's scary. It's like a one half of a conjoined twin trying to remove the other half from their lives. Mozilla started transitioning Thunderbird out of their umbrella while TB is still highly dependent on Firefox code. Yeah, scary.
Maybe we need a successor to Thunderbird? Something that's not tied to Firefox so much? Because it seems like we can't trust Mozilla and however many unpaid/underpaid volunteers to maintain it well enough.
If you are referring to Mozilla Messaging and the period to 2012, no the only transitioning was in terms of product functionality. The community organized in 2014, unaffiliated with Mozilla, and it's not until about 2018 when staff were hired that community leadership were able to seriously reduce technical debt. But seriously reducing dependency on Firefox code is some distance away.
> Maybe we need a successor to Thunderbird? Something that's not tied to Firefox so much?
You are looking a millions of dollars paid developer time.
> Because it seems like we can't trust Mozilla and however many unpaid/underpaid volunteers to maintain it well enough.
Mozilla are not running the show here, the community is.
Perhaps it's difficult to keep up with the history, but https://blog.thunderbird.net/ has past relevant postings, plus developer and other mailing lists. To cite a couple, big changes in encryption https://blog.thunderbird.net/2019/10/thunderbird-enigmail-an... https://mail.mozilla.org/pipermail/tb-planning/2019-December... and development priorities http://lists.thunderbird.net/pipermail/maildev_lists.thunder... which includes a new address book.
There is a significant professional development staff which is nicely paid, and the number of developers will soon double. https://www.thunderbird.net/en-US/careers/
Unlike a web browser, email has not changed much in the last 15 years, so I don't see why development needs to advance at a high speed.
I doubt that any UX fashion statements are going to be enough to make up for the huge loss of functionality.
As a daily user for 10+ years I can say there is certainly room to incrementally improve TB in many areas, like calendar and contacts, but don't mess with UX success.
I unfortunately can't remember my complaints to make them more specific for a lively discussion, but I guess I am an anecdotal counter-point for thinking the UX was actually not a success.
Car manufacturers don't try to reinvent the steering wheel & pedals UI every couple years.
Also, I see that a dark mode would be a requirement today as everything else either complies with OS's dark mode setting (Windows 10, OS X) or has it's own dark theme.
The modernization of the FF UI, combined with the reduction in the ability to customize it enough to make it the way I want, is one of the reasons I stopped using Firefox (not the main reason, though!)
Whatever TB does, I hope they at least allow people the ability to modify the UI enough to make both of us happy!
Seriously, can I just have frames back instead of the "our whole site is one HUGE page" trend.
I work a rotating six week schedule with different workdays week to week. In iCal/Apple Calendar, I can intuitively copy/paste events to a different day of the week if the rotation changes. Thunderbird, with its 90s UI, doesn’t provide you with this option.
I’ve found refuge in eM Client on Windows, but it took a while before I came across the app.
I use thunderbird for email and calendar for calendar. When i compared Apple Mail with Thunderbird i found quirks small tech issues with Apple Mail especially when using something else than gmail.
Why should the baby be thrown out with the bathwater, just to chase cosmetic trends?
Can you give a compelling technical reason why this would be good for users, without using superficial UX fashionista platitudes?
Just because something isn't "on trend" doesn't mean it is bad. Some of the most important and beloved software has user interfaces that have not changed in decades.
I don't care if a UX designer would be embarrassed to use it in front of other mail clients. Trying to chase trends will usually just leave your software looking dated, anyway.
Unless you're willing to roll up your sleeves and keep existing functionality with your new trendy UX, then don't bother, because deprecating real functionality at the cost of a superficial fashion statement is really egregious and it needs to stop.
Nobody wants their workboots replaced with tennis shoes. And especially not because a UX designer wanting to stroke their ego and make a name for themselves.
Most of the sibling comments here are a “get off my lawn” type variety that IMHO are not fully informed by what good UX means. Great design isn’t superficial, in the least. A great user experience is a great user experience... it doesn’t mean compromising because something was hard, and it doesn’t throw away how the product is used or has evolved.
We should be aiming to improve and innovate to be helpful, not stagnate. And improvement means people’s existing needs are considered, not disregarded as many here seem to think.
I don't think anyone disagrees with that. The complaint I am making, is that a lot of UX design is superficial, and done for the wrong reasons. Most of what Mozilla has done is terrible.
They've essentially gutted their browser because they want to be cool like Google.
While I don’t personally know the designers at Mozilla, I’m doubtful that they simply “wanted to be cool like Google” and instead did their own research. I could be wrong but usually work isn’t so arbitrarily done for large products and teams.
https://partofthething.com/thoughts/host-your-own-contacts-a...
However I have not found a way to connect it to O365. If anyone has figured it out, I'd love to know how.
Second to this, they should probably work on their own first class mail and calendar server as at least open core, and probably as SaaS as well. As much as I like some of the mail hosts out there, for some, the ability to self-host is big. The various pieces and software you have to cobble together are cumbersome, and even then, you don't get anything close to what Exchange+Outlook gives you.
It would be nice to see Thunderbird fill this space, it used to be what I would consider a best of breed email & newsgroup client, now, I'm not sure I would say anything close to that.
Why's Mozilla got a stock ticker if it isn't publicly traded?
Ximian's Evolution?
I would love for someone to do this, so we could have a nice, self-hosted store for our vital data but still access that data from all our devices, over VPN, etc.
The problem, as always with these things, is who that someone would be. While many HN readers might appreciate the potential advantages, I fear the target market for such a product is significantly smaller than for Thunderbird, which for better or worse is itself aiming at a relatively small minority of users in the era of Google Mail and friends.
For anything it's worth, I'd contribute financially to such a project personally and so would my businesses, since it would be a significant benefit in each case.
o365/exchange, gmail/gdocs/gcalendar and fastmail are probably the big three providers that should have seamless integration at this point. A SaaS option from Moz would be nice, as would a self-hosted option. I bring these up in line with Moz's efforts to get VPN subscribers, they could likewise do groupware.
I quite disagree here. Servers and clients are very different in their architecture and implementation, and you are going to have very little opportunity for code reuse or even knowledge sharing between the people implementing the client and those implementing the server [1]. I don't think you can turn email servers into a profitable revenue stream unless you do full SaaS, and I don't think Mozilla is really capable of putting in the resources to make a Mozilla Email SaaS feasible.
A better bet would be to try to put together something to more effectively cobble together the existing open-source email server components and do the installation and support as a service, but I again don't think that Mozilla is the organization best-placed to provide that service.
[1] The big exception here is LDAP. But Thunderbird doesn't even really maintain its own LDAP library--it should move to WinLdap/OpenLDAP depending on OS.
True, but also the only way to really know how to develop a good one is to have experience with building the other.
I've been giving specifically to support Thunderbird development, not other Mozilla work [0] for the past few years because I think it's vitally important that email remains an open protocol, supported by mainstream desktop clients. Without Thunderbird, I fear email will be lost to the Gmail & Apple walled garden.
We hope everyone will resume via https://give.thunderbird.net
Feels like an odd choice (and perhaps, an important omission?) when the announcement calls out the importance of donations to Thunderbird.
You'd be donating to a nonprofit and getting the tax benefit, then the nonprofit would be passing it onto a for-profit corporation. End result: tax-deductible donation to a for-profit corp. That doesn't sound like something the IRS would like.
It sounds like the ability to directly generate revenue was seen as outweighing the benefit of allowing tax-deductible donations. (This is my own speculation.)
Would there be a limit? I don't think so. If I was running, say, a non-profit website host, 100% of my raised donations would be going, as expenses, to a for-profit company (some commercial cloud-hosting provider.) That's still an entirely-legitimate model for a non-profit to operate under.
I don't have as much free time as I used to, that and Thunderbird is removing legacy add-on support faster than I would like.
I think what is truly optimal is to keep the CLI nature of the MUA, but have a slave browser window that displays the HTML portion of a message. Then you can tile your terminal to one side of the screen and the browser window to the other. Use the already excellent UI to browse mail and compose mail. When you encounter a message with an HTML part, render that in the slave browser window and render whatever text part exists in the terminal.
I'm having the very same problem, but never knew there actually was an extension for that - though it's a bit disheartening to learn that at the same time it no longer works in the latest Thunderbird version. Hm... (There's also https://bugzilla.mozilla.org/show_bug.cgi?id=1518025 to port that functionality into Thunderbird itself, but it seems to have possibly stalled a little?)
You are 18 months behind on security updates for an internet-facing program. You are vulnerable to RCE, as CVE-2019-17026 is actively being exploited (among others, as the most recent example).
Is your email address mentioned anywhere online? Public Git commits? Do you ever see spam in your client?
In 2020 it is unfortunately simply not valid behaviour to use old versions of software,
Re: CVE-2019-17026 - Mozilla themselves state that it affects Thunderbird, but you're right, these JS issues might not be possible to exploit with just a malicious email as the attack vector.
So how about CVE-2019-11703, CVE-2019-11704, CVE-2019-11705 (aka MFSA2019-17)? It's a serious issue that gives RCE in Thunderbird 52.9.1. Is this issue reachable from an *.ics attachment, or will something happen without interaction if you have Lightning installed or receive a malicious calendar invite? This is still quite new and the bugzilla is still private.
CVE-2019-11713 gives RCE if any embedded images are reached over HTTP/2, that seems very plausible. At least you have the defense that images aren't loaded by default. Do you ever load images in emails?
CVE-2018-18500 is an older RCE but unpatched as well. This one is really interesting - I don't know if custom HTML elements are rendered in emails, but this issue happens in the parser before rendering so it's probably exploitable, the HTML is always parsed at least.
Less interesting but still plausible are the ones like CVE-2019-11740 and CVE-2019-11709 and their ilk, there's a new one of these with every Firefox platform update where nobody has (publicly) researched the details, but the patch is there for reversing so given the economic calculus I'm sure someone out there has put the effort in.
And finishing off with CVE-2019-11707 and other Javascript things like that, if you have any extensions installed that can be convinced to call the affected function in an exploitable way. If you're stuck on 52.x it's likely for extension reasons, and it's also likely your extensions themselves are no longer getting updates and have their own attack surface.
Having looked into the list of CVEs more closely, this is an impressively short list for a 18-month old version of any program (skipping over all the XSS issues and sandbox escapes). But I would give up extensions in a heartbeat versus trusting my personal email account to any one of these.
Given the way I use Thunderbird, none of the disclosed vulnerabilities affect me, so I'm not terribly worried at this time. Should one appear that does affect me, I'll reevaluate what I'm doing.
> In 2020 it is unfortunately simply not valid behaviour to use old versions of software
How true that is depends on the software and your use of it. Should the old version of TB pose an unacceptable risk, then I'll move on to something else.
Can anyone offer insight on what this means? My assumption might be some sort of for-profit endeavor?
> Ultimately, this move to MZLA Technologies Corporation allows the Thunderbird project to hire more easily, act more swiftly, and pursue ideas that were previously not possible.
Not sure how a different legal structure would solve what sounds like an organizational problem.
https://en.wikipedia.org/wiki/Mozilla_Foundation#MZLA_Techno...
I'm interested in more clarification on what this change "actually means" as well.
The non-profit Mozilla Foundation had many rules about what we could and could not do. The new Corp gives us more freedom, legally.
...unless there are plans for profit and charging a subscription or some such.
Thunderbird will now be under MZLA Corporation, which is owned by Mozilla Foundation.
Why not put it pack in Mozilla Corporation? Because Mozilla Corporation has tried to jettison it a few times for not aligning with their goals, I guess?
That's uncomfortably vague.
Hopefully this doesn't mean we end up with pocket on our thunderbird home screens.
Nomen est omen?
"Mozilla Messaging (abbreviated MoMo) was a wholly owned, for-profit subsidiary of the non-profit Mozilla Foundation. ... Its main focus was developing Mozilla Thunderbird, the e-mail client developed by the Mozilla Foundation. It was spun off from the Mozilla project in 2007; on 4 April 2011, it was merged into the Mozilla Labs group of the Mozilla Corporation." (https://en.wikipedia.org/wiki/Mozilla_Messaging)
You need to setup an Entire Separate For Profit Company for a different product?
Why ? Months is an eternity on the Internet.
edit: aye, aye for the downvotes, that's what karma is for, but would someone please explain why more information about the future direction of Thunderbird can't be shared now ? Does it mean there are no plans at all at the moment ?
Not giving people what they want will drive them away, which is the worst way to keep something open. It’s not like you need proprietary binary blobs to support Gmail...
Now only JMAP exists as a more modern mail standard.
Also think Thunderbird should implement JMAP (Fastmail standard) and/or Google RESTful gmail API because these are open standards worth supporting.
Another feature that I would like to see more fully supported in Thunderbird (through better synchronization with mail provider server back-end) is editing emails, to include most importantly the ability to remove bulky attachments without losing email text or touching important meta-data. Unfortunately gmail treats each email as an immutable object, and the hacks that have been suggested to date to work around this limitation have all been clunky at best.
I am afraid when we start adding gmail specific features at certain point google makes compatibility breaking change and becomes email. The people not using gmail will have to start because of network effect and email died.
Integration with the big <whatever>s instead of supporting and insisting on open standards is the antitheses to the open web.
I would love to use providers that support open standards. I don't have that luxury at work and suffer everyday when it comes to emails and calendaring.
I would rather that they worked on the stability of their IMAP code (maybe rewriting that part of the codebase necessary) and fixing performance issues in general.
https://assets.mozilla.net/annualreport/2017/mozilla-2017-fo.... See page 7.
Mitchell Baker was paid $2,458,350 in 2018.
https://assets.mozilla.net/annualreport/2018/mozilla-2018-fo.... See page 7.
Mozilla has not released their annual report for 2019, yet.
Almost like vultures who are skinning a company while they still can, emptying the bank account knowing that eventually they'll get fired for poor performance.
CEOs don’t set their own comp.
But apparently it's run like all the VC-backed companies.
OP's point still stands though. Mozilla spent millions acquiring Pocket. They also made it so users can't disable it as a plugin like they used to be able to.
If you want to make an ex-Mozillian shudder, sneak up behind them and whisper "Context Graph" in their ear.
X here is 3.