1: Start up new email (for me it was Fastmail) and preferably get your own domain
2: Forward all mail from gmail to your new account
3: Create a rule that flags messages that are still delivered to gmail, go through them at your leisure and swap to the new address
Also, make sure you take backups of your old emails every once in a while. Google Checkout should be able to provide those.
Renew your doman for 10 years now, and then every next year do 1 year renewal. If you forget it then you still have 9 years of buffer.
Another alternative is using one that accept recurring payments through PayPal; that way you would have to handle card expiration only with Paypal.
Beyond this, I've had a few pretty good ones over the years... right now, I've got about 30 of them, and just keep thinking I should let most of them go.
Source: it happened to me last month (the provider being OVH).
Most registrars are going to send you multiple emails leading up to the expiration, when it expires, and after it expires reminding you it expired. You'd have to miss a lot of emails.
And once it has expired, you have (depending on the TLD) over a month of grace period where it's not available for general registration where you can still renew it. You'd have to miss the fact that all of your services were offline for over a month.
It’s actually hard to lose a domain if you have a good registrar. There is 90 day quarantine period even if you cross the renewal treshold. You can also domain lock, which means you need to manually unlock a domain before moving.
Even if you decide to keep Gmail, you should switch your email to your own domain.
Here's a blog post about this nightmare happening to someone: https://medium.com/@N/how-i-lost-my-50-000-twitter-username-...
The security of your identity will depend on your registrar, your DNS provider, and your email provider.
The domain registrars are generally a race to the bottom and focused on "add-on" sales as most people are shopping on price and that's going to reflect in the overall quality of the things that most people don't really notice like, y'know, security and validation.
You don't hear a lot of stories about Amazon/GCP/Azure handing over someone's entire account based on a couple digits of a credit card number and it would be a PR nightmare if they did (hell, look at the flak they catch just for the data that people leave public on their services that ends up released... imagine if they handed it to someone). An active account with 2FA/etc enabled and a secure recovery email is probably safe enough for most people.
Spend the extra couple bucks to register through one of those guys instead of JimbosDiscountDomains.
Doesn't that bring us back to the same potential problem though?
I recently trialed hosted email with AWS and while it is very basic it only costs 4/user/month - cheaper than my google apps service. I was also able to register a new domain at market rates and get dns automatically setup (I think?) on AWS as part of the service. Now because I tie my monthly AWS spend with my registrar I'm more confident I can get some customer service as well.
staying inside a vendor's ecosystem for very selective services can actually work out quite well, as long as the seller/customer incentives align and they are relatively commodity services.
The main issue raised several comments up is portability. No provider locks you to only using their email offering/cloud offerings if you register their domain through them. Even if they did, transferring domains is trivial and well-supported everywhere.
As far as any other objections people usually raise around using hosted email and the like, a domain really has no comparable privacy implications in the real world (you're not handing Google or Microsoft a huge corpus on your life). It's also through their enterprise offerings where as long as your bill is paid they're generally not going to have some automated review suspend your account with no reason, and if they did they have actual support you can get in touch with.
This solves basically all of the problems with using an @gmail.com/@outlook.com/etc email address.
(Disclaimer: I work at such a small registrar. No, I’m not going to tell you which one; we aren’t targeting the global market, anyway, only our local area.)
The requirement is being able to switch email providers, especially google, when they lock your account. You don't secure your flow of email with a domain if that domain is managed by google, too.
To attempt to actually answer your question, I believe the nature of the governance around registrars would ensure you have recourse to transfer your domain in the case that Google be Google. It might not be slick. I don't know. But, it's unlikely they can override the overarching policies for such things and continue being a registrar.
While I am aware that Google tends to have quite a few false positive account bans, it is one of the most extremely unlikely things to happen, if all you do with it is pay for your domain registration.
EDIT: Oh daaamn it looks like they did it! Huh, faith restored. jgc, CloudFlare should follow!
EDIT 2: I'm just full of failures today, CloudFlare supports U2F as well. This is great news all around.
There's also the risk of Google shutting down your account because you do something they don't like. This will lead to a similiar outcome and you won't have any recourse.
I've started using @mydomain where the is the website/service I've registered for... doesn't help with my existing stack though.
Unless a client wants to use google docs I‘ve never found an account to add any value anyway. I don’t use google search much any more but when I do it works fine without cookies.
And I try chrome occasionally (it’s needed to use google docs) but it uses too many resources to use as any kind of default. It’s also harder to enforce privacy with it.
As personal servers of course “critical“ is pretty idiosyncratic, though I have used them to start and host various companies overnthe years until it was worth giving them their “own” hardware and identity.
I admit the age of managing a rack full of servers in a colo has largely passed.
Do you pay for Google Domains, or just have some other thing forwarding to gmail, and gmail configured to send with that as a 'from' address, which I think is possible? What's your advice?
https://github.com/ProtonMail/ios-mail/pull/16
As I understand it (and don't quote me on it) they're in the middle of a refactor, so I guess I get it.
replying to emails, I can change <randomtag> to whatever I want.
They also offer random domains that you can setup burners under, though that does involve some ahead of time setup.
Many programs won't even automatically reply from the same alias the message was received at.
No support for U2F (FIDO) keys[2].
No support for sending SMS to phones.
In comparison, my Google account is protected with: (a) three distinct U2F FIDO keys that are stored safely in different countries, (b) three separate phones for SMS authentication (my phone, dad's pone, mom's phone), (c) lastly there's the authenticator app which I rarely use. This is so much more versatile and reassuring that ProtonMail's extremely-mininal 2FA implementation.
Also, ProtonMail has no excuse for not supporting SMS-based 2FA. They can send a SMS to your phone, when you setup a new account -- but for some reason can't do this for 2FA. Despite being a paid service, they trying to save on the SMS charges that SMS-based 2FA would incur?
[1] https://protonmail.com/support/knowledge-base/two-factor-aut...
I see https://news.ycombinator.com/item?id=18008062 from 2018 where the jury seemed to overall favor FastMail.
I try Firefox with a fresh install on nearly every major release and I keep it installed as a secondary browser, but I can never manage to use it as my daily browser. For whatever reason, none of my company's (major tech company but not a competitor to Mozilla in any way) internal web pages load in Firefox. No error, no warning, nothing in the console, just zero content. Blank page. I've tried it on two computers with the same result and just nothing. No extensions installed, nothing I've installed on my network or computer to block anything. It just doesn't load anything.
On the other hand I keep Firefox installed because Chrome refuses to load my dev environment with a self-signed certificate. Firefox will let me click "I accept the risk" but Chrome just refuses to load with a self-signed cert.
I'd love to use just one (preferably Firefox) but I guess the web is still hard to get right.
Are you sure you aren't sending HSTS headers that demand the site be TLS in some way?
Also, have you considered the slightly-saner way of doing it, which is making an internal self-signed CA, trusting that internal CA, and then having it sign the rest of your "self dev stuff" certs?
If it was not HSTS you can click through a non-obvious button in both.
macOS operates in a similar way. I really like how the difficulty increases depending on the task:
• Want to allow one app through Gatekeeper? Instead of double-clicking the app icon directly, right click it and select "open".
• Want to turn off Gatekeeper for all apps? You need to open the Terminal and execute a command.
• Want to turn off System Integrity Protection? You need to reboot your computer into recovery mode and execute a Terminal command there.
You probably shouldn't be using an opensource project without at least a cursory glance at the code anyway, especially as a power user.
<key>Disabled</key><true/>
under the first <dict> and then unload each file, e.g. launchctl unload ~/Library/LaunchAgents/com.google.keystone.*
The auto-updating stops and stop them reloading after a reboot/logon.I don't think that's a bad way to go about it either, if it's sufficiently buried.
I'm primarily just thankful there's a workaround, hidden or not, given how many tech companies seem to respond to these things by disallowing them completely.
Just put it in the manual. If experience has taught me anything, it's that "normal users" never read the manual.
Firefox continues to do a good job of just letting me visit the damn website after warning me.
Both examples on latest current, taken right now:
Firefox: https://i.imgur.com/4VMjDZ4.png
Chrome: https://i.imgur.com/YosvXEu.png
For HSTS, both Firefox and Chrome act identically and do not allow clickthrough: https://i.imgur.com/WPCTep1.png
It did work in Chrome. And then after an update it didn’t work anymore. I don’t know why and it seems like no one else here does either.
Have you tried disabling the tracking protection, maybe it's mistakenly blocking some JS?
Other thing they could be doing is adding certificates to the Windows certificate store, that Firefox does not trust. Though I expect you would see an error about invalid certs in that case.
https://security.stackexchange.com/questions/133254/how-does...
Nowadays, everywhere gives you plenty of space, but for me personally, it’s just been the fact that I’ve been using it for so long and switching is a hassle. I’m sure it’s the same for a lot of other people, and for the majority, they probably also don’t care enough.
Pretty sure Hotmail (which at the time was like 20% of all web traffic) was still offering a whopping 2MB of space when Gmail launched. It was only after Gmail came out that they started bumping the quota from where it had been since the mid-90s.
Gmail was a HUGE deal. People were going nuts over the invites.
It has a full QWERTY keyboard and reasonably well working Sailfish OS port.
I will very occasionally find a site that's broken in Firefox and works in Chrome though.
One day I noticed that some of the stuff I blacklisted (mostly ads) started showing up again.
Why? Firefox's new DNS over HTTPS was bypassing all my firewall DNS rules.
A misstep by Firefox, though it was done with genuine intent to safeguard users (as opposed to just being spun that way). Though they've walked it back it still needs to be opt-in or be trivially easy for average users to opt-out.