Ik.me: a free email address for life developed and hosted in Switzerland
infomaniak.com
infomaniak.com
There is no such thing as free. They’ll nag you for hosting on their site. UI will degrade over time. Something will give, if not now, at some point in the future. Lifetime is a bold claim. I’m being cynical but this smells like an attempt to get a whole lotta buzz.
I also do not buy the Swiss marketing. You know how you know a company is Swiss? They’ll tell you. 100% of the time, every time.
That said, I think Swiss laws are great and immune to a lot of bullshit.
Edit: I meant free in absolute sense. There are some relatively free things out there. For example: readthedocs.org, but runs on donations from big companies like Microsoft. Same with GitHub (free private repos after Microsoft acquisition). Perhaps Ik is big enough to afford to build goodwill through free email? I know Apple is getting a lot of flak lately, but iCloud email is also “free” and not adtech driven.
I wouldn't say companies like this come and go: Infomaniak was my first (dial-up!) internet provider in 1995 and I still have my email there. Back then they used to be a small computer shop ran by passionate hackers in Geneva, organising demo scene competitions and such, and now and they grew up and are one of the biggest and most interesting internet company in Switzerland.
How about this then: Free services come and go?
Most recent example: Google Photos. Google isn't going anywhere, and neither is Photos. But free unlimited storage forever is definitely going away, even though it was _the_ distinguishing feature back when it launched.
The more you get for free, the lower the chances the provider will be able to cross-subsidize the free tier from the paid ones (and/or make enough money from ads/selling your data) in a sustainable manner.
Unlike crashing on someone’s couch, for an actually very insignificant amount (and a nonzero quantity of technical skill), you can own actually own the domain and the email server and not depend on the charity of another, and not be even possibly inconvenienced someday by the service ending when someone turns out the lights on their way out.
The cost of maintaining such a service is also minimal, but nonzero and can be an intimidating feat to attempt. The alpha nerds will beat their chest and state that they are so technically inclined that this approaches zero for them.
I believe the worst problem here is spam. Google grew that much as email provider also because they have among the best filters out there, but what about different servers on small hosting providers? Security issues aside (I assume their sysadmins know how to setup a safe email server), I've planned that route many times and resisted because having to fiddle with constantly changing spammers lists is something I really wouldn't want to waste a minute on.
> That said, I think Swiss laws are great and immune to a lot of bullshit.
In 2016, people voted in favour (65.5%) for giving mass surveillance power to our intelligence service [0]. And we also did it before it was cool (and legal), so trust us, we are good at that [1].
[0] https://www.admin.ch/opc/en/classified-compilation/20120872/... [1] https://en.wikipedia.org/wiki/Secret_files_scandal
[0]https://www.swissinfo.ch/eng/voters-say-no-to-longer-holiday...
[1]https://www.admin.ch/gov/en/start/documentation/votes/201806...
Absolutely!! And the politicians said: But to all the young peoples..don't fear that's the only thing we do, it's to prevent excessive/addicted gaming.
And funny enough, now we have 10x more advertisements for online-casinos but Swiss based (probably we should talking about that addictive thing again? And maybe micro-transactions in Games too?)
In 2012 they terminated the "free for life" status of all of those they had given out.
So yeah, it can and will happen.
I'm Swiss and i have to tell you that your 100% right!
Even the ~good privacy was slaughtered with the last Secret service law. The NDB (the Swiss CIA/NSA-komplex) has a really mixed past.
Started with the CryptoAG Skandal (aka never trust/buy Swiss security Products ever), the Data-leak (everyone had access to any digital datas...), and the Fichen-skandal (where the NDB/UNA wanted to be a bit more like the Stasi in east germany)
It might be hard to argue without suing, but legally there are provisions that if the AGB contain “surprising” terms, you have to be made specifically aware of them or they are invalid. There is currently a high-stakes case building because of this: Some of the epidemics insurances for restaurants had a provision that “pandemics” are excluded and won’t pay out for COVID-19, now restaurants are suing.
https://www.srf.ch/news/schweiz/epidemie-versicherer-kein-ge...
Also the lobby is really big...even bigger then the financial lobby:
https://www.nau.ch/politik/bundeshaus/so-viel-geld-pumpen-sc...
And that is the real interesting graphic:
Mailbox has been around since early 90s ive been happy user for a longtime.
You make good point that Swiss (German also) laws should protect your privacy more than US laws. That includes fastmail and icloud.
So, mailbox.org (my current mail host), posteo (they don't even allow custom domain!) and the like should be avoided. It's nothing but lock-in.
Because you will eventually start using it. the domain sounds very easy and tempting and it is easy to tell someone <4 letter name>@mailbox.org rather than <4 letter name>@<9 letter first name>.com.
They refuse to accept cancellations of their paid premium services for when the paid for duration ends.
They insist you to login the day the duration ends to switch to the free mode. If you miss the date (by not much), they say they'll cancel and reimburse you.
The intent of this scam is clear, they hope you miss the date and pay for one more year. However, they have absolutely no legal standing in refusing the cancellation.
I'm engaged with customer protection organisations against this scam by tutanota.
Theoretically you might save a bit with Fastmail - it seems like you can have 1 standard account that is $5/month and owns the domain and then other basic accounts at $3/month that have an alias for the domain, but I don't know how that works in practice. For a large family the savings could add up.
Now they have changed branding and pricing so hopefuly its moving again.
But I’m using them for few years and never been happier. :)
Posteo [1] runs on green energy, and does support TOTP (in constrast to Migadu). 12 EUR/year.
EDIT: Posteo doesn’t have custom domains, total deal breaker for me.
We (Migadu) do support TOTP + Yubikey on the admin account. We also support TOTP on the webmail just like Posteo does. However, we call that B.S. ourselves and are working on a real solution for mailboxes.
If you do setup 2FA on Posteo, how is your e.g. IMAP access protected? They most likely offer an app-specific password which is very different than 2FA. We do those too, they are called _identities_ in our context.
We have a long and bumpy road behind and ahead of us, but one thing we made clear on day one is that we will not B.S. users. Email is not perfect, it has serious conceptual issues due its age, but one should not go about it as "there we fixed it!" (Hey hey.com!)
[1] https://security.stackexchange.com/questions/173807/does-ima...
I don't like such tone.
TL;DR I didn't verify how Posteo's TOTP works.
FWIW, I've never used Posteo; I have some German friends who are happy with it. I'm staying local, using Soverin as my primary e-mail provider.
The reason for using a token for authorization is that the user can revoke the token (e.g. when device is lost), instead of having to change their password. These are indeed not TOTP because they are not time-based, nor do they depend on another factor (ie. password); they replace that factor. It is indeed dishonest to call such MFA/2FA.
Its perfectly possible to get IMAP to work with TOTP though. For example, you can use PAM to authenticate, and PAM can use TOTP or FIDO2 (ignoring the issues with PAM every major OS barring OpenBSD uses it). We use something similar for OpenVPN because of requirement of ISO 27k1.
I don't trust webmail at all because I don't audit the JavaScript. Nor can I verify that every visit. Same issue with OpenPGP.js. Then again, I also don't trust e-mail authenticity because the protocol is broken by design, and nobody has come up with a suitable alternative. Which is why I wouldn't pay much for it; as I would not and do not use it much, since its fundamentally broken. For example, at rest and at transit there is not enough data integrity/authenticity.
A lot of people are using a weak password as first factor, btw. Do you protect against such?
Corrected, not intention to make a "tone", just pointing out that information is intentionally omitted.
> Its perfectly possible to get IMAP to work with TOTP
Yes, but that's not available in generally available email clients. There are OTP extensions to IMAP.
> I don't trust webmail at all because I don't audit the JavaScript
This. We are working on one that uses no JS or just conditinaly for enhancements.
> Then again, I also don't trust e-mail authenticity because the protocol is broken by design, and nobody has come up with a suitable alternative.
Glad I am not the only one thinking that =)
> A lot of people are using a weak password as first factor, btw. Do you protect against such?
No, we set a minimum 6 char password. However we think it is less secure to have a complex one you canot remember than one of average strength.
Cheers.
It seems we agree on a lot of things (though I believe 6 char is a bit on the low end for a password).
> Yes, but that's not available in generally available email clients. There are OTP extensions to IMAP.
With regards to TOTP, if IMAP server can auth via PAM, then you can use a TOTP extension in PAM (OATH IIRC). It does mean the user cannot auto refresh their e-mail as they'd need to enter the TOTP after a timeout again. If you combine that with the fact that people often use TOTP client such as Google Authenticator on their smartphone, then it doesn't make their smartphone with e-mail client more secure. It would, however, allow a user to use a YubiKey as authentication method.
You can use it free or upgrade with a fair tiered model.
Would recommend it anyone.
If you don't get a lot of mail hitting your inbox, it's not immediately obvious it's happened unless someone tells you that their email bounced.
I agree, which is why I've been paying for Pobox.com since 1996. $20 a year for three forwarding aliases of your choice. Fastmail purchased the company a few years ago but I've noticed no changes.
Has that changed?
I’m a fan of their HTML style which is perhaps why I like their browser based email app.
That said, I'm a very happy paying customer.
Here is the official commercial register entry of the Canton of Geneva. The company was founded in 1996: https://ge.ch/hrcintapp/externalCompanyReport.action?company...
And having family in Switzerland, I agree with OP: first you see the flag, then you see the company or product name.
There's no reason not to own a domain for your email these days.
https://en.m.wikipedia.org/wiki/There_ain't_no_such_thing_as...
Honestly, it depends where you are from.
Given that I am from Europe, when I host in the same country as I am from (ie. The Netherlands), I am only dealing with local law. The only problem I could have, is when I am dissident according to my country. I'm not though, and if I was I'd have to host in a country unfriendly to mine.
Fastmail is an Australian company. I don't believe Australia has strong privacy laws. EU, at least, has GDPR. For most people, The Netherlands is an excellent place to host your data.
If you consider non-US cloud services, you end up in Europe as well. For example Hetzner, Jottacloud, TransIP just to mention a few.
You should also ensure they use a local domain. For example, thepiratebay.org isn't local if you consider the service is from Sweden (and if its hosted in The Netherlands, neither is thepiratebay.se). Ik.me uses the .me ccTLD; Montenegro. Not a country known for its civil rights, AFAIK.
That being said, I don't believe in 'lifetime' either. Lifetime just means 'as long as we last'. Its a risk an early adopter takes to invest. If the service succeeds, yes they might have lifetime. If it fails, it was an expensive purchase.
Case in point: Emby. I bought a lifetime license. Then they changed to closed source in version 4, and it lead to me switching to the last 3.x fork, Jellyfin. License useless.
The weird thing here, is that they provide the e-mail supposedly lifetime and free. TANSTAAFL, so the default should be suspicion. They don't do advertising. What's their profit model?
[1] https://www.migadu.com/procon/
EDIT: Posteo is here: https://posteo.de/en
> Our whole service was built around the premise of giving email liberties back to the users, not taking them away. We refuse to fence users and lock them in.
This is a very interesting take! I completely agree with it. While it may not work for many but one of the biggest mistake I made was I've used <4 letter name>@mailbox.org extensively. But I am making an active effort to change that and remove it from use completely.
This is kind of a hidden lock in. Because there's no free email service unlike Tutanota where you can keep using email on their domain in reduced capacity.
Same for Posteo. It just doesn't make sense.
I will eventually move away from Mailbox. I will be watching Migadu. Though 20/day out can be limiting. Though it's rare I've sent 20 mails per day but there has been days when I did.
> https://www.migadu.com/procon/#no-mailbox-2fa-yet
I do not agree with the tone here. Yes, IMAP doesn't support 2FA but I'd want the Migadu control panel interface to be protected by 2FA. I like how Mailbox has handled it.
Foe example there's a 200 email per day "limit" on the cheapest plan, but each plan comes with a 25% tolerance.
Similarly the storage "quota" on each tier.
I just asked Migadu's support about whether there was a 10GB option available, as 5GB was too small for mea and 30GB too high / costly. "Sure," he replied in under 4 minutes - "there's actually no fixed storage limit on each plan, please see https://www.migadu.com/pricing/#how-do-storage-limits-work" And sure enough - 5GB, 10GB, 15GB... all would be possible on the "5GB tier".
If you get close to or exceed the 30GB quota of the next tier up, their systems contact you and suggest upgradng which sounds pretty reasonable.
I'm just going to check if Apple or Google are quite so accomodating...
Let's hope that the "modern rewrite" doesn't slow it down too much ;)
On topic - kudos for being free. There must be a threshold where a company that's "free forever" can be thought of as being there for the long haul, and I think 15 years definitely cuts it!
They are telling me for years to make a paid plan and that was always the idea. Maybe it's 15th birthday is good for that too.
With all due respect, you probably should plan around this. What if you suddenly die tomorrow? I'm not trying to threaten or scare you, its just that you (and your customers) should plan around this. An example of such planning which likely fits the glove for all readers here, is to have your private key or password at a notary.
It's ok, I did do this; like said above, the source (and all keys/access) are in escrow at a notary for the projects I run in case of bus-hitting. Also, I am not working alone, but yes, I will rethink this again as it was a while ago that this was arranged.
My (very brief, IANAL) intro to civil law in Switzerland covered an interesting detail in contracts: contracts (or parts) need to follow “good morals” to avoid being invalidated [0], an example of which would be that the contract shouldn’t bind the parties for perpetuity.
So this part of the contract couldn’t be enforced by the other party (the customer), while the provider actively advertised it. I wouldn’t be surprised if this would be seen as bad advertising and would lead to potential compensation for customers and competitors, if they stop providing the service.
[0]: https://www.admin.ch/opc/en/classified-compilation/19110009/...
Edit: added the English translation of the link.
Do we really care though? You can just scrap the company and do an other one.
An other option is just to change the terms, display a pop-up to users saying "Hey, our terms changed, do you accept the new ones?". You can bet 99.999% will click yes and not read the new terms.
In this case probably yes, that's what the limited liability is for in companies. Though if you have legal issues with the old company, some jurisdictions may not let you start another one (or at least be director).
If it's Google (Photos) or HP (lifetime printing) making the promise and driving competitors out of the market, I think it's a valid claim.
> An other option is just to change the terms
I'm not sure if that's an option if your customer has signed up under "lifetime" terms. While these parts of the terms they've signed up for are void, they could claim that they've had damages (costs or missed opportunities) by this "immoral" offer.
I love Switzerland but I will never use a Swiss host because you pay more and get less every time.
Currently restricted to Swiss citizens, this offer will soon be extended to the whole of Europe.
For further details: https://news.infomaniak.com/en/free-swiss-email-address/
Phone numbers are available to all residents.
https://www.infomaniak.com/en/support/faq/2144/blocked-order
Why not?
With the same reasoning you could deny selling people food unless they show you their government ID.
Would you consider such an abomination a country where privacy still exists?
If you strip people from basic anonymity for no sane reason they have no privacy.
If all you want is to prevent people from signing up infinite accounts then have them solve a bazillion captchas or pay a token amount of cryptocurrency, but don't ask them to connect their account to completely unrelated private information.
Email operates independently of cell phone numbers, so it shouldn't be required to connect yours to your mail address.
Example everyone can relate to: when you go to a doctor, they look at your medical history and in most cases you need an appointment first. This means your visit is no longer anonymous. However, I think everyone agrees that you still deserve privacy with respect to the details of your visit.
If that control is gone there is no privacy.
I vaguely remember Google making moves toward killing it, but last I tried it, Google Voice let you get a number without providing any ID whatsoever.
And only postpaid phone plans require ID in the US.
The US and aforementioned European countries (among others)/are better about this because anyone can just get a SIM/number.
Having your own domain gives you a lot of options to move your email around to the best deal and hosting at the time, companies are going to come and go and if you utilise free email a domain in front of it will avoid having to change 500 accounts on the internet when you inevitably have to move.
But in any case, Google shutting you off is much more likely than your registrar doing so.
It's a standard KYC-based e-mail service.
I would personally assess the risk of some damned stupid thing happening in the Balkans that loses them the domain higher than the same thing happening to a .ch address, and perhaps a bit too high for a service whose main selling point is for life.
[0]https://www.infomaniak.com/en [1]https://www.infomaniak.com/en/about
Notably, they provide[1] VOD and AOD for the Swiss French public radio and television (RTS), the French Belgian public television (RTBF), and the Montreux Jazz Festival.
[1] https://www.infomaniak.com/en/multimedia/vod-aod/audio-on-de...
Self hosted or paid is my first choice if at all possible especially for one of the most important services.
It is extremely hostile, yes.
https://www.swisstransfer.com/fr
i'm hosting a website and cloud server by them and quite pleased so far.
HN, please...
As such, this should not be on HN.