I don't think it means they're interested in tying accounts to a specific identity, just an identity, to prevent bots or bad actors from signing up for thousands of accounts. This is a necessary reality of being an email provider. If you do not police your outbound mail then other mail servers will block or auto-junk your users' messages.
There is no way to preserve privacy while also not becoming a festering ground for Viagra spam mail.
Disclaimer: using protonmail until my current subscription runs out, then selfhosting
Self-hosting at least means that this should not apply, I think.
Sure. But I'm not worried about someone who has an actual warrant for ME getting at stuff.
What I want to stop is some random law enforcement idiot from Dipshitsville, Texas, from sending an electronic request to Google for "every email with the word "abortion" and "protest" in it" who promptly turns over all my email.
If you want my email, you're gonna have to get up off your chair, file a warrant with somebody's name on it in front of a judge, crossfile in some different legal jurisdictions, and have someone come seize my machines.
That will stop most everybody short of NSA.
If your threat is the NSA, you're screwed anyway. If they can't get at your email legitimately, they'll just fabricate the evidence they need against you.
The NSA doesn’t need evidence; you must have them confused with the FBI.
Right now only hotmail bounces mail. Am using DO/Singapore. Other centers fare better.
My server is a "Mail-in-a-Box" running on a DigitalOcean VPS.
That way no one reads the emails sent to you and the ones that you send get through (and outbound privacy is not expected if you are sending to gmail or another provider anyhow).
That also makes it harder to track conversations and would take manual work to recreate the conversation threads.
This is completely not true. Comes up every time there is a thread related to email. Every time many of us who host our own email servers will explain how it is not true. You can absolutely self-host your email server for your domains, configure it correctly and it will work fine.
gmail has a huge false positive spam identification problem, but it applies to all emails, even those from gmail to gmail.
Excision Mail which runs on OpenBSD hits the majority of what you need technically. https://github.com/Excision-Mail/Excision-Mail
The bigger problem is finding a hosting provider that hasn't had their entire space blacklisted.
For that, you're likely going to have to pick a "responsible" provider, have a couple of rounds of back and forth with them to prove you're neither an idiot nor a spammer, and ask them to manually open the port for you. And they're going to demand something that will tie to identity.
From talking to other people who tried the same, my theory is that the main reasons for my success were having everything configured well from the very beginning, running on a single static IP for multiple years, hosted at reputable mid-range server provider (not the cheapest, not the most popular) and not sending any "broadcast" email whatsoever for a very long time.
Does anybody else find that weird?
“I completely misunderstood Swiss privacy laws and fell for a sales pitch from an email and VPN company that goes out of its way to track every user no matter how they sign up! Its to avoid email abuse, exclusively!”
And why is that again? I want to understand that argument.
In case of DDoS scenario: Well, too late, traffic already served and server already done the workload.
In case of password brute forcing: Well, then implement a latency, or cryptographical challenge to delay it more efficiently.
In case of "evil" human: Well, if a human can get past your security so easily, then your approach to security through obfuscation might be wrong.
So, again, what is the scenario where a captcha helps you to avoid being "attacked" by malicious actors?
My question is related to the specific /login page, not the registration page.
I understand the benefit for blocking spammer signups, but not for the current case of the login page where users have an account already, were verified that the account/password was correct (captcha appears in second step), and then have to enter a second decryption password manually.
In that scenario there's no argument on the "WHY" a captcha helps. It simply doesn't.
The only reason I can think of is because they want more unique identities. More unique people means a greater chance for a purchase. More mail accounts just cost more.
The entire business model of free accounts requires someone paying for something extra. By unique identifying people they can limit new accounts and increase their chances of an upsale.
What if they changed how they operated. Instead of looking for more unique identities why not accept multiple addresses and include an ad at the end of every free email letting the receiver know this came from protonmail. That would give a benefit for each email sent and provide more advertising and give users a reason to upsell?
My guess is having that ad after every mail would bother you (the customer) more than having your identity uncovered.