New ProtonMail
protonmail.com
protonmail.com
PM also blatantly lie in their advertising. They cannot provide end-to-end encrypted mail because limitations in existing email protocols prevent it. All they can do is quickly wrap the contents of your mail in encryption once it has arrived.
With Apple now starting to offer unlimited email aliases to their premium users, I think ProtonMail will fall behind by only offering a handful.
But the lack of wide deployment of PGP is not their fault, surely they can't be blamed for that. It offers you the functionality and makes it quite trivial to use, assuming the recipient actually has a key. That's your contacts' job really.
True universal E2EE e-mail between people was something that Estonia tried by giving everyone access to S/MIME. Clients sucked and still suck in that aspect, it was rarely used because of that reason. The functionality no longer exists. Way ahead of its time I guess.
Most services offer either pre-paid subscriptions where you buy say a year upfront and it doesn't auto-renew and/or some auto-renewal where they charge your credit card at the end of the previous billing period. If you decide you don't want the service, you can, in the first case, simply not renew and in the second, you have to cancel but you're made quite aware that your credit card will be charged.
This is not the case however, with Protonmail.
With Protonmail, you can go through the whole checkout process without saving a credit card, which one would assume means the plan is prepaid, as it would be basically anywhere else on the internet.
But it's not possible to have a non-recurring payment on Protonmail. If they don't have a credit card on file, they'll put an "invoice" (what I not-so-fondly prefer to call a ransom) for the next billing period on your account, which they expect you to pay. If you don't pay, they block your _entire_ account.
If, for example, you buy a year of ProtonVPN to try it for a while and end up not liking it much but also don't think it necessary to explicitly cancel, at the end of the year you'll get an "invoice" for an entire year of ProtonVPN. If you try to ignore it, your Protonmail inbox will no longer be accessible. If you leave it for several months, you'll be forced to pay for them, even if your entire account was locked and services inaccessible for that time.
I've talked to support but they show zero sympathy.
The whole billing model feels like a malicious scam to me.
>U2F
Supported by FM desktop browser app, works well.
>unlimited email aliases
Yes, but the FM GUI does not scale. There's a linear list, access to it reached by picking through layers of UI salad down from the top view. List presentation is bulky; ordering by order of creation, only.
[0] -- https://www.fastmail.com/help/receive/addressing.html
They are considering their core product to be an alternative to the full Google Suite.
ProtonMail relies on a subscription model, which means that users upgrade to get additional storage, more custom domains, priority support, etc. Because our users pay us to protect their privacy, our financial interests are perfectly aligned with theirs, and unlike adtech companies, we have no incentive to collect data on our users.
You misunderstood something, end-to-end encrypted mail just works from a proton to a proton address.
>Messages between ProtonMail users are also transmitted in encrypted form within our secure server network.
https://protonmail.com/security-details
But yeah, the free storage is a joke and the complicated add-on pricing too. Calendar and imap on the other-hand is pretty important for me.
BTW: When did Apple open-sourced their email server?
With regards to IMAP, we offer Proton Bridge, which enables the integration of your ProtonMail account with email clients such as Outlook, Thunderbird and Apple Mail.
This is no longer email, it's a proprietary messaging platform. They offer email to other email providers, and encrypted messaging to other protonmail users, and they bundle both message types into your email inbox.
Signal could bolt on an email transport to allow you to send and receive emails from Signal and that would be the same: communications within Signal would be encrypted, communications to external email servers would not be (any more "encrypted" than, say, gmail is).
mail root
subject: restart server
blabla
ctrl D
No, I am aware of this, but PM's advertising lies by omission.
>When did Apple open-sourced their email server?
I'll counter this by asking when ProtonMail open sourced theirs.
Show me that advertisement.
>I'll counter this by asking when ProtonMail open sourced theirs.
Yes the whole infrastructure:
Look at the landing page. It clearly advertises end-to-end encryption and claims PM cannot read your emails, which is false. It does not mention that E2EE is only available between PM users.
>Yes the whole infrastructure
Don't move the goalposts. You said the server. Their server is not open source.
How so? The storage is encrypted with a key they don't have. They can read all of the non-encrypted email traffic that passes through their servers, but that's true of any router in the path of nearly all email traffic as well.
They don't have the ability to decrypt the store of emails. This is valuable because most email hosting providers are one hack or subpoena away from being a massive info dump of all of their users.
Details are important buddy:
https://protonmail.com/security-details
The Server part is Linux, Dovecot, and Postfix.
Look here https://protonmail.com/support/knowledge-base/what-is-encryp...
It clearly states what is encrypted.
To the extent that PGP is E2E, it's available between anyone.
Apple use Postfix as an MTA for iCloud.
iCloud has an MTA?
You can E2E encrypt the body of the message with GPG, I don't think the protocol prevents it.
Based on my understanding, that claim is for people who use ProtonMail to email other ProtonMail users. In that situation, emails are indeed end-to-end encrypted, without you having to encrypt the email content yourself, first.
I had to complain on their subreddit AND twitter for them to do anything about it and to this day I still receive notifications to backup emails that "I've received a new message in my protonmail account" but cannot actually access said protonmail account.
For now, I've just resorted to hosting email on namecheap and AWS, DO NOT consider protonmail as a "secure" stand in for gmail - it's flat out not worth it and their support is basically non-existent.
It would be good if there was a better alternative than self hosting.
Anything I'm missing by not being on Protonmail?
https://protonmail.com/blog/zero-access-encryption/
If you're saying they could change the functionality to reverse this or backdoor it then erm.. yes.. maybe.
I guess if you're not going to trust anyone (and personally I'd trust ProtonMail based on their honest blog posts, security responses and response to security blog posts criticising their work) then you'd want to self-host. But I'd argue at that point email isn't the solution you're looking for.
> Someone using a Gmail account sends an email to a ProtonMail account. When it arrives at ProtonMail, our servers can read that email because Gmail does not support end-to-end encryption. However, after receiving the email, we encrypt it immediately using the ProtonMail account owner’s public encryption key. Afterwards, we are no longer able to decrypt the message.
It's noted that they can potentially read it but they encrypt it right away. I'm not saying that they have the functionality to read it in that step, I'm saying they could add it if they chose to. It's their code, after all.
> I guess if you're not going to trust anyone (and personally I'd trust ProtonMail based on their honest blog posts, security responses and response to security blog posts criticising their work) then you'd want to self-host. But I'd argue at that point email isn't the solution you're looking for.
I think you're reading too much into my post. I'm saying that the potential exists for the provider to read the messages, simply because email is a plaintext protocol (outside of things like GPG and S/MIME which I insinuated but didn't actually mention). I do, however, agree with you that if you don't want to trust anyone than other solutions would be more beneficial.
My favorite thing about the new v4 interface is that it makes the settings mobile-friendly. My Filters (eg send all emails from x to Archive) can be easily updated from my phone. I couldn’t do that from Outlook or GMail.
PS to those holding off on Protonmail due to lack of support for catchall on your custom domains on the Pro plan, I recommend ForwardEmail.net. It’s free, privacy-focused and has worked perfectly for me.
I like ProtonVPN, no complaints about that.
I like their web interface in general, but having a combined email and calendar app for both iOS and iPadOS, with email/calendar auto calendar entries would be fantastic.
I mean, to provide semantic understanding of content, they need to read content, and the value proposition of ProtonMail is that it is E2E encrypted, i.e. they can't read your mail.
Or wait, now that I check again, it changed... I see that now I can have "1 - 5000 users *" for 6.25 eur/month? Is that real? A real inbox per user? Why is it only 6 users when I go to 24 eur/month? Do they mean aliases? I think they used to mean aliases... I'm confused now.
* Customizable features (:S)
Prices I see are a little bit different from what you are seeing but the pricing structure should be the same.
Is this true? Is this a service mainly for people who are emailing other people on similar services?
I don't have experience with the protonmail's bridge, but so far I haven't experienced any outages or slow behavior.
I use a custom domain and I think protonmail and fastmail are feature parity in this area. Protonmail just offers fewer domains and addresses at a given tier.
PM’s interface by comparison is significantly clunkier and more expensive.
You can either get your recipient to get their own ProtonMail account (for free!), or use a protocol that was designed respecting security and privacy in the first place i.e. don't use any email service.
You can in theory get transparent pgp e2ee using two MUAs on separate PM accounts communicating with PM via PM Bridge. But it's simpler/easier to just use their web front end. No configuration/installation of MUA or Bridge required. At least this way you don't end up with a plaintext copy sitting in your MUA's outbox. In essence the encryption is applied one hop too late (by the Bridge) if you're concerned about the security of your client endpoint or filesystem.
This is a good resource: https://protonmail.com/blog/protonmail-threat-model/
Their open source software is used in other contexts as well. For example, their OpenPGP.js project is used by Mailvelope to add PGP to generic webmail.
Also, AIUI, the fact that their accounts are free makes the service attractive for spammers, so email sent via their mail servers tend to get marked as spam.
I have since moved from Gmail to Fastmail and like it quite a lot. Any reasons for why I should reevaluate?
Fastmail costs money, yes, but there are other free alternatives now like Tutanota, which I surmise has the same issue in regards to spam.
That was DDoS extortion, wasn't it? Probably cheaper and much faster than buying mitigation, I'd suspect they've improved in that aspect by now.
> Also, AIUI, the fact that their accounts are free makes the service attractive for spammers, so email sent via their mail servers tend to get marked as spam.
Not by any normal service provider.
When researching what email provider to choose a few years ago, I found a lot of tales about it being a haven for spammers and with the baggage all that entails, but maybe that was pure FUD? Difficult to tell in my position.
There's simply so much more lower-hanging fruit for spamming. Why deal with the mess that is signing up and all that jazz? I'd say it's definitely a risk, like with all other providers, but not more so than with others.
That depends: are you cool with google reading your emails and selling the content to advertisers?
With regards to abuse, we've invested heavily and improved the rigor of our anti-spam measures, which have been largely successful in combatting abuse.
One critical differentiator between ProtonMail and Fastmail is that we have zero access encryption, which means that we cannot read or access your inbox, providing a higher level of privacy.
I can't find this option if it already exists.
Also, and I understand this is a reach, but if you could please ask you engineering team to rewrite the whole front end in htmx, that would be great. :)
And, if I do really want to understand how email works and how to get the perfect setup for me, what's a good introduction to read?
E-mail is generally very shitty to set-up, quite often because the software is just incredibly shit. It's easy to footgun in subtle ways.
Spam filters and spam filtering add an another layer of complexity that requires a reasonable amount of effort, building up reputation, flawless sending. Good luck if you ever end up on a blacklist.
I'm not saying it's impossible, some all-in-one product _might_ work and _might_ not be high-maintenance. Things like maddy sound very promising. But I'd be wary, especially when you don't know much about e-mail it's difficult to detect potential issues as well.