Your online identity is owned by your email provider (2019)
ctrl.blog
ctrl.blog
I run my own mail server because I am a sys-admin and running a mail-server is something I do for fun. but the amount of agency you gain once you have a domain is staggering. people without a domain are pretty much second class net citizens.
I wish municipality offered domains, for example: you move to St Louis you would get name.stlouis.mo.us this would give you the same agency online that a mail address gets you offline.
Also it's funny to see people react to their business name being in my email :P .
On one occasion, I was checking into a Hilton hotel and the employee thought I worked for corporate due to my email, hilton@domain.tld.
In the past, I used to explain to them how I control the domain and I have separate emails for every company due to spam reasons. However, this usually caused confusion so now I sometimes go along with what they think or hint that I'm some 'mystery shopper'.
And I had no way to apply for the government licence thing I needed, and the people on the phone suggested I use the website.
Unfortunately the bar is a bit high for most to realize most of this. I miss the days when your isp would offer web, ftp and email hosting.
It's quite another thing for email. While it might not be that difficult to set up a basic email server, but to actually get it set up all correctly, and secure, and whitelisted, and get anything else on the 'net to actually interact with it is a little less trivial. And an email server that can't effectively send email (that won't be ditched along the way by some anti-spam measure somewhere) would be pretty limited.
Maybe useful for receive-only stuff like password reset links or one-time authentication links though?
I work as a sysadmin and I don't want to bother with self-hosting my own email. I happily pay someone else to do that for me.
I have run some mailers (postfix) for some clients who didn't want to spring for a MAAS provider, I would to my knowledge, set up everything correctly with SPF, DMARC, DKIM, stuff would still land in the spam folder half the time.
Maybe still my mistake, maybe over eager receivers, maybe my hosts were just in a bad net block.
And this was just for low volume transactional stuff, they would add manual "not spam" rules which is OK for them receiving sub-LOB notices but really put me off trying to run my life out of a self hosted machine.
I saw someone post the Helm the other day, which is an interesting idea of having on-prem storage with an off-site dns/sig layer. Still kind of beholden to another service though - and I personally don't want to host my mail in my house but on a VPS. Did make me wonder about how viable a low cost "we just provide the DNS stuff" mailer service would be or if that exists.
This gives you full control of receiving emails (for the online identity part) and gmail can't lock you out of your life with no recourse. But you don't need to deal with outbound email handling which is a bit more work.
Basically your sending side (if you choose to) can be essentially unrelated to your self-hosted mail receiving infrastructure except in the small fact of using your sending identity in the From: headers of your e-mails: you@yourdomain.com.
Your me@isp.net address (or perhaps the me part of it) is used for authenticating, along with the password. It will likely be used as your envelope address when sending; the SMTP command will be MAIL from: me@isp.net, though there could be flexibility there to accept other sending envelope identities.
In any case, your mail's From: header will have the me@hn.com.
If the ISP were to filter on the From: addresses after receiving the content of the e-mail, you'd have to negotiate something with them.
Ah yes, doh.
A common problem with new mail setups is the receiving end marking your messages down because the domain is newly registered, as this is seen (correctly in some cases) as a potential spam flag. Nothing you can do about that one except double-check you SPF & DKIM config and wait.
One of many gotchas with hosting your own mail. I still consider it to have been with doing so all these years.
Well except for Gmail refusing to not put me in the spam box despite a 10/10 mail-testing score. Screw you Gmail.
I always found it weird that the US numbering system assumes that mobile phones are static. Must be some weird technical debt buried somewhere.
Including a city in the domain seems like it unnecessarily complicates things. If the goal is to provide free access to a more permanent online "identity", people shouldn't be forced to change it when they move.
Real overkill method is own a TLD. It's unrealistic for an individual though.
OP put own in quotes because of this.
Still, while horror stories with registrars certainly exist, they are vastly outnumbered by horror stories of gmail/et.al. locking people out for no reason and no recourse.
There is the ideal view that you should be able to have your own virtual island where absolutely nothing can deprive you of ownership (including existing govs. depending on your beliefs), and I kinda root for the people who try to push it as far as possible. But pragmatically, registering your domain goes a very long way and is IMO the best trade-off you can get without going crazy.
That potential is perhaps even greater with domain registrars and all the other service providers involved in email services (registrar, domain host, email provider). Any issue with any of these services could mean you're not getting notified of problems and you may no longer be able to get into the admin account.
And if you try to avoid that by storing a different notification/recovery email with them (if at all possible), it opens another can of worms. My main domain almost expired on one occasion because I didn't get the renewal reminders at the alternative address I had stored there years ago. I had simply forgotten about it.
And after I had canceled my legacy G Suite account recently, I received a message from Google at one of my old recovery addresses telling me that this G Suite (Workspace) account was going to be automatically upgraded unless I log in to check some box. Only I could no longer log in as the account didn't exist any more, nor could I contact support as that requires logging in as well.
Every single account I pay for requires some sort of constant monitoring and maintainance. Otherwise, things just degrade and access is eventually lost. That's why I'm not sure whether I would really recommend everyone rent their own domain.
Some people straight keep renewal schedules in their calendar like they do for anniversaries and tax filing deadlines. Funnily enough, registering domains at specific occasions makes it easier to remember to check the status (credit card registration etc)
At the core of it, I’m not sure it’s that different from anything you actually “own”. Someone “owning” a house would still probably get it seized if they disappeared for years without ever paying property and local taxes. Losing a house is pretty extreme, but to your point a domain name is also becoming a pretty big deal nowadays.
I do too, but will I still be using that same calendar in 6 or 7 years when the renewal comes up? The calendar is linked to some of the same subscriptions.
Australia kinda does this with their `.id.au` second level domains for 'Individuals (by real name or common alias)'
Not many folks use it or know about it.
Interesting, is there any links/documentation on this? Is it for every citizen or something?
It costs more wholesale than a regular .com, requires handing over PII to a small company and isn't subject to the same price increase limits.
Obviously won't work for everyone but I bought <firstname><lastname>.com instead and its 50% cheaper per year than the equivalent .id.au which should have maybe a few dozen other people in Australia vying for it with first/last name and I assume no one else with my middle names included.
john@smith.stlouis.mo.us? Who gets that first?
arkhramud@maprikhoychich.stlouis.mo.us? How hard is to trace a person from one location to another?
To fix this email problem abandon the email as an account identifier. Use a 'username', or as I do a random set of characters and digits. There is no reason my account (login) has to be indexed as "john.smith@example.com". It can be "SDf23wfwef". And, at an other site, it can be "hdf3gf0s", and so on.
I believe this would also reduce spam.
An alternative is to use what freenet used with your idea. Just issue sequentially lettered & numbered emails with aaaaaaaa.stlouis.mo.us. a through z and 0 through 9 would give 2.8 billion addresses just for stlouis.mo.us. Moved away? forward the email for a period, bounce (?) for a period with new address, then re-issue.
I just use the name of the service. So for example it would be github@example.com for my Github Account.
For some reason (probably a good reason) the internet can never be grounded, we always are going to stick to obscure formats that don't necessarily line up with real life and then get surprised when gov agencies collect that data and corps make money selling that exact data, out from under us.
Then what happens when John (who is actually John Jr., but never uses the Junior unless legally required) has a son John III? Then John Sr. moves in rather than to a nursing home.
Your physical home address used to get printed under your photo in the 1940s newspapers. They stopped when people started to get murdered. I think there's good reasons we don't publicly ID off home addresses anymore. It sure would make life somewhat simpler if we could though.
Citation needed.
Were the murderers foiled by having to use the phone book instead of the newspaper? Was it the lack of pictures that stopped them?
Its already unique and tied to each citizen.
Do you know of any resources that I can read to help me do it on my own?
It's increasingly becoming a hassle.. Especially sending mail from a "consumer" line is tricky, they block outgoing port 25 and no longer really provide a relay host for you to go through either.. I basically had to infiltrate my current ISP to get access to people in netops and gaslight them into configuring reverse-dns and leak enough info to me to get access to use their relay..
Back when I got my first ADSL, the ISP apologized for blocking port 25 and explained how to use their relay.. Things sure have turned sour in that regard.
To this end, I've become convinced that the only fair thing to do is make email a human right. Nation states absolutely should provide and host, e-mail accounts for their citizens. (it can be up to the citizens how they want to use these accounts, if they want to use them only for receiving mail from the state, or if they want to use them for everything else too).
Then redirect the SMTP port with a VPN to your local server, which can be anywhere in the world. You can run IMAP the same way if you want to.
On top of that, most people don't care (don't know why they should) and don't have the ability to host this infrastructure themselves, and frankly, they shouldn't have to either..
Because nation states are well known for producing usable software at a reasonable cost to tax payers? IRL this would cost billions and everyone under 60 would forward their gov’t mail to gmail.
The largest transfer of public property into the hands of private enterprise in human history was the Internet. At that time it was wild and limitless and full of promise. It’s pretty much stagnated from there.
Just like scientific and medical research, tech research is the most effective and has the largest societal benefit when done at public universities on the taxpayer’s dime.
counter-example: Bell Labs.
Also, is it good that Bell labs was the way it was? Americans seem to have quite a hard go with telecom, maybe not as bad as some countries, but from what I can see the country is riddled with regional functional monopolies, gaps in service, high prices for rural areas, and bad behavior regarding net neutrality on the part of ISPs. Perhaps the situation wouldn't be so bad if the USA had nationalized, or at least partially nationalized, its phone and internet systems?
Also, maybe I'm missing your point, but it seems very strange to say they internet was transferred to private enterprise. Private enterprise built on a government foundation, but almost everything that people use the internet for now was built by private enterprise, and the standards which constitute the most important contribution of the government were not, and are not now, under corporate ownership.
The ground was set by the Scientific and Advanced-Technology Act on October 2, 1992. This passed Congress with almost no debate. However, there were innovative politicians who attempted to allocate a certain amount of bandwidth for a public right-of-way.
The United States has very little publicly-owned internet infrastructure and few advanced digital public services. The USA also happens to lag behind other nations in simple metrics like the speed that ISPs deliver. Maybe it's a coincidence that many of these nations have more robust public services.
Not perfect, but better than what we have today.
Well, actually - yes? My country has lots of problems, but government-issued software is surprisingly good. I would have trust issues however after it came up, that they used Pegasus very liberally.
Yes, they are. The software, hardware, and automated systems underlying transit systems in Japan, Taiwan, some of the UK, and a couple other countries, continues to make trains not crash into eachother for just about a hundred years now depending on the system. I don't know too much about it, but it seems the same to be true for whatever runs the stoplights around town.
It's not always nationalized, but the software used to plan trash pickups and routes, bus routes, bus signage, sewer planning and control, shipyard signaling, and numerous other public works is at least tangentially taxpayer funded and government organized. Those seem to work pretty swell considering their level of complexity (at least in the countries I've lived in).
Here in Taiwan the government websites can be notoriously terrible, but some are really fantastic, for example https://data.gov.tw . There's also strict requirements for accessibility that are rigidly enforced, which is a nice thing you don't often get from private software (you have to depend on a disabled person suing a site before it'll be made accessible in the USA - abled people don't have "standing" it seems).
Honestly, it sounds like you're making a very generalized libertarian argument, and I don't want to risk a politics flamewar, but I'm really not sure what alternative you're offering for governments building software, that doesn't involve total dissolution of the government. The department of motor vehicles needs a website one way or the other, they're either going to build it in house or pay contractors to do it, either way, taxpayers are paying for the website, and any additional app-like online services.
Was there some specific examples you had of unusable software or unreasonably priced software that would justify such an extreme solution? Cause the dichotomy to me seems false: surely there are ways to improve the quality or reduce the cost of taxpayer funded software, if necessary? Surely that's easier than... whatever it is you're suggesting?
edit: Some other good examples of nation-state provided software in Taiwan, there was some fantastic contact tracing apps and backends implemented by the government. The UI was admittedly quite.. sparse, but it was undeniably functional and accessible. And, it came with strong guarantees about data anonymity, which you can never trust from a private company.
edit: I'm clicking through some various USA websites now and these all seem just fine to me. I guess the accusation is that they took too much money to develop? https://www.congress.gov https://www.vaccines.gov/ https://www.cdc.gov https://www.hhs.gov/
seems the same to me for the UK although their cookie banners are hilariously absurd https://www.nhs.uk/ https://www.gov.uk/
The only example I can think of for the US government attempting to offer something like that at scale was the notorious healthcare marketplace created for the ACA. It catastrophically failed at launch, took months to fix, and the people who fixed it were people who left private industry to do so for philanthropic reasons. If you read the story of how it came to be in that state, it's pretty much what you'd expect. Lots of different departments arguing, contractors coming and going, tons of coordinating meetings, budget overruns, finger pointing. This despite this being a crucial piece of infrastructure for the biggest health care reform in years. That pretty much set my expectations for how good at software the federal government is, but I'm open to hearing proper counterexamples if you can supply one.
Also, the instant payments network that you can use to send money from any bank to any bank in seconds from your cell phone, the PIX, is government software.
Also, I am a small company owner and I can access a lot of government web applications online using a SSO with my optional digital certificate, or I can login into them by using my banks identity services as an oauth provider. No SMS funky business.
If anything, it is the private banks, that while in my experience have far better software than American banks, that is behind. I, for one can use the same digital certificate that I use for fiscal purposes to access my vaccination certificates, but I can’t use yet on most banks.
Of course there is a lot of government software that is basically enterprise software, bad software, but a lot of it, and usually the ones that I need to use more frequently are pretty good. They may not follow the latest flat design fashions, but they are accessible, ease to use, responsive, safe and fit for their purposes. And mind you, we are talking about Brasil, not exactly a model of good governance.
Gov.uk
Because everyone utilises such systems, everyone has a vested interest in the privacy of such systems. Under liberal democratic governments, protections for privacy, security, and integrity are typically quite strong. Not inviolable, and you'll likewise find a significant set of criminal laws for crimes transacted utilising postal systems (mail and wire fraud, etc.), but specified and typically balanced.
Mind: that emerged over time, and a significant early interest of governements in operating messaging services was of course message intercepts.
That said, the early history of telegraphic and telephonic communications (both often privately owned and operated) is hardly much better. See the case of AT&T and the Republican Party swinging presidential elections, as told in Tim Wu's The Master Switch.
The thing is, all of these solutions are much maligned - despite being a lot better than what we had before (send/receive paper). If the state were to offer email accounts, people would complain about how bad they were (whether true or not) and argue that we should "let the market sort it out".
Which brings us to where we are now. With the market "sorting it out".
I know the NSA can probably do it but at least it’s somewhat gated to that intelligence community. Opening it up further is a recipe for disaster.
I do want to have an option to use other emails for my streaming accounts, shopping, and all the other stuff, so that I'm not required to use the same email address everywhere. I can rent my own domain name and use the email service tied top that.
That'd work for me.
The best time to use a custom domain name under your control for personal email was when you first started corresponding via email. The second best time is now.
Interestingly, running my own server in a data center lets me run a permanent, private VPN from my home network to the data center, effectively hiding me away from any monitoring from my cable provider, using the DNS I want to make use of, blocking traffic I don't want leaking out or coming in. I have a smaller, less capable server in the UK also running a permanent, private VPN. Depending on which WiFi SSID I connect to within my home, determines if I appear as being in the US or the UK, which gives me access to different streaming services, different streaming content, different website experiences, etc.
What do you base that confidence on? Short, meaningful names are valuable and there is no reason to believe that somewhere down the line they won't be recycling ones that aren't used anyway as premium accounts.
Nominet (.uk)
Whilst not entirely without controversy[1], they do allow any man or his dog to become a member[2], you only need to have "an interest in the operation of the .UK domain".
Nominet membership gives you the ability to maintain your names directly and bypass the middlemen.
The alternative (as others have already pointed out) is to write out a (very big) cheque to ICANN and setup your own TLD where you are the registrar.
[1]https://publicbenefit.uk/
[2]https://www.nominet.uk/corporate-governance/members/This way you retain the ability to seamlessly change mail provider. And you gain other benefits like infinit number of alias while requiring a low level of technical knowledge and maintenance.
Only issue I see is that their mobile apps seem to be a joke when it comes to privacy. I wouldn't trust them not to read/scan my emails either, but that's not always a deal breaker.
1972
> you move to St Louis you would get name.stlouis.mo.us
2022
This is a good reason for not using any of the new vanity gTLDs though as they can make their own rules unlike old gTLD (which are regulated much more closely by ICANN) and ccTLDs (which are regulated by the corresponding country).
I understand that some domains carry some legal attachment. That the new vanity domains are not as trustworthy as others, some are even filtered, as email validators reject it for not being a "valid" address even. Some TLDs need to have a business registered on a location, etc. And I understand that the oldest ones (com, org, net) are among the most universally accepted. But I don't know what carries greater risk: 1. me losing control over my domain, or 2. me losing access to my email account (Posteo in particular - I wouldn't just trust any email provider).
However there are few issues we have anyway even being Netizens:
- some DNS hierarchies are NOT domestic to our country so in case of political issues between countries or in case of legal issues we do not have much domestic legal protection, witch in Democracy is the protection of our people between us;
- there are too many intermediaries who only resell, they are a danger. Registars MUST BE national and international public bodies ONLY, not private companies and domains must be NOT allowed for sale, people can register them, de-register them but no commerce on them;
- a minor, but no so minor, email issue, is that with modern anti-spam or to be more precise modern bully-sheriff companies hosting their own mailserver is hard. It works of course, but some giants often simply drop your mails.
Personally while I'm a fierce against PRIVATELY controlled digital IDs I favor public ones, not mandatory of course, BUT if you are a Citizen than choose a domain name, it will be on your ID card who happen to be a smart-card PCSC/Java/something OPEN in both middlewire and hw design itself. That's yours and you can use from your homeserver as you wish. Then you are perfectly free to use anything else not much tied to your identity.
All that said: can someone point me in the direction of a hosted email service that is reliable (this is a must, I don't want emails to bounce and I don't want spam), has native mobile apps w/push notifications, has a good web ui, and generally just works? And can anyone confirm that once I pull my email from google apps that I could then use it for those google services?
Fastmail does all that, I'm using it for years now: https://www.fastmail.com/?STKI=/u226717
I have no idea how it works with the Google stuff, as I'm actively trying to avoid it; but last time I checked, you could create a Google account with any email you like, and things just work.
While a US municipality may or may not operate their locality-based domain (here, the university does), ordinary persons are able to get subdomains under them. The only reason I haven't is because the university here doesn't bother to respond when I follow the process. But you may have better luck where you are.
Gandi isn't even cheap really.
What we need is a system where we can efficiently route messages to/from public keys like the tor url system.
This way you always own your address and no one can ever take it away without the private key.
- How do you deal with a private key being lost? You can't treat this as a "almost never happens" scenario so you need a way to find people's (new) public keys which will be subject to all the same threat models as current domains or any other addressing scheme: there will be some kind of central authority.
- How do you deal with private keys being leaked? Again, you will need a way to revoke keys without having access to the private key which again is only doable with an external source of trust.
My sister and mother also now have their own domains, administered by me. :)
Edit: We then need a standard for discoverable DNS settings that providers can publish, together with an endpoint that the domain name provider calls to inform the email provider that it should accept email from person@personaldomain.person and forward it to person@emailprovider.com. Then your domain name provider can discover these, and switching email provider can be done with a click of a button without you having to have any knowledge of DNS. Of course email providers will have little interest in supporting something like this, so this is where regulation would be needed.
Unless there is state-guaranteed ownership of a domain name, this will remain to be chicken-and-egg problem: to manage a domain one needs an account with an email, and to have an independent email one needs a domain. Even then, moving between countries is normal now which poses a huge challenge to the concept of "online identity", because what one state guarantees is not necessarily what another recognizes.
The reason that email is popular as an online identity is that it is an easy and cheap method for the service provider and user to establish an identity. It would be acceptable for a domain name provider to use a more expensive way of establishing identity since you only have to go through this process for this single provider. A physical office could work if you don't live in a country where people have government-issued digital identities.
Edit: Actually, why would we need all that? We don't need anything but a username, password and maybe a phone number to sign up for GMail, so why should it be different for a domain name provider? Sure, you need some recovery mechanism if you lose your credentials, but that problem is already solved by current email providers by using phone numbers, recovery codes, TOTP, Yubikeys, etc.
Ideally your domain registrar would allow to use a username, multiple emails, a phone number, and a 2FA not connected to any of them, like TOTP.
Managing this all is a tall order. This is why gmail and hotmail are so popular.
That way whoever owns the private key will always own the address. It cannot be seized.
I really wish email providers would make custom domains either the default, or a very obvious option when signing up. Google is already a domain registrar, and other providers could partner with one. Granted, this option would not be free (though Google could probably swing making it free; they just wouldn't let you use the domain for anything else unless you start paying for the registration), so that would reduce its desirability for most people, unfortunately.
(On the downside, I wish I could convert my GSuite account to a regular Google Account, because GSuite accounts are occasionally crippled in random ways, and now I'm not even using the email part of it anymore. But that's a separate complaint.)
They don't because it creates huge friction to leave. They'll have to be mandated to do this, and I think they should be.
Even if it was cost-effective for Google (which I doubt), it's not going to happen because it would mean that, to be effective, Google would have to allow you to transfer it out of their hands (to change your provider) and thus, it would also mean that you could basically use Gmail to hold domains for free.
Although, for that to fully work,you would need international cooperation on a standard for that protocol.
Now you distribute UBI, allow voting etc. And it is all pseudonymous.
That’s what we are building out at Intercoin.org/applications btw :)
But out of curiosity, what exactly do you imagine happens in vote selling? Someone pays off each individual in half the population to vote a certain way? How do they do this at scale and how do you know it isn’t more cost—effective to just influence them?
Most people who voted for Biden instead of Bernie ahead of Super Tuesday made up their minds on the way to the polls. Biden wouldn’t have even won if nearly all the other participants wouldn’t have dropped out and endorsed him. He was losing badly to Bernie (and Pete) but as soon as he managed to prove electability in one state, all the other candidates fell on their sword. It’s like in a poker tournament where the chip leader loses to some guy who isn’t even 2nd or 3rd because everyone else stands up and gives him their chips.
And also, there are trade offs the other way. There are tons of failure modes in voting non electronically. I write about them here:
Voting should always have a paper trail. And there's also the problem of allowing the technologically illiterate/aversive to vote.
A sister comment just asked what we would do about selling votes. Well, if you can use the piece of paper to prove how you voted, I guess you “can sell your votes”
Don't believe me? Check out how many progressives said you shouldn't be able to participate in society if you didn't get the COVID vaccine.
The amount of physical disparate papwerwork you have to still do for these things is incredibly annoying.
USPS is a better last mile tech support provider imho. Natural fit if they end as a trust anchor and gov identity proofing provider.
That's another thing where Proton makes me use their app, which can be annoying.
I think that is true, but it would have to be a better solution. Some groups heavily push for this reformation of online identity but most of them have in common that they want to strongly bind online identity to your offline one. That simply isn't desirable in many cases.
Originally, the idea was that you owned a domain name. Gradually, domain registrars have moved this to the concept that you're just renting it from them. Although you can still transfer domains to another registrar.
I'd like to find a domain registrar whose contractual terms stated that you own your domain name, and they are contractually prohibited from cancelling it or revoking it without a court order. Basically, a contract that forbids what lawyers call "self-help".
> Personal .cr domain names may only be registered by Costa Rican citizens over the age of 12 having an identity card and included in the Citizens' Registry of the Supreme Electoral Court of Costa Rica. In order to certify that they are citizens of the Republic of Costa Rica, the identity card must be valid at the time of submitting the application to register the personal domain name.
> NIC Costa Rica shall only approve a personal domain name once it verifies that its holder meets the requirements set forth in Section 9 of this document for the registration of personal domain names. The applicant must also send a copy of both sides of the identity card to the email info@nic.cr.
> Requests for personal domain names under .cr shall be reviewed by NIC Costa Rica using the tools provided by the National Registry and the Supreme Electoral Court of Costa Rica, as well as any other means NIC Costa Rica considers necessary.
The recent discussion of CP flagging wreaking havoc[0] has caused us to start evaluating because we do have young children and we do take pictures for healthcare providers. Feels like a ticking time bomb for us.
[0] https://www.nytimes.com/2022/08/21/technology/google-surveil...
From my point of view they didn't really do anything wrong. They flagged something that was suspicious, which is fine. Then relied on the authorities to clear any wrongdoing due to the nature of what they flagged. At that point they should have reinstated the account.
The software Dad probably should have known better than to assign Google the task of handling that type of image. But still, that he lost his account when valid explanation provided is unforgivable.
I don't understand how people can ignore the big "eye" of Google and other tech giants, watching everything we do, treating everyone like a low-life suspect. Scanning our shit and forcing our content through a kind of twisted police line-up. I stopped using Google for anything personal years ago, but feel sorry for people caught up in their clumsy joke of a service.
With a little practice and experience, it's not difficult for those with technical skills to host their own email on a cheap rented server (along with a personal website etc). Buy a suitable domain, host at a reputable supplier on a dedicated host (i.e. IP) and there should be few problems (test with free accounts from the bit tech outfits).
Even nicer is to use Dovecot for IMAP either locally or remote. I run it locally with fetchmail to periodically (or on demand) grab email from the public server, with a little utility that lists the remote headers first so I can decide which/whether any are worth even downloading and reading - quite often it's a single click to delete everything unread.
Google Domains has (at least in theory) the option to transfer the domain to another registrar. Gmail does not let you transfer the email to annother mail provider (because that would be impossible).
Google: https://support.google.com/mail/answer/56256
In contrast, Microsoft only waits a year before recycling email addresses.
Just like a company can't yank your ability to send snail mail, they shouldn't be able to yank your ability to send electronic mail.
Sure domain registrars and email providers are not infallible, but it's a huge step up from trusting Googles customer service to do the right thing
As I have a small child and use a lot the telemedicine services I do have a fear that I will be blocked soon.
A drawback to this is that cloudflare does not allow you to forward to multiple email addresses.
[0] https://www.nytimes.com/2022/08/21/technology/google-surveil...
Not affiliated with them, just a happy user myself.
I personally use a "stable" firstname@lastname.com for supposedly trusted, long-term services (e.g. bank, utilities, etc.) and for services that require my identity for obvious reasons (e.g. shipping/billing address).
For sites where I prefer not to reveal my identity (not even to the site operator), I use Fastmail’s Masked Email (akin to iCloud Hide My Email). This, however, means I don't own those addresses, and if I need to change email provider for whatever reason, it's a PITA to update the email address field on possibly hundreds of sites (assuming you can).
I could buy a domain like randomstring.com to use with catch-all, but then I would be more likely to be tracked across sites, especially in the case of data leaks (which do happen eventually).
Then there are those awkward in-person situations when somebody asks my email and I have to say firstname@lastname.com.
What's a good tradeoff?
I suggest making up a domain name unrelated to your actual name exactly because of this.
Saying "homer@juniper plant.com" feels less awkward to me than saying "homer@homer simpson.com".
It is going to be mostly for things like a spare "fun" Reddit account, or some one off crappy give your email to download the PDF sort a thing.
My personal email is contact@{custom domain} and currently points to Gmail because I never took the hassle to change it, but if someday I decide to move elsewhere (I'm contemplating Fastmail and Protonmail), all I will have to do is update my destination email at ImprovMX and that's all.
This is a liberty that only us, tech people, can grasp. My parents, even my wife, doesn't see the importance of being locked to mail provider.
Really? I’ve had dozens of email addresses over decades. I have a few favorites but even those have changed over time. I think your is hyperbole.
Registering a domain requires an existing email. Which is obviously going to be from a third party / consumer email provider whose domain I don’t have control over.
Kind if circular reference situation!
A crypto based toplevel domain like the Ethereum Name Service. But with a twist:
If I lose my private key, the domain is not lost, but locked for 3 months and nobody, not even the registry can move it. After the 3 months, if I stay "silent" and not confirm my ownership via my private key, the registry can move the domain.
The registry should have this process: During these 3 months, I have to start an expensive process at the registry to validate my identity and ownership of the domain. When completed successfully, the registry will move the domain to my new public key.
So the worst thing that could ever happen to my domain (and my emails under that domain) is that I end up in a situation that is normal for domains today: That the registry has control over it.
Blockchain-based "solutions" are not actual solutions because they don't account for this fairly common case. Once they do, they rely on a 3rd-party, and you're back to square one.
a lot of famous folks have already using them [1].
would i rather have an entity that i have no power against (google) or only my own error? the outcome is the same, i had x, now i don't. personally, i'd prefer being responsible, but it is a by a thin margin.
that being said, key management has and will continue to get easier. so over time, the risk of key loss should diminish.
I'd wager that's not the case for 90% of users choosing the email provider they trust the most, both in terms of what they expect the risks are, and what they actually risk in practice.
> key management has and will continue to get easier
You're talking about the blockchain space where it was not even the state of the art when it started. Key management remains a problem in all spaces, but it has even more dramatic consequences when you have no recourse.
one key management wallet i like is https://www.argent.xyz/
maybe this is rudimentary by traditional standards but this an advancement for wallet management.
the key feature is you can recover access to your assets even if you lose your keys through social recovery.
Then there is the wide spread practice of tying identity to a single email address that may be used to reset passwords. There is no good technical reason to limit it just one email address or indeed just email addresses; that's just a historical quirk that gets mindlessly copied by world + dog when they spin up a new service because of the mistaken belief widely held by non technical product managers that that just is how things are done. Only a minority of websites provide 2FA, which enhances security but does not solve the root problem of people not owning their identity. Changing your email address is not a feature that is commonly supported either. Whatever email address you pick when you signup is what you are stuck with.
If your email provider shuts you down, you lose the ability to reset passwords, receive notifications, etc.
IMHO the way out of this mess is to start making multi modal signins more common. Some companies already do this but it is not a widespread practice. Simply encourage users the ability to add multiple ways of authenticating themselves. Phone number based authentication, device based authentication (using e.g. QR codes), public key based authentication (ssh or otherwise), social media account based verification, etc. are all viable strategies to authenticate. And why have just one? Combined with 2FA this makes for a much more durable account ownership. It can also remove a lot of onboarding friction as you don't actually need users to provide a lot of information about themselves.
A lot of the reasons for this not being so common has to do with a misguided notion of big trillion dollar companies wanting to "own" the relation with their users. So Google will not allow people to use their MS owned identities to sign in or vice versa. Even though both implement variations of OpenID 2.0 and generally have a large overlap in terms of how they implement security technically. It's a simple matter of ownership. They own you. They consider you their property. Your identity is theirs to control. This is the notion that needs to be challenged for this to ever be resolved.
Imagine that citizenship worked like that. It doesn't of course. But imagine. There would be a lot of stateless citizens no longer able to prove who they are because gmail shut them down or whatever. That would be unacceptable of course. Banks can't get away with that either. A passport is all you need to reclaim ownership of your bank accounts. And in case of your death, a death certificate and some paper work from a notary is good enough for your surviving relatives. Online identity should be just as strong. People confuse the means of authentication with the actual identity.
The axiom of online identity is useless and only exists for the sole purpose of control by capitalist cybernetics
And for the most part, they can be as pseudonymous as you want them to be, or they can be linked directly to your real-world ID, if you want that.
Those things give you control, instead of others.
> These extra trips through different email servers strip the emails of information about the sending server which is critical to protect against spam and email forgery.
Sure, a forwarder can strip information from a forwarded message; but that's a rogue SMTP server. And this would be your previous email provider; so you'll know whether they're rogue before you start forwarding messages through them.
> Email was designed in the 1960s
s/1960s/1970s/
You get your own domain; then host your email at a provider that offers bring-your-own-domain. Now you have a portable email. Your domain registrar cannot interfere with your messages, unless you choose to host your email with your domain registrar.
I agree that an email address is a poor identity token. As with SQL, an identity should be an opaque object with no embedded meaning. In addition to being an identity, an email address is a communications endpoint, and is parseable, so it's not opaque.