Mailpile: Let’s take email back
mailpile.is
mailpile.is
What happened to building something and selling it?
According to the campaign page, the need is so great because:
"We're asking for a lot of money, so of course you should know why. $100.000 means paying two people $4166 a month for a year, including all taxes, insurance and other fees."
I suppose people get what they pay for, but I find it insulting to ask me to pay your salary for a year so that you can avoid risk.
If you were truly concerned about online privacy, you'd build it anyway. So is privacy the mission, or the pitch?
So this is exactly the Richard Stallman model of software. Pay people to develop it, don't charge anything for the software and give away the source.
There is no economic incentive for the donors (they might get a mail program, might not, but they will never get their money back or a return on that money.)
I suppose rms originally imagined that someone like the mailpile people would take the money they were given to create mailpile and give it to some other developer to create the tools they need. However, as we see in this campaign, all the money they get will go toward feeding, housing, and insuring themselves. (wait till they learn about payroll taxes, that will make them fiscal conservatives in a hurry :-)
Like the parent comment I can see how this works in the "old" world (make a company, product, sell it, rinse and repeat) but am curious to see if it can work in this other way.
Since they are already providing it for free to those who need it, and producing at as free software, selling it as a finished product is unlikely.
> If you were truly concerned about online privacy, you'd build it anyway.
Many people do altruistic work during their free time. crowdfunding means you can do the same work, but not be limited by what scraps of time that exist after work.
The extremely few people in the world that would quit their job to do altruistic work is few. They are so few that almost every time it happens, it get posted here as news.
If I made a poll, asking how many people here cared strongly about something in the world, I would get close to 99% hands that said yes. If I then asked how many of those people would agree to quit work to work altruistic on that subject, how many hands would I see?
Edit: I can't reply to child, so I'll do it here.
It has nothing to do with a free ride. I don't want the product because the solution isn't right for me, but I would much prefer to pay a monthly fee for something than give a 'free ride,' as you call it, to a developer, in advance.
I have no sympathy for the family argument, because I spent a year building a business on the side while I was employed full-time, so that when I quit my job, I could support my family.
I believe there's something to be gained when the venture does not include a parachute.
I think you mean, "I could not disagree more." What you wrote means you agree perfectly. It says that if you take the amount of disagreement between you and your parent, there could not be less disagreement, i.e. there is zero disagreement.
Why do the Mailpiles believe privacy is the best angle to help people the most in taking email back? If you were to work on only one thing to fix email, would privacy be the most important thing to work on?
The counterargument here isn't examples of specific cloud services like Dropbox that people can trust. It's an argument for general global security. Organizations like the United Nations Security Council and NATO generally provide a much stronger joint defense against evil than individual pieces of armor offered to citizens.
So they'd actually be taking home closer to $5416 per month.
Still "sad" (given that average rental rate on a two-bedroom apartments is $2K+ per month in the general bay area), but not quite as much.
I was just saying that the figures others were reporting were overly pessimistic.
First reaction for me was: 'Wow, this is awesome, and I'm looking for something like this. How much do they need? Wow, 100k to build a mail app? No thanks.'
I get that this is a free product and is open source, but I'd like to know what they plan to do after the 100k is gone? Instead of a proposal a) pay us to work on it for a year, I'd like to see proposal b) help us bridge between now and phase 2, which is where we'll x.
I'd just like to see a little more thought put into it.
One core question is: how big a team will we need in a years time to continue development? The answer to that depends on many factors - since this is open source, it is actually perfectly OK to work for a year, ship something awesome and hand off to the community once things are a bit more mature.
However, since we do assume there will still be quite a bit of work to do in a years time, our preferred business model is actually listed in the pitch: backers are joining a community and we will reach out to them again in a years' time and ask them to continue supporting us if they are happy with the work we have done. Mailpile has a broad enough appeal that it may be possible to sustain the team using this model alone, which would IMO be ideal.
However, plan B includes things like grants from human rights / free-speech orgs that need better tools for activists in the field, corporate support from companies unsatisfied with the current crop of tools, and subscription support services (like https://pagekite.net/, SMTP relaying, etc) which help the average Joe run his own Mailpile.
These guys probably have a great product, and are probably great people, and for that reason alone, I feel bad that my comment leads the thread. However, I never said anything that suggested this was a scam, and I don't believe it is. Like I said, people get what they pay for. It's just that I see this trend getting worse, and I think long-term it will hurt crowdfunding.
You also say that you're not suggesting they're running a scam but at the same time you compare their outreach to a money grab.
I don't know, perhaps your arguments are very good ones and I am a heartless bastard because they don't sway me. At their root, it seems like you're saying that these guys are proposing something that violates your sense of fairness somehow. I'd be interested in seeing an argument that applies more universally, and not just that you personally find it unfair.
Myself, I think the cool thing about crowdfunding is that it's so open and free. I might personally find it frustrating or unfair that money gets allocated in a way that doesn't match my values, but too bad for me!
However, my comment seems to have resonated with many others, so could be offered as advice for ways to improve the campaign.
I'm curious, what does "abusing crowdfunding" mean, in precise terms? What is wrong with what Spike Lee's request for money? I understand crowdfunding to be simply a kind of transaction. A banker's job is to facilitate transactions between people, not to discriminate in favor of the ones he likes.
Maybe write a blog post about it and submit the link? Alternative, do something like (https://news.ycombinator.com/item?id=5332317).
Isn't that the whole premise behind a huge chunk of the projects on indiegogo and Kickstarter? "I want to make a cool thing, but I can't afford to quit my day job; please pay me up front"?
I mean, I'm truly concerned about online privacy, but there are several barriers standing between me and my solution--not the least of which is the ability to eat and shield myself from the elements while crafting said solution. How is what these folks are asking any different from pitching a business plan to a VC? Sure, if you're going to a VC it's expected you'll actually have a business plan, but the function is the same: Convince people with resources that what you're doing is worthwhile and achievable, so they'll give their resources to you.
Suppose a third-party developer can make a major contribution to the project, to solve a nasty bug or add a technically challenging feature.
How does that developer get paid? How is their contribution valued?
I've spoken to someone who worked there, and they agreed it was hard to keep the balance - if you start hiring all open-source contributors, then the remaining coders out in the open will get de-motivated, since they weren't offered a job.
Um, you mean software consulting?
This model is beautiful. It's a bunch of email privacy advocates hiring a couple of skilled guys for a year to write the open source software we all wish existed.
Seems fair to me. I'm not so entitled as to demand someone altruistically create this for me.
And I explicitly _don't_ want them to make a business of it, because that changes the incentives completely.
I think your take on this is a function of our indoctrination into a particular form of capitalist mindset. We don't reward what's of value to society. We reward what can be sold. It's skewed.
In addition, there is this idea that we should be cogs in the machine as kind of a de facto life goal. Get an education and go to work for someone else. Want to be an entrepreneur and do more? Well, it will cost you dearly. You either go see the gatekeepers with capital and hope they smile on you, only to end up back in the position where you are essentially working for someone again (your investors). Or, you bootstrap and work your ass off trying to support yourself/family while holding down a day job. BTW, like you, I did the latter.
I think this is exactly why we don't have enough people using their talents to contribute something vs. just trying to make cash.
Society should encourage this, and if crowdfunding can help more people to pursue their talents/dreams (especially for the good of society), then I am all for it. We need more of this.
I mean, why is it the mindset that we must endure some arbitrary and unrelated pain in order to pursue our passions? Isn't this part of the problem?
Is the need to make a living in a society that values only what is profitable really a meaningful test of one's mettle or determination? Am I more ready to pursue my business/project simply because I hustle and hold down a day job in order to eat? Or, am I simply distracted and spending only half my time pursuing my project, and therefore less efficient and less likely to complete it?
Our tendency to believe that one must struggle in the prescribed way to prove one's self is a product of that same indoctrination. It's just how things are now. But, what if more people could make a living pursuing passions and interests that benefit society? I think they would be even more determined, because it is their own passion/cause/etc.
To your point, competition might indeed be greater, but that would be a good thing. Why would we want to stifle access and opportunity? Everyone would still have to bring their A-games and compete against others who are presumably now also able to focus on their passions. So, with focus and dedication, everyone's A-games just get better. Everyone benefits, including consumers, stakeholders, other beneficiaries, and society.
But, what you seem to be suggesting is that we continue to insist that only those who run the gauntlet and/or get by the gatekeepers get a shot. There could be some extraordinarily well-qualified individuals who could launch revolutionary businesses if only given access. To my mind, that's part of the promise of crowd-funding.
So, I have to say, it's kind of odd to me that someone in crowd-funding holds the position you're describing. Crowd-funding is supposed to democratize both investing and access to capital. So, "the people" decide what's of value to society vs. the same investor class. But, what you seem to be advocating sounds more like the gate-keeping and denial of access to opportunities that are the current norms. In my mind, it's hard to reconcile the spirit of crowd-funding with that position.
The closest model I'm familiar with to what they're doing is the FreeBSD Foundation, so this is more classic "pay us for OSS" than anything else. So I don't think this is a startup proposal. Unusual for HN I know, but given the plan I doubt they're tracking pirate metrics or blabbering about pivots.
Which is sort of a pity because actually my problem isn't email (there is plenty of webmail I can deploy privately), my problem is group calendaring with multiple share/sync options (for which only Google Apps meets my requirements).
'pay us in advance for developing a product
that hasn't been market tested or validated,'
I'd say that the fundraiser, if it succeeds, is pretty good market validation.People will look at the app for themselves, decide whether it's a good value proposition for them or not. Nobody needs your bitching and moaning; if you don't like it, don't pay anything.
You're just demoralizing people for the sake of it. I'm disgusted that yours is the top ranked comment.
But on a deeper level, your response equivocates between two entirely different things, i.e. giving an opinion on a board vs. paying for something.
My problem with the OP's opinion wasn't that he was giving his opinion, it was that his opinion was completely arbitrary. Why is it wrong to ask for donations of 1/2 salary for a year? Maybe the OP is jealous, but certainly he has no good reason.
On the other hand, this mail application seems to have good grounds for existing, and their method of funding is just a simple use of the market -- people choosing to buy something if they want it. There's nothing arbitrary about it at all.
This is exactly what they are doing, by crowd funding it. They are essentially testing the market.
- This is an MUA, correct? Based on the features on the project page, it sounds like MailPile will not act as an MTA or MDA, and is predominantly interfacing with mbox/maildir. I see features for IMAP and POP3 on the roadmap, but its not clear if using those protocols is idiomatic for MailPile.
- How is PGP/GPG handled? The server-side code for MailPile must have access to my secret key, correct? Is MailPile's web interface then accessible via HTTPS (given the proper cert)?
- Is there a plan for a key management interface?
- It sounds like the MUA itself (MailPile) is a server, and it would access maildir/mbox directly. Is there any API planned for accessing that data through MailPile's programatically, or is MailPile's main goal to provide a browser interface?
- This might have been covered, but will the web interface support mobile as well?
Thanks for working on this...it really sounds like a great project!
And yes, API access to mail is something we already support, every "command" can return either HTML, plain text or JSON. Probably XML to come as well.
We'll have to help with key management, otherwise it won't be usable by normal folks.
Mobile web support, yes, probably sooner than later.
Hope this clarifies!
I personally use (al)pine over SSH, so I don't need this ... my email is already on my own mailserver and I already access it over a secure channel, etc.
But my wife ... she's not going to put up with pine. So then I run a pop daemon. And she pops from gmail. And her email is in third party hands, etc.
If there were a decent web mail client, I could turn off popd, one less open port, and access only over SSL. Which I would hide with port-knocking, of course. I can teach her port-knocking, right ?
So try to do the key management as automatic and "out of the way" for users as possible. That's the biggest hurdle with using PGP right now.
The problem is, of course, ensuring the key is correct, and not some hijacker's.
a. Home server. Most people don't have a fixed IP or domain name, so it's going to be a pain for them to access their home server on the run. I do have a fixed IP, but I'd still hesitate to rely on my home connection whilst I'm roaming.
b. Localhost. No one can complain about reliability or accessibility when you are hosting the service right there on your own PC. But now I'm tied to that one PC - I can't check my e-mail from work, or from my phone.
c. Cloud / co-location. Now we have reliable hosting, but privacy?? I'd hesitate to upload my private key to a cloud server. Also, I now need 24/7 internet access even to read my old mail.
Perhaps localhost is the best place for it. My canonical e-mail store can remain IMAP in the cloud, but I can run an instance of Mailpile on each of my devices.
Will the client/server model work on a phone? - Surely most phones refuse to give enough CPU time to apps in "the background". I suppose you could weld a browser instance on to the front of it, and call it a standalone app.
c. might be OK for some, but we don't recommend it.
Another solution is to run Mailpile in multiple places and teach it to sync multiple instances. Complicated, but might be worth doing.
Dealbreaker right there.
Edit: Great, so the source is already available.
Also, if privacy is important for you, you shouldn't look into subscription services, whatever software package they use.
By subscription I mean that I am happy to support an open source project with regular funding. Initial funds from Indiegogo are not sufficient to maintain a long-term service and we'd be hesitant to move our most important business infrastructure to something that may not be updated regularly as the security environment changes. If you were to look into making this a business with recurring revenue I believe you would find there is a lot of support.
(you know, i just read chapter 2 of 'how to win friends and influence people' which tells me that criticising people never works because they simply work harder to justify themselves. it's the most depressing thing i have read in a long time, but it seems to be horribly, universally true. and it's so frustrating when the world seems to be populated by incompetent idiots. how do you convince someone 'nicely' that they complained about something without even reading it?)
There's another aspect to criticism: I posted because I care about this topic, and care deeply. If I didn't care I wouldn't upvote or post.
In any case, just give the person the information they need without attacking them -- they won't feel defensive and they'll probably feel pretty stupid on their own.
For bonus points, try to empathize and think about something stupid you once did -- surely you've done some idiotic things in the past.
No, but give me 5 minutes, and I'm sure I will.
what depresses me is that people don't admit it, learn, and move on. instead we get "well, i am showing how important it is to make this information more explicit because everyone else is as dumb as i am". no. we are not.
ps and no, i am not interested in winning you as a friend. what makes you think i would be? i am interested in influencing people. i want people to be smarter. it's frustrating that this can't be done by simply pointing out the correct answer. instead, people need to be molly-coddled into changing their minds without noticing. by pretending to be friends. an enormous amount of effort is needed to effect the smallest change.
i don't deny it. i think i need to read and learn from that depressing little book. but god i wish people would think a little more.
Not seeing the fork ribbon in the upper-right isn't about someone being "dumb" anymore than you not knowing how to change your own oil, fix a leaky faucet, put in a new electrical outlet or build a fucking house, makes you dumb.
You didn't just "simply point" out the correct answer. You added, "you really can't have looked very hard." which is an assumption on your part; a conclusion you reached based on your filter of the "world seems to be populated by incompetent idiots".
"Incompetence" isn't toxic, viewpoint and attitude are. There will always be someone "dumber" than you, and there will always be someone "smarter" than you. Once you realize this and internalize it into your world view, you will come to the same conclusion that book teaches, and that is one of cooperation.
Like my parent here alluded to, you didn't just point out an answer, you projected your thought process onto another person. Why do some people get depressed at what seem like tiny insignificant details, while others live happily in the worst of global conditions? The answer is Perspective. The pain/difficulty anyone feels is very much real to them, it is not an objective measurement -- so when you project the idea that a person just couldn't have tried very hard, you make the assumption that you know what it's like for that person to 'try' anything in that context.
If you look at my own comment history, you'll see that I have dealt with the difficulty of explaining myself to others quite a bit, but also that I try to turn it into a productive thought-provoking discussion with a neutral tone and strong points. For example, what I am saying right now is very similar to a direct attack on your ego (and I wouldn't blame you if you took it as such), but I try to present my words in such a way that will invoke action from your rational 'executive brain' long before it hits your emotional 'reptilian brain', if that makes any sense?
The only real course of action that makes sense is cooperation; any other interpretation would basically implicate that either the world revolves around you, or that everyone is like you, and those ideas should be clearly false to everyone.
The more you care that the other side gives up their own facts to accept yours, the less effective your stance will be, no matter how nondisputable the facts. It is much better to act amnesiac and give people wiggle room so they don't feel bad about adopting a new point of view and fear being inconsistent with their past point of view. Correcting someone always implies they were wrong, not something to be reminded of.
what i understood from reading the book making friends and influencing people, i thought that the "friends" he refers to are Customers/Business contacts.
which is often a lot off from our definition of friends (or at least mine...)
The distinction is pretty blurry.
If I do Ctrl+F for "open source", the only result I get is that your designer enjoys contributing to open source projects.
You should consider explicitly mentioning open source somewhere in the main content, how about in the Self Hosted section? Congratulations on the awesome project by the way.
It is an order of magnitude more efficient to simply move on to the next person, because there are always more people.
Working to fix that results in better usability for a website and better readability for text - and that benefits everyone.
In my case, I saw the Github reference, and got the open source bit, but had no idea how to contribute. Where was the hulking big green "contribute now" button that allowed me to enter a credit card number and hit go? Going back I see that this was through a black button on the top of the page. But for me it's now too late as the site has made me feel stupid and I, and I suspect others, am significantly less likely to play.
Perhaps that's a timely reminder to re-read Krug's "Don't make me Think".
this doesn't make any sense to me. how exactly do you know what code a remote server is running as a subscriber (not an admin)?
you obviously can't just believe what what it prints when you click "see the source!" in a web page.
they could crypto sign the code you download, but that doesn't mean they gave you what they're actually running.
Right now, every single email I receive is encrypted. I have my public GPG key on my mail server, and every incoming email that's not already encrypted is encrypted using that public key. That way if the anyone compels my VPS provider for access, they just get a bunch of encrypted email.
So my problem isn't receiving or encrypting email, it's reading it. The only real option I have right now is Thunderbird, which isn't great, and is no longer under development. Mailpile doesn't look like a mail service to me, it looks like a browser-based but locally-hosted MUA, which might be the remedy to Thunderbird that we need.
Seriously, it's not that hard to install and setup.
Once you have it all going the capabilities are immense. It also lives on your machine, using your SSL certs, and using as much in-place HDD encryption as you want.
This is how you take your privacy back. You care enough about it to do it yourself.
Mailpipe, if it ever happens, should help a lot getting some of that mail from the claws of Gmail and the likes. They can have my money.
[1] - https://blog.zimbra.com/blog/archives/2013/07/telligent-acqu...
Additionally SPF gives us a way to check if the sender address has been forged. GPG signing is more robust, but again, more user overhead.
Not to mention, I already have S/MIME support in my mail application and can get GPG support via a plug-in, but I use neither, because few recipients can handle it.
So what is new with Mailpile? What is it supposed to change?
In my opinion, if the goal is to make email more secure, we should look into ensuring that all MTAs is setup to support TLS and use it when delivering mail to other hosts (AFAIK Exim4 only announces STARTTLS when connecting to its submission port).
Getting SPF records setup would also be a plus.
This would go a long way in making email more secure, and only requires action from administrators of mail domains.
¹ http://www.postfix.org/postconf.5.html#smtp_tls_security_lev...
http://www.exim.org/exim-html-current/doc/html/spec_html/ch-...
Sure, I can set up my own mailserver already, but the amount of effort it takes is too much compared to just setting up a Gmail account. If they can get set-up and spam-protection right, then this could be huge!
Thumbnails shouldn't be high-res pictures that actually are scaled to stamp proportions. It's slow to appear on poor connection and for a moment I thought there were no screenshots and just words like "compose". And it slows down my poor 2nd gen asus notebook.
Do you see Mailpile offering some way to do the same thing in the future, with clients flagging spam and the result being used to train a 'community' filter?
http://www.indiegogo.com/projects/mailpile-taking-e-mail-bac...
also, getmail is python and does pop and imap downloads, so could be used there.
[otherwise, this seems awesome and if i run out of my own dumb ideas i will seriously consider contributing]
I built the search engine from scratch initially because it was just an interesting problem I wanted to experiment with. However, now that I have one that works, I see massive benefits to not having too many external dependencies. It makes integration and packaging ever so much more pleasant.
My email corpus is on the order of ten million messages. Needless to say, seeing the words "can index roughly four messages per second" made me cringe rather hard.
Good luck!
I think this sentence should be the first thing anyone sees when they go to the page. The text at the moment assumes everyone already knows roughly what Mailpile is, so I didn't figure it out until I read HN comments.
Also, are there screenshots somewhere?
In addition to it being confusing, because of dynamic IPs and residential port blocking you may be able to run it on your computer, you just won't be able to do anything with it due to other internet infrastructure... - Sending mail from home is almost guaranteed to fail sometimes/often, due to dynamic ip ranges which are frequently blocked. - Port 25 and port 80 are blocked by most major american ISPs these days for residential services. Making this unusable from a home server. Not to mention it's against many ISPs terms of service to run a server from home without paying for a business package. (That's right, it's not just google fibre) - SPF records and other forms of email authentication? You would also need a third party DDNS service if using a dynamic IP.
So with all of that said, I like the interface pictures. It could be a good competitor to webmail clients like roundcube and friends.
It's an MUA - it can sent mail just as well as any other MUA. Use your ISP's smarthost if you are using it from home.
> Webmail is fundamentally not something that can run on your own computer.
This statement is plain wrong, even if by "your own computer" you really mean "your desktop box". I can run any server I like on my desktop box. If it has a well designed installer, then it would be as easy to set up as a "normal" app - the end user might not ever know the technical details.
> The word is "web" mail, not desktop mail, it's just going to confuse users.
Now I do agree with you. The product seems to be a little bit of both, so there is some potential for confusion. "Web-mail you run on your own computer" does seem to explain it pretty well though.
By the way, there seems to be a copy-paste typo in the description for 'Spam Detection'; it reads 'PGP encryption and verification of emails and recipients'.
When I saw the "pagekite" username on github, I immediately hoped for plug-and-play self-hosted IMAP/SMTP. Here is what I envisioned in the blissfully ignorant moments until I read what the project was actually about:
The user gets to download/buy a USB stick image / raspberry pi SD image. After plugging it into a pi or other box and turning that on, user types in the URL "mailpile" on their laptop web browser and on first run, user gets asked by web app to plug in a big harddrive for storing email on[1]. The box runs some IMAP server (dovecot?), connected to some MTA that does TLS (postfix?). The user has paid for an already setup domain name, kept in sync with the IP address of that box (which runs a dyndns-like daemon), user also gets access to some server that relays SMTP without breaking TLS (since most mail servers will not accept SMTP from just any dynamic IP). So on first run, the user also has to enter the credentials for the service they paid for, these credentials are used to let the box get its SSL key signed by the CA, tell the dyndns service that this box gets to update this domain name etc.
Now if two users run this, they don't even need PGP to communicate in an encrypted way, it looks just like any other sent email. Nor can anyone requisition their mail without breaking into their house.
So the paid service would be to get a dyndns-updatable domain name with SSL, and access to some server that relays SMTP. The service would have to dole out domain names and either be a CA itself, or be able to intermediate in the SSL key signing process.
[1] For bonus points, dejadup runs there and user gets to say "send encrypted backups to dropbox/some ssh account/some other USB drive"
of
On the project page you write
> An intuitive, modern user interface makes strong security accessible to everyone.
Can you share a bit more about the way you envision this?
What about perfect forward secrecy for server connections?
What about transparent text compression?
Edit: Just to clarify why I'm asking this, the project looks very interesting and I suppose the choice of AGPL wasn't made lightly, as it might slow down adoption by commercial organizations, so I'm interested in the reasoning behind this choice.
However, we are open to discussing, and if a significant fraction of our backers would prefer a more liberal license we will probably switch.
BTW, beware of code ownership of pull requests from corporations.
Make sure you have on file release forms for every copyright holder who submits code that grant you permission to relicense later on. For one line bug fixes it can be a pain, but it's worth it.
One problem with this though is that it places an unfair advantage with the current maintainer. A fork of the project wouldn't inherit the relicensing permissions from all the contributors.
Ogre3D was able to successfully transition from LGPL to MID/BSD because of contributor agreements.
The Apache Software Foundation, Free Software Foundation, and others all require contributor agreements for very good reasons.
If your projects starts out with very liberal licensing, it's not necessary strictly speaking (unless you're concerned about patents). But that's the tradeoff.
By choosing the (A)GPL but forcing contributors to grant relicensing rights, you've excluded both those who consider copyleft licenses non-free, and those who consider copyleft licensing an important requirement.
And while the Apache Foundation already has a "permissive license" it's not quite as permissive as BSD / etc.
And if the Apache Foundation wants to relicense, to say, a future version of their license, they're still going to potentially need that contributor agreement.
Again, as I said before, there are tradeoffs.
Contributor agreements are a necessary mechanism to protect the project and ensure its future when dealing with patents or preparing for the potential of relicensing.
But in the current startup world several aynrandian douchebags would take it and make web services or paid apps. Put a lot of money on viral marketing. Pester them with feature requests. And never, ever contribute back to the community or acknowledge it helped their business.
I know a famous BSD developer who switched to *GPL because of this. Also, search for tptacek's explanation. It's counter-intuitive but this is the best license at the moment, mostly for reasons Stallman didn't forsee.
Aren't the reasons you outline in your comment exactly (a subset of) the reasons that Stallman foresaw?
I was referring to tptaceck's reasons in the previous sentence you missed to quote.
I mean seriously, what's the appeal to paying for Mailpile when I could just use an open-source webmail client on my server? (Which I will by the way, thanks for the idea)
1: http://www.horde.org/apps/imp
PS: Here are more: http://www.noupe.com/ajax/10-ajax-webmail-clients.html
According to Paul Graham frightening startup ideas http://www.paulgraham.com/ambitious.html, email is a bad ToDo list, How are you going to implement a better Todo list?
I have created a alpha prototype which attacks these problems conceptually, namely, Message Classification, Message Sharing, Bidirectional Messaging, Pull Messaging, Sender Revocation, Message Expiry, Centralized Attachment etc as a Mobile App but approached this as a separate todo protocol using the Push Messaging Infrastructure.
You can download the working app from Google Play https://play.google.com/store/apps/details?id=priya.pullgrid... and can see a website created http://www.pullworld.com (Undocumented - You can download the Frontend App Html Source - Have not even shared in HN as Show HN because it is incomplete in documentation). The purpose of the Prototype is just as a proof of concept and not really to solve the email problem.
I would love to share my knowledge/architecture if you are interested, so that you can really attack this problem as envisaged by pg and since you are planning to do it open source and with email, would love to contribute if you are thinking of mobile in the future using Html/OpenGL based client.
Gmail (which I'm not suggesting is an ideal, just what I happen to use) doesn't even bother to show me my spam folder - and, in the last week, it's redirected 1178 messages there.
Update: To clarify why we left it out of the pitch - we just took it for granted that you can't have a functional e-mail client without dealing with spam.
There are plenty of nice-enough webmail UIs around, and people complain about the speed of Gmail but I find it perfectly fine. Spam's the thing.
I don't think this does much to stop snooping.
* It's a bit hard to find where the HTML/JS templates are. I think that's important for folks who are good at design and willing to help the project.
* search.py, looks like it stores indexes in memory, is that correct? Will it work if I run multiple instances of httpd?
Mostly, the reason we do things the way we do, is because one of our primary goals is to make an end-user desktop app. Packaging is therefore a significant task and minimizing dependencies will help a lot.
We still have quite a bit of work to do on our website and message.
Back in 2001 or 2002, I was following the progress of Zoe, what I thought to be a very promising new approach to email archives. It kept your email in mbox or eml files, used Lucene for indexing and search and then provided a web interface on an embedded web server.
The Zoe project is no longer active (the homepage is dead and the files are gone), but this MailPile sounds very much like it. Almost exactly like it. I hope it does better.
Mailpile stores in RAM about 180 bytes of metadata per message (actual size depends largely on the size of various headers), but Python overhead brings that to about 250B. This means handling a million messages should consume about 250MB of RAM - not too bad if you consider how much memory your browser (or desktop e-mail client) eats up.
Totally killed my interest, I want to run this on a small server (e.g. NAS), for everyone in my familyIf you're interested in this, you might also want to check out:
https://echoplex.us (overview) https://chat.echoplex.us (in action) https://github.com/qq99/echoplexus (github)
Lead developer here, FYI
I have a couple of questions:
- Any plans for a plugin/extension system?
- Are there any screenshots of the interface anywhere?
Thanks! : )
http://www.indiegogo.com/projects/mailpile-taking-e-mail-bac...
The tech lead is from the Empire though - an ex-Googler - not exactly a privacy caring company :) Maybe that's why he left :)
Am I understanding this correctly that this is basically a selfhosted imap/pop/smtp frontend?
I am curious how you guys would use it, i.e. where would you actually host your emails? Running your own mailserver on a vserver sounds fun and not to expensive but I don't know if I want to maintain something like that in the long run. If something breaks this just sounds like a lot of work.
You guys pay for mail hosting? Use the one that comes with your website domain?
Contrasting Mailpile with other tools, one difference is that the basic design is that of a search engine, not a tool for reading mail from folders. Most current desktop mail clients are built on top of a bad paradigm, in my opinion.
Another exciting thing about this model, is that since the UI is a website (of sorts), we can leverage the collective experience and creativity of the web design community. That is a much, much larger pool of talent than UI designers who know C++ or Objective C, or whatever.
Finally, making the app a web server means you get an API to interact with your e-mail almost for free.
I abhor the idea that clients only ever interact with messages from a single folder.
Notmuch does two things:
- Indexes a Maildir and places messages into a Xapian fulltext database. - Provides an API for tagging, threading, retrieving, searching, creating template replies, etc. for the messages in its index.
Getting mail into the folder is the burden of another program (say offlineimap or getmail), and sending mail is also handled by other tools (say MSMTP or sendmail).
I think Notmuch would have made an absolutely killer framework to base Mailpile off of.
Maybe they do on Silicon Valley, but I'm sure you realize that's a pretty insignificant subset of email users.