I think this sentence should be the first thing anyone sees when they go to the page. The text at the moment assumes everyone already knows roughly what Mailpile is, so I didn't figure it out until I read HN comments.
Also, are there screenshots somewhere?
In addition to it being confusing, because of dynamic IPs and residential port blocking you may be able to run it on your computer, you just won't be able to do anything with it due to other internet infrastructure... - Sending mail from home is almost guaranteed to fail sometimes/often, due to dynamic ip ranges which are frequently blocked. - Port 25 and port 80 are blocked by most major american ISPs these days for residential services. Making this unusable from a home server. Not to mention it's against many ISPs terms of service to run a server from home without paying for a business package. (That's right, it's not just google fibre) - SPF records and other forms of email authentication? You would also need a third party DDNS service if using a dynamic IP.
So with all of that said, I like the interface pictures. It could be a good competitor to webmail clients like roundcube and friends.
It's an MUA - it can sent mail just as well as any other MUA. Use your ISP's smarthost if you are using it from home.
> Webmail is fundamentally not something that can run on your own computer.
This statement is plain wrong, even if by "your own computer" you really mean "your desktop box". I can run any server I like on my desktop box. If it has a well designed installer, then it would be as easy to set up as a "normal" app - the end user might not ever know the technical details.
> The word is "web" mail, not desktop mail, it's just going to confuse users.
Now I do agree with you. The product seems to be a little bit of both, so there is some potential for confusion. "Web-mail you run on your own computer" does seem to explain it pretty well though.
Do you see Mailpile offering some way to do the same thing in the future, with clients flagging spam and the result being used to train a 'community' filter?
By the way, there seems to be a copy-paste typo in the description for 'Spam Detection'; it reads 'PGP encryption and verification of emails and recipients'.
When I saw the "pagekite" username on github, I immediately hoped for plug-and-play self-hosted IMAP/SMTP. Here is what I envisioned in the blissfully ignorant moments until I read what the project was actually about:
The user gets to download/buy a USB stick image / raspberry pi SD image. After plugging it into a pi or other box and turning that on, user types in the URL "mailpile" on their laptop web browser and on first run, user gets asked by web app to plug in a big harddrive for storing email on[1]. The box runs some IMAP server (dovecot?), connected to some MTA that does TLS (postfix?). The user has paid for an already setup domain name, kept in sync with the IP address of that box (which runs a dyndns-like daemon), user also gets access to some server that relays SMTP without breaking TLS (since most mail servers will not accept SMTP from just any dynamic IP). So on first run, the user also has to enter the credentials for the service they paid for, these credentials are used to let the box get its SSL key signed by the CA, tell the dyndns service that this box gets to update this domain name etc.
Now if two users run this, they don't even need PGP to communicate in an encrypted way, it looks just like any other sent email. Nor can anyone requisition their mail without breaking into their house.
So the paid service would be to get a dyndns-updatable domain name with SSL, and access to some server that relays SMTP. The service would have to dole out domain names and either be a CA itself, or be able to intermediate in the SSL key signing process.
[1] For bonus points, dejadup runs there and user gets to say "send encrypted backups to dropbox/some ssh account/some other USB drive"
On the project page you write
> An intuitive, modern user interface makes strong security accessible to everyone.
Can you share a bit more about the way you envision this?
Good luck!
What about perfect forward secrecy for server connections?
What about transparent text compression?
Edit: Just to clarify why I'm asking this, the project looks very interesting and I suppose the choice of AGPL wasn't made lightly, as it might slow down adoption by commercial organizations, so I'm interested in the reasoning behind this choice.
However, we are open to discussing, and if a significant fraction of our backers would prefer a more liberal license we will probably switch.
BTW, beware of code ownership of pull requests from corporations.
Make sure you have on file release forms for every copyright holder who submits code that grant you permission to relicense later on. For one line bug fixes it can be a pain, but it's worth it.
One problem with this though is that it places an unfair advantage with the current maintainer. A fork of the project wouldn't inherit the relicensing permissions from all the contributors.
Ogre3D was able to successfully transition from LGPL to MID/BSD because of contributor agreements.
The Apache Software Foundation, Free Software Foundation, and others all require contributor agreements for very good reasons.
If your projects starts out with very liberal licensing, it's not necessary strictly speaking (unless you're concerned about patents). But that's the tradeoff.
By choosing the (A)GPL but forcing contributors to grant relicensing rights, you've excluded both those who consider copyleft licenses non-free, and those who consider copyleft licensing an important requirement.
And while the Apache Foundation already has a "permissive license" it's not quite as permissive as BSD / etc.
And if the Apache Foundation wants to relicense, to say, a future version of their license, they're still going to potentially need that contributor agreement.
Again, as I said before, there are tradeoffs.
Contributor agreements are a necessary mechanism to protect the project and ensure its future when dealing with patents or preparing for the potential of relicensing.
But in the current startup world several aynrandian douchebags would take it and make web services or paid apps. Put a lot of money on viral marketing. Pester them with feature requests. And never, ever contribute back to the community or acknowledge it helped their business.
I know a famous BSD developer who switched to *GPL because of this. Also, search for tptacek's explanation. It's counter-intuitive but this is the best license at the moment, mostly for reasons Stallman didn't forsee.
Aren't the reasons you outline in your comment exactly (a subset of) the reasons that Stallman foresaw?
I was referring to tptaceck's reasons in the previous sentence you missed to quote.
also, getmail is python and does pop and imap downloads, so could be used there.
[otherwise, this seems awesome and if i run out of my own dumb ideas i will seriously consider contributing]
I built the search engine from scratch initially because it was just an interesting problem I wanted to experiment with. However, now that I have one that works, I see massive benefits to not having too many external dependencies. It makes integration and packaging ever so much more pleasant.
My email corpus is on the order of ten million messages. Needless to say, seeing the words "can index roughly four messages per second" made me cringe rather hard.
of
http://www.indiegogo.com/projects/mailpile-taking-e-mail-bac...