You could self host your email
Yes. But then again. If no one I know uses a private provider, my emails will still get scanned and read.but it its 1000% less convenient
Email is never private, even with encrypted email, headers give away metadata. HOWEVER, Tuta & Proton are not scanning your emails to market shit to you and train AI. That's the main advantage.
You can't know if they are not reading you emails to do anything. That is the issue. Because of how email works, we know that they COULD. And experience tells us that tech companies profit from breaking promises and laws.
Mail transport these days is usually encrypted over the wire, but once it lands at the receiving server (i.e. gmail) it is stored in the clear, or at least in a way that the host can read it.
I have private email for two reasons: using my own domain, and to promote it in general. Sure, everyone else is on Google/MS right now, but as they continue to enshittify things, maybe more people will want to move away from that. And the more people do that now, the faster/easier it will be for others.
GPG and mailbox.org or anothet "just" email service
I wouldn't say you have gained nothing. The amount of data provided to google or microsoft when using their email is significantly more. For example, your app or client is checking email all of the time, giving them telemetry on your location and activity, all your devices, 24/7. Google logs and analyzes all of your interactions with Gmail's web pages, how long you have certain emails open for, what you don't bother to open, what you tag as important, etc.
Much of the one-way email you sign up for from companies and organizations come from smaller outfits like sendgrid or their own infrastructure, so you are cutting google out of information about your associations and interests.
Also, in regards to that 90%, you can either be part of the problem for all your contacts, or part of the solution. The network effect is huge.
Proton does offer what is essentially a self-contained PGP portal. You send anyone an email and they get a "hey, this is me, open the message below" thing and then a link to a message that's hosted on Proton servers. So your Granny doesn't need to set up a public/private key pair, you can just send the encrypted portal option.
No idea of Tuta or others do this.
Plus, no matter who you chose, you personally aren't feeding the Google algo. You can do what I do, which is you leave all the hyper data hungry services in the data eating world, just feeding on each other alone. Then you have real conversations over email or fediverse.
No idea of Tuta or others do this.
Tuta does too.
Yeah. I chose proton over tuta because of this option to send the link to the encrypted message. I think tuta does have it, but it didn't show the entire conversation. If you wanted to see the entire chain I think you and to either find the mates email to get the latest URL, or open each URL by itself.
The problem with those is that you have to exchange the password by some other means than the email itself, so it's really not practical for the other person
Note that ProtonMail actually supports automatic encryption to email accounts that publish their public keys in a Web Key Directory, which I’ve set up for mine. When you type such an email address in the To field, it’ll turn into a special color with a lock symbol.
Likewise, ProtonMail also exposed a WKD so people can send encrypted emails to ProtonMail accounts. I don’t know of any mail clients that support this though (I used the command line to pull keys)
Wow, til I learn about WKD! I used to have a key on keyservers, but hated how that was basically a spam trap and the fact that anyone could upload a key there for my own address. It was easy because I own my own domain and already have a web server there.
I set it up and tested it with help from https://www.webkeydirectory.com/
Looks like it's being added to clients: https://wiki.gnupg.org/WKD/DistributionOfWKD
I use Tuta mail and protonmail.
There is no "unencrypted" transfer between sender and receiver if you both use tuta or proton.
If you send an email to me from a Gmail account, it is unencrypted until it reaches the Tuta servers and the Proton severs, once there it is encrypted and remains so until I login to my account to access the email.
TUTA MAIL:
The entire mailbox – emails, calendar and address book – are stored end-to-end encrypted in Tuta.
Data that Tuta encrypts end-to-end:
Emails, including subject lines and all attachments
Entire calendars, even metadata such as event notifications
Entire address book, not just parts of the contacts
Inbox rules / filters
And the entire search index.
Tuta uses symmetric (AES 256) and asymmetric encryption (RSA 2048 or ECC (x25519) and Kyber-1024 as quantum-safe algorithms) to encrypt emails end-to-end. When both parties use Tuta, all emails are automatically end-to-end encrypted (asymmetric encryption).
PROTONMAIL:
Emails from non-Proton Mail users to Proton Mail users
The email is encrypted in transit using TLS. It is then unencrypted and re-encrypted (by us) for storage on our servers using zero-access encryption. Once zero-access encryption has been applied, no-one except you can access emails stored on our servers (including us). It is not end-to-end encrypted, however, and might be accessible to the sender’s email service.
All messages in your Proton Mail mailbox are stored with zero-access encryption. This means we cannot read any of your messages or hand them over to third parties. This includes messages sent to you by non-Proton Mail users, although keep in mind if an email is sent to you from Gmail, Gmail likely retains a copy of that message as well. Password-protected Emails are also stored end-to-end encrypted.
Subject lines and recipient/sender email addresses are encrypted but not end-to-end encrypted.
Well, the way I see it is it's like taking candy from someone who says "I put razorblades in this candy" versus somebody who says "I did not put razors in this candy." Sure, maybe the latter is lying but are you going to pick the former? There's really no viable way to run your own email server with actual delivery anymore, and it's clearnet in transit anyway, so I don't really see the downside in "trusting" Proton or another provider enough to pick that over Google. To get any benefit, you would need to move things over though. If you're unwilling to do that work, the reality is you're just on Google and Microsoft and training their AIsand it is what it is. If you think about it, though, even if you move half of your logins to Proton or Tuta or whatever instead of Google, you are depriving them of half of what they know about you going forward.
There’s really no viable way to run your own email server with actual delivery anymore
SMTP relays make IP reputation a complete non-issue. As long as you aren't sending hundreds of emails a day, there are multiple free options (free tier, subsidized by paying corporate customers who send a lot of emails).
I pay the amount of maybe 10 $ a year for having my own domain hosted at a mail-hotel, and that means I control my own e-mail. I think it's worth it. There more who switch, the better.
Makes me feel like I'm doing the best I reasonably can, even if it's of limited effect. Also, built-in aliasing service.
This is the best reply so far. Probably not enough for me to stay, but at least not pretending it's safer
Tuta lets you encrypt a message for the sender only, with a passphrase.
They'll have to follow a link but still...
I think Proton mail is worth it just to diversify off Google but I don't lend much faith in how effective privacy will be with email. The free service is enough for that. If I wanted more faith in encrypted communications, encrypted chat applications. I sub to proton for drive and VPN. ProtonPass has all the email aliases for throwaway websites
the thing with proton is you don't really know that they're private and they pretty much always collaborate with the police and their android vpn app collects some data that it doesn't need to. I would suggest you:
- don't use email, that's the ideal solution
- use a provider like cock.li and send messages encrypted with pgp. this isn't ideal, pgp leaks a lot of data and cock.li gets sinkholed by most email providers.
- use proton and encrypt emails with pgp, you have not much privacy but it's less worse than microsoft and not much convenience loss, except that proton doesn't allow email clients(at least if you don't pay), I don't know about ms).
they pretty much always collaborate with the police
a corporation is a legal extension of the state, hence why all of them will always collaborate when ordered by the courts or otherwise required by law.
some will even collaborate when they are not required by law such amazon ring providing pigs access for no reason, facebook censoring content per request of US or Israel... needless bullshit but hey it helps get government contracts ;)
bottom line, expecting corpo to do anything for you for 5 bucks a month is naive, at best they should not do it for no reason and they should not sell your data.
but even that is a tall order for these parasites.
yeah, the solution is to use a provider which is not a company.
I don't know how old are you or where you live, but for everyone I know it's non optional. My government requires an email. And for any site I want to use I require an email. Even Lemmy.
that's why I said 'ideal'...
There is an advantage of using a provider that suports MTA STS. This is Strict Transport Security and forces at least transport encryption.
There is an advantage to use a provider you pay for too and at least claims not to read your email.
It is also nice if they can host your domain and have good delivery.
Edit: I meant MTA STS not SMTP STS.
Haven't heard of MTA sts. I'll have to research it, but it probably doesn't change the fact that when exchanging emails with another provider, they have to work with plaintext
Privacy
A place to discuss privacy and freedom in the digital world.
Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.
In this community everyone is welcome to post links and discuss topics related to privacy.
Some Rules
- Posting a link to a website containing tracking isn't great, if contents of the website are behind a paywall maybe copy them into the post
- Don't promote proprietary software
- Try to keep things on topic
- If you have a question, please try searching for previous discussions, maybe it has already been answered
- Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
- Be nice :)
Related communities
much thanks to @gary_host_laptop for the logo design :)