TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Own-Mailbox, the first 100% confidential mailbox

529 pointsby yannskialmost 10 years ago

49 comments

pjc50almost 10 years ago
It used to be possible to run your own SMTP server, inbound and outbound, from home. This was so badly abused by spam that port 25 is blocked almost everywhere.<p>Domestic systems tend to be in configurations that make it hard to accept inbound TCP connections. You could serve SSL on a random port and open a port using UPNP, and it will work <i>most</i> of the time.<p>It&#x27;s a difficult circle to square. The most trustworthy system is one you administer yourself and manually inspect all updates, but in practice the amount of work required makes that almost impossible. If you allow the OEM to do updates they can compromise you. If you don&#x27;t do updates you end up vulnerable to exploits.<p>The &quot;send a reference to the message not the message&quot; technique was part of DJB&#x27;s &quot;internet mail 2000&quot; proposal: <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Internet_Mail_2000" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Internet_Mail_2000</a>
评论 #9799556 未加载
评论 #9799042 未加载
评论 #9802512 未加载
评论 #9799504 未加载
评论 #9799049 未加载
评论 #9801113 未加载
radiospielalmost 10 years ago
This looks very similar to what we built one year ago at <a href="https:&#x2F;&#x2F;kinko.me" rel="nofollow">https:&#x2F;&#x2F;kinko.me</a>. And then we even managed to solve most of the problems outlined in the comments here (Port 25 blocked, etc.) But our crowdfunding campaign failed, and I have seen other campaigns with similar topics and target audiences fail since.<p>Consequently I doubt that a relevant audience for that type of device really exist -- even though I wished own-mailbox would succeed.
评论 #9799951 未加载
tptacekalmost 10 years ago
How does transmitting an HTTPS link solve email encryption for people who don&#x27;t have PGP? The link is sent plaintext. Does the system require users to register out-of-band somehow? That&#x27;s how corporate email &quot;encryption&quot; systems work (the &quot;send an HTTPS link&quot; approach is popular with financial firms).<p>The underlying approach this system uses --- webmail, but on a special purpose box the user owns --- is actually sound. It seems like a pretty good refinement of Mailpile.<p>On the other hand, they should tone the rhetoric down. I winced at &quot;100% secure&quot;.
评论 #9798615 未加载
评论 #9798597 未加载
评论 #9798867 未加载
_asciiker_almost 10 years ago
The reason for SMTP servers being better off in a proper data-center is not really due to port 25 being blocked at home, it&#x27;s the entire infrastructure that assures reliability, so if your power goes out or your home router decides to die or your ISP is having issues, etc, you would start losing emails right away.<p>EDIT: I understand SMTPs are resilient but it also depends on the type of error they get back, even then it can&#x27;t be expected that all servers keep retrying for long periods of time or even handle triple bounces. So you &#x27;could&#x27; start losing emails right away, is a better way of saying it.
评论 #9798879 未加载
评论 #9798891 未加载
评论 #9798909 未加载
评论 #9800346 未加载
评论 #9799114 未加载
评论 #9799271 未加载
评论 #9799842 未加载
评论 #9798914 未加载
评论 #9798866 未加载
ppppalmost 10 years ago
Many ISP&#x27;s including my own in the U.S. don&#x27;t allow running servers from home, especially SMTP.
评论 #9798380 未加载
评论 #9800448 未加载
评论 #9798357 未加载
评论 #9798419 未加载
评论 #9799072 未加载
评论 #9798552 未加载
评论 #9798365 未加载
评论 #9798358 未加载
lisperalmost 10 years ago
SC4 is in-browser encryption that works with your current email account:<p><a href="https:&#x2F;&#x2F;github.com&#x2F;Spark-Innovations&#x2F;SC4" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;Spark-Innovations&#x2F;SC4</a><p>It&#x27;s open-source and audited. Based on TweetNaCl. Feedback very much appreciated.
评论 #9799600 未加载
nadamsalmost 10 years ago
A couple of problems as noted already that will make this a show stopper:<p>&gt; Port 25 is blocked inbound on most residential accounts - preventing you from receiving email<p>&gt; Many SMTP servers are configured to automatically bounce email from residential IPs - so sending would be a problem<p>The point of GPG is to make sure that the only person that can read the message is the one you sent it to. Having a HTTPS site doesn&#x27;t prevent the random person from viewing the link and doesn&#x27;t verify the user. Now - this might be interesting if the web app that shows the email has as GPG library in Javascript requiring the user to have GPG keys.<p>I think a better scenario is if keys haven&#x27;t been exchanged - to send an email with &quot;Alice would like to communicate over secure email - please download and generate a set of keys&quot; with instructions on what to do. But I have no idea how not to make it look spammy.<p>This is just hilarious:<p>&gt; Why shouldn&#x27;t I trust and use any cloud email service with JavaScript client-side encryption?<p>&gt; Encryption is done in JavaScript, and therefore relies on browser&#x27;s JavaScript engines, which 80% of the time [1] are proprietary software coming from Google, Microsoft, and Apple, most eminent NSA collaborators.<p>The author does know that Chrome is open source right (well I guess technically Chromium but I hope it&#x27;s based on the same code)?<p>&gt; Why not use a raspberry Pi?<p>&gt; Mainly because it cannot be trusted enough for this kind of application. [...] The Raspberry pi is provided with non-free software and the hardware needs non-free driver to work.<p>I&#x27;ve used Debian Linux on it before and didn&#x27;t need to install third party drivers?
评论 #9799335 未加载
评论 #9799562 未加载
评论 #9799194 未加载
评论 #9799482 未加载
phaeralmost 10 years ago
* Reliability of ones Internet connection should not be much of an issue, because SMTP servers should retry to deliver a mail for several hours&#x2F;days. Otherwise a secondary MX could be used as a backup for mails in transit.<p>* Policies of ones ISP are often a problem for something like this, you likely need a &quot;business connection&quot; for something like this.<p>* Dynamic DNS could be used for receiving, but you won&#x27;t have much success in sending mails unless you have reverse DNS working and that requires a static IP as far as i know. Most users will only get a static IP for &quot;business connections&quot;.<p>* I&#x27;d be really interested how the combine their usage of GPG with multiple client. Is there some sort of key management included? How does it work with Webmail&#x2F;Roundcube? Is the same key used for desktop and mobile phones?
dlapiduzalmost 10 years ago
It would make sense to add HTTPS to your website if you are promoting security and privacy....
评论 #9798532 未加载
skrowlalmost 10 years ago
This sounds pretty neat, until it breaks and you lose all of your email because it has no offsite backup.
评论 #9798420 未加载
评论 #9800594 未加载
评论 #9799305 未加载
评论 #9798436 未加载
h4waiialmost 10 years ago
While I understand the team behind this is French, the broken English and bad capitalization are haunting.<p>&quot;rasberry Pi&quot;<p>&quot;Plug at your home&quot;<p>&quot;Through a webmail&quot;<p>&quot;Plug it in mini-usb to your computer&quot;<p>&quot;Will I get a root access&quot;<p>Why not have somebody with English as their first language give it a look before making it public?
评论 #9798512 未加载
darkhornalmost 10 years ago
What if the device is confiscated by police? At least Gmail doesn&#x27;t give your data to non-USA countries when you swear to your government.
评论 #9798709 未加载
评论 #9799126 未加载
dfar1almost 10 years ago
Its main feature is security, which is great for paranoid people. But what happens when you are miles away from home and your internet connections to the server goes down? How are you going to check your e-mail?
评论 #9809095 未加载
评论 #9798702 未加载
zekevermillionalmost 10 years ago
If you&#x27;re concerned about privacy, it seems the best method is still to cut-and-paste encrypted envelope into regular mail client to avoid possible vulnerabilities, both physical and software. The obvious problem with a self-hosted server that you order from a company is that it can be intercepted or otherwise compromised before it arrives at your home. Thus it is potentially even more vulnerable than just pasting GPG encrypted message directly into gmail client.
antroveralmost 10 years ago
100% confidential? Nothing is 100% confidential if it&#x27;s connected to the Internet.
juntoalmost 10 years ago
&gt; What about SSL certificates and authorities for HTTPS?<p>&gt; Each Own-Mailbox will generate automatically its SSL key at first setup, and send to us the public part.<p>&gt; Letsencrypt Certification Authority will be used , it is free and very easy to setup, and it will be handled automatically by your Own-Mailbox. Every Own-Mailbox will automatically ask for certification for its key indepently from us.<p>Interesting idea.
ameliusalmost 10 years ago
Are we going to buy physical devices now, for all the things we used to do in pure software? How many devices will we end up with?
评论 #9801635 未加载
padmalmost 10 years ago
Regarding hardware-assisted self hosting, there is <a href="http:&#x2F;&#x2F;internetcu.be" rel="nofollow">http:&#x2F;&#x2F;internetcu.be</a> which, among other things, does email (and bypasses ISPs restrictions by bundling the &quot;box&quot; with a VPN and providing static IPv4 and 6 addresses to each user).<p>It&#x27;s some sort of &quot;freedombox&quot; [0] come true. It works out of the box, in a plug and play fashion (and it&#x27;s based on free hardware [1] and free software [2]).<p>[0] <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;FreedomBox" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;FreedomBox</a><p>[1] <a href="https:&#x2F;&#x2F;www.olimex.com&#x2F;Products&#x2F;OLinuXino&#x2F;A20&#x2F;A20-OLinuXino-LIME&#x2F;open-source-hardware" rel="nofollow">https:&#x2F;&#x2F;www.olimex.com&#x2F;Products&#x2F;OLinuXino&#x2F;A20&#x2F;A20-OLinuXino-...</a><p>[2] Debian, <a href="https:&#x2F;&#x2F;yunohost.org" rel="nofollow">https:&#x2F;&#x2F;yunohost.org</a> ,...
Tloewaldalmost 10 years ago
The funny thing that most people who obsess over encryption forget is that using tough encryption attracts attention, and all the encryption in the world won&#x27;t save you from simple workarounds (<a href="https:&#x2F;&#x2F;xkcd.com&#x2F;538&#x2F;" rel="nofollow">https:&#x2F;&#x2F;xkcd.com&#x2F;538&#x2F;</a>) and ordinary surveillance.<p>The solution for all of us is to make ordinary communication more expensive to break into rather than to go out on a limb with attention-getting extraordinary measures.<p>I&#x27;d also have to say -- no offense intended -- that what I take to be a central European accented voice-over advocating using a new security product to avoid NSA surveillance doesn&#x27;t fill me with confidence. I&#x27;m pretty sure the NSA is at least well-intentioned.<p>I&#x27;d suggest your best pitch accent would be scandinavian or perhaps Australian (not that the Australian government isn&#x27;t horrible, but it&#x27;s pretty harmless).
评论 #9800062 未加载
biturdalmost 10 years ago
How are they going to receive mail? All blocks of IP&#x27;s from any provider are blocked, usually huge blocks, larger than &#x2F;24 often. No one is getting to any comcast users, they as do many others publish lists of their IP ranges so you can block then in your server or use an RBL.
评论 #9799144 未加载
评论 #9799150 未加载
kolmealmost 10 years ago
I thought Posteo [1] is already 100% confidential? Please someone correct me if I&#x27;m wrong.<p><a href="https:&#x2F;&#x2F;posteo.de&#x2F;en&#x2F;site&#x2F;privacy_policy" rel="nofollow">https:&#x2F;&#x2F;posteo.de&#x2F;en&#x2F;site&#x2F;privacy_policy</a>
评论 #9799722 未加载
chinathrowalmost 10 years ago
I see a small market for this: bundled with verifyable co-location space.<p>At home, it&#x27;s simply not going to work unless they also offer a VPN service for the ports in use. SMTP on an eyeball provider IP is simply dead these days.
tiatiaalmost 10 years ago
Wow. I suggested this once (maybe even on HN):<p>Meta-data are also problematic. We are working on a solution for that, but it won&#x27;t be included directly in our first version.<p>It will probably come for free with updates. Our idea is that for every email you send, your box randomly sends ten encrypted fake-emails, at random moments, at ten random addresses. Recipients server automatically sees that it is a fake email when it decrypts it, and automatically drops it.
tincoalmost 10 years ago
I&#x27;ve been working on this exact idea on and off for almost a year now. Very cool to see someone else working on it, they&#x27;ve some nice solutions for hard problems too.<p>I don&#x27;t really like the choice for RoundCube, but without decent funding or a couple of expert web developers they&#x27;ll be hard pressed to build something better.<p>Also nice to hear they&#x27;re also from Europe, it goes to show the U.S. surveillance worries are very much alive here.
tarikjnalmost 10 years ago
This only address the issue of government surveillance of email through service provider backdoors. Since this would as well require auto software update to be as user friendly as the video advertise, you might as well give up the same amount of security for a service that is hosted in a liberty-friendly nation and not have to deal with SMTP flagging and home power issues.
someITguyWIalmost 10 years ago
I run my own mail server even though my ISP blocks port 25 OUTBOUND. I use DynDNS&#x27;s Mail relay service. Only costs about $20&#x2F;yr. I never have have a problem being flagged as spam or anything else. I can receive mail on port 25 INBOUND with no issues. I set my MX RR to my home IP and add a secondary to a dynamic address, also through DynDNS. works great!
Tepixalmost 10 years ago
If you want to set up something like this on your own hardware (not just email, also owncloud, jabber, etc), check out sovereign <a href="https:&#x2F;&#x2F;github.com&#x2F;sovereign&#x2F;sovereign" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;sovereign&#x2F;sovereign</a>
fallatalmost 10 years ago
I, like everyone else in this thread, wanted to run an SMTP server from home, only to realize port 25 was blocked.<p>Now I rent a VPS from DigitalOcean, and availability is like 99.999% and run SMTP and other daemons no problem. I love it.<p>So go out there and find some cheap VPSs people! :)
mdeverealmost 10 years ago
Newsletter subscription not working: &quot;conection à la base de donnée impossible&quot;
vetrasalmost 10 years ago
I don&#x27;t see anybody mentioning this anywhere. Why isn&#x27;t there a wi-fi connection option?<p>I&#x27;m aware of the security issues with low or none wifi secure networks, but most folks (myself included) never have a cable around.
z3t4almost 10 years ago
The S in SMTP is a bit ironic. It&#x27;s very hard to run SMTP now a days.
评论 #9800728 未加载
xyclosalmost 10 years ago
This looks like a great project. One thing I noticed about the website: There doesn&#x27;t seem to be a way to dismiss the video overlay. I had to refresh the page.
lsiebertalmost 10 years ago
I want to know if the code will be available for auditing.<p>Also, if these devices can be blocked by spam blocklists, then there should be some way to use a vpn to handle this.
评论 #9798831 未加载
sp332almost 10 years ago
How do you deal with key management? Specifically, what do you do if someone doesn&#x27;t remember their passphrase or loses their private key entirely?
评论 #9798343 未加载
评论 #9798336 未加载
nblavoiealmost 10 years ago
Getting the error &quot;conection à la base de donnée impossible&quot; which is misspelled. Connection should be written &quot;connexion&quot;.
fgtxalmost 10 years ago
I&#x27;m getting the error message &quot;conection à la base de donnée impossible&quot; when I try to subscribe to your page.
rbcgerardalmost 10 years ago
literally no one i know uses public key encryption - so now everyone needs to clink on a link to read an email from me? don&#x27;t get me wrong I think this is a cool idea, but it still doesn&#x27;t address the core problem with all of the encrypted email services&#x2F;clients&#x2F;etc., user adoption...
jagermoalmost 10 years ago
Good luck. Kinko.me tried the same approach and sadly, there wasn&#x27;t enough interest to fund it.
based2almost 10 years ago
src: <a href="https:&#x2F;&#x2F;linuxfr.org&#x2F;news&#x2F;own-mailbox-la-boite-mail-confidentielle-qui-vous-appartient-vraiment" rel="nofollow">https:&#x2F;&#x2F;linuxfr.org&#x2F;news&#x2F;own-mailbox-la-boite-mail-confident...</a>
tertiusalmost 10 years ago
Can we stop saying &quot;from anywhere in the world.&quot; It&#x27;s not 1994 anymore.
评论 #9803871 未加载
kpcyrdalmost 10 years ago
&gt; The Own-Mailbox sends a HTTPS link to your correspondent, so that he can access the message in encrypted form. He can answer you using HTTPS protection.<p>So anybody who can read the unencrypted mail containing the link can access and read the real mail?
评论 #9798585 未加载
bechampionalmost 10 years ago
Now i will keep hearing that music when i write emails.
brian_smithalmost 10 years ago
This seems a lot like Looking Glass just without Tor.
exadecialmost 10 years ago
&quot;You&#x27;ve allready Subscribed&quot;<p>You might want to fix that
wgxalmost 10 years ago
The newsletter signup form is broken :(
OceanPowersalmost 10 years ago
A networked computer can never be confidential. Period. Full stop.
评论 #9799037 未加载
评论 #9800794 未加载
评论 #9799410 未加载
silverdreamalmost 10 years ago
No thanks...
hiimnatealmost 10 years ago
&gt; USB<p>Absolutely useless
itistoday2almost 10 years ago
Anything relying on HTTPS is not &quot;100% confidential&quot;.