• sloelk@lemm.ee
    link
    fedilink
    arrow-up
    2
    ·
    10 hours ago

    I tried this, but unfortunately the two factor authentication (2fa) doesn’t work very well. I couldn’t use carddav, caldav or active sync with app passwords (which also reduce the login to one factor) on my iPhone. So I won’t switch without proper security.

    Did you have better results with android?

  • Rose56@lemmy.ca
    link
    fedilink
    arrow-up
    6
    ·
    2 days ago

    Looks good, I wanted to leave proton mail, maybe this is a good chance? Tempting for the standard, but I’m in no need for the cloud storage and the subdomains.

    • huppakee@lemm.ee
      link
      fedilink
      arrow-up
      6
      ·
      2 days ago

      I don’t know the specifics, but American companies have to turn over data if the government asks. The government can still ask foreign companies to hand over, but a company like this will ask for a warrant or a legal order which they might only get by successfully arguing youre a terrorist or a child porn producer or something like that. So in general your data is much safer with a European company, especially when it comes to privacy.

      BUT that data has to go through a physical cable through the ocean to get to you and they can’t keep you safe once the data leaves their service. So you’ll still need security on your end, like encryption and a VPN. I think keeping the government out of your data is a very good thing, and a safe mailbox is very important but if it is your only safeguard you still can get compromised. As far as I know there are things you can do to keep your data from being ‘fished’ with a broad net and things you can do to prevent someone from fishing your data with a spear (like a targeted hack), start defending your data against being fished with a broad net. For that I’d say avoid services offered by US companies. So yes, by all means get that mailbox.org account.

      I believe the encryption nerds would recommend this company because of PGP, but I don’t know enough about law or tech to tell you more.

      • rhel@lemmy.blahaj.zone
        link
        fedilink
        arrow-up
        4
        ·
        1 day ago

        To add to that, they are very open about inquiries from legal authorities, see their yearly Transparency Reports:

        Not all the enquiries we receive are legal, and our data protection officer will critically assess every single request in order to make sure it is in line with the requirements of the law. If there are any doubts about the legality of a request, our specialised lawyers will be consulted. If a request is formally and legally correct, we will service it, otherwise it will be rejected.

        BUT E-Mail is an insecure form of communication by default, so you should definitely look into PGP encryption, see Privacy Guides - Email Security.

    • warmaster@lemmy.world
      link
      fedilink
      arrow-up
      10
      ·
      2 days ago

      It’s standards based and interoperable. I’m using Thunderbird on desktop and JTX board + DavX on Android. I like the freedom to chose what I want to use.

      • peaches@lemm.ee
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 day ago

        Is there an app to use on iPhones? I was thinking for a while to switch to it, but I don’t know what could I use for iPhone to access the emails.

        • JustEnoughDucks@feddit.nl
          link
          fedilink
          arrow-up
          7
          ·
          1 day ago

          Apple mail

          It uses standards instead of a proprietary app like proton/tuta so you can simply add it to almost any mail client.

    • Blaze@feddit.nlOP
      link
      fedilink
      arrow-up
      6
      ·
      2 days ago

      It’s cheaper, and supports IMAP, you can use PGP yourself for encryption.

      Both have their pros and cons depending on your use case

      • JustEnoughDucks@feddit.nl
        link
        fedilink
        arrow-up
        5
        ·
        edit-2
        1 day ago

        I don’t understand the usecase for tuta and proton. Their “automatic encryption” only works for people also with those providers if I am not mistaken, otherwise it just uses the same method as PGP (password that you have to send the recipient).

        It seems to me that for 99.9% of emails going through the account, it is not any more secure that other providers like mailbox, posteo, nubo, etc…

        Maybe I am understanding them incorrectly though.