this post was submitted on 10 Sep 2023
61 points (93.0% liked)

Privacy

32159 readers
233 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 5 years ago
MODERATORS
 

And what do you actually use? I know the answer is probably self-hosting but maybe there are other solutions for a decent privacy.

you are viewing a single comment's thread
view the rest of the comments
[–] thecam@lemmy.world 16 points 1 year ago (3 children)

A privacy email provider and email aliases for everything you sign up for.

Email Providers

Protonmail

Tutanota

Email Alias Providers

Simplelogin

addy

[–] beeb@lemm.ee 6 points 1 year ago (4 children)

Proton pass does e-mail aliases if you pay up for the high tier subscription

[–] TheButtonJustSpins@infosec.pub 4 points 1 year ago (1 children)

Which is through SimpleLogin, which Proton bought.

[–] beeb@lemm.ee 1 points 1 year ago

Cool, didn't know that!

[–] cooopsspace@infosec.pub 3 points 1 year ago* (last edited 1 year ago) (1 children)

Theres plenty of good reason to keep your alias provider separate from your email provider.

The first being you can lift and shift to another email provider very easily.

Secondly if something happens to your account you don't lose the lot.

Thirdly, just get a domain with alias provider and it matters not what email provider you use ever.

[–] Atemu@lemmy.ml 3 points 1 year ago (1 children)

The first being you can lift and shift to another email provider very easily.

All alias providers I have seen (including SimpleLogin) allow arbitrary target/"backing" mailboxes.

just get a domain with alias provider and it matters not what email provider you use ever.

Personal domains are nice for "important stuff" that should be tied to your real person.

One of the features of mail aliasing services is it to provide pseudonymity which you cannot achieve if the domain literally contains your real name.

[–] cooopsspace@infosec.pub 2 points 1 year ago (1 children)

I have a pseudo domain that has none of my info on it.

It's something along the lines of "thisisspam.com" that forwards to my personal email accounts.

The point is, since I and not the service control my addresses I can take them anywhere.

[–] Atemu@lemmy.ml 3 points 1 year ago (1 children)

Problem is that this domain (whether it includes your real name or not) is still related to your person as you are the sole user.

If you created accounts at Google, Amazon and Facebook using a schema of servicename@thisspam.com, don't you think they'd be able to tell it's the same person who created those accounts?

With the likes of google.quothfaaoa@aliassingservice.com, amazon.qwrlaklfas9@aliassingservice.com and facebook.1afglasdah@aliassingservice.com, that identification vector is simply ruled out.

[–] cooopsspace@infosec.pub 1 points 1 year ago

This is going to be controversial, but if I was a user of these three scummy sites what you say above isn't the hill I'm willing to die on or care about.

However I have half a dozen domains, I could quite easily add one or two more for dumb shit like this if I wanted to.

[–] Atemu@lemmy.ml 1 points 1 year ago

They do but it's a limited kind of alias. You can't set up reverse-aliases (you send first) for example which the regular SimpleLogin can.

[–] thecam@lemmy.world -1 points 1 year ago

But its though SimpleLogin, not ProtonMail itself.

[–] gabriele97@lemmy.g97.top 3 points 1 year ago (1 children)

I am new to the alias world so I've a question. How can I be sure that an alias provider doesn't have access to my emails when they are forwarded?

[–] thecam@lemmy.world 6 points 1 year ago (1 children)

Unfortunately there is no way, it requires trust. Just like you need to trust your email provider to not have access to your emails.

[–] Atemu@lemmy.ml 4 points 1 year ago (1 children)

A point can be made here for email providers that also provide aliasing services such as Protonmail/SimpleLogin: Since they're the same entity, using an aliasing service requires no additional trust.

[–] thecam@lemmy.world 2 points 1 year ago (1 children)

True but I believe SimpleLogin is based in France while Protonmail is based in Switzerland. Two seperate governments.

[–] Atemu@lemmy.ml 2 points 1 year ago

Indeed, interesting

SimpleLogin is the product of SimpleLogin SAS, registered in France under the SIREN number 884302134. SimpleLogin SAS is part of Proton AG.