Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. You may look at a problem and think "Aha!

You may look at a problem and think "Aha!

Scheduled Pinned Locked Moved Uncategorized
27 Posts 21 Posters 101 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • evacide@hachyderm.ioE This user is from outside of this forum
    evacide@hachyderm.ioE This user is from outside of this forum
    evacide@hachyderm.io
    wrote last edited by
    #1

    You may look at a problem and think "Aha! The solution is to run my own email server." Now you have two problems, Google is marking all of your email as spam, an unknown number of threat actors using your server to spread malware because you forgot to patch something, and a small pile of subpoenas.

    uep@timeloop.cafeU sarah@sosial.linkS cptsuperlative@toot.catC threesigma@mastodon.onlineT praetor@mstdn.socialP 17 Replies Last reply
    1
    0
    • evacide@hachyderm.ioE evacide@hachyderm.io

      You may look at a problem and think "Aha! The solution is to run my own email server." Now you have two problems, Google is marking all of your email as spam, an unknown number of threat actors using your server to spread malware because you forgot to patch something, and a small pile of subpoenas.

      uep@timeloop.cafeU This user is from outside of this forum
      uep@timeloop.cafeU This user is from outside of this forum
      uep@timeloop.cafe
      wrote last edited by
      #2

      @evacide also there are regexes in there somewhere

      1 Reply Last reply
      0
      • evacide@hachyderm.ioE evacide@hachyderm.io

        You may look at a problem and think "Aha! The solution is to run my own email server." Now you have two problems, Google is marking all of your email as spam, an unknown number of threat actors using your server to spread malware because you forgot to patch something, and a small pile of subpoenas.

        sarah@sosial.linkS This user is from outside of this forum
        sarah@sosial.linkS This user is from outside of this forum
        sarah@sosial.link
        wrote last edited by
        #3

        @evacide@hachyderm.io

        Problem: Google is marking all my e-mail as spam
        Solution: I don't want to talk to people using gmail.

        h2onolan@infosec.exchangeH 1 Reply Last reply
        0
        • evacide@hachyderm.ioE evacide@hachyderm.io

          You may look at a problem and think "Aha! The solution is to run my own email server." Now you have two problems, Google is marking all of your email as spam, an unknown number of threat actors using your server to spread malware because you forgot to patch something, and a small pile of subpoenas.

          cptsuperlative@toot.catC This user is from outside of this forum
          cptsuperlative@toot.catC This user is from outside of this forum
          cptsuperlative@toot.cat
          wrote last edited by
          #4

          @evacide

          Also, this isn’t supposed to be my full time job.

          Also, also I have a hard enough time just getting through my inbox.

          G 1 Reply Last reply
          0
          • evacide@hachyderm.ioE evacide@hachyderm.io

            You may look at a problem and think "Aha! The solution is to run my own email server." Now you have two problems, Google is marking all of your email as spam, an unknown number of threat actors using your server to spread malware because you forgot to patch something, and a small pile of subpoenas.

            threesigma@mastodon.onlineT This user is from outside of this forum
            threesigma@mastodon.onlineT This user is from outside of this forum
            threesigma@mastodon.online
            wrote last edited by
            #5

            @evacide
            Butter emails.

            1 Reply Last reply
            0
            • evacide@hachyderm.ioE evacide@hachyderm.io

              You may look at a problem and think "Aha! The solution is to run my own email server." Now you have two problems, Google is marking all of your email as spam, an unknown number of threat actors using your server to spread malware because you forgot to patch something, and a small pile of subpoenas.

              praetor@mstdn.socialP This user is from outside of this forum
              praetor@mstdn.socialP This user is from outside of this forum
              praetor@mstdn.social
              wrote last edited by
              #6

              @evacide That's a feature. Not a bug. There is so much damned money in hosted e-mail it's outrageous.

              1 Reply Last reply
              0
              • evacide@hachyderm.ioE evacide@hachyderm.io

                You may look at a problem and think "Aha! The solution is to run my own email server." Now you have two problems, Google is marking all of your email as spam, an unknown number of threat actors using your server to spread malware because you forgot to patch something, and a small pile of subpoenas.

                morattisec@infosec.exchangeM This user is from outside of this forum
                morattisec@infosec.exchangeM This user is from outside of this forum
                morattisec@infosec.exchange
                wrote last edited by
                #7

                @evacide
                These are good threat model points to consider.

                I’ve had quite good experiences with nixOS simple mailserver and landing in people’s inboxes with 10/10 delivery on test websites. However, nothing really prevents Gmail (or others) from suddenly deciding to fuck over someone in particular by their choice (or gag order I guess)

                Patching is always going to be an uphill battle for any non-managed service but can be made manageable. Setting and forgetting your infrastructure is just… not an option.

                Subpoenas, I don’t even begin to know where to begin with that. It also depends on your location and country. If there exists guides for that, with actual legal opinions, then I have not seen it but would love to read it.

                1 Reply Last reply
                0
                • evacide@hachyderm.ioE evacide@hachyderm.io

                  You may look at a problem and think "Aha! The solution is to run my own email server." Now you have two problems, Google is marking all of your email as spam, an unknown number of threat actors using your server to spread malware because you forgot to patch something, and a small pile of subpoenas.

                  count_01@mastodon.socialC This user is from outside of this forum
                  count_01@mastodon.socialC This user is from outside of this forum
                  count_01@mastodon.social
                  wrote last edited by
                  #8

                  @evacide The solution to all your new problems is the Jason Mendoza maneuver. Then you'll only have one big problem.

                  1 Reply Last reply
                  0
                  • evacide@hachyderm.ioE evacide@hachyderm.io

                    You may look at a problem and think "Aha! The solution is to run my own email server." Now you have two problems, Google is marking all of your email as spam, an unknown number of threat actors using your server to spread malware because you forgot to patch something, and a small pile of subpoenas.

                    f4grx@chaos.socialF This user is from outside of this forum
                    f4grx@chaos.socialF This user is from outside of this forum
                    f4grx@chaos.social
                    wrote last edited by
                    #9

                    @evacide I just receive my own email and use my isp to send it. as nature intended.

                    1 Reply Last reply
                    0
                    • evacide@hachyderm.ioE evacide@hachyderm.io

                      You may look at a problem and think "Aha! The solution is to run my own email server." Now you have two problems, Google is marking all of your email as spam, an unknown number of threat actors using your server to spread malware because you forgot to patch something, and a small pile of subpoenas.

                      cm@chaos.socialC This user is from outside of this forum
                      cm@chaos.socialC This user is from outside of this forum
                      cm@chaos.social
                      wrote last edited by
                      #10

                      @evacide I haven't had a call from police detectives since I stopped running a mixmaster remailer (not on the same system I run my private email on, I'm not crazy)... and TBH, Austrian police is pretty civilized. Now to get google to stop marking everything as spam, I'm still looking for a solution to that...

                      1 Reply Last reply
                      0
                      • evacide@hachyderm.ioE evacide@hachyderm.io

                        You may look at a problem and think "Aha! The solution is to run my own email server." Now you have two problems, Google is marking all of your email as spam, an unknown number of threat actors using your server to spread malware because you forgot to patch something, and a small pile of subpoenas.

                        wpalant@infosec.exchangeW This user is from outside of this forum
                        wpalant@infosec.exchangeW This user is from outside of this forum
                        wpalant@infosec.exchange
                        wrote last edited by
                        #11

                        @evacide And modern email ecosystem is ridiculously complicated. With DKIM, SPF, DNSSEC and whatever else you need to get everything running reliably it requires serious commitment. Mess it up just a little and you’ll be left wondering why everybody has to turn over their trash bin in order to find your emails. What, DMARC is supposed to help? Yeah, now you’ll receive tons of notifications regularly leaving you wondering whether you’ve misconfigured something, the receiving server messed up or it’s about actual spam. And the existing software is woefully unprepared to handle anything beyond the basic SMTP protocol – or does your email server software of choice support SRS without requiring you to sacrifice your firstborn child?

                        I have my reasons to run my own email server but I wouldn’t recommend that to anybody these days. And even I gave up on sending emails from my server directly, delegating this task to my hosting provider instead – it just isn’t feasible.

                        1 Reply Last reply
                        0
                        • evacide@hachyderm.ioE evacide@hachyderm.io

                          You may look at a problem and think "Aha! The solution is to run my own email server." Now you have two problems, Google is marking all of your email as spam, an unknown number of threat actors using your server to spread malware because you forgot to patch something, and a small pile of subpoenas.

                          max@toet.dnzm.nlM This user is from outside of this forum
                          max@toet.dnzm.nlM This user is from outside of this forum
                          max@toet.dnzm.nl
                          wrote last edited by
                          #12

                          @evacide Which is as it should be.

                          1 Reply Last reply
                          0
                          • evacide@hachyderm.ioE evacide@hachyderm.io

                            You may look at a problem and think "Aha! The solution is to run my own email server." Now you have two problems, Google is marking all of your email as spam, an unknown number of threat actors using your server to spread malware because you forgot to patch something, and a small pile of subpoenas.

                            sblaydes@bsd.networkS This user is from outside of this forum
                            sblaydes@bsd.networkS This user is from outside of this forum
                            sblaydes@bsd.network
                            wrote last edited by
                            #13

                            @evacide it takes some effort, which everything to stay safe requires.

                            1 Reply Last reply
                            0
                            • evacide@hachyderm.ioE evacide@hachyderm.io

                              You may look at a problem and think "Aha! The solution is to run my own email server." Now you have two problems, Google is marking all of your email as spam, an unknown number of threat actors using your server to spread malware because you forgot to patch something, and a small pile of subpoenas.

                              northernscrub@m.dollha.usN This user is from outside of this forum
                              northernscrub@m.dollha.usN This user is from outside of this forum
                              northernscrub@m.dollha.us
                              wrote last edited by
                              #14

                              @evacide I don't get this. I've had multiple sysadmins look at me in abject forror when I tell them about the mailserver I've run at home for several years, and yet the only time I've ever had an issue, the receiving host responded with what I was doing wrong -which was a misconfigured dmarc. My emails do not go to spam. Gmail, Hotmail, all the others are happy to receive my electronic scratchings. I have rDNS properly configured. In fact, my own hosted email has been vastly more reliable than the email provided for me by several reputable domain providers.

                              There's so much fud about hosting email out there, it's really not that hard to do.

                              evacide@hachyderm.ioE wpalant@infosec.exchangeW 2 Replies Last reply
                              0
                              • northernscrub@m.dollha.usN northernscrub@m.dollha.us

                                @evacide I don't get this. I've had multiple sysadmins look at me in abject forror when I tell them about the mailserver I've run at home for several years, and yet the only time I've ever had an issue, the receiving host responded with what I was doing wrong -which was a misconfigured dmarc. My emails do not go to spam. Gmail, Hotmail, all the others are happy to receive my electronic scratchings. I have rDNS properly configured. In fact, my own hosted email has been vastly more reliable than the email provided for me by several reputable domain providers.

                                There's so much fud about hosting email out there, it's really not that hard to do.

                                evacide@hachyderm.ioE This user is from outside of this forum
                                evacide@hachyderm.ioE This user is from outside of this forum
                                evacide@hachyderm.io
                                wrote last edited by
                                #15

                                @northernscrub How many activist organizations that can expect to be targeted by court orders are you hosting on your mail server?

                                northernscrub@m.dollha.usN 1 Reply Last reply
                                0
                                • evacide@hachyderm.ioE evacide@hachyderm.io

                                  @northernscrub How many activist organizations that can expect to be targeted by court orders are you hosting on your mail server?

                                  northernscrub@m.dollha.usN This user is from outside of this forum
                                  northernscrub@m.dollha.usN This user is from outside of this forum
                                  northernscrub@m.dollha.us
                                  wrote last edited by
                                  #16

                                  @evacide none, but I *am* hosting part of a community that has refused to enact the new OSA requirements, which runs both a revolt/stoat instance, and a bridge between that instance and our discord, two IRC rooms, and matrix room on a connected domain, for which the primary domain manages email. Perhaps small potatoes, but given my governments authoritarian stance on anything internet...

                                  evacide@hachyderm.ioE 1 Reply Last reply
                                  0
                                  • northernscrub@m.dollha.usN northernscrub@m.dollha.us

                                    @evacide none, but I *am* hosting part of a community that has refused to enact the new OSA requirements, which runs both a revolt/stoat instance, and a bridge between that instance and our discord, two IRC rooms, and matrix room on a connected domain, for which the primary domain manages email. Perhaps small potatoes, but given my governments authoritarian stance on anything internet...

                                    evacide@hachyderm.ioE This user is from outside of this forum
                                    evacide@hachyderm.ioE This user is from outside of this forum
                                    evacide@hachyderm.io
                                    wrote last edited by
                                    #17

                                    @northernscrub So none, then? Ok.

                                    1 Reply Last reply
                                    0
                                    • evacide@hachyderm.ioE evacide@hachyderm.io

                                      You may look at a problem and think "Aha! The solution is to run my own email server." Now you have two problems, Google is marking all of your email as spam, an unknown number of threat actors using your server to spread malware because you forgot to patch something, and a small pile of subpoenas.

                                      da_gut@dice.campD This user is from outside of this forum
                                      da_gut@dice.campD This user is from outside of this forum
                                      da_gut@dice.camp
                                      wrote last edited by
                                      #18

                                      @evacide@hachyderm.ion the answer is never run your own mail server. God that’s a pain in the ass.

                                      1 Reply Last reply
                                      0
                                      • evacide@hachyderm.ioE evacide@hachyderm.io

                                        You may look at a problem and think "Aha! The solution is to run my own email server." Now you have two problems, Google is marking all of your email as spam, an unknown number of threat actors using your server to spread malware because you forgot to patch something, and a small pile of subpoenas.

                                        jhaas@a2mi.socialJ This user is from outside of this forum
                                        jhaas@a2mi.socialJ This user is from outside of this forum
                                        jhaas@a2mi.social
                                        wrote last edited by
                                        #19

                                        @evacide I've been running my own server for years. (I used to operate the mail for a tier-3 ISP.)

                                        I can't recommend the practice lightly.

                                        The main reason I can't recommend it has nothing to do with security - that's much easier to do these days than it's ever been.

                                        It's exactly as you say: Gmail and the other secret email police don't want you to run your own stuff. Nevermind that the majority of my spam is coming in from G and O365 validated domains these days.

                                        wesgeorge@mstdn.socialW 1 Reply Last reply
                                        0
                                        • northernscrub@m.dollha.usN northernscrub@m.dollha.us

                                          @evacide I don't get this. I've had multiple sysadmins look at me in abject forror when I tell them about the mailserver I've run at home for several years, and yet the only time I've ever had an issue, the receiving host responded with what I was doing wrong -which was a misconfigured dmarc. My emails do not go to spam. Gmail, Hotmail, all the others are happy to receive my electronic scratchings. I have rDNS properly configured. In fact, my own hosted email has been vastly more reliable than the email provided for me by several reputable domain providers.

                                          There's so much fud about hosting email out there, it's really not that hard to do.

                                          wpalant@infosec.exchangeW This user is from outside of this forum
                                          wpalant@infosec.exchangeW This user is from outside of this forum
                                          wpalant@infosec.exchange
                                          wrote last edited by
                                          #20

                                          @northernscrub I hope you have some wood around to knock on. If your emails really get delivered reliably then this is just incredible luck, particularly for a server on a residential IP address. Having rDNS configured was sufficient a decade ago, maybe two. Now you need SPF, DKIM, and even then your emails may be dropped silently. I’ve got into the habit of emailing my own Gmail account with important mails first, just to see whether these would go to spam – they normally would, so I’d pull them out, and it increased the chances of the actual recipient seeing the email. Microsoft would just randomly blacklist my server with no way to appeal. And in case you are wondering: no, my server wasn’t sending any spam and in fact no bulk mail at all. Eventually I just had to give up: there is no way a low volume mail server can function today, so I started using my hosting provider’s email server as sending relay. Getting the server off blacklists is now their concern.

                                          1 Reply Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups