Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

While I find Eastlink's behavior in this situation reprehensible, I have to note that the final statement in the article is quite true:

"your email address may not be your own"

If you entrust your email to a third party, you are taking a risk. IMO that risk is a lot bigger if the third party is your ISP, because they know they are in a very strong negotiating position with respect to you. That's why I have never relied on my ISP for my email service (even though they offer it, I don't use it). It's very cheap nowadays to get ownership of your own domain and full control of the email addresses under that domain. Yes, you still have to depend on your hosting company for those services, but you are in a much stronger position with them than with your ISP, because hosting is so much more competitive.



Do you really own a domain name or just a fixed term lease that may be revoked by multiple parties and by multiple means?


You own your domain name in the same sense that you own any property in a society where governments have overwhelming force at their disposal. Yes, if the government really, really wants to take your ownership away, they can. But it's still a lot harder and a lot rarer than having ISPs screw over their customers.


I mentioned in another reply the problem with DNS is that multiple entities can mess up with you and government is only one among many.

Correct me if I am wrong, but is a registry even obliged to offer a renewal of your domain when your current lease expires? Without jumping through the whole loop of "owning and defending a trademark", what legal recourse do individuals have when faced with malicious takeovers?


> You own your domain name in the same sense that you own any property in a society where governments have overwhelming force at their disposal.

You might as well say "...in any society." If a government doesn't claim a monopoly on violence, someone else will.


> You might as well say "...in any society." If a government doesn't claim a monopoly on violence, someone else will.

Whichever entity (even if nominally a collection of entities considered together) has (whether or not it claims) a monopoly on the legitimate use of force is the government, whatever it calls itself.


That's pretty much the point I was trying to make. A society without a government that monopolizes force can't really exist, or at least not for long.


> A society without a government that monopolizes force can't really exist, or at least not for long.

This is falsified by many historical examples. I gave one upthread (some of the American colonies, such as Pennsylvania in the early 1700s). Another would be saga period Iceland, which existed for several centuries with no government that monopolized force.

I think history does show that societies without a government that monopolizes force are vulnerable to a failure mode which basically consists of an outside entity being willing to invest enough resources to overwhelm the force available within the society, and thus establishing a government by takeover. This is what happened in both of the examples I gave above (Iceland was taken over by the King of Norway, and Pennsylvania ended up caught up in the general tightening of everything when the British decided to get tough on the colonies after the French and Indian War).

In other words, any time a group of people try to set up for themselves a place where they can live the way they want to, interfering with no one else and with no one else interfering with them, it doesn't last; someone else always ends up coming in and taking over and trying to tell them what to do. I view this as a bug, not a feature.


I think you've just crushed a lot of libertarian dreams. But you're right. If there is no official and relatively accountable government, it would be just some war lord of some other type of bully taking over and demanding their own "tax" to let you be in any given area.


I didn't say "monopoly on violence". I said "overwhelming force". It is perfectly possible for governments to have a monopoly on violence but still not have overwhelming force at their disposal: in fact that was the case when the US Constitution was written (for example, "keep and bear arms" in the 2nd Amendment was intended to include private ownership of warships). It is also perfectly possible for no entity to have a monopoly on violence and for no entity to have overwhelming force at its disposal compared to others (for example, in a number of American colonies, such as Pennsylvania in the early 1700s, while there was technically a "government", it did not have a monopoly on violence and private enforcement of laws was common, with all citizens being in roughly the same position as far as the force at their disposal).

I was merely recognizing the fact that, in today's world, governments, at least of developed countries like the US, do have overwhelming force at their disposal compared to private citizens. Whether that is because they have a monopoly on violence or for some other reason is irrelevant to the point I was making, which is simply that private citizens have to recognize and deal with the reality and limitations of what "ownership" means in today's world.


If it's so - how does that work on worldwide scale, on the legal side of things?


Found a company, register a trademark in the same name in all relevant jurisdictions, hire a legal team that are trawling the internet and the world in general for trademark abuse so the trademark is defended. Hope that some registrar or internet body do not change a policy of some sort or another. Did I miss something?


There is no guarantee you'd win in court, especially if your domain is seized by a state level actor.

This is why I think private keys combined with some kind of immutable log (cough...blockchain...cough) are far better as identity tokens than anything based on DNS.


Identity tokens only implement the underlying address space. Friendly identifiers either have to be immutable (read:nearly worthless), or handled by some form of registry.

First come, first served registey with some form of expiry implemented via smart contracts might be possible, but it seems unlikely any one registry would ever become 'the canonical registry', as that just puts is back in the same situation as DNS.

This is a hard problem to solve without asking folks with big sticks/guns to enforce policy decisions.


I am not sure if there has to be a "canonical" registry. For example, most western countries have multiple competing credit rating agencies reporting on individual identities and the system seems to work okay on that aspect.

I will give my ideas more thought down the road. We have already tried this with PGP but it had too many issues to be practical. In any case, whatever we end up building is going to be better than DNS which is one entity with too many pairs of hands controlling it, all the way from ICANN to the registries to malicious social engineers.


Juan Benet of Protocol Labs was talking about how naming things is really a consensus problem (ep 15 on the Y Combinator podcast)


Running your own domain and email server also adds new attack vectors for somebody wishing to gain access to your email. In addition to the obvious security issues related to running your own server the attacker may also use social engineering for the registrar, hosting provider provider or DNS provider support people.

If more people would realize the importance of email address as the key to their online identity, this might open up a business opportunity for banks. My bank knows me, they have the proper ways for offline identification (if I loose my online access and I have quite good confidence on them. I would not expect the bank to run full email service for me, but they could provide forwarding service. Should I run to trouble with the actual mail provider, let's say Google blocking my account, I could just work with the bank to setup forwarding to other location.


You don't have to run anything yourself, just "hold the key to the domain" so to speak. Relying on a mail provider to host the email server is fine, and if they try to take it from you, you can be up and running with a different provider in less than 10 minutes, with it fully probagated 24 hours time. You are still in complete control over the future of all email on that domain.


Unless the TLD fails.


Then there will be much bigger things than getting email to worry about, especially if you have a .com or any of the other main ones.


And five days later on HN: "Taking Control of All .io Domains With a Targeted Registration" https://news.ycombinator.com/item?id=14737322


This person registered their email address 20 years ago, well before gmail. At the time, the options were

(A) Pay for an email address.

(B) Run your own email server.

(C) Use the email provided by your ISP


(D) Use Hotmail (1996) or Yahoo mail (1997) or one of several other similar services

(E) Use university or organization e-mail account [1]

(F) Buy your own domain and set up mail forwarding to another account or service [2]

[1] Okay, not really much better than your ISP account, but it's a different dynamic and still slightly better, though not everyone would have this option.

[2] I can't actually find a positive reference to mail forwarding being an option around the exact time-frame, but I know I had done this for some people around the early 2000's at least. Though it's a variant of (A) it's still distinct because it's a domain, not just an account.


F was a standard option with British ISPs, at least, in 1996.


Today, the options are the same.

Just running your own server got a lot easier, and you can buy stock Gmail or Outlook Web clients under your own domain.


> Today, the options are the same.

No, today there is another one:

(D) Pay a hosting company to host your own domain and its email. This is kind of like running your own server, but without having to run the machine yourself, have an Internet connection that supports that (most ISPs forbid hosting services on your publicly visible IP address in their terms of service), etc.


(E) Pay your registrar to forward your e-mail to another account.

I used to run my own server, but I got tired of constantly dealing with spam filtering, RBLs, etc. I just forward several accounts across a handful of domains to my gmail account, and I have gmail setup to send 'from' my own domain (with validation).

I could switch to another service (or my own server) and other than me, no one would notice a thing.


> I have gmail setup to send 'from' my own domain (with validation).

How do you set this up? I have several domains pointing to my gmail but can't send from them...

Edit, should have just googled, https://support.google.com/mail/answer/22370?hl=en

Edit 2: this really: https://blog.alexlenail.me/i-want-to-send-emails-from-my-goo...


Running your own server is a lot harder today. You need to set up SPF and DKIM, at minimum. You also need to hope that you don't get erroneously blackholed by Google (GMail), Yahoo, or Microsoft (Hotmail/Outlook.com).

I would consider Gmail to fall underneath option A rather than option B. If Outlook Web is Microsoft's GSuite competition then it is not running your own server either.


It's a bit of a wash, honestly.

You don't have to deal with Sendmail cf files, and there are secue options other than qmail.

Though yes, it's rather the PITA.


Yahoo may have had free email and this time. I'm not sure the exact timing but after I got real internet instead of just dial up email I switched to Yahoo from Juno right around that time.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: