I know it's in it's infancy here, but if it's a solo passion project I'd consider open-sourcing it so the E2EE can be verified.
If you plan on launching this as a monetized project of some sort, I, as a potential customer, would suffice for audits but I'm sure they can get pricey.
I'll give it a shot either way, just my two cents
sc0rt 14 minutes ago [-]
I'm just a new user like everyone else commenting here. I should have been clear about that with a comment in the original post, sorry. I think x.com/rootshell0 looks like they have an X account but idk
guessmyname 27 minutes ago [-]
> Key bundle missing — please try again
I’m trying to create an account to test this service. I get this error message, what does it mean? Why is the error message so short to the point where I (the user) don’t know what to do next? Why can’t software developers learn how to communicate better with their non-tech users? And this is coming from someone with a 30+ years career in software engineering.
edit: after hitting the button “I’ve saved my recovery phrase - continue” multiple times and getting the same repeated error message, it finally worked but then the API returned “error: Registration failed”. And at this point I give up. This is why many projects, even at Big Tech companies, fail: too much friction for new users, or too many features, or too many options to choose from.
felooboolooomba 3 minutes ago [-]
Hang in there mate. I've called the Whambulance.
sc0rt 22 minutes ago [-]
I am just a user who signed up for this same as everyone else here. I cannot answer any of the technical questions, but I did find an X account that looks like it is for this email server, x.com/rootshell0
Sorry I can't be more help!
ASalazarMX 2 hours ago [-]
I'd like to know more about the operator, besides them being from USA. Having the data in Iceland sounds great, but we should be wary of any new service designed specifically to attract confidential conversations.
sc0rt 21 minutes ago [-]
Maybe x.com/rootshell0 is their X account? I wish I could tell you more.
mike-cardwell 56 minutes ago [-]
You defeated https://www.emailprivacytester.com straight off. Which is more than most new email services. You seem to be relying on CSP entirely for this, but it works.
daneel_w 17 minutes ago [-]
I gave your service a test, seeing all buttons in gray, and could not figure out if the service was broken, if my browser was broken, or if my e-mail client (Betterbird) was doing something good. Then I remembered that I use LuLu[1] to deny it all network access besides reaching my private e-mail server. Not ideal, I've learned to live with the caveats, but I do suppose it really does get the job done of stopping in-mail tracking.
You declare HSTS preload, but you are not in the preload list. You can not be added to the preload list at https://hstspreload.org/ because www.rootshell.is exists but has an invalid certificate.
Your MX TLS configuration supports various anon ciphers. These should be disabled.
Your DANE is broken. Try any of a number of freely available online validators.
mike-cardwell 51 minutes ago [-]
Weirdly, if I click Load Images, all I get is a load more CSP errors and the image fetches don't happen.
mike-cardwell 29 minutes ago [-]
[dead]
Bender 2 hours ago [-]
Nice, the more stand alone non corporate email providers the better. You have it on a good host. I've never tried to email from their CIDR blocks, curious how it works out.
I’m never hosting or dealing with any companies in Iceland. I had a run in with a hosting company there who was DoS attacking us from compromised nodes. I emailed them and they told me to get a letter from a local lawyer telling them to stop and they’ll look at it. In the end we contacted our DC provider and they dumped all traffic from their entire blocks.
A year later same attitude from a different one hosting a web site for Covid misinformation which was against their own AUP.
pixel_popping 2 hours ago [-]
Excellent! Simple and functional UI, Thank you for this.
Another company tried the Iceland root, and after growing steadily and without reporting issues (at least I never saw anything reported) just shut down one day.
Rendered at 21:25:58 GMT+0000 (Coordinated Universal Time) with Vercel.
If you plan on launching this as a monetized project of some sort, I, as a potential customer, would suffice for audits but I'm sure they can get pricey.
I'll give it a shot either way, just my two cents
I’m trying to create an account to test this service. I get this error message, what does it mean? Why is the error message so short to the point where I (the user) don’t know what to do next? Why can’t software developers learn how to communicate better with their non-tech users? And this is coming from someone with a 30+ years career in software engineering.
edit: after hitting the button “I’ve saved my recovery phrase - continue” multiple times and getting the same repeated error message, it finally worked but then the API returned “error: Registration failed”. And at this point I give up. This is why many projects, even at Big Tech companies, fail: too much friction for new users, or too many features, or too many options to choose from.
[1] https://objective-see.org/products/lulu.html
Your MX TLS configuration supports various anon ciphers. These should be disabled.
Your DANE is broken. Try any of a number of freely available online validators.
Or at least the app’s logo is the root user symbol: a number sign [2]
Normal users typically get a $ prompt, while the superuser (root) gets a # prompt [3]
[1] https://wiki.debian.org/Root
[2] https://en.wikipedia.org/wiki/Number_sign
[3] https://unix.stackexchange.com/a/291733
A year later same attitude from a different one hosting a web site for Covid misinformation which was against their own AUP.