reminder: riseup and protonmail have snitched before"People use rise up under the impression that they wouldn’t cooperate with law enforcement but 8 years ago they buckled under pressure and handed over info to the FBI"
"If you choose to keep using rise up just be aware of this. if it’s a dealbreaker consider alternatives. Some are listed at blackblogs.org/policy/"
"Protonmail also complies with cops and has specifically done so against anticapitalists."
infodump, re: riseup and protonmail have snitched before@oya If you really have to use email, look for an ethical, transparent governance model such as as a small cooperative or an NPO. If you've got the skills to bootstrap such a thing, do it.
If you need secure communications, just use Signal at this point; if for any arbitrary reason you needed anonymity at the ISP level, and none of your comrades had an iOS device, you'd be looking for Briar; and if you or your comrades needed plausible deniability, you'd rather use Cwtch.
(Briar is more robust and can e.g. use presence indicators to send a message when a device is online, while Cwtch will rely on third-party servers – something that can be emulated anyway with Briar Mailboxes, for example on your own Android device.) (Cwtch is also developed in Go, a language that's under a CLA with Google, which is, as Drew Devault wrote, a promise that a future version will become closed source.)
People may also use XMPP as an email replacement, and I wonder if @thunderbird could transfer its mailbox interface to XMPP addresses? Would it make sense?
IMHO, there's no reason to use OpenPGP for encryption; it isn't merely that Linus Torvalds has called it out, that Latacora has called it out (twice), or that there are serious concerns with OpenPGP keyservers: this norm is so obsolete and complex to develop that it's actually justified ProtonMail's sectarian PRs for about a decade, deliberately worsening its users' paranoia so they'd keep paying. Our relationship to OpenPGP is similar to that we'd have with a cult, if you'll forgive my terrible syntax here. We need to replace it with something else, and we need to learn that we can't trust OpenPGP development companies.
(I recently wrote two French-speaking PDFs against OpenPGP, so I'm still kind of in the mood to call it out.)