@steel_for_humans@piefed.social
I'm questioning the privacy focused choices that I made
2026-04-12 10:59 UTC
Replies (16)
-
@pHr34kY@lemmy.world 2026-04-12 11:52
That sounds like a bit of a ride. I just selfhosted everything. There’s still things tied to my gmail, and probably always will be. However they’re not seeing the important stuff like medical, school, banking and services. NGL; selfhosting is quite a commitment too. Especially for email. There are a lot of hoops to get trust as a server, and full text search took me years to get working right. Hosting a keepass database on a personal webserver is not as convenient, but there’s 100% control. I inherently don’t trust any company that sells trust or privacy as a product. I’ll only fully trust open source software running on my own metal.
-
@atropa@piefed.social 2026-04-12 12:32
Typical case of too fast, too much in 1 go. First field research and only then gradually switch. I am a satisfied user of posteo.com and mailbox.org, supporter of the KISS system. On linux I switched from thunderbird to betterbird, K9 mail on grapheneOs. Onedrive replaced by filen.
-
@klymilark@walsh.fallcounty.omg.lol 2026-04-12 12:52
@steel_for_humans Sounds familiar, honestly, I did similar. I'm also on Mailbox.org (great service) since email is... not a private form of communnication. You only get the benefits of E2EE if you're sending emails to the same e2ee email provider (proton > proton, tuta > tuta, etc), so it didn't feel worth it to me to stick with tuta over mailbox because I also wanted an email client, which tuta didn't offer at the time, but mailbox did. None of your choices were wrong, you just bounced around a lot, which isn't super uncommon in the beginning. I went from KeePass, to Google's passwords (this was like... 10 years ago when google first offered password management), back to KeePass, to Nextcloud, now moving back to KeePass. I have passwords in 3 separate password vaults (two keepass, one nextcloud) that I need to sort through at some point. The biggest recommendation I have: Don't switch again until you have stuff sorted out on your current one. Switching multiple times before you have everything setup is Besides that just take your time
-
@skooma_king@piefed.social 2026-04-12 13:44
I don’t think it’s wise to have your password manager and TOTP/MFA on the same platform. It’s especially risky if you bind your TOTP to your actual password manager, e.g., your example of one click authentication. Convenient? Definitely. But your entire identity stack is more a huge liability if you are ever compromised.
-
@nukloid@fosstodon.org 2026-04-12 14:15
@steel_for_humans I have been using mailbox.org (1$ plan) for around 2 years and its been great. Also, maybe check out KeePass to store your passwords. I plan to switch to it once my bitwarden subscription is up. Partially because of security and privacy, and partially because they have increased the subscription price. Maybe you can even mix the 2. Keep most generic things in bitwarden, and keep the critical / 2FA stuff in keepass.
-
@grrgyle@slrpnk.net 2026-04-12 14:27
I don’t have technical advise but congrats on taking your privacy seriously. It sounds to me like you’re fundamentally doing very well, probably learning a lot, even if your setup isn’t ideal right now. From my perspective, it’s never going to be truly ideal—like perfect. Migrating and moving around, adapting and optimising, are how you maintain a good posture. Especially when dealing with companies or even other people like solution maintainers, you’re going to get disappointed in some of them and have to migrate. If you were happy staying put you’d be on Windows 11 complaining on Facebook right now. ;) So pat yourself on the back for that win, friend—you’re doing it!
-
@utopiah@lemmy.ml 2026-04-12 14:52
just that the mobile Proton Mail app does not support fulltext search. I know why, but I still think it’s doable the same way as in the web browser If your mobile has a modern Web browser I’m pretty sure you can do full text search in there too. Also FWIW it’s a constant struggle for everyone. Corporations do their very best, both technically but also with marketing and lobbying, to make it nearly impossible. We have to learn, help each other, vote and it will never stop. Still, each step mattes so kudos on even attempting.
-
@RecursiveParadox@piefed.social 2026-04-12 14:54
Thank you for posting this. I was just about to continue de-googling by moving my email to Proton.
-
@mazzilius_marsti@lemmy.world 2026-04-12 18:06
Instead of completely moving to 1 service, I would try to compartmentalize the digital life better. For me I tried: all banks and very sensitive stuff => Proton Mail every other emails => Gmail. Password Manager: yes Proton Pass is nice but i like things to work offline and access whenever i can => KeePass. I secure my database with a password and a keyfile. I transfer and uodate my database with Syncthing. 2 FA stuff: i had Authy but it is a piece of shit app now. So I am moving to Keepass. Yes, you can add TOTP to anything in Keepass. The only thing i still need Authy for is Steam.
-
@PierceTheBubble@lemmy.ml 2026-04-12 23:03
Generally the rule of thumb is: if a service (including one focused on privacy and/or security) actively advertises itself (which Proton does a lot: especially through content creator sponsor-deals), be extremely wary. I was once also considering migrating to Proton, but luckily tried integrating the account into Thunderbird first; which led me to second-guess Proton’s intentions. It really didn’t sit well with me, they’re baiting users into (over-)committing to their service, encrypt their (primary) mailbox’s contents, and as a result paywall the process of data-migration (including to third-party email clients). I instead went with a humble Disroot mailbox (I make a yearly donation to), and use fully separate Proton addresses as effective aliases: as I’m not interested in them being associated to my personal email anyway. Other than that, I’ve simply integrated all email accounts (I care about) into Thunderbird. For the big-tech accounts, I’ve backed-up their contents in Thunderbird, re-imported them locally (to be able to search them), and deleted all contents from the servers. I’ve changed the email of more important services to the Disroot account, and listen for any others I might’ve forgotten, on the empty big-tech accounts (which rarely receive anything). For password managers I’ve always used KeePassXC: synced across devices by having the (encrypted) database on Google Drive, and later synced locally using Syncthing. The KeePassXC-Browser extension does the filling on the browser, and I’ve always used Keepass2Android for mobile (through the keyboard). Nowadays I just use my laptop for anything requiring login, and rarely use secondary (mobile) devices to begin with: eliminating the need for cross-device syncing altogether. The KeePass database lives on my secondary hard drive, and make sure to create backups periodically (which also goes for Thunderbird contents). Limiting the services you depend upon also helps tremendously, so that even if all passwords are lost, you rarely feel affected. I’m confident I could lose 99% of my passwords, and wouldn’t care whatsoever. In fact, I’ve effectively been through that process already (when changing all recursive passwords to stronger, unique ones: through the “forgot your password?” fields), and could easily do it for important services once more. The most valuable piece of advice I could give, is to identify the important parts, and start from there. If you care enough for the emails effectively held ransom by Proton, perhaps configure the bridge once and extract the data; never to return.
-
@zarenki@lemmy.ml 2026-04-13 02:27
Encrypted email in the way that Proton and Tuta do it has a lot of drawbacks. Because I almost never use my personal/non-work email to communicate with another human, and automated mails tend to have the message body be no more sensitive than the subject line and metadata, zero-knowledge encryption at rest for just the mail body has a negligible privacy impact for me. It helps to consider your actual needs and privacy goals, using the services or software that fits them best rather than just following what others say has the best privacy. I used Proton for two years and, similarly, just recently migrated off of it last month. Since I use custom domains for email through it, and I never cared to use their other services outside of Mail (and occasionally VPN), it was a quick and painless migration. Unlike the painful migration of changing my email address everywhere to be non-gmail (which I still haven’t 100% finished after two years), this time I only needed to update DNS records and copy mailbox data. After migrating, having actual IMAP/JMAP access without a bridge is nice. Note that you don’t necessarily need to import your entire mailbox when migrating. I never imported my email archive from gmail to proton; an offline archive of all old received emails on my NAS is enough for me if I ever need to search through it. I can even view that archive in Thunderbird. My thoughts on a few of the other Proton services: Proton VPN is really nice. One of the few good ones with port forwarding. But some other options have better pricing than VPN Plus alone outside of the Proton Unlimited bundle. SimpleLogin (or Proton Pass masks) is nice, though using anonymous email masks is a trade-off in dependence. I prefer disposable addresses under my custom domain for anything associated with my identity regardless (like services that use my billing or shipping info), and shared domain masks for anything else. My existing shared-domain email masks in Proton still work even after my subscription ended. Addy and Firefox Relay are fine alternatives, and some other mail services like Fastmail have their own equivalent included. I’d rather self-host CalDAV/CardDAV than rely on online services for calendar, contacts, etc. I had already been using a local KeePassXC database and a NAS for many years so I had no reason to use Proton Drive and Pass, except for the latter’s email masks.
-
@lattrommi@lemmy.ml 2026-04-13 04:15
I can’t offer any good advice, just take consolation in the fact that I have done some of the same, but likely worse. I try to switch to a new email, don’t fully migrate or close the old one, end up with a convoluted mess, end up just checking emails individually. I have protonmail, 4 gmails and a yahoo account. Yes yahoo. Part of that is sentimental, I signed up for it in 1998 and it’s hard to let go. I have a folder of email bookmarks and just right click ’open all in new tabs’ to check them. As for passwords, well, I wont talk about that. It’s not good but still not worst practices at least.
-
@sem@piefed.blahaj.zone 2026-04-13 14:15
Thank you so much for writing this all out. I am in a similar position. One question I have: even if you used your own domain instead of passmail.com, how do you export all if the alias rules from proton pass to another system?
-
@jalappy@lemmy.ml 2026-04-13 19:14
Skimming through most answers I’d like to add my own solution for password management. This will likely take you a bit of time the first time, but after that I think it’s trivial to manage (or migrate to a solution provided by others) Basically I have a master password tied to an identity file (or KEY), and use this key to encrypt and my passwords to keep on local drive (1 file 1 password). This leverages age, an encryption program and protocol by FiloSottile, so that every password uses post-quantum encryption (if you care for that), and can be stored on-device or on cloud without worrying for data leaks. To give some details: - i made a KEY identity file using a passphrase (which is thus my master password) - then I simply wrote my username and passwords into txt files, each named after the service which covers (i.e. amazon.txt has my amazon username and password) - as third step I encrypt each file using the KEY, so that to view the content I need both the KEY file and the passphrase - last, i copied each encrypted file on a cloud service, for backups, and moved the key file to a usb Therefore to decrypt a file (to see my logins) I plug in the usb (acting as a yubikey of sort, but I’m poor), via the age cli I insert the passphrase and voilà… This seems bothersome at first, but I can securely manage password and ifnI were ever to switch to bitwarden or something else, I just need to batch decrypt my pass files (a for loop does the job, pastinf the same passphrase each time)
-
@emotional_soup_88@programming.dev 2026-04-12 11:31
Thank you for sharing your story and journey! The following is a comment from a meta perspective. Absolutely no pun intended... If it's any consolation at all, I think this illustrates how a lot of digital industry giants have purposefully created ecosystems that are hard to leave, with the sole purpose of reaping your data, of course. It also shows how attaining even small steps towards digital privacy, which should *not* be this complicated, requires social and economic sacrifices, which in itself is insane, considering that privacy is supposed to be a universal human right. Now, a more direct comment. Always keep in mind that the end user is NEVER to blame for such back and forth struggles as you describe. You "wouldn't" commit, you say. Did ANY of the big tech giants ever make it easy for you, I ask? Personally, I'm using Tuta, SimpleLogin and KeepassXC (and it's fork for Android). My setup won't really give you any good hints though, since I'm not trying to achieve that smooth and dynamic workflow and ecosystem with easy credential sharing, exports and inter device operation. I log in and out of every instance every time on every device and manually update my password database and manually synch it to all my devices. It's a hassle, but then again, it takes just a few more minutes and I like "fiddling"..
-
@technocrit@lemmy.dbzer0.com 2026-04-12 17:18
Thanks to OP for sharing this cautionary tale and thanks to everybody in here giving helpful advice. I would like to self-host everything but y'all are scaring me off email.