Why Does Google Know Everything You’ve Bought on Amazon for the Past Six Years?(nytimes.com)
nytimes.com
Why Does Google Know Everything You’ve Bought on Amazon for the Past Six Years?
https://www.nytimes.com/2019/06/04/opinion/google-purchases.html
36 comments
A quote:
"Scrolling through my Purchases, I couldn’t shake the most basic questions: What good reason is there for Google to store six years of detailed purchase information? Why can’t I delete it without deleting the emailed receipts? Why aren’t there default time limits on how long information is stored?"
These are silly questions. If you don't delete the email, Google still knows you made that purchase.
There's a difference between the emails being stored on googles servers and being available for data extraction by their algorithms, and them keeping the extracted and indexed/queryable data stored as well as the emails.
There is no difference as far as what Google knows about you.
Well, deleting them would presumably avoid future, more invasive / nefarious algorithms that are yet to be conceived of.
Why?
To me, there is no difference.
To me, there is no difference.
So, you're telling me it's finally time to market this plug & play home email server idea?
Better get started, your competition just launched 6 months ago: https://arstechnica.com/gadgets/2018/12/review-helm-personal...
yep - co-founder of Helm here
here's another review from Micah Lee at The Intercept for anyone who's interested: https://theintercept.com/2019/04/30/helm-email-server/
here's another review from Micah Lee at The Intercept for anyone who's interested: https://theintercept.com/2019/04/30/helm-email-server/
Why does Helm require users to have their location turned on? I use bluetooth on Android all the time with my location kept off.
People really do not want to run their own email. I used to, and have my own domain, but these days I pay a small ISP to manage it.
People might be OK with a quasi-managed solution where you pay a fee to the cloud provider to route in and out through a non-spam IP, and the provider does regular updates and configuration on the home server.
People might be OK with a quasi-managed solution where you pay a fee to the cloud provider to route in and out through a non-spam IP, and the provider does regular updates and configuration on the home server.
I've toyed with the idea myself, if you've worked around the lack of fixed IP's problem then sign me up.
Dynamic IP isn't really the issue. If a server can ping, it can update its DNS record. This obviously won't work without WAN connectivity, but neither will an email server and there lies the problem - consumer WAN access can't be 5 nines guaranteed and if we start engineering redundant fallover/load-balancing as a backup, what's the benefit of that over a hosted email service?
edit: practical problem no 2 is that if your residential ISP sees activity on the standard SMTP ports, it will quickly dropped like a hot potato (if they don't outright block unsolicited connections to those ports altogether which is common). Complaining about it will garner the response "sounds commercial to me, get a business account".
edit: practical problem no 2 is that if your residential ISP sees activity on the standard SMTP ports, it will quickly dropped like a hot potato (if they don't outright block unsolicited connections to those ports altogether which is common). Complaining about it will garner the response "sounds commercial to me, get a business account".
> If a server can ping, it can update its DNS record
Isn't there a significant delay for this to propagate?
> consumer WAN access can't be 5 nines guaranteed
2 nines are more than sufficient, plus the occasional longer term outage for various network outages. Even for most business 5 nines isn't that important.
> practical problem no 2 is that if your residential ISP sees activity on the standard SMTP ports
Weirdly enough this isn't a problem for my ISP, I couldn't buy a static IP but they're happy to open any ports I want. YMMV.
Isn't there a significant delay for this to propagate?
> consumer WAN access can't be 5 nines guaranteed
2 nines are more than sufficient, plus the occasional longer term outage for various network outages. Even for most business 5 nines isn't that important.
> practical problem no 2 is that if your residential ISP sees activity on the standard SMTP ports
Weirdly enough this isn't a problem for my ISP, I couldn't buy a static IP but they're happy to open any ports I want. YMMV.
You set the DNS TTL to 30 or 60 seconds, then there's no problem with caching the old IP.
Email is extremely tolerant of downtime. There are also commercial backup mail servers (these accept and cache the email until your server is back up), which can be used as the only public way to receive email. Some will deliver it to a non-standard port.
Email is extremely tolerant of downtime. There are also commercial backup mail servers (these accept and cache the email until your server is back up), which can be used as the only public way to receive email. Some will deliver it to a non-standard port.
> You set the DNS TTL to 30 or 60 seconds, then there's no problem with caching the old IP.
This will not work. Most of your visitors will depend on some upstream resolver (for example google's resolver), which will cache you for 24h (you can explicitly request a flush - but the whole point of this system is that it's automated). AFAIK (which is a year or two out of date), every big DNS resolver that you might expect someone to use does this, to prevent the enormous performance issues from people setting their TTL to anything less than that.
Edit: Of course if you use a good relay server that isn't owned by you you can mitigate this, because they'll keep the emails in a queue for you until you can be found again.
This will not work. Most of your visitors will depend on some upstream resolver (for example google's resolver), which will cache you for 24h (you can explicitly request a flush - but the whole point of this system is that it's automated). AFAIK (which is a year or two out of date), every big DNS resolver that you might expect someone to use does this, to prevent the enormous performance issues from people setting their TTL to anything less than that.
Edit: Of course if you use a good relay server that isn't owned by you you can mitigate this, because they'll keep the emails in a queue for you until you can be found again.
Years ago, 24 to 48 hrs was the case for a DNS resolution update. But I have redirected DNS many times over the last few years and it resolves correctly, worldwide within a few minutes. Almost everytime. Occasionally, I will see a few locations in India or China cache for longer than the ttl but never longer than 4 to 6 hours.
And this isn't just a record cache. Even a nameserver change seems to get picked up in less than 15 minutes worldwide.
And this isn't just a record cache. Even a nameserver change seems to get picked up in less than 15 minutes worldwide.
I haven't generally seen evidence of this when I've changed the IP address of websites.
After the TTL expires, the only hits left on the old IP are from China (Great Firewall?).
After the TTL expires, the only hits left on the old IP are from China (Great Firewall?).
Practical problem #3 is spam email.
Google and the like are pretty good at filtering it. So good that the volume of spam has fallen. But about 10 years ago perhaps 90% of all email was spam. I wonder what the volume is now?
What are the current spam filtering options available to those who want to run a home server? Are they nearly as good as what Google uses?
Google and the like are pretty good at filtering it. So good that the volume of spam has fallen. But about 10 years ago perhaps 90% of all email was spam. I wonder what the volume is now?
What are the current spam filtering options available to those who want to run a home server? Are they nearly as good as what Google uses?
I no longer consider google to be 'good at filtering' - it's over zealous - so it could be true that the huge spam problem has been reduced by a large percent, but that comes at a great cost.
To some the cost is less - to those who use email for business, I'd say there are significant loss possibilities. I have recently discovered this in several situations.
I think of it more like an a middle man in the ATM or a change making machine that is looking for counterfeit bills - sure it may be great to have it shred 90% of the counterfeits, and some people may never get several hundreds passed through - but if you did and the machine shredded the hundreds being sent to you often - I would not consider that good.
To some the cost is less - to those who use email for business, I'd say there are significant loss possibilities. I have recently discovered this in several situations.
I think of it more like an a middle man in the ATM or a change making machine that is looking for counterfeit bills - sure it may be great to have it shred 90% of the counterfeits, and some people may never get several hundreds passed through - but if you did and the machine shredded the hundreds being sent to you often - I would not consider that good.
You use spamassasin (and maybe spamd as well). In a very practical sense it is miles better than what office365 has. It's not better than google (because what is?), but it comes close.
Is using a non-standard port a feasible option? Not that I think it's a good idea to put anything you'd expect reasonable availability to behind consumer-grade internet. Why not host your own email using VPSes?
No, there's no real provision in email for SMTP to be on non-port 25. You can make it listen on something else, but the only thing a remote server is going to do is look up the MX record, and then try opening port 25 on it.
Since you'll want a forwarder anyway (many many email servers blacklist anything on a known-ISP IP range (ie, home users)), you might be able to find one that allows you to configure a specific port to forward to, but it'd be non-standard.
Since you'll want a forwarder anyway (many many email servers blacklist anything on a known-ISP IP range (ie, home users)), you might be able to find one that allows you to configure a specific port to forward to, but it'd be non-standard.
Your practical problem number two sounds like a very localised issue, because this is not something that would happen in my neck of the woods (in fact, I doubt it is even legal).
Which will be useless given how many places blacklist the ISP IP ranges. You'll still want a email forwarder that can do the MX store & transfer for your server.
As long as you can send email to gmail and hotmail you've captured most email traffic people are likely to send. AFAIK, those services don't do what you describe.
Those communications have more or less been replaced by IM. You still need an email address for things like job applications, legal/financial matters, bills, online shopping status updates, etc. None of those use hotmail or gmail.
It's more about inbound mail, many of the big mail services wont send TO you if you're on an ISP IP
I think the only email services that are not going to mine your emails for valuable data are paid services that have made strong commitments to privacy. This was an interesting podcast interview with founder of Fastmail https://overcast.fm/+Hbyc810T0
I was about to counter that self hosted is an option, but that doesn't technically qualify as an "email service".
I'll note that the privacy centric services are only good as long as they're still maintained by a founder... you trust. If things go sideways, they can always be "acquired".
I'll note that the privacy centric services are only good as long as they're still maintained by a founder... you trust. If things go sideways, they can always be "acquired".
[deleted]
Everybody should already migrate to something of their own domain or proton mail or the likes.
I have a couple of domains, one self-configured on Digital Ocean and one on Bluehost. Bluehost has an 5-inbox email as part of the plan. Is it likely that Bluehost can do the same kind of surveillance that Gmail can?
Yahoo Mail is perhaps better for privacy? Even if they strive to be just as evil as Google, they are probably not nearly as competent.
In addition, Verizon, Yahoo's overlord, is probably run by "old school" telecom management that doesn't fully appreciate the financial goldmine of data mining.
In addition, Verizon, Yahoo's overlord, is probably run by "old school" telecom management that doesn't fully appreciate the financial goldmine of data mining.
> probably not nearly as competent
I'm not sure this is a good argument for Yahoo! being better for privacy. Sure it means they're less likely to keep track of your purchase metadata from emails but it also means they're more likely to be hacked again and leak all your emails to the world.
I'm not sure this is a good argument for Yahoo! being better for privacy. Sure it means they're less likely to keep track of your purchase metadata from emails but it also means they're more likely to be hacked again and leak all your emails to the world.