Hi everyone. I’m thinking about using SimpleLogin but I have some concerns regarding security and privacy.
When using reverse aliases, emails pass through SimpleLogin’s servers—I read they use Proton and UpCloud servers.
If you’re sending an email with sensitive information, wouldn’t this pose an additional risk?
According to what I’ve read in SimpleLogin’s security policy, they claim they don’t store any emails once delivery to the recipient has been completed.
I hope someone who uses this service can shed some more light on this and other related questions.
Hi Pale, how are you? Yes, it’s similar to any other provider that isn’t E2EE—actually, I don’t think any provider maintains end-to-end encryption with external services, for example when sending from Proton to Gmail.
When it comes to sending sensitive information (nothing extreme), it would only be as a last resort and always when there are no other options available. In those cases, would the option be to use Proton’s password-protected messages feature?
On another note, I read that using SimpleLogin for bank account access is not recommended—I’m not sure why they say that.
It is another party to trust, if you don’t already use Protonmail. I use Fastmail and their own aliasing features, such that it’s still just a single party handling my emails.
Hi Pale. Currently, I’m increasingly using SL aliases for all services, including the important ones. I hope I don’t regret it. SL assured me that this was 100% effective and secure.
Hi Linux. Thank you very much for your comment. I understand your point about not putting all your eggs in one basket. Still, you’re also trusting Fastmail. Thanks a lot for your help.
Does anyone know if PGP encryption is maintained E2E if sending from a Proton address to a SL alias or catch all alias that’s linked to a Proton address?
Hi Doc. How are you? SL’s PGP makes sense if you’re using SL and Gmail, Outlook, or something like that. Someone who uses Proton and SL would already have encryption through Proton. So it would be somewhat redundant, wouldn’t it? Thanks for your comment.
In terms of SimpleLogin themselves I’m not too worried; I don’t do the kind of thing that got ProtonMail famous for handing out someone’s details to Swiss authorities. I’d say though that if someone was into activism that could get them into trouble like that, email is not the best tool at all.
My concern is more “all eggs in one basket” related. I’d be using this to make sure that different forum profiles, for example, are harder to correlate when those inevitable data breaches happen. (I know there are other techniques like writing style if someone really wants to, but why make it easy for the casual stalker). If I look up my email address on HIBP, it already reveals a fair history of all the different sites I’ve been on and anyone can do that, so the aim is to stop that building up further.
But - what if SimpleLogin gets a data breach? “x million SimpleLogin users’ data stolen” and all of your related aliases leaked. So now instead of just having MySpace, Dropbox and a bunch of others connected under your email address as the same person, you have all 50 websites you used SimpleLogin for connected as the same person. Or am I misunderstanding something in their security model?
You add 1 trust point with the alias, but remove the need to trust your actual e-mail with every site you choose to provide the email for. Even that, if the same entity manages the alias as your email, it’s more like a 1.5 instead of 2 trust points.
I think maybe the difference is it’s not the email address itself that I’m protecting. That already got let out of the bag years and years ago and it’s only spam filters that keep me sane. But the correlation problem means trusting one place not to get breached and leak every alias.
Of course, it’d be a monumental data breach that would probably put them out of business, just makes you think given how often there are massive email and username leaks on various sites and services.
Edit: I posted that and then immediately realised it wasn’t me you were responding to..