# Skiff Mail (Email Provider)

**URL:** https://discuss.privacyguides.net/t/skiff-mail-email-provider/11411
**Category:** Tool Suggestions
**Tags:** completed
**Created:** 2023-01-07T00:56:47Z
**Posts:** 354

## Post 1 by @nishil — 2023-01-07T00:56:47Z

Hi there,

We have done a lot of work to improve our services over the past few months to meet the requirements laid out to be listed on privacyguides for Email Services. We believe we have resolved the previous criticisms laid out in Github Issue #1363. However for reference, I have explicitly laid out what criteria we have met and where we might still have some work to do, but we do believe that we at least meet the minimum criteria for listing consideration.

After this submission, we will submit additional posts for consideration of Skiff services under the “Calendar & Contact Sync”, “File Sharing & Sync”, “Notebooks”, and “Cloud Storage” categories.

Technology

Minimum to Qualify:

[YES] Encrypts email account data at rest with zero-access encryption.

Best Case:

[YES] Encrypts all account data (Contacts, Calendars, etc) at rest with zero-access encryption.

[YES] Allow users to use their own domain name

[YES] ​Integrated webmail E2EE/PGP encryption provided as a convenience.

​[NO] Support for WKD to allow improved discovery of public OpenPGP keys via HTTP.

[YES - Done by link sharing an e2ee Skiff Page] Support for a temporary mailbox for external users.

[YES] Subaddressing support

[NO - In testing/imminent release] Catch-all or alias functionality for those who own their own domains.

[NO] ​Use of standard email access protocols such as IMAP, SMTP or JMAP.

Privacy

Minimum to Qualify

[YES] ​Protect sender’s IP address. Filter it from showing in the Received header field.

[YES] Don’t require personally identifiable information (PII) besides a username and a password.

[YES] ​Privacy policy that meets the requirements defined by the GDPR

[NO] ​Must not be hosted in the US due to ECPA which has yet to be reformed

Best Case:

[YES - cryptocurrency only] - Accepts Bitcoin, cash, and other forms of cryptocurrency and/or anonymous payment options (gift cards, etc.)

Security

[YES - TOTP] Protection of webmail with 2FA, such as TOTP.

[YES] Zero access encryption, builds on encryption at rest. The provider does not have the decryption keys to the data they hold.

[YES] DNSSEC Support

[YES - See note below] No TLS errors or vulnerabilities when being profiled by tools such as Hardenize, testssl.sh, or Qualys SSL Labs; this includes certificate related errors and weak DH parameters, such as those that led to Logjam.

Note: Currently, we use AWS SES as a backup solution as shown by the MX records showing AWS SES as a lower priority than our own servers. We have a plan to deprecate SES in the next 3-6 months as we build on our track record of operating a reliable email service.

[YES] ​A server suite preference (optional on TLSv1.3) for strong cipher suites which support forward secrecy and authenticated encryption.

[YES] A valid MTA-STS and TLS-RPT policy.

[YES] Valid DANE records.

[YES] Valid SPF and DKIM records.

[YES - DMARC reject] Have a proper DMARC record and policy or use ARC for authentication. If DMARC authentication is being used, the policy must be set to reject or quarantine.

[YES] A server suite preference of TLS 1.2 or later and a plan for Deprecating TLSv1.0 and TLSv1.1

[YES] SMTPS submission, assuming SMTP is used

[YES - HSTS enforced and preloaded] HTTP Strict Transport Security

[N/A] Subresource Integrity if loading things from external domains.

Best Case:  
[NO - In development] Support for hardware authentication

[YES] DNS Certification Authority Authorization (CAA) Resource Record in addition to DANE support.

[NO - in development] Implementation of Authenticated Received Chain (ARC), this is useful for people who post to mailing lists RFC8617.

[YES - See Note.] Bug-bounty programs and/or a coordinated vulnerability-disclosure process.

Note: We accept security bug reports at security @ [skiff.com](http://skiff.com). However, we do not issue bounties at this time.

[YES] CSP

[N/A - See Note.] Expect-CT

Note: This header has been deprecated and is no longer available in Firefox and Safari. Chromium browsers enforce CT by default. More info can be found at MDN [link removed to 2 link max limit]  
Trust

Minimum to Qualify:  
[YES - See Note] Public-facing leadership or ownership.

Note: Co-founders Andrew Milich (CEO) and Jason Ginsberg (CTO) have been profiled or referenced in major publications and a sample are referenced below:

[https://www.fastcompany.com/90764245/id-love-to-dump-gmail-for-this-slick-private-email-but-theres-a-catch](https://www.fastcompany.com/90764245/id-love-to-dump-gmail-for-this-slick-private-email-but-theres-a-catch)

\<Links removed due to 2 link max limit\>

Best Case:  
[YES - See Above.] ​Public-facing leadership.

​[NO - On roadmap] Frequent transparency reports.

Marketing

Minimum to Qualify

[YES] Must self-host analytics (no Google Analytics, Adobe Analytics, etc).

[YES] Must not have any marketing which is irresponsible

Best Case

[YES - Youtube Channel] - Clear and easy to read documentation.

---

## Post 2 by @mika — 2023-01-07T04:42:44Z

Does Skiff optionally support CardDAV and/or CalDAV? Or otherwise offer a way to sync contacts with a phone and share calendars with others?

---

## Post 3 by @amilich — 2023-01-08T00:00:28Z

We do not yet support CardDAV or CalDAV, but we hope to in the future. They have been requested frequently.

---

## Post 4 by @sbeve — 2023-01-08T00:15:19Z

CardDav and CalDav protocols do not support end-to-end encryption AFAIK

---

## Post 5 by @mika — 2023-01-08T01:43:41Z

Correct, but a contacts service isn’t useful to most people if it has no way to sync with devices, like on your phone.

This can either be via (optional) non-encrypted sync like with CardDAV, or with a workaround like EteSync uses.

---

## Post 6 by @dngray — 2023-01-08T10:51:56Z

I [noticed that](https://www.reddit.com/r/PrivacyGuides/comments/101v4yt/why_no_one_suggests_skiff_mail_along_with_proton/j2wkzef/), and am having a look at it now.

---

## Post 7 by @ph00lt0 — 2023-01-08T12:45:49Z

@nishil I see that you still have some outdated ciphers accepted, this is likely a misconfiguration. Nothing too big but maybe good to look into:

> **[Website test: skiff.com](https://internet.nl/site/skiff.com/1861645/#control-panel-12)**
>
> Test for modern Internet Standards IPv6, DNSSEC, HTTPS, HSTS, DMARC, DKIM, SPF, STARTTLS, DANE, RPKI and security.txt

Also please consider to add a security.txt see [https://securitytxt.org/](https://securitytxt.org/) so that people can actually find where to report vulnerabilities.

As for email:

> **[Email test: skiff.com](https://internet.nl/mail/skiff.com/845767/#control-panel-6)**
>
> Test for modern Internet Standards IPv6, DNSSEC, HTTPS, HSTS, DMARC, DKIM, SPF, STARTTLS, DANE, RPKI and security.txt

DNSSEC is not correctly configured, therefore you do not meet the requirements of PG.

Also TLS for email allows 1.0 this version should not be accepted. I wonder generally why [inbound-smtp.us-west-2.amazonaws.com](http://inbound-smtp.us-west-2.amazonaws.com) is used. This seems to have a weak configuration also DANE is missing.

---

## Post 8 by @dngray — 2023-01-08T15:09:02Z

Hi, so I’m doing a bit of a review on this now.

## More clarification on E2EE to users

I think many users are going to simply think “Encrypted” means that it is “E2EE” when it’s not. Most users **are** going to be emailing non-skiff users. I think Proton Mail for example makes this really obvious: [How to check encryption status using lock icons | Proton](https://proton.me/support/encryption-lock-meaning). That article is linked from the compose window.

 ![2173304711](//forum-uploads.privacyguidesusercontent.com/original/1X/a2cd83c2d78208a5df75fb671103a518c22325b5.png)  
I also did **not** see an option there to send a Temporary Inbox, style message to non-Skiff users. Notably this is something that Proton Mail, Tutanota and Mailbox have.

This gives the ability for external users to reply E2EE in their web browser. While not ideal it’s better than nothing.

I realize email encryption is hard and really the only standard is PGP. I know you’re really not going to want to hear that seeing as you wrote [Skiff - Private, encrypted, secure email - 10 GB free](https://skiff.org/blog/pgp-dead-what-next) but it is an unfortunate truth that PGP will probably never entirely _die_ until something replaces it, that can be federated across email providers.

What Skiff is right now, is certainly not going to replace it. It also won’t be the The Signal Protocol either, as this requires key exchange which isn’t possible on an asynchronous communication protocol like SMTP. There has been an attempt (and you might remember criptext, which hasn’t seen any activity in ages). Signal Messenger isn’t going to replace email, as there is still a workflow for “letter” style immutable responses as opposed to transient back-forward conversation.

There are also efforts to modernize PGP such as [RFC 9580 - OpenPGP](https://datatracker.ietf.org/doc/draft-ietf-openpgp-crypto-refresh/). In that article I would have personally used a better source than a sensationalist [wired.co.uk](http://wired.co.uk) article claiming that PGP is dead, (I would have used [https://efail.de](https://efail.de)). There are a few loud voices that want to make that claim, but until another RFC with benefits over the current one is created, that’s unlikely to happen.

Efail was a “blip” in 2018, now that vulnerable clients are fixed, and developers are using gpgme instead of directly invoking gpg and trying to parse HTML emails, the issue really isn’t quite as dire to even bother mentioning. Modern versions of Thunderbird, don’t even use GnuPG anymore (where that proof of concept originally was discovered), instead they use [OpenPGP.js](https://openpgpjs.org).

Also forward secrecy may not be as important as you think: [Op-ed: Why I’m not giving up on PGP - Ars Technica](https://arstechnica.com/information-technology/2016/12/signal-does-not-replace-pgp/) explains that quite well. Additional efforts such as using a security key can provide extra security against key theft. You can’t have your Skiff keys stolen because Skiff doesn’t give you access to them, so that is one way to solve that problem.

Even established providers like Tutanota have only come as close as providing a “Temporary inbox” where users put a message in a JavaScript implementation on the provider’s website, which I might add does introduce other security issues such as does it have the same guarantees as a client side implementation from a third party. This is important regarding the introduction of a backdoor or interception order (perhaps an NSL, remember [Edward Snowden and LavaBit](https://www.wired.com/2016/03/government-error-just-revealed-snowden-target-lavabit-case/)) for particular users. We may see something based on [MLS](https://datatracker.ietf.org/wg/mls/documents/) but until then I think PGP is here to stay.

## Marketing

I see many articles like this one [Skiff - Private, encrypted, secure email - 10 GB free](https://skiff.org/blog/end-to-end-encryption-email) which focus heavily on E2EE in a very general sense. The article leaves out that emails that are sent to non-skiff users are **not E2EE**. It feels like a point you’re striving to not highlight. This is the sort of thing we see networks like Telegram do a lot, leaving users to genuinely think that **all** their messages are E2EE, when they aren’t.

There does seem to be a fair bit of “marketing fluff”, on the blog as opposed “real content”. This kind of thing happened during the early days of CTemplar. I would like to see improved quality there, such as articles about real issues, (Proton has a section for this) and changes in the Skiff product. I would also suggest having more screenshots when providing guides of how to do particular things in Skiff. These are useful when third parties want to support users of your product.

With the above article it mentions “_In this guide_”, but it’s not really a guide, it’s a basic explainer on transport encryption vs end-to-end encryption.

One section there stuck out to me “The importance of end-to-end email encryption” talks about compliance in the business sector. An important part of **Compliance and governance** - besides sounding important is that your manager can actually audit what email you’ve been sending from the company domain which is why things like [Google Vault](https://workspace.google.com/products/vault/) exists. I would tone down the “this is good for business”, marketing because the reality is when you are a business, you have a right to know what your employees are doing with the company domain.

There is more to providing service to businesses than simply giving them bigger data caps or allowing more seats. Even Proton Mail is not perfect in this regard, and with their resources and time it’s taken a long time to get anywhere close. In Skiff’s defense, all privacy providers, that is ones which use E2EE in as many places as possible, are going to have to solve a lot of very difficult problems, and engineer a lot of custom solutions to meet existing business workflows. I haven’t seen a single one with commercial features like email routing, groups and distribution lists, shared calendars, shared inboxes, custom DKIM keys, and other functionality.

Please avoid outrageous claims like:

> **one of the most progressive providers in the data security industry**

This simply is not true, while Skiff may be a good product some day, competitors do still lead in many areas, and that is to be expected as they’ve had longer for their products to mature. I think in general “honest marketing” goes a long way. An example of that would be what [IVPN does](https://www.ivpn.net/blog) (they’re a VPN provider), but they’re quite happy to tell you about the limitations of their product and what it should be used for. (As an example).

This might also explain why I see Skiff users constantly spruiking the product on Reddit. I had wondered about that.

 ![2404416683](//forum-uploads.privacyguidesusercontent.com/original/1X/fad9a5294f9103a784f50d2298975d0193627b10.png)

## Community

I noticed was that they only have a Discord community, which in general isn’t [very privacy friendly](https://discord.com/privacy). I would have like to have seen a Matrix community. Skiff could then make sure at least their data is stored on a server they own, (for example like [Mozilla.org](http://Mozilla.org) have an EMS instance). I’d actually like to see a Mastodon account too for announcements, as it is nice to have less commercial and invasive alternatives to Twitter.

Honestly I don’t think anyone uses LinkedIn these days. It does feel like “old school marketing firm” made those decisions.

## Email

The email interface, is very basic, for example I noticed you cannot have nested folders [unlike Proton Mail](https://proton.me/support/using-folders-labels). [Tutanota doesn’t support this either](https://github.com/tutao/tutanota/issues/927). I’d probably have a toolbar in the composition window though for users who don’t know they can use markdown.

I also noticed there’s **no way to see email headers** , which makes it impossible to really dissect an email to see if it’s not a phishing email. Gmail etc lets you see DMARC status and all headers. Both Tutanota and Protonmail, as well as all the other providers we list on the website have this.

## Import

I noticed the [import features](https://skiff.org/blog/migrate-email-account) in Skiff, support importing via EML, MBox, Outlook or an IMAP server. This has always been a struggle point for privacy providers, notably Tutanota is only [thinking about that now](https://tutanota.com/blog/posts/kickoff-import) after having an issue in their tracker for a very long time [Email import · Issue #630 · tutao/tutanota · GitHub](https://github.com/tutao/tutanota/issues/630).

Meanwhile Proton Mail [Easy Switch](https://proton.me/support/easy-switch) only came about rather recently. Before that users had the pleasure of dealing with the [Import/Export](https://proton.me/support/export-emails-import-export-app) and it’s [unreliability](https://blog.cavelab.dev/2020/03/importing-emails-to-protonmail/).

Things should improve with Proton Mail, with the new [v3 bridge](https://github.com/ProtonMail/proton-bridge/releases), that has a completely re-implemented APIs, and IMAP implementation, and avoiding issues like [Our ProtonMail Adventure - A Five Act Drama](https://blog.sigma-star.at/post/2022/07/protonmail-adventure/).

Curious to know why there’s $10 credit from coming from Outlook, but not gmail or uploading email from another provider.

 ![1144667428](//forum-uploads.privacyguidesusercontent.com/original/1X/15ab90fbd7351429394345d1e1440e86ccd7c2e3.png)

## Export

There also seems to be no export feature, as this post also notes:  
[https://www.fastcompany.com/90764245/id-love-to-dump-gmail-for-this-slick-private-email-but-theres-a-catch](https://www.fastcompany.com/90764245/id-love-to-dump-gmail-for-this-slick-private-email-but-theres-a-catch)

I do see features like “Connect a wallet to send and receive email from your Web3 identity” this I don’t consider an important feature. When you are missing key features like export I don’t know why Skiff is wasting time on this.

I’m now thinking of adding export as a requirement to the PG criteria. This is the first time we’ve come across a provider without that feature. **Data liberty** is as important and we don’t believe user data should ever be held hostage.

I also notice that article mentions:

> But even if Skiff adds more of these features, it still has one inherent challenge: It’s a new, unproven service [backed by venture capital](https://techcrunch.com/2022/03/30/skiff-series-a-encrypted-workspaces/). While Gmail isn’t going anywhere, I can’t confidently say the same about Skiff.

The concern there is, if the VC decides to not give it more funds and the product isn’t in as good health as it should be, viability may be an issue long term. Without an export feature that would make me very uncomfortable.

## Filters

No add email filtering rules, ie a label or a folder. All mail must be manually organized/moved/labeled.

## Pricing

Email doesn’t take up a lot of space, and most users won’t need 100GB of storage. The pricing of [Proton Mail](https://proton.me/mail/pricing) and [Tutanota](https://tutanota.com/pricing) is quite _different_ to Skiff’s pricing on the entry level accounts.

## Calendar

So the calendar is simple with a nice design. It does appear that there are some fairly important features missing though - such as the ability to share calendars.

It would also be nice to be able to import calendars from a URL, rather than just an ICS file. Common usecase for this would be subscribing to public holidays etc.

I noticed that it said during the import that “Repeated events are not yet supported”, I would consider this a crucial missing feature.

## Drive/Pages

This certainly seems to be the strong point. If we do go forward with listing Skiff, we’ll be mentioning this is the **main reason** you’d want to use Skiff. This would be one of the stronger features of the product. One of the weak points of things like Proton Drive is there isn’t really any way to author documents in your web browser, let alone collaborate with other users.

## Privacy Policy

> All information processed by us may be transferred, processed, and stored anywhere in the world, including, but not limited to, the United States or other countries, which may have data protection laws that are different from the laws where you live. We endeavor to safeguard your information consistent with the requirements of applicable laws.

Doesn’t seem to be anything about GDPR there. Typically these days even for non EU providers they will address that.

I did notice this piece which was a bit ambiguous:

> **De-identified and Aggregated Information.** We may use information about you to create de-identified and/or aggregated information. We may use such aggregate or de-identified information for any purpose, and such information is not subject to the limitations set forth in this Policy.

Sometimes de-identified information is able to be reversed. I don’t particularly like to see open ended clauses in a privacy policy.

### Skiff Acceptable Use Policy

I did notice in there:

> - scrapes content hosted on our Site or through the Services without prior Skiff’s prior written authorization;

This would imply one isn’t allowed to write a scraper to export their email.

## Other questions:

As Skiff is using its own implementation to achieve E2EE within the service, is there a cryptographic audit for this? I see mention here [Skiff - Private, encrypted, secure email - 10 GB free](https://skiff.org/blog/open-source)

> We have been committed to open source software since the very beginning of Skiff. We strongly believe that privacy cannot be just a promise; software must be available for anyone to independently audit and validate.

Realistically though this isn’t just “going to happen” because the product is open source. Is there funding available for a paid audit that encompasses the implementation, and network?

After having a look at the repo, particularly [Commits · skiff-org/skiff-apps · GitHub](https://github.com/skiff-org/skiff-mail/commits/main) it appears no development takes place in public, so this might as well be a public FTP. Also you should look at using `.gitignore` and not upload metadata like `.DS_Store` files. The issue with that is, it provides a lack of transparency around new features and potential regressions, essentially someone has to sit down and figure out what the codebase does, how it fits together etc.

The above statement really does feel like you’re hoping an audit will fall in your lap somehow.

---

## Post 9 by @amilich — 2023-01-08T20:08:31Z

> [@dngray](#):
>
> audit

Posting a few initial responses with more to come. This is super comprehensive feedback, and we appreciate the feature requests and constructive criticism.

1. External mail sent and received to non-Skiff providers is still stored encrypted with user public keys, so it is not accessible by Skiff. It is quite hard to capture these nuances in tooltips, but the point is that even external mail is safe, and it is **never** unencrypted. I completely disagree that it is misleading.

2. I think PGP is quite out of scope for the criteria here. Given the articles you linked to, if only 30,000 external users use it, it’s basically unused by the Proton user base, and Tuta does not support it. Both Skiff and Tuta also encrypt email subjects, which I think is an enormous privacy benefit.

3. Sending encrypted content to other users is possible. You can use a Skiff document on view/edit mode, which is end-to-end encrypted with a link URL and also offers password protection (additional encryption) and watermarking. Proton, Tuta, and all other providers do not offer functionality like this, but I actually think it’s better because it offers real-time collaboration, commenting, and more.

4. I think discussing our community channels is a bit out of scope. We had a Matrix community, but it was bombarded with drugs and crypto spam that made it completely unusable and safe for users. We do have a Mastodon at ioc.exchange. I honestly think this is quite of scope, particularly given many recommended services on PrivacyGuides (Proton, Tuta, Brave, etc.) use many of the same social channels (Twitter).

5. Import from other providers is coming. MBOX and EML should also give you the same credit. We have Gmail import ready to launch as well.

6. The funding discussion is a bit one-sided. Venture capital is simply capital, and all companies require it to survive. Brave, DuckDuckGo, Proton, and many other recommended companies have taken venture funding - including Brave + DuckDuckGo in the last year! Skiff has many years of capital and paying customers to keep our services running.

7. Export is coming. We’re prioritizing everything we can, and we’re just building import options. There are super comprehensive export options on Pages/Drive - export to MD, DOCX, PDF, and ZIP for entire folders, or even exporting entire teams - so we have no bias against it.

8. The blog is being reorganized, but a lot of it is written for content marketing and SEO. If you dig into the Proton/Brave sites, you’ll see similar content, just not as publicly visible. For example, see [Learn | Brave](https://brave.com/learn/) with “the best private browser.” These types of lines are typical to SEO optimized blog posts.

9. I agree on the pricing comment, but the plans are optimized for using Skiff as a suite, where 100 GB is actually quite helpful for Drive/Pages storage. Also, the free plans are much more generous, and the paid plans more expensive.

10. Repeating events are coming to Calendar soon.

11. We have undergone 3+ audits, all from Trail of Bits. [GitHub - trailofbits/publications: Publications from Trail of Bits](https://github.com/trailofbits/publications). If you’d like more info, Dan Guido (TOB’s CEO) has Tweeted about us a bunch. The audits cover all Skiff products, security model, and infrastructure.

---

## Post 10 by @dngray — 2023-01-08T20:43:13Z

> [@amilich](#):
>
> External mail sent and received to non-Skiff providers is still stored encrypted with user public keys, so it is not accessible by Skiff. It is quite hard to capture these nuances in tooltips, but the point is that even external mail is safe, and it is **never** unencrypted. I completely disagree that it is misleading.

The issue is that isn’t really E2EE. As soon as an email leaves Skiff’s system it no longer has E2EE. It is only E2EE while Skiff has it. Generally when people think of E2EE email they expect it to be E2EE on both ends, the recipient and the sender’s end point.

- I’m **not** a Proton Mail customer, but I **can** send an E2EE email to one of their users.
- I’m **not** a customer of Tutanota, but if one emails me with an encrypted email and provides the temporary password - say over the phone, I **can** make sure that email is E2EE when it leaves my browser.

Perhaps not with the same assurance as PGP, (for example Tutanota could in theory disable E2EE for a particular user), ie by changing the server side code so when a particular user sends me a temporary inbox link, there is no encryption.

If I am a Thunderbird user, Mozilla cannot be compelled in any way to target a specific user. PGP without forward secrecy still can provide the highest level of assurance because implementations don’t necessarily come from the provider. Key theft is basically impossible with a Yubikey.

For commercial providers even Proton wants to keep an encrypted copy of the private key, this is because of support requests they do not want to deal with. I accept responsibility that loss of my keys will mean a loss of my email.

The point I’m trying to make is that it is **not accurate** by any means to say “PGP is dead” or that it is “broken”, there are certainly improvements that could be made.

> [@amilich](#):
>
> I think PGP is quite out of scope for the criteria here. Given the articles you linked to, if only 30,000 external users use it, it’s basically unused by the Proton user base, and Tuta does not support it.

You really can’t know how many PGP users there are. It’s a decentralized protocol without reporting functionality. There are many implementations and many providers. I have run into Proton Mail (and occasionally Tutanota) users (outside of the privacy communities), but I’ve never run into a user of smaller privacy providers.

> [@amilich](#):
>
> Both Skiff and Tuta also encrypt email subjects, which I think is an enormous privacy benefit.

While this is important, it may not be as important as making sure the email body is encrypted on both the recipient’s server and your own. Email subjects can contain sensitive information and while there is [Protected Headers for Cryptographic E-mail](https://datatracker.ietf.org/doc/draft-autocrypt-lamps-protected-headers/02/) it’s unfortunately not widespread. Proton Mail for example doesn’t support it.

Email metadata is a lost cause, you’ll never be able to encrypt To, From, and that’s some of the most private data out there.

> [@amilich](#):
>
> Sending encrypted content to other users is possible. You can use a Skiff document on view/edit mode, which is end-to-end encrypted with a link URL and also offers password protection (additional encryption) and watermarking. Proton, Tuta, and all other providers do not offer functionality like this, but I actually think it’s better because it offers real-time collaboration, commenting, and more.

I would agree that is one of Skiff’s benefits, which I did mention above. For a small team that mostly keeps things internal that would be the strongest customer base, unfortunately by itself, it’s quite niche.

This doesn’t really help with incoming email from various sources or if you have to share something sensitive with an external user.

> [@amilich](#):
>
> I think discussing our community channels is a bit out of scope. We had a Matrix community, but it was bombarded with drugs and crypto spam that made it completely unusable and safe for users.

I’ve seen that on Telegram and Discord as well. The main concern is that Discord encourages users to hand out their phone number, and provides no E2EE on messages. While it could be argued there nothing is really private there, inevitably you’re probably going to field support requests from that source. Discord’s privacy policy is a bit opaque when it comes to collecting data for advertising, where it ends up, etc.

For user support I actually think a forum-styled system is better because bar of entry is low, and content can stay up there long term, and it certainly helps with SEO. Common go-to services for this are [https://www.useresponse.com](https://www.useresponse.com) and [https://uservoice.com](https://uservoice.com).

> [@amilich](#):
>
> We do have a Mastodon at ioc.exchange. I honestly think this is quite of scope, particularly given many recommended services on PrivacyGuides (Proton, Tuta, Brave, etc.) use many of the same social channels (Twitter).

They do, it was just something that I noticed. Might be worth adding that to the bottom of your page footer. This had no bearing on listing, but I thought it was worth mentioning anyway.

> [@amilich](#):
>
> Import from other providers is coming. MBOX and EML should also give you the same credit. We have Gmail import ready to launch as well.

Okay, that wasn’t really obvious to me.

> [@amilich](#):
>
> The funding discussion is a bit one-sided. Venture capital is simply capital, and all companies require it to survive. Brave, DuckDuckGo, Proton, and many other recommended companies have taken venture funding - including Brave + DuckDuckGo in the last year! Skiff has many years of capital and paying customers to keep our services running.

Just to clarify, I was not saying that VC funding is bad, or anything like that, only that it is cruicial to viability of a company to continue, especially during the early days. VCs do without a doubt want to see a ROI.

> [@amilich](#):
>
> Export is coming. We’re prioritizing everything we can, and we’re just building import options. There are super comprehensive export options on Pages/Drive - export to MD, DOCX, PDF, and ZIP for entire folders, or even exporting entire teams - so we have no bias against it.

Yes I noticed that, and I figured as much. I do get that creating an email provider from scratch **is hard** because you basically have to provide what users of other services already have. Your competition is well resourced, Google, Proton etc.

> [@amilich](#):
>
> The blog is being reorganized, but a lot of it is written for content marketing and SEO. If you dig into the Proton/Brave sites, you’ll see similar content, just not as publicly visible. For example, see [Learn | Brave Browser](https://brave.com/learn/) with “the best private browser.” These types of lines are typical to SEO optimized blog posts.

Yes, I’m well aware they do that.

> [@amilich](#):
>
> Repeating events are coming to Calendar soon.

:+1:

> [@amilich](#):
>
> We have undergone 3+ audits, all from Trail of Bits. [GitHub - trailofbits/publications: Publications from Trail of Bits](https://github.com/trailofbits/publications). If you’d like more info, Dan Guido (TOB’s CEO) has Tweeted about us a bunch. The audits cover all Skiff products, security model, and infrastructure.

Are any of them public? I would be curious to take a look.

---

## Post 11 by @amilich — 2023-01-08T21:08:13Z

They’re not in a publishable format today, but we are undergoing one with Cure53 ([https://cure53.de](https://cure53.de)) next that we plan to publish.

---

## Post 12 by @amilich — 2023-01-08T21:08:51Z

Also, to clarify the E2EE doc case, I agree the UX is worse but you could create a Skiff document, create an editable link, add a password, and send it out to get the same benefit as a password-protected email. We hope to add that feature soon.

---

## Post 13 by @dngray — 2023-01-09T04:04:45Z

> [@amilich](#):
>
> They’re not in a publishable format today, but we are undergoing one with Cure53 ([https://cure53.de](https://cure53.de)) next that we plan to publish.

I’m really glad to hear that :+1: .

> [@amilich](#):
>
> I agree the UX is worse but you could create a Skiff document, create an editable link, add a password, and send it out to get the same benefit as a password-protected email.

You’d still have to send out the link, which would be difficult.

---

## Post 14 by @amilich — 2023-01-09T05:54:23Z

Couldn’t you just make a doc, make a public link, and send that via email? Doc stays E2EE (you can add password).

I agree this is more complex than an email password button, but we had originally made this use case with Pages (our first products) so you could share E2EE data externally.

---

## Post 15 by @nishil — 2023-01-09T05:57:12Z

I’m not sure why that site is replying with those results. If you look at [hardenize.com](http://hardenize.com), you can see it is a clean report.

 ![Screen Shot 2023-01-08 at 9.48.05 PM](//forum-uploads.privacyguidesusercontent.com/original/1X/c22fb09717d7e7b0faffcfd9648faa845a0efe24.png)

I also reran the test on internet.nl and it shows the correct results when I ran it. I’m unsure why when you ran it, it didn’t show a lot of those protocols showing up.

The github issue mentioned that it was acceptable to have SES as long as there is a plan to deprecate and this is also reflected in the listing criteria.

However, I personally believe this is minimal risk as our servers with TLS 1.2 and ciphersuites are prioritized over SES. The SES server should only be used if our primary server is down as mentioned in the comment. This is also mitigated that email clients (sending servers in this case) will negotiate the highest possible TLS and cipher available to it and the server (Skiff’s mailserver in this case).

I believe that this poses a minimal risk to users but acknowledge that downgrade attacks can happen. For this reason, we have a plan over the next 3-6 months to deprecate SES as a backup solution.

I agree on the ciphersuite ordering issue and security.txt. I’ll get the security.txt in this week but hopefully sometime tomorrow along with the ciphersuite changes. Appreciate the help here!

---

## Post 16 by @nishil — 2023-01-09T05:59:33Z

> [@dngray](#):
>
> You’d still have to send out the link, which would be difficult.

Isn’t sending a link via signal or some other E2EE messaging platform more secure than a link sent over email? I would certainly think so. A user isn’t prohibited from sending over email and we can do some UX to make it more integrated for sure, but the ability at the end of the day is there along with using a more secure transmission mechanism like Signal. I would argue that is stronger.

---

## Post 17 by @dngray — 2023-01-09T06:55:12Z

> [@nishil](#):
>
> Isn’t sending a link via signal or some other E2EE messaging platform more secure than a link sent over email? I would certainly think so.

This is a terrible user experience that in practice users will **never** do. Nowhere on the site instructs them to do this to circumvent limitations in the product. One of the main points of email is that it is an immutable copy, like a letter in the mail. It cannot be changed or revised after being sent.

The criteria on the site is very much an entry level bar (must pass to even consider discussion), it isn’t however exhaustive. Some things are more important than others.

Unlike other websites we do thoroughly test the products before adding them. It has to pass the “would I recommend this to my client test” as well. I work in an area, where I provide consulting services. It is often my job to find a solution to recommend to my clients that can solve their particular use case.

> [@nishil](#):
>
> Note: Currently, we use AWS SES as a backup solution as shown by the MX records showing AWS SES as a lower priority than our own servers. We have a plan to deprecate SES in the next 3-6 months as we build on our track record of operating a reliable email service.

Not so sound paranoid, but I wouldn’t be at all surprised if there wasn’t a [PRISM](https://en.wikipedia.org/wiki/PRISM) ingestion point on the SES network. Without E2EE to external users there will be a high chance that email won’t be so private.

I do see three **major issues** preventing Skiff Mail from being added at this time:

- Not E2EE as soon as it **leaves Skiff network** , not warning to users about this, essentially leading users to believe everything is E2EE. The blog article on E2EE is a good explanation of what E2EE is, however the product does not reflect this description in practice unless, you’re a Skiff user sending to other Skiff users.
- No ability for users to leave Skiff, if they decide it doesn’t work for them, there are going to be users who decide they need **nested folders** and **filters** to sort email.
- No ability to get **email header information** , this is important for forensics or determining whether email received is phishing.

It however may be more appropriate to recommend this product on our [https://www.privacyguides.org/cloud/](https://www.privacyguides.org/cloud/) page or [https://www.privacyguides.org/notebooks/](https://www.privacyguides.org/notebooks/) section. Of course, I would really like to see that Cure53 report first.

I’m also keen to hear back from @amilich in regard to the other issues mentioned in my previous posts. I’m also curious to know where the “30,000 external users” data comes from, because I’ve noticed you say this a few times here, and on Reddit. I don’t believe that is true at all.

I do obviously understand that will take time to reply.

---

## Post 18 by @ph00lt0 — 2023-01-09T09:58:18Z

It is very worrying that you do not have an answer to why this occurred as it comes from your own DNS configuration. If it doesn’t show now it means that you have changed the config. I am happy if it is solved, but does that ensure it won’t happen again. Did someone test in production?

---

## Post 19 by @ph00lt0 — 2023-01-09T10:01:38Z

If TLS is set to preferring a certain version it is prone to downgrade attacks. Many evil governments make use of this to extract user meta data therefore it is better to enforce it. Nobody realistically relies on TLS 1.2

Also yet again it shows the issues mentioned above today: [Email test: skiff.com](https://internet.nl/mail/skiff.com/846171/)

---

## Post 20 by @amilich — 2023-01-09T18:21:17Z

It’s quite demoralizing and frustrating from the corporate experience to be put in this position (I’m Skiff’s CEO). I see the greatest success for Privacy Guides to work with companies to make more privacy-respecting, secure services. We’ve done exactly that in good faith - respecting your criteria and allocating engineers on our team to get us to the point of recommendation. This costs an enormous amount for a product to implement.

We’ve now spent months implementing all of the best practices, both because we want Skiff to be as secure and private as possible, and because we want to be recommended on your guide. We’re becoming quite popular (almost half a million users in the last year) and would love to share and help grow your community while ensuring that products are held to high standards. Moving the bar constantly is extremely frustrating and demoralizing to our team. Transparently, it’s hard for us to even believe that the criteria are created in good faith.

Our solution for external sharing was not intended for email. It is much more powerful to share E2EE real-time collaborative docs/files with subpages, embedded E2EE files, and so much more. It’s both confusing and frustrating to require that we implement a less powerful, worse experience that was never part of the original spec.

Email headers is a reasonable feature to look for, but password protected emails and feature requests (like nested folders) are completely out of place.

---

## Post 21 by @dngray — 2023-01-09T19:25:40Z

> [@amilich](#):
>
> We’ve now spent months implementing all of the best practices, both because we want Skiff to be as secure and private as possible, and because we want to be recommended on your guide.

The [features discussed](https://github.com/orgs/privacyguides/discussions/119#discussioncomment-2858793) will help your users in the immediately as they are industry RFCs that many email providers (including non-privacy ones implement).

On the current criteria we do have core requirements, that being [E2EE](https://www.privacyguides.org/email/#technology) and do evaluate other such things such as [marketing](https://www.privacyguides.org/email/#marketing) used surrounding a product.

If we did add Skiff Mail, it would be one of the weakest recommendations when compared to the others listed. That would not be fair to the others already listed.

> [@amilich](#):
>
> Our solution for external sharing was not intended for email. It is much more powerful to share E2EE real-time collaborative docs/files with subpages, embedded E2EE files, and so much more.

That may be the case, however this evaluation was for listing in the email section.

There are certain expectations for email, these are that not collaborated on (unless you have shared inbox functionality). Once an email is sent it is **not** expected to change. This is vastly different from a collaboration office suite use case. They are complimentary tools to each other and they have their different roles.

What you’ve suggested, (paraphrasing), “just send a link to an encrypted document”, would be like me having explain to a lawyer that he “doesn’t want email” and he should just talk in a “online office suite”. They would not be happy with that solution.

The issue still remains that people will use your service and be under the illusion that emails that sent to remote providers are E2EE. **That is a big problem** and one you still need to address.

Even if you do not have a technical solution to that problem, you need to be honest about it to your customers. Accepting limitations of a product and informing users about that is something we hold in high regard. After all their safety should be first priority.

> [@amilich](#):
>
> We’re becoming quite popular (almost half a million users in the last year) and would love to share and help grow your community while ensuring that products are held to high standards.

The popularity of your product is not something we evaluate, and it doesn’t concern us in our evaluation.

Our priority is to evaluate products and inform our readers about that product and what our experience consisted of. It is one of the reasons we do **not** accept money from any of the products listed, unlike some other websites.

Our site has always been community focused, factual, in evaluations.

> [@amilich](#):
>
> Moving the bar constantly is extremely frustrating and demoralizing to our team. Transparently, it’s hard for us to even believe that the criteria are created in good faith.

The things I mentioned in my review weren’t necessarily blockers to being added. They were observations I made and I wanted share with the community.

The criteria is very much a minimum bar used to filter out products which are not “up there with the others”.

> [@amilich](#):
>
> Email headers is a reasonable feature to look for, but password protected emails and feature requests (like nested folders) are completely out of place.

We are evaluating you on is the lack of export functionality.

This is important that customers and their data are not locked up in a service that they **cannot** move away from should they want to, or need to. I acknowledge that you say this feature is coming.

The other things I mentioned (filters, nested folders etc) are observations I made while testing the product. These things are common enough and its important users know what they are getting into before they use your product, as they may rely on these things for their workflow.

Password protected emails are important. A common usecase has been to share a “password” during a phone call or an in-person meeting. Then the sender will supply the document required to their customer or contact.

The extra functionality such as collaboration is not always needed when sending a sensitive document. In my consulting, my clients regularly want to send privileged legal documents or medical reports.

---

## Post 22 by @amilich — 2023-01-09T19:35:08Z

Export/headers/password protection are all great features to have.

I still completely disagree with Skiff Mail being the “weakest” recommendation. Nested folders were not supported on Tuta until a month ago, and Skiff Mail has numerous other helpful features that are either paid or non existent on Proton/Tuta (schedule send, auto reply, default signature removal on the free tier, both folders and labels, separate Calendar application, native macOS app, etc.).

---

## Post 23 by @dngray — 2023-01-09T19:43:43Z

> [@amilich](#):
>
> I still completely disagree with Skiff Mail being the “weakest” recommendation.

It is because all the others provide some way to send an E2EE email. The issue with Skiff is that it is difficult to make that initial share without using some **other** product first.

Sharing a document on a collaboration suite, isn’t the same as an immutable copy with a date on it at a particular point in time.

The email header functionality is crucial for determining whether someone is the target of spearfishing. Some scammers will go to some effort to find out a lot about a victim, their org and then try to pretend to be someone within that org. All our current recommendations allow for this.

> [@amilich](#):
>
> Nested folders were not supported on Tuta until a month ago,

That was **not** part of the evaluation, but something I noticed along the way. It was worth mentioning because it is a feature that users may have had with other providers that they will lose when importing their mail into Skiff.

The last client I migrated had over a thousand directories. They had been using email for 20 years and had about 40k emails. They did not want to lose that structure, and it was necessary that the product I selected for them supported that feature.

> [@amilich](#):
>
> either paid or non existent on Proton/Tuta (schedule send, auto reply, default signature removal on the free tier, both folders and labels, separate Calendar application, native macOS app, etc.).

The first tier of paid usage on Skiff is quite a bit more than it’s competitors. Sure, you do get more storage, but quite often a user won’t have 100GB of email or files to store. This impacts your product, because it means that a lot of people will stay on the free tier, which doesn’t make you any money. Money is needed for viability, and its important that the company remains healthy.

---

## Post 24 by @ph00lt0 — 2023-01-09T23:19:16Z

I am going to vote AGAINST listening Skiff.  
I have made a test account and for this account I have set a recovery email. After doing this I started receiving unsolicited spam from Skiff on this email address. I have never signed up to the newsletter and this email alias was created today specifically for the recovery.

For this newsletter the email alias is shared with Sendinblue to send out the newsletter. I have never given any consent for this. Unacceptable. Generally sending out marketing emails.

Besides my sincere doubt about the security settings and the professionalism of the team on this, this is an absolute no go. I am leaving this discussion feeling betrayed by Skiff, this is a false privacy promise.

---

## Post 25 by @amilich — 2023-01-09T23:28:50Z

You received a product update with no tracking that can be opted out of. However, these emails should also go to your Skiff Mail address, not your external one.

I apologize for this - it is likely a bug from when we went from emails as logins (before Skiff Mail) to usernames as logins (everyone gets a Skiff Mail address). There are no trackers in the emails and you can unsubscribe to this and all future mail.

We don’t use Sendinblue.

I apologize that you feel disappointed, but I’d suggest looking at the responses above in good faith and realizing that we spent months on the recommended criteria - not even the minimum criteria.

---

## Post 26 by @amilich — 2023-01-09T23:33:39Z

To even explain more, many Skiff users only use Pages/Drive. Until May 2022, no Skiff user had a Skiff email address. So, all of those users received a Privacy Digest update containing product launches.

Here is a public link with a year of such updates:

> **[Skiff - Private, encrypted, secure email - 10 GB free](https://skiff.com)**
>
> Skiff Mail privacy-first, end-to-end encrypted product home, with Mail, Calendar, Pages, and Drive overview.

---

## Post 27 by @ph00lt0 — 2023-01-09T23:55:56Z

I will correct it was indeed Sendgrid, not Sendinblue, doesn’t change the argument.

Skiff send a marketing email, regardless of whether this is a product email it is SPAM. I do not want to unsubscribe, I never signed up for this.

Good bye

---

## Post 28 by @amilich — 2023-01-09T23:59:30Z

It’s not spam. It’s a critical product update with a major new feature offering. How would you suggest we notify our users that they can now privately purchase domains for even more private email? Or, that Skiff Mail even exists?

Sendgrid is used to manage unsubscribes in the email. As a note, other services you recommend use similar products. For example, Bitwarden users Hubspot to manage their product updates and newsletter - Hubspot is much worse for privacy than Sendgrid, which is a transactional mailing services.

Honestly, it’s so frustrating to see us held to arbitrary standards not enforced to the other products on the site. It breaks my heart to see our team respect your criteria and process and feel like they’ve been slapped in the face after months of work.

---

## Post 29 by @amilich — 2023-01-10T00:03:10Z

Also, I’d love to get Skiff Drive and Pages considered as well. I believe they are quite compelling feature wise compared to Cryptee/ProtonDrive/NextCloud. Should we open a separate ticket?

---

## Post 30 by @ph00lt0 — 2023-01-10T00:03:58Z

I have never received an email from bitwarden on my account there though hub spot and definitely not on a recovery address.

Abusing of this data is punishable under GDPR. [Twitter expecting a massive fine for misuse of phone numbers](https://nypost.com/2020/08/04/twitter-expecting-a-massive-fine-for-misuse-of-phone-numbers/)

Your whole attitude now shows how you think if this issue. This isn’t privacy by design. You do not inform/bother people if they didn’t ask for it. There is no excuse.

Also your dns settings are still incorrect. So don’t understand why you say there are different standards. You don’t meet them…

---

## Post 31 by @amilich — 2023-01-10T00:07:30Z

This is categorically false.

Also, the NYPost is not considered quite a reliable source of privacy/GDPR violations (do you realize how many trackers are on that link?)

What DNS setting?

---

## Post 32 by @amilich — 2023-01-10T00:08:09Z

Honestly, I’d appreciate if other team members were able to chime in here. We’re not making any progress on substantive issues, just spreading disinfo about privacy law at this point.

---

## Post 33 by @ph00lt0 — 2023-01-10T00:10:56Z

Lol here you go man:

> **[Art. 13 GDPR - Information to be provided where personal data are collected...](https://gdpr.eu/article-13-personal-data-collected/)**
>
> Art. 13 GDPRInformation to be provided where personal data are collected from the data subject Where personal data relating to a data subject are collected from the data subject,...

I know the GDPR very well i dont think you want to start this debate. Article 13 clearly states you need to inform the subject what is the intended purpose of data collection. You have therefore misinformed me.

---

## Post 34 by @amilich — 2023-01-10T00:11:41Z

Not correct. I’ve taken multiple privacy law classes, and this is a textbook example of legitimate interests: [GDPR Legitimate Interests - GDPR EU](https://www.gdpreu.org/the-regulation/key-concepts/legitimate-interest/).

I’ve also consulted with our legal counsel on this issue. We’re so far out of scope at this point.

---

## Post 35 by @ph00lt0 — 2023-01-10T00:12:29Z

The DNS discussion we had above here. Internet.nl clearly shows one of your configured severs does not meet the requirements.

I want to be clear, i am not a team member. Just because you mentioned this.

---

## Post 36 by @ph00lt0 — 2023-01-10T00:13:50Z

You are pulling legimate interest card. Well fair enough but no privacy activist will approve. And this case i highly doubt authorities would.

Legal loves this clause anything could be legimate interest. Also selling user data for profit. (People tried). It is a hilarious clause in the GDPR that needs to be refined. It leaves a lot of loopholes. But using data for other means is not allowed, you should read up.

---

## Post 37 by @moonwriting — 2023-01-10T00:18:18Z

I’m pretty sure that both Tutanota and Proton are also sending product updates from time to time. Since you can easily opt-out of these emails, I don’t really see a problem with this.

---

## Post 38 by @ph00lt0 — 2023-01-10T00:19:00Z

Definitely not via third parties and not to recovery addresses. I think they are opt in but good point if they do, generally a bad practice.

---

## Post 39 by @dngray — 2023-01-10T05:03:16Z

> [@ph00lt0](#):
>
> Skiff send a marketing email, regardless of whether this is a product email it is SPAM. I do not want to unsubscribe, I never signed up for this.

We don’t consider internal emails from the provider about their product to be spam, however when I created a Skiff account I didn’t test the recovery email.

> [@amilich](#):
>
> Sendgrid is used to manage unsubscribes in the email. As a note, other services you recommend use similar products. For example, Bitwarden users Hubspot to manage their product updates and newsletter - Hubspot is much worse for privacy than Sendgrid, which is a transactional mailing services.

We don’t consider sendgrid to be an issue, however sharing the recovery address with them is an issue. When a user provides the recovery address they do not expect to be contacted on it unless they initiate account recovery.

> [@amilich](#):
>
> Honestly, it’s so frustrating to see us held to arbitrary standards not enforced to the other products on the site. It breaks my heart to see our team respect your criteria and process and feel like they’ve been slapped in the face after months of work.

The criteria is purely a “we don’t even discuss products which don’t adhere to basic industry standards”, because there are thousands of them.

The things you implemented [there](https://github.com/orgs/privacyguides/discussions/119#discussioncomment-2858793) (MTA-STS etc) are to prevent downgrade attacks on the transport encryption. As we know **emails that leave Skiff are not E2EE**.

We consider this a **critical baseline** because non-privacy providers like Google and Outlook implement these features in order to provide some safety to their users.

Once, the baseline is adhered to, we do actually _test_ the product.

The target hasn’t moved. Your service was always going to be compared against our existing recommendations.

The criteria did not mention these requirements because implicitly they already provided:

- Export, facilitating in data liberty
- Using recovery email only for recovery
- Allowing users to see email headers, to determine whether the email is authentic.
- Provide some way to send an encrypted message to non-users of the provider

> [@moonwriting](#):
>
> I’m pretty sure that both Tutanota and Proton are also sending product updates from time to time.

They do, but not to the recovery address. Not even Gmail will send product updates to the recovery address.

I’m not going to judge this too harshly, as I suspect it may have been a bug, it certainly should be investigated and fixed so it doesn’t happen again.

> [@amilich](#):
>
> I’ve also consulted with our legal counsel on this issue. We’re so far out of scope at this point.

Having read enough privacy policies I did state [in my initial report](https://discuss.privacyguides.net/t/new-email-services-recommendation-skiff/11411/8) that I didn’t see any mention of GDPR.

One of the things I did notice in the privacy policy:

> We may use information to market and advertise our products to you directly if you have signed up for the services and/or provided us with your email address. This includes marketing via email campaigns and notifications within the Platform. You can opt out of direct email marketing messages from us by clicking the “unsubscribe” button included in the footer of the emails we send you. For more choices about use of tracking technologies for advertising more generally, please see “Your Privacy Choices” below.

It’s not clear that is the recovery email. When I read this originally I assumed it was the [skiff.com](http://skiff.com) address.

> **International Data Transfers**
> 
> All information processed by us may be transferred, processed, and stored anywhere in the world, including, but not limited to, the **United States or other countries, which may have data protection laws that are different from the laws where you live**. We endeavor to safeguard your information consistent with the requirements of applicable laws.

Emphasis added. This particular section stuck out to me originally, and leads me to believe this service isn’t GDPR compliant. In fact it seems to be a carve out specifically stating that attention to US law is the only thing considered.

> [@ph00lt0](#):
>
> You are pulling legimate interest card. Well fair enough but no privacy activist will approve. And this case i highly doubt authorities would.

One of GDPR’s primary reasons for existing is to establish legal basis for data collection. It is important that providers of any service stick to that reason when they collect a piece of data.

@amilich Just a personal message to you.

We’re not saying any of these things because we are mean, but because we **genuinely** care about privacy, and it is a passionate subject of ours.

Many of us are experts within the industry, and work in IT as sysops, netsec, devs and auditing sectors in our day-to-day jobs. I think you may have an idea that is the case already based on some of the feedback and intricate understanding of technical aspects.

---

## Post 40 by @dngray — 2023-01-18T05:25:28Z

> [@ph00lt0](#):
>
> Definitely not via third parties and not to recovery addresses. I think they are opt in but good point if they do, generally a bad practice.

Can confirm, just received a marketing email to my recovery address. That email address was unique and has not been used for anything else.

```
From: "Skiff Updates" <updates@marketing.skiff.org>
Subject: Block email trackers with Skiff
```

---

## Post 42 by @dngray — 2023-02-04T10:45:40Z

Are some of the audits going to be available?

---

## Post 43 by @amilich — 2023-02-05T22:27:51Z

Is this in response to my comment or for OnlyOffice?

---

## Post 44 by @dngray — 2023-02-06T02:30:19Z

In regard to Skiff, I was just curious about if there was some kind of ETA on the cure53 report.

As Skiff uses its own encryption, (and we’re not cryptographers), we’re keen to know what professional cryptographers have to say about it.

---

## Post 45 by @amilich — 2023-02-06T02:51:26Z

It’s coming up this spring but we’ve done 3 additional security audits. Do you have any particular questions that we could send to Trail of Bits? You could ask the CEO on a public forum or anywhere else. Also, just wondering - I didn’t see public security audits for a bunch of other recommended tools. Is there any reason why it feels like we have to exceed additional criteria?

I think having criteria is great because it makes a process objective, but that has to involve sticking with it.

---

## Post 46 by @amilich — 2023-02-06T03:21:36Z

I expect us to release email download in the next 2 days as well.

---

## Post 47 by @dngray — 2023-02-06T03:36:17Z

> [@amilich](#):
>
> It’s coming up this spring but we’ve done 3 additional security audits. Do you have any particular questions that we could send to Trail of Bits?

Not specifically, we’d like to see the report in it’s complete state. Customarily we also link to the report in the description so that our recommendation can be validated.

> [@amilich](#):
>
> I didn’t see public security audits for a bunch of other recommended tools. Is there any reason why it feels like we have to exceed additional criteria?

It may very well be added to the criteria shortly. The reason is there are a lot of “web apps” which offer “E2EE”, but are designed by web developers without any background in cryptography. We don’t want to be adding _those_ kinds of things to the site. If there’s anything to learn from the LastPass incident it’s that these things need to be validated to ensure quality.

We’re not singling Skiff out specifically, but it is a shift we’ve made across the site (you may notice that on the instant messenger section) for example. We are dubious about adding anything that doesn’t have a report but offers E2EE as a feature.

> [@amilich](#):
>
> I think having criteria is great because it makes a process objective, but that has to involve sticking with it.

It does, but we also don’t want to be in a position where we can’t tighten it either without removing a heap of recommendations that we previously made. We try to make recommendations based on what we expect the tentative criteria will be.

---

## Post 48 by @nishil — 2023-02-06T20:26:03Z

> [@dngray](#):
>
> Not specifically, we’d like to see the report in it’s complete state. Customarily we also link to the report in the description so that our recommendation can be validated.

> [@dngray](#):
>
> It may very well be added to the criteria shortly. The reason is there are a lot of “web apps” which offer “E2EE”, but are designed by web developers without any background in cryptography. We don’t want to be adding _those_ kinds of things to the site. If there’s anything to learn from the LastPass incident it’s that these things need to be validated to ensure quality.

I don’t believe that this is common practice. It is totally fair to ask for something to back up our e2ee claims but simply stating to want to see the entire pentest report is a standard no one else is being held to including

- most of the products listed on this site
- is not industry standard
- Protonmail has switched to releasing letters of attestation

We can argue all day about what the standard should be but again, this is not standard. These reports are typically shared under NDA for large customers to gain an understanding of a vendor’s security program. When auditors write these reports, they are not written for a general public audience even for a technical one.

Yes, I also have worked in appsec my entire career and have run multi million bug bounty programs, conducted internal and external technical audits, built vendor security programs, presented at reputable conferences so we also have some idea of what we are talking about as well :slight_smile: We are not some random, shady shop sprung out of the depths of the internet trying to trick users into handing over their data. We also have a fundamental belief in user privacy which is why Skiff set out building e2ee applications in the first place. We have put a lot of thought and effort into building a modern e2ee application worksuite and I highly encourage you to read our [whitepaper](https://skiff-org.github.io/whitepaper/Skiff_Whitepaper_2022.pdf) which outlines so much.

A reasonable ask would be to open source the crypto libraries, ask questions on the core crypto components, and ask for some proof of an audit. We’ve done the first. Open to questions and engaging on discussions there. And third, we’re working to release some joint statement with Trail of Bits on this.

Regarding the claims on the crypto libraries, a very reasonable question would have been asking for how our core crypto libraries work which could be examined and verified using a web debugger to see these libraries working. We didn’t invent any crypto. We use standard accepted libraries like tweetnacl and have open sourced the core abstractions built on these standardized crypto libraries to make these claims easier to verify.

Not only this but all of our advisors reputation is at stake such as the CTO of Signal if we were to be unintentionally or intentionally lying about these claims as you seem to be suggesting.

I’d much rather engage on real technical discussions or reasonable asks like mail import (which we have prioritized as Andrew mentioned) or the entire checklist for mail service providers like in the original github issue (which we also accepted as reasonable and largely completed that work).

---

## Post 49 by @dngray — 2023-02-07T13:20:34Z

> [@nishil](#):
>
> I don’t believe that this is common practice. It is totally fair to ask for something to back up our e2ee claims but simply stating to want to see the entire pentest report is a standard no one else is being held to including
> 
> - most of the products listed on this site
> - is not industry standard
> - Protonmail has switched to releasing letters of attestation

It does happen particularly for new products, and we’ve seen that with Signal audits regarding the protocol, as well as Matrix in the past. These components generally don’t change significantly.

We’re not necessarily saying we want to see the “entire” pentest report, just the part that relates specifically to Skiff’s E2EE implementation, and what the status of that was.

While Protonmail may very well [have done that](https://proton.me/blog/security-audit-all-proton-apps), they are a significantly bigger and more established company. Does Skiff have such a blog article pointing to their letter of attestation? The TrailOfBits audits don’t really have any online footprint that I can see besides what is claimed here and a very brief mention on [Publications from Trail of Bits](https://github.com/trailofbits/publications). It does not say whether anything was found, or anything still exists.

> [@nishil](#):
>
> We are not some random, shady shop sprung out of the depths of the internet trying to trick users into handing over their data. We also have a fundamental belief in user privacy which is why Skiff set out building e2ee applications in the first place.

It still remains that Skiff is still a fairly new company that had it’s launch late 2021, the pivot to email was more recent as of 2022. It is newer than _most_ other companies in the industry. Just to reiterate, we’re not quizzing you on these things, because we’re singling Skiff out, but rather we do want to tighten that category.

> [@nishil](#):
>
> We have put a lot of thought and effort into building a modern e2ee application worksuite and I highly encourage you to read our [whitepaper](https://skiff-org.github.io/whitepaper/Skiff_Whitepaper_2022.pdf) which outlines so much.

I’ve read that whitepaper and it does make sense to me, there wasn’t anything out of the obvious there, however my area of expertise is not cryptography.

> [@nishil](#):
>
> A reasonable ask would be to open source the crypto libraries, ask questions on the core crypto components, and ask for some proof of an audit. We’ve done the first. Open to questions and engaging on discussions there. And third, we’re working to release some joint statement with Trail of Bits on this.

This would be the sort of thing we’d be very interested to see, because currently it feels very “unofficial” that audits have even taken place. Normally companies are quite proud and will announce that it has taken place on their blog.

> [@nishil](#):
>
> Regarding the claims on the crypto libraries, a very reasonable question would have been asking for how our core crypto libraries work which could be examined and verified using a web debugger to see these libraries working. We didn’t invent any crypto. We use standard accepted libraries like tweetnacl and have open sourced the core abstractions built on these standardized crypto libraries to make these claims easier to verify.
> 
> Not only this but all of our advisors reputation is at stake such as the CTO of Signal if we were to be unintentionally or intentionally lying about these claims as you seem to be suggesting.

I wasn’t inferring that you were “lying” about anything specifically, just that a blog article with some official mention of the audit would be useful when claiming that one exists. it would be useful for us to link in the description. The method you’ve described above we have in fact in regard to some other products “out there”.

> [@nishil](#):
>
> I’d much rather engage on real technical discussions or reasonable asks like mail import (which we have prioritized as Andrew mentioned) or the entire checklist for mail service providers like in the original github issue (which we also accepted as reasonable and largely completed that work).

To begin with I think we’re looking at adding this to the [productivity tools](https://www.privacyguides.org/productivity) section and the [calendar contact](https://www.privacyguides.org/calendar-contacts) sections.

Just in regard to @ph00lt0’s concerns about GDPR, it does seem that you’re still sending marketing emails to user’s recovery addresses. I think these emails should be directed to their @skiff.com address as a recovery address may not be very private.

The general standard isn’t to send marketing emails to recovery addresses and in fact I’ve never seen a product do that.

---

## Post 50 by @amilich — 2023-02-08T00:18:23Z

I agree with this and we’re working with Trail of Bits to get a public blog post or attestation out. I hope that happens soon. I think we don’t take issue at all with some criteria related to audits, just that we’ve done everything by the book and want to be an incredibly strong recommendation.

We launched EML export yesterday (I worked on this personally!), which should resolve some other concerns above.

---

## Post 51 by @amilich — 2023-02-08T03:14:42Z

It would be great to be on the Productivity/Calendar sections. As a note, I don’t see anything about CryptPad being independently audited, let alone requiring that the audit be reviewed or have a public attestation.

---

## Post 52 by @dngray — 2023-02-08T03:44:55Z

> [@amilich](#):
>
> We launched EML export yesterday (I worked on this personally!), which should resolve some other concerns above.

I’ve tested it just then, works quite well, which also means headers can now be accessed :+1:

It would seem that _each_ email has to be individually exported, this limitation would be something we have to mention in the description as we have with [another email provider](https://www.privacyguides.org/email/#tutanota), as it makes it still quite impracticable to export a users entire mailbox.

I did notice a bug when I sent a plaintext email to my Skiff address.

I replied to it with my Skiff address and the plain text part on the reply didn’t have any line breaks, where there should have been. The HTML portion was also on one line, but that’s okay as the `<br>` and `<p>` tags were intact.

> [@amilich](#):
>
> As a note, I don’t see anything about CryptPad being independently audited, let alone requiring that the audit be reviewed or have a public attestation.

It’s not, but we would like to mention that Skiff is in the description (and cite that), as a result it would also get a higher ranking on the page, until which point we have enough options, to tighten the criteria, keeping the best.

---

## Post 53 by @amilich — 2023-02-08T04:05:51Z

I completely understand, I think we just would like to know what we are missing to be on Productivity/Calendar today and on Mail.

---

## Post 54 by @dngray — 2023-02-08T04:16:42Z

I replied above, (edited my reply and addressed the EML export thing).

I didn’t expect you to reply so quickly :slight_smile:

I would be curious to know whether this EML export feature could at least be expanded to at least allow folder/label export.

---

## Post 55 by @amilich — 2023-02-08T04:30:43Z

I am definitely open to that, we will work on export features but it takes time. I personally implemented the EML export and also redid our Pages/Drive export to do Markdown export for files, folders, and ZIPs as default.

So, I think it’s a great feature for us to implement, but is that what is missing to be recommended as an email provider?

Not sure what you mean by description on the page - am I missing a section on productivity tools?

---

## Post 56 by @dngray — 2023-02-08T04:32:37Z

> [@amilich](#):
>
> I am definitely open to that, we will work on export features but it takes time. I personally implemented the EML export and also redid our Pages/Drive export to do Markdown export for files, folders, and ZIPs as default.

I tested that just then and it works particularly well. It includes all sub pages which is wonderful. Very nice to see LaTeX support there too. I could certainly see this being used by students in compsci for collaboration.

> [@amilich](#):
>
> Not sure what you mean by description on the page - am I missing a section on productivity tools?

I’m talking about on the email, description, like we do for Tutanota, we mention that you can only export a folder of emails at a time. In this case we would **have** to mention that you can only export individual emails.

This is typically where we mention any attestation reports, or audits, or anything of that nature. We do sometimes mention limitations there as well.

Depending overall on how the product stacks up against competitors, we adjust its placement on the page.

> [@dngray](#):
>
> Just in regard to @ph00lt0’s concerns about GDPR, it does seem that you’re still sending marketing emails to user’s recovery addresses. I think these emails should be directed to their @skiff.com address as a recovery address may not be very private.
> 
> The general standard isn’t to send marketing emails to recovery addresses and in fact I’ve never seen a product do that.

Just a further detail on that. I noticed with the address that I have no recovery email set, the marketing emails are correctly placed in the [skiff.com](http://skiff.com) inbox. I think this should be the default. Not sure if you have an internal bug about that.

---

## Post 57 by @amilich — 2023-02-08T04:51:20Z

It is definitely a bug. What should happen is that users who signed up before Skiff Mail should receive it at an external email, and Skiff Mail users should not. But sometimes the earlier users then later signed up for Skiff Mail. There are a lot of nuances like this, but it categorically does not conflict in any way with GDPR; these emails are also likely transactional as they are to users who have _signed up_ and are receiving information on how to set up new features. For example, Gmail import, remote content blocking, etc. They also all have unsubscribe links.

---

## Post 58 by @dngray — 2023-02-08T04:53:00Z

> [@amilich](#):
>
> What should happen is that users who signed up before Skiff Mail should receive it at an external email, and Skiff Mail users should not.

That doesn’t happen to be the case. I signed up after Skiff Mail, gave it a recovery address, and the emails are being sent to the recovery address **and** the [skiff.com](http://skiff.com) address. This account was opened on the 10th January 2023 so that’s certainly after Skiff Mail launched.

Users in this case may very well want to see these emails, but not on their recovery inbox.

---

## Post 59 by @amilich — 2023-02-10T19:59:29Z

Any updates on the thread regarding adding Pages/Drive/Calendar and Mail?

---

## Post 60 by @drive — 2023-02-11T09:38:10Z

Does Skiff Drive support backward secrecy?

Suppose someone, say X, has access to a shared folder. X decided to store the encryption key of the root shared folder.

In the future, if X gains access to the encrypted metadata and content of new subfolders & files under the original shared folder, can they decrypt the content even after the password has changed?

My preliminary examination of ProtonDrive’s architecture suggests they have a similar issue, although I haven’t confirmed this yet. According to the whitepaper, Skiff seems to have similar architecture, but I decided to ask here.

Unfortunately, I couldn’t find a whitepaper on Cryptee. But, if I have to guess, most drive products might have a similar issue due to the complexity of solving this issue.

PS: I am an early adopter of Skill mail and pages and am excited about its future. Best of luck to you and the team!

---

## Post 61 by @drive — 2023-02-11T10:00:55Z

> [@dngray](#):
>
> We also don’t want to be in a position where we can’t tighten it either without removing a heap of recommendations that we previously made. We try to make recommendations based on what we **expect the tentative criteria will be.**

It’s not entirely fair to evaluate Skiff against newly proposed standards, as there are already established services that don’t meet these criteria.

If PrivacyGuide wants to introduce blocking standards for new services, it should be clear and upfront about it. This would involve adding prominent warnings about the existing services and specifying all the criteria they don’t meet.  
Also, simply stating that Skiff meets a certain criteria doesn’t necessarily address the lack of **warning** for legacy listings.

---

## Post 62 by @dngray — 2023-02-11T11:15:54Z

> [@drive](#):
>
> If PrivacyGuide wants to introduce blocking standards for new services, it should be clear and upfront about it.

We have not introduced any “blocking standards” that specifically exclude Skiff products.

I would like to make some mention of the audit that did occur in the description. I think this would be a good thing in Skiff’s favor if I did that. To do that, I’d like some description of what it contained, what was found, what commit was audited etc.

I took a look at the Skiff source code, is that it appears this not an active development repository, that means the source in [skiff-org/skiff-mail](https://github.com/skiff-org/skiff-mail/commits/main), is almost certainly not what is in production. That means the “open source” claim is really a _kind of_, it might have been at one point in time.

> [@nishil](#):
>
> Regarding the claims on the crypto libraries, a very reasonable question would have been asking for how our core crypto libraries work which could be examined and verified using a web debugger to see these libraries working. We didn’t invent any crypto. We use standard accepted libraries like tweetnacl and have open sourced the core abstractions built on these standardized crypto libraries to make these claims easier to verify.

Would I be right in assuming that [those libraries](https://github.com/skiff-org/skiff-mail/blob/main/skiff-mail-web/tsconfig.json#L22) are not available in the source repository? Or are they somewhere else?

---

## Post 63 by @anon20402919 — 2023-02-11T12:44:36Z

about the mails, without discussing new criteria, we should already wait a few months, for what is mentioned here: [Skiff Mail (Email Provider) - #15 by nishil](https://discuss.privacyguides.net/t/new-email-services-recommendation-skiff/11411/15)  
Not all servers support DNSSEC and DANE yet. Even if they are backup servers, I think it’s better to wait until the problems mentioned here are corrected.  
But it doesn’t concern pages/drive in the meantime.

---

## Post 64 by @amilich — 2023-02-13T02:08:03Z

What problems are you referring to? We have quite literally satisfied all of the criteria.

---

## Post 65 by @amilich — 2023-02-13T02:09:20Z

This is a copy of the `typed-envelopes` repository. I completely agree with the commenter above as well. It’s confusing for any user to have a list of recommended software when some elements of the list are held to different and higher standards, and some are held to lower standards. That’s why we focused on compliance with all criteria.

---

## Post 66 by @amilich — 2023-02-13T02:09:56Z

This is a good question. There is functionality to rotate encryption keys for Skiff Drive and Pages files as people may be unshared. However, this is a bit ineffective for files because they are static, so, if you previously had access, you could have downloaded them.

---

## Post 67 by @jonah — 2023-02-13T18:42:17Z

> [@amilich](#):
>
> What problems are you referring to? We have quite literally satisfied all of the criteria.

I believe the question raised by @anon20402919 is whether the criteria apply to _all_ email servers or only primary email servers. Amazon SES configuration may be outside of Skiff’s control, but they don’t seem to meet our email server criteria even though Skiff’s own servers appear to.

Might warrant a separate discussion [@team](/groups/team).

> [@amilich](#):
>
> This is a copy of the `typed-envelopes` repository.

So, Skiff Mail is not open source, the only open source component is the encryption library at [skiff-org/typed-envelopes](https://github.com/skiff-org/typed-envelopes), right? Just trying to wrap my head around this :slight_smile:

---

## Post 68 by @amilich — 2023-02-13T18:57:31Z

Skiff-mail is open source. We don’t update it every day yet. Many open source products work this way. ProtonMail was not open source until version 2. Signal develops major features, such as their in-app stories and payments, outside of their open source repo before publishing it back in there.

Again: Why are the standards different for us?

We can remove SES as a backup. But, now that we built email export (prioritized because of this thread), you can inspect headers yourself and see it is not used.

---

## Post 69 by @jonah — 2023-02-13T19:19:58Z

> [@amilich](#):
>
> Skiff-mail is open source. We don’t update it every day yet. Many open source products work this way.

Do you have a planned release schedule of any kind? My understanding is that projects that typically develop in this manner still publish their source code before _releasing_ even if the actual work isn’t being committed in the open. I know Skiff Mail has had multiple releases since the [skiff-org/skiff-mail](https://github.com/skiff-org/skiff-mail) repo was initially published.

> [@amilich](#):
>
> Again: Why are the standards different for us?
> 
> We can remove SES as a backup. But, now that we built email export (prioritized because of this thread), you can inspect headers yourself and see it is not used.

Because your product is different than other products we currently recommend in numerous ways. We have not had to deal with the question of backup email servers before _for example_, because none of the other providers we recommend outsource their backup MX to a third-party.

I’m sure Amazon SES _isn’t_ used _in normal operation_, because it’s set at a lower priority. I’m not telling you that your use of Amazon SES for sure means that you don’t meet the criteria, I’m telling you that _I don’t know_ whether we should hold backup mail servers to the same criteria or not, and that’s something we need to discuss further amongst ourselves. Is the future risk that the less-secure (than your own servers) Amazon SES might be used for incoming email in case of a Skiff outage or misconfiguration significant enough for us to be concerned about it? I have no idea at the moment. :slight_smile:

Of course, just removing Amazon SES as a backup entirely would certainly make that discussion _easier_ for us. I wouldn’t assume to know what’s possible for you to do.

---

## Post 70 by @amilich — 2023-02-13T19:39:52Z

The core point here is that we do satisfy the minimum and recommended criteria, and adding a backup mailserver was done because it seems like a correct engineering practice to build fallbacks. In fact, many of our users complain that Proton and Tutanota have biweekly or monthly outages where emails aren’t received.

You may be largely correct on releases, but we have not released anything major. We made an update when Skiff Calendar was launched, which was the last major release inside Mail.

---

## Post 71 by @jonah — 2023-02-13T20:46:50Z

`52.88.57.209` on `inbound-smtp.skiff.com` seems to be down as we speak, so maybe it is a good idea for you to have backups.

Anyways, I think _you’re_ missing the point that @dngray has been telling you in this thread actually, which is that we are not obligated to tell people to use your service based on the completion of a checklist. A number of people have asked you questions here that I don’t believe have been addressed, and that certainly is a factor for consideration. Scrolling up through this thread, here’s a few I want to remind you about:

- Do you have information about your audit? For example, “[what it contained, what was found, what commit was audited etc.](https://discuss.privacyguides.net/t/skiff-email-provider/11411/62)”
  - I see you mentioned wanting to have Trail of Bits publish this, is the hold up on your end or theirs?
  - I also am confused about the scope of this audit. Was Skiff Mail audited, or Skiff Pages/Drive, or all of the above?

- [Why are you sending marketing to recovery email addresses?](https://discuss.privacyguides.net/t/skiff-email-provider/11411/58)
  - I think we’ve muddied the waters in this thread here with all this “GDPR” talk, which is a controversial subject. Ignoring legalities entirely, our position is still that this is not something we expect a privacy-oriented service to use recovery emails for without consent.

We also can’t make recommendations based on future promises, and I think there are things you’ve committed to that we want to see completed:

1. That audit, see above.
2. Exporting email folders, [you said you were open to that](https://discuss.privacyguides.net/t/skiff-email-provider/11411/55), and I think that is an important issue to us, because data control/liberation is one of our fundamental values. Our position is that privacy is ultimately about a person controlling their own data, and portability is an important aspect of that, either in the form of standards-based export formats, or supporting standards like IMAP/SMTP (which I realize isn’t possible in your case without bridge software like Proton Bridge, so I wouldn’t suggest that).

* * *

Finally, now that I’m looking at Skiff Mail myself, I have my own question: Would you ever consider removing this “Encrypted” security indicator from Skiff Mail?

 ![Screenshot 2023-02-13 at 13.52.27@2x](//forum-uploads.privacyguidesusercontent.com/original/1X/ee320c63a3d362e5498959b21d83b2d6af44d848.png)

Positive security indicators are generally considered to be mostly useless, and I’d rather see no indicator at all for emails that will be sent with TLS, and a red warning indicator for emails being sent to a domain that does not support TLS. I think that given Skiff Mail’s marketing, people will assume a padlock next to a recipient implies End-to-End Encryption.

The green End-to-End Encrypted mark on communications between Skiff users is still perfectly reasonable.

---

## Post 72 by @amilich — 2023-02-13T21:03:30Z

1. Audit - discussed at length. Trail of Bits has audited our entire code base, of every product, twice. Because of this thread, we are asking them to write a blog post. Their work costs hundreds of thousands of dollars, and I don’t see any audit reports for Cryptee, for example, and Proton simply publishes attestation.

2. Exporting folders. We built EML export because of this thread. Exporting folders seems completely unrelated.

3. Recovery emails are not being used without consent. There is a bug with sending mail to new Skiff Mail users (we never had email until 8 months ago), but they are free product updates with unsubscribe links. All products you recommend send product updates.

4. The encrypted comment is inappropriate. Do you see the badge that Proton adds? We thought that “encrypted” was far _less_ misleading, because the Proton badge makes it sound end-to-end encrypted. As you write, “people will assume a padlock next to a recipient implies End-to-End Encryption” - in that case, the Proton badge is **far** more misleading.

 ![Screen Shot 2023-02-13 at 12.59.36 PM](//forum-uploads.privacyguidesusercontent.com/original/1X/a5d2311028a4bbad507acbb29ee3f826abf2cbd5.png)

Also, [inbound-smtp.skiff.com](http://inbound-smtp.skiff.com) is not down.

Again, I stand behind every decision and feature we’ve built as a better design choice than the alternatives.

---

## Post 73 by @amilich — 2023-02-13T21:06:05Z

I don’t feel like you all have any obligation to add our products, but they clearly stand the test of the criteria for Mail, Pages, Drive, and Calendar. In some of those categories, they also seem to be far more trustworthy than the alternatives.

---

## Post 74 by @amilich — 2023-02-13T21:09:17Z

As another question: Why was Etesync added (just reviewing [Remove EteSync](https://discuss.privacyguides.net/t/remove-etesync/9978))? They admit there is no professional audit: [Get the protocol professionally audited · Issue #1 · etesync/android · GitHub](https://github.com/etesync/android/issues/1), and the thread suggests the product has been deprecated.

I mean all of this with the best of intentions: I deeply want there to be incredibly technical, high quality guides for secure products. And, it is great to have companies work with you to improve their products and the criteria. But, it is easy to lose faith when we are doing that - working through the issues and meeting the criteria.

---

## Post 75 by @jonah — 2023-02-13T21:45:17Z

> [@amilich](#):
>
> The encrypted comment is inappropriate. Do you see the badge that Proton adds? We thought that “encrypted” was far _less_ misleading, because the Proton badge makes it sound end-to-end encrypted.

Firstly, if you’re going to take personal offense to my replies here, then I’m happy to leave this thread to @dngray instead.

Secondly, I don’t know how you can argue with a straight face that putting “Encrypted” next to non-E2EE recipients in your email composer, and “Thread is encrypted” above non-E2EE threads is less misleading than Proton’s messaging, which is **no lock at all** next to non-E2EE recipients in their composer, and a tooltip next to saved emails that specifically says “Stored with…” to avoid wrongly communicating that the message was _transmitted_ with E2EE, which it was not. To be clear, I’m not super happy with Proton’s UX here either, but I disagree that they are worse.

 ![Screenshot 2023-02-13 at 15.13.13@2x](//forum-uploads.privacyguidesusercontent.com/original/1X/5c67c188963241824584e0fdf34abcc542a42c88.png)

I was giving you the benefit of the doubt before by just inquiring about it, because I can see why you went with these indicators, and they’re not completely unreasonable by any means, but if you can’t even understand what my perspective on this is in the first place, then we might have an issue.

* * *

> [@amilich](#):
>
> Exporting folders. We built EML export because of this thread. Exporting folders seems completely unrelated.

I appreciate that you built individual email exports, it’s great. I already explained why exporting folders is completely related to this discussion:

> I think that is an important issue to us, because data control/liberation is one of our fundamental values. Our position is that privacy is ultimately about a person controlling their own data, and portability is an important aspect of that, […] in the form of standards-based export formats […]

A lack of bulk exports effectively means that those mailboxes are tied to Skiff Mail.

* * *

> [@amilich](#):
>
> - Recovery emails are not being used without consent. There is a bug with sending mail to new Skiff Mail users (we never had email until 8 months ago), but they are free product updates with unsubscribe links. All products you recommend send product updates.

We tested this **1** month ago, so I don’t think this only applies to Skiff users from before the launch of Skiff Mail. If you think we are wrong and you do not send product updates to the recovery email specified for new Skiff Mail users, then I will test this with a new account again.

I don’t believe any of our recommended providers send product updates to account recovery emails. I will test this out to confirm this is the case.

* * *

> [@amilich](#):
>
> As another question: Why was Etesync added (just reviewing [Remove EteSync](https://discuss.privacyguides.net/t/remove-etesync/9978))?

I don’t know what you’re asking, EteSync is not something we currently recommend. Are you asking why it was originally added half a decade or so ago?

* * *

I appreciate your prompt responses here a lot. I’m trying to be overly transparent here to give you clarity about our current perspective, not to be adversarial. :slight_smile:

---

## Post 76 by @amilich — 2023-02-13T22:28:03Z

I will see if we can switch to using the exact copy Proton is using. I disagree with your analysis completely - and note that “zero knowledge” and “zero access” are terms that security engineers deeply dislike.

---

## Post 77 by @amilich — 2023-02-13T22:29:18Z

It is completely possible to export folders. Simply select each email and export them. My main issue is that we are consistently held to completely different criteria than other recommended products. Tutanota also lacks bulk export features - see [Reddit - The heart of the internet](https://www.reddit.com/r/tutanota/comments/z0h9ms/export_all_emails/). We’ve done exhaustive research on all of these features and providers.

---

## Post 78 by @jonah — 2023-02-13T22:48:49Z

I don’t see why you would switch to copy that is “ **far** more misleading.”

---

## Post 79 by @amilich — 2023-02-13T23:26:33Z

We’ve made a good faith effort to address and respect every concern and idea here. Unfortunately, it doesn’t feel like there is any consistency in your criteria or recommendations.

---

## Post 80 by @dngray — 2023-02-14T01:58:28Z

> [@amilich](#):
>
> Skiff-mail is open source. We don’t update it every day yet. Many open source products work this way. ProtonMail was not open source until version 2. Signal develops major features, such as their in-app stories and payments, outside of their open source repo before publishing it back in there.

The issue is it’s open source in name but not in nature. The source repositories you do have are copies of code at some point in time. The [whitepaper (2022)](https://raw.githubusercontent.com/skiff-org/skiff-org.github.io/main/whitepaper/Skiff_Whitepaper_2022.pdf) suggests:

> Open-sourcing enables everyone to review, use, and contribute to Skiff’s products - making our community stronger and furthering our mission.

This statement in a whitepaper reads with thick coats of marketing paint. External contributions aren’t really going to happen while the community cannot see any kind of activity or development cycle.

Typically what happens is advanced users will try development branches, while testing for bugs/regressions they may have personally. Others may contribute specific features they want. For that matter there doesn’t appear to be any build instructions either.

> [@amilich](#):
>
> Again: Why are the standards different for us?

Just to be clear about my above comment:

> The criteria on the site is very much an entry level bar (must pass to even consider discussion), it isn’t however exhaustive. Some things are more important than others.

We’re not a site that provides “free marketing”, we do evaluation when a product is to be considered, the criteria is very much a first round of scrutiny.

It is impossible to include everything in the criteria because there are a many ways in which a product can have issues. The requirements for products which offer E2EE are more stringent, because there are higher levels of privacy expected.

> [@amilich](#):
>
> Their work costs hundreds of thousands of dollars, and I don’t see any audit reports for Cryptee, for example, and Proton simply publishes attestation.

Their work may cost a lot, but it’s not really useful to anyone but people evaluating the quality of _your product_. We did suggest that Proton’s attestation reports were sufficient as they provide some information about what and when it took place. While Cryptee doesn’t have an audit, it is developed in public.

Our future direction is that we very much want to tighten the criteria to audited products as we have for the instant messenger page. The reason is because we anticipate more projects to offer E2EE and we want to separate those which don’t adhere to best practices/quality from those that do.

There are many products which come and go, and we like to avoid removing things when we can.

> [@amilich](#):
>
> Recovery emails are not being used without consent. There is a bug with sending mail to new Skiff Mail users (we never had email until 8 months ago), but they are free product updates with unsubscribe links. All products you recommend send product updates.

There is a general expectation that recovery emails **are used for recovery** and **not** for marketing. No product I’ve seen sends marketing emails to the recovery address, and that includes the likes of Gmail.

> [@amilich](#):
>
> The encrypted comment is inappropriate. Do you see the badge that Proton adds? We thought that “encrypted” was far _less_ misleading, because the Proton badge makes it sound end-to-end encrypted. As you write, “people will assume a padlock next to a recipient implies End-to-End Encryption” - in that case, the Proton badge is **far** more misleading.

Proton Mail does however show in the compose window a tip that links users to their [Encryption lock meaning](https://proton.me/support/encryption-lock-meaning) article. Also in that screenshot there is a major keyword there _stored_ which indicates it is talking about how it is stored on Proton’s servers. They are also very clear about [what is encrypted](https://proton.me/support/proton-mail-encryption-explained).

In contrast when compared to Skiff’s articles such as [How to password protect an email](https://skiff.com/blog/how-to-password-protect-an-email) it feels highly SEO optimized without any actual information of help. A good portion of the article talks about Outlook and Gmail, rather than how to achieve security with your own product. I touched on that [earlier in this thread](https://discuss.privacyguides.net/t/skiff-email-provider/11411/8#marketing-2).

> [@jonah](#):
>
> We also can’t make recommendations based on future promises

Just to be clear here, what I’m trying to avoid is the criteria being used as a checklist with minimum effort and then radio silence after being listed. I’m not saying that’s necessarily what is going to happen here though.

> [@amilich](#):
>
> We built EML export because of this thread. Exporting folders seems completely unrelated.

The purpose of EML export is to give control to users over their data. If they have many emails they’re not going to want to individually export each one, that essentially equates to a dark pattern, preventing them from leaving or having control.

> [@amilich](#):
>
> Tutanota also lacks bulk export features - see [https://www.reddit.com/r/tutanota/comments/z0h9ms/export\_all\_emails/](https://www.reddit.com/r/tutanota/comments/z0h9ms/export_all_emails/). We’ve done exhaustive research on all of these features and providers.

You can still export entire folders of mails. While not ideal they do have other features you do not, such as password protected emails for external users.

---

## Post 81 by @amilich — 2023-02-14T03:50:41Z

I think you are missing the point of auditing. Auditors look at far more than just a codebase. They look at secrets management, infrastructure, software design process, employee security practices, and more. “Developed in the open” is not that. Security engineers would _never_ advise someone to use unaudited, supposedly E2EE products.

If you say the requirements are higher for E2EE products, I’d think that a formal audit is a hard requirement. Also, Cryptee uses Google authentication. I’ve seen posts here about that and would think it is disqualifying as well.

So, it’s still confusing where/what the criteria are. I hope that makes sense.

---

## Post 82 by @mika — 2023-02-14T04:08:47Z

As a total outsider to this discussion, both (a) asking for claimed open-source development to be open-source and (b) asking for audits to be published seem totally fair to me.

---

## Post 83 by @dngray — 2023-02-14T04:44:38Z

> [@amilich](#):
>
> I think you are missing the point of auditing. Auditors look at far more than just a codebase. They look at secrets management, infrastructure, software design process, employee security practices, and more.

It depends on the scope of the audit commissioned, this is what we’re curious about. The more things it covers, the more expensive it will be.

> [@amilich](#):
>
> “Developed in the open” is not that. Security engineers would _never_ advise someone to use unaudited, supposedly E2EE products.

I think you’re misinterpreting what I mean by “developed in the open”, what we’re talking about is an open workflow where issues (bugs) are raised, which in turn progress relate to pull requests. We see this with major vendors like Redhat, Mozilla, even Google for example. This enables external contributors to, “get up to speed”, or even know what you’re working on.

> [@amilich](#):
>
> If you say the requirements are higher for E2EE products, I’d think that a formal audit is a hard requirement.

That is very much the direction we want to have, once there are products in that category, likewise if it were a requirement we need to also be able to point to such an audit in some way. If there are no audited products we can’t have that hard requirement. As an interim, we use a ranking system to put the products which have audits higher on the page.

> [@amilich](#):
>
> Also, Cryptee uses Google authentication. I’ve seen posts here about that and would think it is disqualifying as well.

That is optional. Google uses an [OAuth](https://en.wikipedia.org/wiki/OAuth) API which is quite clearly [documented](https://developers.google.com/identity/protocols/oauth2). The only thing Google really knows is that someone might have a Cryptee account if they choose to use that feature. In any case I don’t think these comparisons to Cryptee are helpful, and it feels a bit like a straw man.

---

## Post 84 by @amilich — 2023-02-14T04:57:42Z

The product is open-source, but we do not open-source in development features. We publish on major releases, which is consistent with products like Signal (recommended).

Did you realize that Tuta and Proton do not publish audits? They have published some attestations, but Trail of Bits (our auditor) does not write attestations. Other products we’ve mentioned (Cryptee) do not even have audits.

It takes 5 seconds to verify that Trail of Bits did complete 2 audits of Skiff that were each 4-6 person weeks, which covers everything in our product, codebase, SDLC, infra, etc.

If you read the thread in detail, you’ll see what I am pointing out as the core issue: Constantly changing requirements and comparisons.

---

## Post 85 by @amilich — 2023-02-14T04:59:02Z

It’s strange to have such common practices treated with such skepticism. Given the CTO of Signal is an advisor of our’s, and the CEO of Trail of Bits is as well, of course we would rely on the best practices set by those organizations, which are the top in their respective domains.

@dngray if it is an issue that you do not have enough products on the collaboration products, notes, or calendar pages, why not add Skiff Pages/Drive/Calendar?

---

## Post 86 by @jonah — 2023-02-14T05:43:45Z

A post was split to a new topic: [Skiff Pages/Drive (Productivity Tools)](/t/skiff-pages-drive-productivity-tools/11758)

---

## Post 87 by @dngray — 2023-02-14T05:31:49Z

> [@amilich](#):
>
> The product is open-source, but we do not open-source in development features. We publish on major releases, which is consistent with products like Signal (recommended).

Okay, so that’s going to become a regular thing now?

> [@amilich](#):
>
> Did you realize that Tuta and Proton do not publish audits? They have published some attestations,

I did say that would be sufficient, as it would have information about what was undertaken, and give us something precise to link to.

> [@amilich](#):
>
> but Trail of Bits (our auditor) does not write attestations. Other products we’ve mentioned (Cryptee) do not even have audits.

They’re also not claiming to have an audit either.

> [@amilich](#):
>
> It takes 5 seconds to verify that Trail of Bits did complete 2 audits of Skiff that were each 4-6 person weeks, which covers everything in our product, codebase, SDLC, infra, etc.

That’s the first time you’ve mentioned the scope of the audit.

> [@amilich](#):
>
> Given the CTO of Signal is an advisor of our’s, and the CEO of Trail of Bits is as well, of course we would rely on the best practices set by those organizations, which are the top in their respective domains.

I don’t doubt the quality of their audit, I just wanted to have some more information about it, and something we can link to if we do mention it. We’re not a fan of making a claim on the site we cannot back up with a citation.

> [@amilich](#):
>
> @dngray if it is an issue that you do not have enough products on the collaboration products, notes, or calendar pages, why not add Skiff Pages/Drive/Calendar?

The audit would indicate where on that page it resides. That is the point I’m trying to make. Ideally I would like to put it **above** Cryptee because it has an audit.

---

## Post 89 by @amilich — 2023-02-14T05:47:18Z

Meant to post from my public acct:

What do you mean claiming? You can see it publicly on the Trail of Bits website, multiple times. Dan also tweeted about us here - [https://twitter.com/dguido/status/1498403981978124299](https://twitter.com/dguido/status/1498403981978124299). We’re working on more but TOB does not do attestations.

Why not link to the TOB site demonstrating that they did an audit?

Here is a quote Dan sent me that he’s shared with some of our advisors before:

In Skiff’s case, our last project was 6 person-weeks of effort and reviewed all available source-code for the project. This let them achieve a substantial depth of coverage, given the large amount of time, the expert qualified staff from Trail of Bits, and the open availability of the source code and interactions with their engineering team. In my opinion, the latest Skiff audit represents a substantially larger investment than what other privacy projects typically make (e.g., they are typically from a low-quality firm, have a small level of effort, and a limited scope).

---

## Post 90 by @amilich — 2023-02-14T05:54:38Z

I understand how important this information is and am glad it’s getting covered. A lot of the frustration is that many years of work goes into preparing for even submitting to PrivacyGuides, which I would regard as having some of the highest criteria in this space.

---

## Post 91 by @dngray — 2023-02-14T07:38:09Z

> [@amilich](#):
>
> What do you mean claiming?

Not anything bad.

> [@amilich](#):
>
> You can see it publicly on the Trail of Bits website, multiple times. Dan also tweeted about us here - [https://twitter.com/dguido/status/1498403981978124299](https://twitter.com/dguido/status/1498403981978124299). We’re working on more but TOB does not do attestations.

They did, and I don’t deny that, its just that besides them doing one, nothing else is really known publicly.

> [@amilich](#):
>
> Why not link to the TOB site demonstrating that they did an audit?

People will wonder about context.

> [@amilich](#):
>
> Here is a quote Dan sent me that he’s shared with some of our advisors before:
> 
> In Skiff’s case, our last project was 6 person-weeks of effort and reviewed all available source-code for the project. This let them achieve a substantial depth of coverage, given the large amount of time, the expert qualified staff from Trail of Bits, and the open availability of the source code and interactions with their engineering team. In my opinion, the latest Skiff audit represents a substantially larger investment than what other privacy projects typically make (e.g., they are typically from a low-quality firm, have a small level of effort, and a limited scope).

It does sound promising, but I can’t really link to a forum post in the description.

> [@amilich](#):
>
> I understand how important this information is and am glad it’s getting covered.

Precisely, too few things are audited.

> [@amilich](#):
>
> A lot of the frustration is that many years of work goes into preparing for even submitting to PrivacyGuides, which I would regard as having some of the highest criteria in this space.

The reason we do that, is because we want to cut through the noise and be able to clearly define best options in the market. At the same time our reputation is also important, so for us to endorse a product, we truly have to believe in it/be able to justify enough to use it ourselves, (if that makes sense).

I don’t doubt that Skiff related system of products will be good. As far a source/repositories go we’d like to see something [more like this](https://github.com/ProtonMail/gluon/commits/dev) which will in turn lead to more of [this](https://github.com/ProtonMail/proton-bridge/issues) and [that](https://github.com/ProtonMail/proton-bridge/pulls) (if you get my meaning).

---

## Post 92 by @amilich — 2023-02-14T21:41:11Z

I totally understand - this is a great example of a direction we should be going in. FYI, Skiff is _much_ younger (Proton will turn 10 this year, and Skiff 3). We only started the discussion when we were confident that our products stand the test of the criteria and guide.

---

## Post 93 by @jonah — 2023-02-24T18:23:03Z

I think w/ our latest criteria changes, I’d be fine with adding Skiff Mail once Amazon SES is no longer in use, which is something that’s planned anyways to my understanding?

Going to mark this thread as “waiting” (for that change) and see if the rest of the team has any other input?

---

## Post 94 by @amilich — 2023-02-24T18:36:12Z

That makes sense. We have definitely been planning on removing it. I’m assuming you still don’t like the SES as an “extreme” backup if Skiff mailservers go down? As an engineer I always like having more backups, so it would be helpful to know.

---

## Post 95 by @jonah — 2023-02-24T18:57:35Z

Yes, basically.

We added a criteria (within the last few weeks) specifying that mail infrastructure has to be on servers you own/operate instead of outsourced. There were a few reasons for this, having a setup like yours might enable downgrade attacks if `inbound-smtp.skiff.com` was blocked on a network for example. Ultimately we feel it’s conceivable that backup MX servers might be used in situations other than actual outages of the primary servers, and it’s easier to just avoid that situation altogether.

Since mail senders are required by spec to retry delivery if the receiving server is offline for at least a good while, I’m not really concerned about outages personally given that they don’t last 1+ day or anything… Of course if you had a mail server on separate infrastructure with a lower priority for backups that you still manage yourself that would be fine. (It could simply queue incoming mail for delivery once the primary servers come back online, so it would potentially be less complex and less prone to outages than your primary servers.)

Even ignoring that, not being able to configure the security defaults of Amazon SES would disqualify you anyways once the changes at [Minimum TLS requirements (for Email Providers)](https://discuss.privacyguides.net/t/minimum-tls-requirements-for-email-providers/11830) are made, which sounds like will be happening soon based on our talks with other providers so far. (Your main mail servers already meet our future criteria in that thread).

---

## Post 96 by @Ganther — 2023-03-01T12:30:25Z

> [@nishil](#):
>
> [NO] ​Must not be hosted in the US due to ECPA which has yet to be reformed

Shouldn’t this be the biggest blocker? It would seem that being hosted in the US is a severe disadvantage for Skiff as opposed to Proton Mail (Hosted in Switzerland).

I fail to see how the ECPA will affect it though, as it only affects emails stored for 180 days, which will obviously not affect Skiff seeing as they are stored E2EE.

When it comes to incoming messages, it’s a lot unclearer. Lavabit was forced by a federal judge to fork over the encryption keys. What exactly is stopping the same from happening for Skiff?

> **[Secrets, lies and Snowden's email: why I was forced to shut down Lavabit](https://www.theguardian.com/commentisfree/2014/may/20/why-did-lavabit-shut-down-snowden-email)**
>
> Ladar Levison: For the first time, the founder of an encrypted email startup reveals how the FBI and the US legal system made sure we don't have the right to much privacy in the first place

Also, bare in mind that the number 1 flaw of any email service is that they rarely use E2EE with one another, only with one self. Hence most incoming emails will never use E2EE, so it would seem that Skiff could be affected in the same way Lavabit were.

---

## Post 97 by @anon20402919 — 2023-03-01T15:22:52Z

[Any plans of hosting the data for European users in Europe? : Skiff (reddit.com)](https://www.reddit.com/r/Skiff/comments/113scy7/any_plans_of_hosting_the_data_for_european_users/)

According to skiff, American privacy laws are good…

---

## Post 98 by @jonah — 2023-03-01T19:31:44Z

> [@Ganther](#):
>
> I fail to see how the ECPA will affect it though, as it only affects emails stored for 180 days, which will obviously not affect Skiff seeing as they are stored E2EE.

I think we will likely remove this requirement for this reason if/when we add Skiff Mail, as all of the providers we recommend will use E2EE storage (hopefully anyways… Startmail kind of doesn’t, but we’re discussing that in [another thread](https://discuss.privacyguides.net/t/minimum-tls-requirements-for-email-providers/11830/18) and may just end up removing them).

---

## Post 99 by @Ganther — 2023-03-01T20:31:04Z

They didn’t exactly win me over when I read that. I also fail to see why they would delete the thread unless I’m missing something.

The thing that worries me the most with Skiff is that when it comes to messages sent E2EE, their choice to host it in the US doesn’t matter. When it comes to messages that aren’t E2EE on the other hand, which is inevitably going to be most of them, the lack of E2EE is definitely a problem. The situation with Lavabit shows that.

Being in the US would also give the NSA and similar organisations an advantage. Switzerland is hardly perfect, but I fail to see how the Lavabit situation would ever happen over there. Proton Mail has been around for ten years now and the worst thing that has happened to them is that they were forced to log an IP of a terrorist.

In short, I fail to see how they can consider the US to be a better choice than Switzerland.

---

## Post 100 by @nishil — 2023-03-01T21:04:03Z

Hi all,

Skiff’s director of security chiming in here again.

There’s a lot in these previous comments about US jurisdiction and I’m not a lawyer so can’t provide legal analysis or recommendations. However, I want to clarify a few things that could help to provide a more constructive conversation.

1. US companies that handed over data to the NSA often did so under a secret court order because these service providers saved the underlying data in a way that they had perpetual access to this data. I’m not here to argue the moral or ethical implications of this. Just trying to establish a common baseline of facts. (Yes, some companies may have more willingly handed over this data than others.)

2. Skiff does not have access to any emails once they are encrypted in our inbound processing pipeline. Skiff performs actions such as spam detection and virus scanning that are legitimately in the user’s interests and ensure viability of the Skiff email product. However once Skiff goes to store this information, we encrypt this data with the user’s public keys and never retain any copy of the underlying email. At best if Skiff is asked to hand over existing data under some secret court order, we would only have access to the underlying ciphertext. (This is all outlined publicly in our whitepaper that I recommend reading at [skiff.com/whitepaper](http://skiff.com/whitepaper))

You can argue that this is insufficient still but I want to lay out the basic facts so that we can have an informed, productive conversation rooted in technical facts that moves beyond “USA bad”

Thanks!

---

## Post 101 by @Ganther — 2023-03-01T21:12:15Z

> [@nishil](#):
>
> Skiff does not have access to any emails once they are encrypted in our inbound processing pipeline. Skiff performs actions such as spam detection and virus scanning that are legitimately in the user’s interests and ensure viability of the Skiff email product. However once Skiff goes to store this information, we encrypt this data with the user’s public keys and never retain any copy of the underlying email. At best if Skiff is asked to hand over existing data under some secret court order, we would only have access to the underlying ciphertext. (This is all outlined publicly in our whitepaper that I recommend reading at [skiff.com/whitepaper](http://skiff.com/whitepaper))

After they are encrypted the emails cannot be accessed by you. No one is disputing this. My worries lie in that you can be forced to save (non-E2EE) incoming messages before they are encrypted just like Tutanota were in the past. I have yet to see this happen for a Swiss company, and it seems to have happened in the past for at least one US email host. That being Lavabit.

---

## Post 102 by @jonah — 2023-03-02T02:46:19Z

I think the concern being brought up here is not regarding keys related to storage, but rather keys related to transport encryption. In the Lavabit case brought up earlier, the US government requested their TLS keys to intercept _future_ traffic, not keys to access existing mailboxes. I don’t see how Skiff Mail could work around this?

That being said, I don’t think this issue is a blocker for adding Skiff Mail in the first place. This is kind of outside the threat model of most people.

---

## Post 103 by @Ganther — 2023-03-02T08:24:38Z

> [@jonah](#):
>
> I don’t see how Skiff Mail could work around this?

I simply wanted to point out that it’s a possibility for a US hosted email service. It doesn’t seem to be a possibility for a Swiss service.

Then again, it’s also a risk for Tutanota as we’ve seen in the past and I don’t think that’s listed anywhere on PG.

Perhaps most worryingly is that in the US with Lavabit they were given a gag order and very little opportunity to fight back against it.

They also didn’t settle for a one person backdoor like with Tutanota. Instead they wanted a backdoor for any and all incoming messages.

---

## Post 104 by @jonah — 2023-03-09T16:24:24Z

> [@jonah](#):
>
> We tested this **1** month ago, so I don’t think this only applies to Skiff users from before the launch of Skiff Mail. If you think we are wrong and you do not send product updates to the recovery email specified for new Skiff Mail users, then I will test this with a new account again.

Just to add a note here: I can confirm Skiff Mail is still sending marketing emails to the address specifically designated as a recovery email.

---

## Post 105 by @Ganther — 2023-03-23T10:48:20Z

From their privacy agreement:

> We may use information to market and advertise our products to you directly if you have signed up for the services and/or provided us with your email address. This includes marketing via email campaigns and notifications within the Platform. You can opt out of direct email marketing messages from us by clicking the “unsubscribe” button included in the footer of the emails we send you. For more choices about use of tracking technologies for advertising more generally, please see “Your Privacy Choices” below.

---

## Post 106 by @cybsectux — 2023-03-29T10:06:33Z

I would like to point out a serious issue with Skiff Mail which I believe should be fixed. In particular, once you adjust the settings of Skiff Mail, under the security section, you could select block remote content. The first problem is that it is not turned on by default. The second problem is that once I selected to block the remote content, on the next day, on a new login session, it was again turned off, meaning it was reversed to the default state. Unfortunately, on every single new login, the setting to block remote content is disabled. For a privacy-respecting and a secure email provider, it is an issue.

---

## Post 107 by @nishil — 2023-03-29T18:23:49Z

Hi there,

We currently don’t sync settings as these preferences are stored locally. You’re likely using a private window so these settings are reset. We are about to launch an improvement to sync user preferences so they are saved into your account. This should be out within a few days if not sooner.

---

## Post 108 by @amilich — 2023-04-03T05:20:26Z

This has been resolved for about 6 weeks now. Any new account since then will not receive any emails to any non-Skiff email address. Note there has always been an option to unsubscribe.

---

## Post 109 by @amilich — 2023-04-03T05:21:48Z

FYI, these emails are weekly update emails are not marketing related. For example, we announced “Skiff Mail” and “Skiff Calendar” via the email addresses people used to sign up. As I’ve written above, these emails were required before Skiff was even an email provider.

---

## Post 110 by @amilich — 2023-04-03T05:22:35Z

PG team - does this complete the criteria you were looking for? We’d still love to be recommended (and would also definitely want Skiff Pages/Drive/Cal to also be on the list). This thread seems to have a lot of views but not much in recent updates.

---

## Post 111 by @jonah — 2023-04-03T13:52:29Z

> [@jonah](#):
>
> I think w/ our latest criteria changes, I’d be fine with adding Skiff Mail once Amazon SES is no longer in use, which is something that’s planned anyways to my understanding?

> [@jonah](#):
>
> Yes, basically.
> 
> We added a criteria (within the last few weeks) specifying that mail infrastructure has to be on servers you own/operate instead of outsourced. There were a few reasons for this, having a setup like yours might enable downgrade attacks if `inbound-smtp.skiff.com` was blocked on a network for example. Ultimately we feel it’s conceivable that backup MX servers might be used in situations other than actual outages of the primary servers, and it’s easier to just avoid that situation altogether.
> 
> Since mail senders are required by spec to retry delivery if the receiving server is offline for at least a good while, I’m not really concerned about outages personally given that they don’t last 1+ day or anything… Of course if you had a mail server on separate infrastructure with a lower priority for backups that you still manage yourself that would be fine. (It could simply queue incoming mail for delivery once the primary servers come back online, so it would potentially be less complex and less prone to outages than your primary servers.)
> 
> Even ignoring that, not being able to configure the security defaults of Amazon SES would disqualify you anyways once the changes at [Minimum TLS requirements (for Email Providers)](https://discuss.privacyguides.net/t/minimum-tls-requirements-for-email-providers/11830) are made, which sounds like will be happening soon based on our talks with other providers so far. (Your main mail servers already meet our future criteria in that thread).

Any updates?

---

## Post 112 by @amilich — 2023-04-03T21:47:20Z

Got it. Thanks for the detailed feedback! Chatting with the team about getting rid of the backup MX.

---

## Post 113 by @jonah — 2023-04-04T01:33:28Z

> <https://github.com/privacyguides/privacyguides.org/pull/2108>
>
> Changes proposed in this PR:
> 
> - Recommend Skiff Mail
> 
> ~~Obviously they don't… meet our criteria yet, so this is waiting on the changes from https://discuss.privacyguides.net/t/skiff-mail-email-provider/11411/111, but I think those will eventually be made so I'll get started on writing this now.~~
> 
> 
> 
> 
> - [x] I have disclosed any relevant conflicts of interest in my post.
> - [x] I agree to grant Privacy Guides a perpetual, worldwide, non-exclusive, transferable, royalty-free, irrevocable license with the right to sublicense such rights through multiple tiers of sublicensees, to reproduce, modify, display, perform, relicense, and distribute my contribution as part of this project.
> - [x] I am the sole author of this work. 
> - [x] I agree to the [Community Code of Conduct](https://www.privacyguides.org/en/code_of_conduct/).

---

## Post 114 by @jonah — 2023-04-04T01:33:35Z

Alright, I’ve come up with another question lol

[https://skiff.com/mail](https://skiff.com/mail) says “unlimited aliases”, but your pricing plans only let you create up to 15 (on business), so what is unlimited?

---

## Post 115 by @amilich — 2023-04-04T02:47:00Z

You can create unlimited aliases on any custom domain.

---

## Post 116 by @amilich — 2023-04-04T03:43:08Z

We removed the backup MX! Thanks for opening the draft PR. We appreciate all the feedback.

---

## Post 117 by @ph00lt0 — 2023-04-04T08:06:40Z

I am going to jump in this converstation again. Because in my opinion Skiff is a well marketing solution but in no way sells that they understand what privacy means.

I was called out by this @amilich for not understanding the GDPR. While I work with the GDPR on daily basis and have been studying this and working with this regulation before it was introduced. However, interestingly the website of Skiff is only spreading misinformation.

Some quotes from the website that are pure misinformation:

> Under privacy laws like the General Data Protection Regulation (GDPR) in the European Union and the California Consumer Privacy Act (CCPA) in the United States, websites are required to obtain explicit consent from users before collecting and processing their personal data, including information collected through tracking cookies. ([Skiff - Private, encrypted, secure email - 10 GB free](https://skiff.com/blog/device-browser-fingerprinting-protection))

This is not true at all. The GDPR doesn’t even mention tracking cookies. Big misconception. All tracking methods are equally treated. It basically suggests that it may not be illegal, while it definetly is. This ‘privacy’ company just repeats bullshit arguments from the ad business.

> The EU’s General Data Protection Regulation (GDPR) and California’s new Consumer Privacy Act (CCPA) both went into effect in 2020, establishing strict new regulations around data privacy.  
> ([Skiff - Private, encrypted, secure email - 10 GB free](https://skiff.com/blog/anonymous-secret-email))

The GDPR came into affect in 25 May 2018 and was introduced 14 April 2016.

> Yeah, we are GDPR compliant. Skiff collects no personally identifying information on signup (although you may optionally provide a backup email).  
> ([Reddit - The heart of the internet](https://www.reddit.com/r/Skiff/comments/10zolyg/is_skiff_gdpr_compliant/?rdt=53836))

Impossible Skfif does not have an EU representation, which is required. Therefore they cannot be be “compliant”.

I believe I have seen simliar statements on the website before but I cannot find them anymore.  
Only notably is that on [Skiff - Private, encrypted, secure email - 10 GB free](https://skiff.com/blog/secure-cloud-storage) other provides are mentioned to be ‘GDPR compliant’ but in the Skiff section nothing is mentioned about this.

It also might be good to point out that GDPR compliant doesn’t really mean anything:

> **[IAPP](https://iapp.org/news/a/whats-the-definition-of-a-gdpr-complaint-spoiler-alert-no-one-knows/)**

I honestly hope you will take this up @amilich and I hope that your company will actually learn from this and keep improving. The changes made are positive and I do want to highlight that. I just personally think your business is not focussed on pure privacy unlike how you sell it. I hope this will change and Skiff has a cool product but I am sceptical of your intentions.

Also I received your latest product update spam on my recovery email this very night. So this still has not been fixed.

---

## Post 118 by @amilich — 2023-04-05T17:02:28Z

As I wrote above, it was fixed 6 weeks ago for all new accounts and we have not received a single report of an issue. For all existing emails, you have had the option to click unsubscribe since the first product update you received.

I don’t think a GDPR discussion will be productive here but note that the quote you stated as “misinformation” does not do anything you say it does. It says, as you state, “websites are required to obtain explicit consent from users before collecting and processing their personal data,” which is correct.

---

## Post 119 by @ph00lt0 — 2023-04-05T17:46:26Z

> [@amilich](#):
>
> As I wrote above, it was fixed 6 weeks ago for all new accounts and we have not received a single report of an issue. For all existing emails, you have had the option to click unsubscribe since the first product update you received.

Once again shows you do not understand the problem. You still refer to opt out. I will not opt out of your emails, I never opted in so why should I opt out? You should just stop sending mails to people who did not consent. If you cannot differentate them you will imho have to ask everyone for consent and stop sending emails to those who did not ask for it.

I am also not going to reply to your other reply on GDPR any further. You comment on half of the few examples I gave and fully neglect the actual pointed out issues.

---

## Post 120 by @ph00lt0 — 2023-04-05T17:59:32Z

Also still other DNS issues appear with Skiff.

This one I did not see before, but may have missed it, but currently: [dmarcdigests.com](http://dmarcdigests.com) is used for RUA dmarc aggregate reports. Seeminglty this company didn’t mind to share this data with Active Campaign. Before they shared it all with [easydmarc.us](http://easydmarc.us). But this surely is better ( :upside_down_face: sarcasm).  
This probably will be once again a, suprise, new requirement for you @amilich, but other providers do not have these practises.

Old one: Skiff still uses ECDHE-ARIA256-GCM-SHA384 for SMTP

---

## Post 121 by @amilich — 2023-04-05T18:17:15Z

We use RUA reports to monitor for dmarc failures. These reports are sent as an opt in basis by recipients.

We ask the recipient inbox provider to send these reports to dmarcdigests to monitor for impersonations of [skiff.com](http://skiff.com) (someone trying to take our product down) and DKIM reply attacks, which we have experienced.

Thanks!

---

## Post 122 by @amilich — 2023-04-05T18:17:35Z

Recommended highly by external auditors.

---

## Post 123 by @ph00lt0 — 2023-04-05T19:19:51Z

You seem to misunderstand the difference between RUA and RUF. RUF is for failures and forensic reports which you would need for violations, they are not shared it seems (luckily).

RUA is for aggregate reports, so not just failures. RUA reports include the following information: timestamps, domainnames, and the ipaddress of sender. I hope that you are aware that Active Campaign is a marketing company, and you just feed them data. They can get more info on what services your users use, not what I expect from a private mail firm. Do you have agreements with Active Campaign on what they can do with this data?

Let me ask this, since I do not have means to test, do you also configure these RUA for custom domains people order at you? I wonder this because that would even further narrow down the information and could directly tell Active Campaign what services someone is using or who they know, etc. Or do they not get to use this monitoring?

Obviously many people got their domains through different providers so can configure it themselves. Appearantly not as greatly as one would hope, most of the other domainsnames I can find on your MX are not having any DMARC. Not saying you should but might be nice to advice them. As for Proton Mail I know this is part off the onboarding of domains.

On the scary story of “DKIM reply attacks” I assume that you mean DKIM replay attacks?  
Here is a cool blogpost on what measures actually work:

e class="onebox allowlistedgeneric" data-onebox-src="https://proton.me/blog/dkim-replay-attack-breakdown"\> ![](//forum-uploads.privacyguidesusercontent.com/original/1X/8ac7e3241f285e1ea1463c593035f1490daa3869.png)[Proton – 13 Jan 22](https://proton.me/blog/dkim-replay-attack-breakdown "02:20PM - 13 January 2022")
 ![](//forum-uploads.privacyguidesusercontent.com/optimized/2X/b/b888e42c90907e23a709010a1ae73e95b60c8e40_2_690x361.jpeg)
### [A breakdown of a DKIM replay attack | Proton](https://proton.me/blog/dkim-replay-attack-breakdown)

Bart Butler, our CTO, explains how we resolved a DKIM replay attack and how you can protect your domain from being impersonated.

---

## Post 124 by @nishil — 2023-04-05T20:20:52Z

You should check all settings against [skiff.com](http://skiff.com) as that is what is relevant to this discussion. Let’s focus on the facts here rather than spreading innuendos and misinformation. It’s really disappointing to see bad faith arguments to continue to be made. We will answer it seriously once in case that the previous questions were actually made in good faith.

Here is our DMARC record for [skiff.com](http://skiff.com). Source: [DNS Propagation Checker - Global DNS Testing Tool](https://www.whatsmydns.net/#TXT/_dmarc.skiff.com)

I have also included it below if you don’t want to click the link.

```
v=DMARC1;p=reject;pct=100;adkim=s;aspf=r;rua=mailto:rua-com@skiff.org,mailto:re+b36bf17d2996@inbound.dmarcdigests.com;ruf=mailto:ruf-com@skiff.org;fo=1;
```

Here we have 100% rejection for DMARC failures. Yes, we accept RUA and RUF reports that recipient email providers can choose to send us.

RUA vs RUF reports (Source: [The Difference in DMARC Reports: RUA and RUF - dmarcian](https://dmarcian.com/rua-vs-ruf/))  
RUA reports - no PII. These are aggregate reports on DMARC failures.  
RUF reports - email is only sent back to us in case of DMARC failure which means **the mail did not originate from Skiff**. We have a legitimate interest in finding spammers impersonating our domain and working with the broader community to take them down.

RUF reports are not sent at all to DMARCDigests. RUA reports again contain no PII of our users. It indicates the IP address of the _sending email server_. This means the IP we get back for legitimate users is the IP address of Skiff’s email servers which is known through our SPF records. Other IP addresses are not authorized to send on behalf of [skiff.com](http://skiff.com). These IP addresses that we receive again from recipient email service providers is the IP addresses of email servers and not users.

Our agreements with DMARC Digests and their parent company are irrelevant because they do not ever receive personal information about our users because they only receive RUA reports do not contain identifying information about our users.

> Let me ask this, since I do not have means to test,

This is categorically false. DNS records are available publicly for custom domains bought through us or when a user brings their own domain. Again, this is where we believe these arguments are made in extremely bad faith by arguing that these items are not verifiable when in fact they are through websites that let you query DNS records or by even using the `dig` CLI tool.

To answer your question since you claim you cannot test this, we do not add RUA and RUF tags for custom domains. To onboard a custom domain, SPF, DKIM, and DMARC are all required before verification. Here is a screenshot of a test domain and the records we require clearly documenting these requirements.

 ![Screenshot 2023-04-05 at 1.06.29 PM](//forum-uploads.privacyguidesusercontent.com/original/2X/4/4cdbbaa4d56f4e27b4f8e29af1696bec373b142c.png)

> On the scary story of “DKIM reply attacks” I assume that you mean DKIM replay attacks?

Yes, we meant DKIM replay attacks. We’ve dealt with them successfully and have just as strong mitigations as Proton and in some cases stronger. For example, the expiry tag we use on our DKIM signatures last just a few minutes. For Proton, this is a few days. Proton does not over sign headers. We do. Here is the evidence for that.

Proton DKIM Signature Header

```
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=proton.me; s=protonmail; t=1680725421; x=1680984621; bh=vkaEgdv9blx7I/kJwDMn9s2jZkAkWlF0qXcEEPbw3JA=; h=Date:To:From:Subject:Message-ID:Feedback-ID:From:To:Cc:Date:
	 Subject:Reply-To:Feedback-ID:Message-ID:BIMI-Selector; b=CxYNgddWxKevJYlJlx8LFHwJUfaPqjOFmjIkBHWV2+UqEIfc1iWqWRSJt6FH5COnb
	 NUWNRguW+6RkXVZ56Ab17KkFpsgqNNafivGHLMQMS8ujpUe98v4FfNsX6RSDHaQxFr
	 Qg/CCOONC7K9g4pcigek5+XGHi7E8iUnOQ7NkNcYRQvMVAyGKEvCNK6Tep77tPdLC8
	 lbRiGrgGfF/skJJW/kYXZnu+x7JRAWXFWr8Td3/VG58mky7LXcq9G1zMGpY3Sf5JK2
	 1oRDm2a4d3iuD6oiufOWvBAisKrJW1o9r6G6wo+q/SLoKt0BiryvxA3KjPPer6hoXk
	 frAf+OBUBtugQ==
```

Skiff DKIM Signature Header

```
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=skiff.com; s=skiff1; h=subject:subject:from:from:to:to:date:date:message-id:message-id:reply-to:resent-date:resent-from:resent-to:resent-cc:in-reply-to:references:list-id:list-help:list-unsubscribe:list-subscribe:list-post:list-owner:list-archive:feedback-id:feedback-id:content-type:content-type:content-transfer-encoding:content-disposition:mime-version:mime-version:sender:resent-message-id:resent-sender:content-description:content-id; bh=fo/cTVEj7VfLbVN/naM8bq4BjudDvGFxFpC11rjyKao=; t=1680725670; x=1680729270; b=Ez+DIa4CkP+DwXHFTomNCsamgQ0dAIsuWsufwanWZZ9s97O//q4I05kJk934K+tec9dvRKPifY MZsGr76I47TCtluQpFZRSdWSYyvuF5bpwD3C1iOXYi1Lthtz/h6XZym8ZQLzUF7IRPBRKMtmkCDK kYfarFAka3c/QYiu9hfo/romY5+DHASn5kK3/iEGm8W20ywD+46xXAfv8kLb/p7VFoFutlnUsAhR OBbix0S+IGCKxgqO3RhZuk7XDY7PjQYcGXkve71CmmbOTTQPhU59JvbCajl/UeVx7QmWUq23OS1/ cpnBEp2SekfwhPDjc5+khoFo5H1cKuPRpmnRVY3Q==
```

Again, this is all verifiable by sending an email from Proton and an email from Skiff to any of your favorite email providers and viewing the raw headers.

If you want to engage in good faith arguments, please do so! We welcome that! We removed SES as a backup and prioritized that work due to legitimate concerns. However, spreading misinformation through innuendo should not be welcome when we actually are looking to build privacy services for the Internet.

---

## Post 125 by @amilich — 2023-04-05T20:22:37Z

We won’t be responding to any further messages back and forth due to the bad faith nature of the arguments (and they appear to be circular). If you have any other questions please write to [security@skiff.org](mailto:security@skiff.org).

We’d love to hear any other questions from the PG team in the meantime.

---

## Post 126 by @ph00lt0 — 2023-04-05T20:39:54Z

> [@nishil](#):
>
> This is categorically false. DNS records are available publicly for custom domains bought through us or when a user brings their own domain. Again, this is where we believe these arguments are made in extremely bad faith by arguing that these items are not verifiable when in fact they are through websites that let you query DNS records or by even using the `dig` CLI tool.

I do not have a custom domain at you that’s why I cannot test this, Hence I ask, I will take your word for this. I am not saying this is not verfiable. I said I cannot test it.

> [@nishil](#):
>
> To answer your question since you claim you cannot test this, we do not add RUA and RUF tags for custom domains. To onboard a custom domain, SPF, DKIM, and DMARC are all required before verification. Here is a screenshot of a test domain and the records we require clearly documenting these requirements.

I am glad, that’s positive!

> [@nishil](#):
>
> If you want to engage in good faith arguments, please do so! We welcome that! We removed SES as a backup and prioritized that work due to legitimate concerns. However, spreading misinformation through innuendo should not be welcome when we actually are looking to build privacy services for the Internet.

I definitely do! As I also said I am happy to have seen the changes made before. I am just critical and hope to push to actually change more.

---

## Post 127 by @ph00lt0 — 2023-04-05T20:40:36Z

> [@nishil](#):
>
> RUF reports are not sent at all to DMARCDigests. RUA reports again contain no PII of our users. It indicates the IP address of the _sending email server_. This means the IP we get back for legitimate users is the IP address of Skiff’s email servers which is known through our SPF records. Other IP addresses are not authorized to send on behalf of [skiff.com](http://skiff.com). These IP addresses that we receive again from recipient email service providers is the IP addresses of email servers and not users.

A domain can be PII sorry not sorry, who are you to judge what is PII? I asked explicitedly about the custom domains here cuz it could directy tie togther that e@bob.example knows e@alice.example.

Edit:  
Just to add to this aswell, even now that you confirmed this is not the case you still give a marketing company access to data of usage of your customers. I cannot see this in another way. By doing so you might be helping them in profiling. Hence I asked about your argeements with them, who could legally restrain them from utilizing it, besides that I think it would be preferable to keep this internal.

---

## Post 128 by @ph00lt0 — 2023-04-05T20:42:16Z

> [@nishil](#):
>
> RUF reports are not sent at all to DMARCDigests. RUA reports again contain no PII of our users. It indicates the IP address of the _sending email server_. This means the IP we get back for legitimate users is the IP address of Skiff’s email servers which is known through our SPF records. Other IP addresses are not authorized to send on behalf of [skiff.com](http://skiff.com). These IP addresses that we receive again from recipient email service providers is the IP addresses of email servers and not users.

I am just being critical and if you don’t like that I am sorry. I am open to a good discussion on what is privacy and the values, we do not seem to see it in the same way. It saddens me you are not willing to discuss it.

---

## Post 129 by @amilich — 2023-04-05T20:56:00Z

Actually, you could test this! You don’t even need a domain to see what records you would need to add. We enjoy having conversations about privacy (this entire thread is for that purpose), but not ones with disinformation or bad assumptions. Also, there’s plenty of documentation available if you prefer “not to test” some of the things being discussed.

BTW, there are legal definitions of PII! Domain names are not on that list. We do agree they are sensitive, though, so I would advise reading the response above again.

---

## Post 130 by @amilich — 2023-04-05T20:56:36Z

Again, I will try to limit responses because it’s quite time consuming to step through this issue by issue.

---

## Post 131 by @ph00lt0 — 2023-04-05T21:05:12Z

> [@amilich](#):
>
> BTW, there are legal definitions of PII! Domain names are not on that list. We do agree they are sensitive, though, so I would advise reading the response above again.

Okay sure lets not use the PII from the US law but a more sane term used in the EU:

> “Personal data is any information that relates to an **identified or identifiable living individual**. Different pieces of information, which collected together can lead to the identification of a particular person, also constitute personal data.”  
> -[Data protection explained - European Commission](https://commission.europa.eu/law/law-topic/data-protection/reform/what-personal-data_en)

**Edit:**  
I think it seems time for a little sum up of the issues I had/have:

- DNS settings (mostly resolved)
- Amazon SES (resolved)
- Giving data to third parties, especially marketing firms
- False GDPR claims
- Being called out for not knowing GDPR? While it seems to be the other way around
- Using emails for recovery for product updates, or as I call it spam (resolved only for new users)

And we seem to have different values when it comes to privacy. I care more about the intensions and the privacy by design aspect of your business, while you are focussed on being complaint for listing.

---

## Post 132 by @amilich — 2023-04-05T21:24:03Z

> [@nishil](#):
>
> Our agreements with DMARC Digests and their parent company are irrelevant because they do not ever receive personal information about our users because they only receive RUA reports do not contain identifying information about our users.

Did you even read Nishil’s response?

> Our agreements with DMARC Digests and their parent company are irrelevant because they do not ever receive personal information about our users because they only receive RUA reports do not contain identifying information about our users.

Of course, we are happy to have discussions about this, but not waste time.

---

## Post 133 by @ph00lt0 — 2023-04-05T21:27:15Z

> [@amilich](#):
>
> Did you even read Nishil’s response?

Yes I have read it and also in previous reply acknowledged it.

> [@ph00lt0](#):
>
> Edit:  
> Just to add to this aswell, even now that you confirmed this is not the case you still give a marketing company access to data of usage of your customers. I cannot see this in another way. By doing so you might be helping them in profiling. Hence I asked about your argeements with them, who could legally restrain them from utilizing it, besides that I think it would be preferable to keep this internal.

---

## Post 134 by @amilich — 2023-04-05T21:28:31Z

Honestly, we’ve spent an incredible amount of time walking through the false pretenses and claims in your posts. And, everything we’ve noted about GDPR is correct - I can’t find a logical argument in any of your comments (especially the one I posted on cookies).

Values-wise, our entire business is architected around privacy. We collect as little PII as possible - even avoiding user IP address collection on login - and that’s why we were banned in Russia in only 8 months of Skiff Mail being launched ([Russia is blocking encrypted email startup Skiff | TechCrunch](https://techcrunch.com/2023/01/30/russia-skiff-block/) or [https://www.wsj.com/articles/encryption-bans-what-is-this-russia-hacking-online-privacy-security-data-signal-whatsapp-emails-protection-11675436242](https://www.wsj.com/articles/encryption-bans-what-is-this-russia-hacking-online-privacy-security-data-signal-whatsapp-emails-protection-11675436242)).

We also take a ton of time to engage with our community on Discord, Reddit, YouTube, Play Store reviews, etc. What is tough is when we get into circular debates or discussions that aren’t grounded in technical fact. We love the PG community - I’ve been participating in threads for over a year! - and spent a huge amount of time making Skiff suitable to your criteria.

We’re launching Webauth/hardware keys soon, are working on options for encrypted email to non-Skiff users, removed MX records that we had intended as a last-resort backup because we do align in values and are open to having our opinions changed. There is nothing more exhausting than practicing these values but spending time on incorrect assumptions.

---

## Post 135 by @ph00lt0 — 2023-04-05T21:40:25Z

> [@amilich](#):
>
> Honestly, we’ve spent an incredible amount of time walking through the false pretenses and claims in your posts. And, everything we’ve noted about GDPR is correct - I can’t find a logical argument in any of your comments (especially the one I posted on cookies).

I am not disagreeing on you efforts, they are appreciated. Yet we disagree on how the GDPR is read, even dates seem to cause a disagreement while all is public info.

The architecture I fully believe is done right. I am not talking about that. I am talking about values. You might be listed by PG team even without having the same view as I have. I just never would go for a provider that does the things mentioned when there are others who do not. I am not sure if being blocked in russia is somthing to celebrate, but okay.

> [@amilich](#):
>
> What is tough is when we get into circular debates or discussions that aren’t grounded in technical fact.

I am not seeing why this is circular I brought up things that are not solved yet and new discoveries. I even made a list now in my previous reply with the list of things I take issue with.

I know you have been around, just like myself (i lost count of years) for a while, and I am happy to have your view on things even if we do not agree.

> [@amilich](#):
>
> We’re launching Webauth/hardware keys soon, are working on options for encrypted email to non-Skiff users, removed MX records that we had intended as a last-resort backup because we do align in values and are open to having our opinions changed. There is nothing more exhausting than practicing these values but spending time on incorrect assumptions.

This sounds really cool and that is just awesome. :clap:

I still hope you will take a look at what I have said and reconsider those. I will continue to report if I find other things, but I think I have well argued for my views and explained what I like to see changed.

---

## Post 136 by @amilich — 2023-04-05T21:56:40Z

I completely understand. We are here both to improve our product and hopefully to be listed. Nishil and I are merely disagreeing with some of the technical points because we do not mass-share user domains with any third parties (also, to be clear, knowing whether a single domain is connected to Skiff is public record via a DNS lookup - no matter what we want to do about it).

We are open to any further feedback and will continue to improve our product regardless. Not that long ago, Skiff was a 2-3 person team, so we would not have existed this far without absorbing a lot of important feedback.

---

## Post 137 by @jonah — 2023-04-06T03:10:29Z

> [@ph00lt0](#):
>
> Just to add to this aswell, even now that you confirmed this is not the case you still give a marketing company access to data of usage of your customers. I cannot see this in another way. By doing so you might be helping them in profiling.

I’m confused about what your concern here is. As far as I can see, the only information even remotely related to “usage” that DMARCDigests receives is:

- How many emails each reporting mailserver received from `@skiff.com`.

I don’t see how this could be used to individually profile any users.

* * *

I also don’t fully understand your argument relating to GDPR here, I think I’ll have to read through this thread again and unpack this tomorrow lol. Although @amilich’s [blog post](https://skiff.com/blog/anonymous-secret-email) that says GDPR went into effect in 2020 is obviously incorrect, that seems a bit nitpicky to me :slight_smile:

Clearly I will have to re-test the whole “marketing emails going to recovery addresses” thing though, since we last tested that ~7 weeks ago and it was supposedly fixed “about 6 weeks ago.”

> [@amilich](#):
>
> For all existing emails, you have had the option to click unsubscribe since the first product update you received.

For what it’s worth, GDPR does require affirmative opt- **in** consent for marketing communications. I suppose if this is indeed fixed then you are compliant in this area now, but you would not have been compliant prior to ~6 weeks ago to my knowledge, which is probably why this issue was brought up.

I would imagine that any of your existing customers in the EU could still file a complaint about this.

---

## Post 138 by @amilich — 2023-04-06T05:58:21Z

My point above was that the emails aren’t marketing mail, particularly before Skiff Mail existed. So, there was a ~6 month period of time where this situation existed and I understand it wasn’t ideal. But, we did fix it, so sign up for a new account, add a backup email, and you will not get any sort of product updates. Anyway, I don’t think it’s necessarily rehashing the nitpick about transactional mail vs legitimate interest vs marketing mail.

---

## Post 139 by @amilich — 2023-04-12T16:22:15Z

Hey all! We just launched Yubikey/hardware key support.

Anything we can do to unblock the thread or the PR to include Skiff Mail?

---

## Post 140 by @anon66296745 — 2023-04-12T17:04:21Z

What makes you guys want to be recommended on Privacy Guides? While I do appreciate that you guys are improving your services and stuff, I don’t know if this is being done because you actually want to be as good as possible for privacy and security and help people with their privacy journeys or because you guys want some free “advertising” by being recommended on Privacy Guides.

---

## Post 141 by @amilich — 2023-04-12T17:19:22Z

We’ve spent a year improving our product to the point where we’re quite confident it stands alone to be on this list by being as good or better than every other existing option. The same is true of every Skiff product: Drive, Pages, Calendar, and Mail.

We have absolutely no desire for free advertising. Our product stands alone in going above and beyond on security, usability, and privacy.

Have you read the other 137 topics in the thread above?

---

## Post 142 by @jonah — 2023-04-12T17:22:14Z

> [@amilich](#):
>
> Anything we can do to unblock the thread or the PR to include Skiff Mail?

A 128x128 SVG logo for Skiff Mail (two if there needs to be a separate one for dark mode) would be quite handy.

---

## Post 143 by @anon66296745 — 2023-04-12T17:35:10Z

> [@amilich](#):
>
> We’ve spent a year improving our product to the point where we’re quite confident it stands alone to be on this list by being as good or better than every other existing option.

I do agree that Skiff Mail is pretty good. In my humble opinion, Skiff Mail will be the second best after Proton Mail.

---

## Post 144 by @amilich — 2023-04-12T17:47:35Z

Thank you! :blush:

We are very open to feedback; that has been the most valuable part of this thread. PNG attached and SVG at this link: [skiff-org.github.io/assets/icons/mail-skiff-logo.svg at 1adb7f41597a4e94bc599bcb9812901977974aee · skiff-org/skiff-org.github.io · GitHub](https://github.com/skiff-org/skiff-org.github.io/blob/1adb7f41597a4e94bc599bcb9812901977974aee/assets/icons/mail-skiff-logo.svg)

 ![Skiff_Mail](//forum-uploads.privacyguidesusercontent.com/original/2X/a/aea3de52154364739d15c13fe55cdbf7912f7f03.png)

---

## Post 145 by @ph00lt0 — 2023-04-12T18:35:50Z

Sure the date thing was nitpicking but the general problem is that this company writes about GDPR while clearly not understanding its fundamentals.

My concern with the RUA was mostly addressed, if that wasn’t clear from above. I do however think that its weird that a privacy friend company goves data to a marketing company, that feels awkward. It could definitely help them to understand Skiff users as population, perhaps Skiff could still provide information on their data agreement on this as I already asked.

---

## Post 146 by @amilich — 2023-04-17T19:15:46Z

I don’t think that’s true at all. Your point above was wrong - our work never asserts that cookie banners are mentioned in GDPR.

We also don’t give any data to marketing companies. Please don’t make this stuff up!

---

## Post 147 by @Ganther — 2023-04-19T13:38:02Z

Another discussion on Reddit regarding Skiff being hosted in the US worth reading is this one:

[Skiff has severe focus on censorship and surveillance by Big Tech](https://www.reddit.com/r/degoogle/comments/12mgp6o/skiff_has_severe_focus_on_censorship_and/jgbrolo/)

---

## Post 148 by @amilich — 2023-04-24T09:24:11Z

I’d recommend reading the article that it links to. Don’t need to get into it here, but that seems like far less of an issue than:

- Tutanota - [German court forces encrypted email provider Tutanota to create backdoor for blackmail case](https://cyberscoop.com/germany-court-ruling-tutanota-email-monitoring/)
- EU chat control - [Chat Control May Finally Be Dead: European Court Rules That Weakening Encryption Is Illegal! | Tuta](https://tutanota.com/blog/posts/chat-control) (from a few days ago!)
- Swiss mass surveillance - [Switzerland votes in favour of greater surveillance | Switzerland | The Guardian](https://www.theguardian.com/world/2016/sep/25/switzerland-votes-in-favour-of-greater-surveillance)

Also: The headline is meant in a positive way - we are completely focused on being anti-censorship!

---

## Post 149 by @amilich — 2023-04-24T09:24:30Z

Just checking in. Let us know how else we can unblock this thread.

---

## Post 150 by @jeffreypezos — 2023-04-24T15:46:13Z

> [@amilich](#):
>
> but that seems like far less of an issue than:

Less of an issue how?

> [@amilich](#):
>
> Tutanota - German court forces encrypted email provider Tutanota to create backdoor for blackmail case

Yeah that’s a downer. But we’ve seen the same thing happen to US companies before.

> **[Naked Security – Sophos News](https://news.sophos.com/en-us/category/serious-security/)**

Google was forced to put surveillance on accounts based on purchases of a single product. I’ve yet to see a similar violation of privacy for a European country.

> [@amilich](#):
>
> EU chat control - Stop Chat Control: EU Study Warns of Law Against Child Abuse (from a few days ago!)

It hasn’t passed yet, and I fail to see how it could ever pass considering the implications it would have to… well.. everything. Email services are also exempt from Chat Control, for whatever that is worth.

> [@amilich](#):
>
> Swiss mass surveillance - [Switzerland votes in favour of greater surveillance | Switzerland | The Guardian](https://www.theguardian.com/world/2016/sep/25/switzerland-votes-in-favour-of-greater-surveillance)

Ultimately, Switzerland does not have a FISA court counterpart. If you want surveillance of a Proton Mail account there is one hell of a circus to go through to get that to happen.

> [@amilich](#):
>
> Also: The headline is meant in a positive way - we are completely focused on being anti-censorship!

… While for some reason placing yourself in a country known for its surveillance. I don’t get it, personally.

To quote a user from the Reddit thread:

> What happened at Tutanota is happening in the US as well, usually with US based VPNs. That’s why Proton’s location in Switzerland is uniquely advantageous. They are in a much better legal position than Tutanota or any US or 5 eyes company.  
> …  
> The US and the EU have no capacity to compel action in Switzerland or on any Swiss company. And Switzerland has stronger privacy protection laws. You’re at a substantial geographic disadvantage.
> 
> Look, competition in this space is good, but companies based in the US are simply not competitive.

---

## Post 151 by @amilich — 2023-04-24T16:02:28Z

I don’t think that’s true at all. I also don’t think we should start a long thread speculating on this here, but:

1. What happened to Tutanota is far worse to anything than we know about happening in the US. Take Signal as the most trustworthy example here. We’re comparing speculation versus a highly recommended email provider.

2. A lot of the Switzerland-privacy is marketing. I would suggest reading this: [Rechtsanwalt Martin Steiger – Steiger Legal](https://steigerlegal.ch/person/martin-steiger/). Again, I don’t think it’s worth turning this discussion into speculation, but here’s a quote:

> ProtonMail has to cooperate with Swiss security authorities. With the BÜPF Surveillance Act and the Intelligence Service Act (NDG) , Switzerland is a full-fledged surveillance state. Switzerland provides legal assistance to the USA on the basis of the 1973 legal assistance treaty , for example for gathering evidence in American criminal proceedings.

FYI, ProtonMail also operates servers in Germany - the very country that forced Tutanota to open a backdoor.

---

## Post 152 by @amilich — 2023-04-24T16:04:56Z

Anyway, I think national laws are incredibly important and US providers are _not_ on worse footing. I do think @jonah or others could be helpful once they have a minute to discuss anything else needed on the listing PR, because technical implementations are far more important than anything else.

Brave, Bitwarden, Signal, and others are great examples here.

---

## Post 153 by @jeffreypezos — 2023-04-24T16:18:41Z

> [@amilich](#):
>
> I also don’t think we should start a long thread speculating on this here

Why not? Isn’t the point of Privacy Guides to discuss any and all privacy upsides and downsides?

For the average user it doesn’t matter if you use Tutanota, Proton, Skiff or Mailbox. But for the activists that risk their lives leaking war crimes committed in some cases by the US itself, I think it’s a fair discussion to have.

> [@amilich](#):
>
> What happened to Tutanota is far worse to anything than we know about happening in the US.

Is it though? Seems like the exact same thing to me.

> Take Signal as the most trustworthy example here. We’re comparing speculation versus a highly recommended email provider.

Signal is a red herring in all of this. They are completely E2EE and naturally can’t be forced to log any incoming messages, since that’s impossible by design. Email certainly isn’t E2EE in most cases.

> [@amilich](#):
>
> A lot of the Switzerland-privacy is marketing. I would suggest reading this: [Rechtsanwalt Martin Steiger – Steiger Legal](https://steigerlegal.ch/person/martin-steiger/). Again, I don’t think it’s worth turning this discussion into speculation, but here’s a quote:

It’s not the privacy utopia we’d all want, but it’s magnitudes better than the US. Quad9 voluntarily moved from the US to Switzerland, and they did so for a reason.

Also, did you link the right thing? I don’t see a single mention of Proton in that link.

> [@amilich](#):
>
> Brave, Bitwarden, Signal, and others are great examples here.

This is another red herring. BitWarden and Signal are both E2EE by design. Brave is a browser, and it’s definitely not the same thing as an email host.

---

## Post 154 by @amilich — 2023-04-24T16:35:19Z

The debate is worthwhile, but it’s not a “yes” or “no” that we’ll arrive at. We have tons of activists using Skiff (why this happened - [Russia is blocking encrypted email startup Skiff | TechCrunch](https://techcrunch.com/2023/01/30/russia-skiff-block/)), some of which expressly told us they don’t use EU services because of E2EE concerns (like Germany) and abuse of Interpol by Russia.

---

## Post 155 by @ph00lt0 — 2023-04-24T17:38:26Z

> [@amilich](#):
>
> I’d recommend reading the article that it links to. Don’t need to get into it here, but that seems like far less of an issue than:

I actually don’t think being hosted in the US is your largest problem, but this reponse once again shows the lack of understanding from your side.

 ![image](//forum-uploads.privacyguidesusercontent.com/original/2X/b/b1df792ede75547f33a21d82eb177e278db12959.jpeg)

---

## Post 156 by @amilich — 2023-04-24T17:51:14Z

Do you have anything constructive to add to the discussion?

---

## Post 157 by @Ganther — 2023-04-25T09:58:08Z

Personally, I think a warrant canary on your website would be a neat addition.

---

## Post 158 by @ph00lt0 — 2023-04-25T11:09:45Z

> **[Are Warrant Canaries Useful?](https://proprivacy.com/privacy-news/warrant-canaries-useful)**
>
> Warrant canaries are intended to reassure customers that a service has not been compromised by the government and served a gag order.

TLDR: no

---

## Post 159 by @amilich — 2023-05-10T20:08:33Z

Any update on this thread? We’ve just added bulk export as well, which was also recommended above a few times.

---

## Post 160 by @NewUser — 2023-05-11T04:30:48Z

Any plans to add the Android app to f-droid?

---

## Post 161 by @pusrsc — 2023-05-11T13:13:41Z

My concern with the product is that it doesn’t seem to have people behind it that are passionate about privacy, rather than marketing the illusion of privacy.

I believe this is evident from product launch, with a privacy policy logging of user IP Address, Mac Address, Cookie Identifiers, Mobile Carrier (Cell Phone Provider), User Settings and Browser or Device Information. Yes, I understand you later changed this, but a company truly passionate about privacy would never dream of including such language in the first place. ([https://www.ghacks.net/2022/05/18/skiff-mail-end-to-end-encrypted-email-privacy-policy/](https://www.ghacks.net/2022/05/18/skiff-mail-end-to-end-encrypted-email-privacy-policy/))

Next is the choice to HQ in the U.S., subject to secret court orders to hand over keys and back doors, and subject to penalty if informing users that this is happening. You could have incorporated in Panama like NordVPN, or anywhere in Europe where the legal process is more transparent for users. The argument that because BitWarden made a poor choice and people still use it, you too can make the same poor choice, is not a good argument.

Next is the App. You’re saying, “here’s our product that is private unlike Google, now go download it from Google so they can track you in FireBase etc.” Again, if the people running the company were truly passionate about privacy, there would be an APK download on the website or on GitHub or F-Droid, and it wouldn’t contain any trackers or dependence on Google.

Next, transparency. I can’t find information anywhere on your website where you are located or who is behind the company. Contrast that with Tuta where there are names and pictures of staff, and the company address. You also do not have a transparency report to inform users about how many times law enforcement has contacted you and how many times you’ve handed over user data. And no independent audits that prove your product is delivering what it is promising? Again, if you were truly passionate about privacy this would all be at the forefront of your mind.

Best case scenario is that Skiff is run by marketing / business people who want to cash in on the privacy market and otherwise have little understanding and concern for privacy.

---

## Post 162 by @anon31041004 — 2023-05-11T15:20:04Z

If Skiff really cares about Privacy they should create a simplified version of their Privacy Policy.  
I’m using Skiff (Pro Plan currently) for almost a year.

I agree with all of your points.

---

## Post 163 by @nishil — 2023-05-11T15:30:56Z

My goodness the cynicism is so real here. Let’s address these points properly.

> I believe this is evident from product launch, with a privacy policy logging of user IP Address, Mac Address, Cookie Identifiers, Mobile Carrier (Cell Phone Provider), User Settings and Browser or Device Information. Yes, I understand you later changed this, but a company truly passionate about privacy would never dream of including such language in the first place.

We had the appropriate technical controls in place that was privacy preserving. Our lawyers wrote the privacy policy and we got another lawyer to redo our privacy policy to actually match what the technical controls are. In fact, this is in contradiction to your belief that we are run by marketing/business people. We paid way more attention to the technology than we did the legalese. Was this a mistake in hindsight? Sure. You can see evidence that we are technical people by reviewing our whitepaper [skiff.com/whitepaper](http://skiff.com/whitepaper) and watching our recent conference talk at [BSidesSF 2023](https://www.youtube.com/watch?v=Xr6yOTGXZf8).

> Next is the choice to HQ in the U.S., subject to secret court orders to hand over keys and back doors, and subject to penalty if informing users that this is happening. You could have incorporated in Panama like NordVPN, or anywhere in Europe where the legal process is more transparent for users. The argument that because BitWarden made a poor choice and people still use it, you too can make the same poor choice, is not a good argument.

We are never going to come to an agreement on this and has been hashed multiple times above. So, I’m just going to say we should agree to disagree on these points.

> Next is the App. You’re saying, “here’s our product that is private unlike Google, now go download it from Google so they can track you in FireBase etc.” Again, if the people running the company were truly passionate about privacy, there would be an APK download on the website or on GitHub or F-Droid, and it wouldn’t contain any trackers or dependence on Google.

We do offer direct download to users who request it and we’ll provide them a link to our Github to download. We are working on stronger support for push notifications outside of google’s ecosystem before publicly advertising it because of the subpar experience. Firebase is used for push notifications. Note that all the tracking in the Firebase APK is off. However, we understand the concern and are working towards moving off of Google’s push notification system. We do have to be practical when a vast majority of users use Google Play Services that our _initial_ focus will be where a majority of users are.

> Next, transparency. I can’t find information anywhere on your website where you are located or who is behind the company. Contrast that with Tuta where there are names and pictures of staff, and the company address.

This is being worked on. Again, we are a bunch of engineers and designers not business people and marketers so we didn’t initially understand the value of an About Us page for some time until we hear this feedback from our users. As builders, we just wanted to focus on building the best product out there. We’ve heard this feedback and should have something published soon (likely sometime this summer at the latest but hopefully earlier).

> You also do not have a transparency report to inform users about how many times law enforcement has contacted you and how many times you’ve handed over user data.

This is a fair criticism. We don’t have this today. Again, our focus is building the strongest technical controls that this isn’t an issue because we won’t have any relevant data to hand over. It is something we want to do and we should do in the future.

> And no independent audits that prove your product is delivering what it is promising?

We do yearly audits. The last few years was done by Trail of Bits. Feel free to contact them to verify that. This year we are scheduled to be audited by Cure53. I am very much looking forward to our external audits so that we can continue building the best product out there. We don’t use second rate firms on this that so many other firms do so that we can check a box.

> Best case scenario is that Skiff is run by marketing / business people

I really don’t understand how you could have arrived at this conclusion. If we were a bunch of marketing and business people, we would have focused on all the things you said and wouldn’t have built the best in class technical controls that we already have today because we’d be so focused on marketing without actually working towards building the best product.

> who want to cash in on the privacy market and otherwise have little understanding and concern for privacy.

The privacy market as a whole isn’t proven to be extremely lucrative. Look at the number of commercially successful companies in the privacy space versus those that make money off of ads. If I was personally trying to cash in, I’d be working at a FAANG company trying to cash in or working in some other space. There’s so many easier ways to cash in than building in the privacy space.

I feel like these are just personal attacks because you have some sort of beef because we haven’t done things perfectly and refuse to accept that as a young startup, we have to absolutely fight for our survival while also combatting cynicism from those in the privacy community who get upset someone is trying to build a better product for them.

It would be great if we can continue to continue this dialogue in a constructive manner. Are there features or other things that are missing? We are open to the feedback as shown above countless times.

---

## Post 165 by @moonwriting — 2023-05-11T16:29:15Z

Can you explain why your app uses trackers including one from Facebook and requires many more permissions than your competitors?

This is the current situation at least with the Android apps: Tutanota: 0 trackers, 11 permissions. Proton Mail: 0 trackers, 14 permissions. Skiff Mail: 2 trackers, 29 permissions.

---

## Post 166 by @pusrsc — 2023-05-11T16:53:28Z

Thank you for taking the time to respond to my feedback. I will attempt to put on my ‘good faith hat’ as I read it and respond to your points.

I think the ‘cynicism’ that you feel from people is actually exacerbation over waiting for someone to come along and ‘get it right, and to then discover Skiff making some very questionable choices, that privacy conscious users have long understood to be antithetical to good practices. Like with location, transparency and the privacy policy.

I am having trouble with the scenario of privacy conscious engineers letting lawyers cook up privacy policy legalize, unaware of what the company they work for does.

But okay, let me ask you this: When the lawyers messed up and put all that stuff about collecting IP Address, Mac Address, Cookie Identifiers, Mobile Carrier (Cell Phone Provider), User Settings and Browser or Device Information. Did you ACTUALLY collect any of this data, or was is just a Privacy Policy mistake?

> We do offer direct download to users who request it and we’ll provide them a link to our Github to download.

Can you please make it public for everyone? Would it be possible to get the apps not requiring notifications on F-droid, which already hosts apps that have their own independent notification system?

> We do yearly audits. The last few years was done by Trail of Bits.

Where is it located? Can you please make it easier to find that stuff?

> I really don’t understand how you could have arrived at this conclusion.

Respectfully, I am equally confounded how you can believe yourself and your product to be privacy oriented when you HQ in an eyes country that can legally force Skiff to install backdoors for harvesting unencrypted user data, which Skiff cannot legally inform its customers about.

I believe the even bigger issue is your view that it is not a deal breaker and that your US location isn’t a potential problem. If your view is that we just have to “agree to disagree,” then you’re not speaking the same language, or even living in the same universe as some of your customers.

> I’m just going to say we should agree to disagree on these points.

That is a super dangerous statement right there.

---

## Post 167 by @amilich — 2023-05-11T18:12:18Z

Wow, this is an incredibly disappointing comment to read. We’ve reviewed every single sentence in your post publicly multiple times. The Ghacks article you cite literally has a correction at the top for being incorrect. It’s full of misinformation.

We’ve _never_ used trackers. Never using Firebase analytics, Facebook trackers, or anything else. We use Firebase for push notifications, which Signal even used until a recent release [Messenger Signal: Google-Firebase-Analytics-Tracker • Kuketz IT-Security Blog](https://www.kuketz-blog.de/messenger-signal-google-firebase-analytics-tracker/). We’ve also published an APK for users who don’t use Google Play.

On transparency, this is completely wrong. I’ve publicly and personally commented on almost every single discussion with my full name: [https://twitter.com/milichab](https://twitter.com/milichab), [Reddit - The heart of the internet](https://www.reddit.com/r/skiff), Discord, LinkedIn, etc. We are _extremely transparent_. Check out our blog, where all of our team members are also listed: [Skiff - Private, encrypted, secure email - 10 GB free](https://skiff.com/blog).

I disagree on the point about the US completely. The EU and UK have far more concerning proposals regarding end-to-end encryption right now. How could you deny or reject that? What happened to Tutanota in Germany is not speculation. What “could” happen to us is speculation not based on any legal fact. I don’t see BitWarden, Brave, Signal, or other privacy apps as having made a “wrong choice.” Quite the opposite.

On law enforcement, we have _less_ information available than recommended software. We don’t collect IP logs of visits. Why would refute this point with speculation?

“No independent audits” suggests you haven’t even read the thread above. I’d argue we’ve undergone more scrupulous auditing than many of the products on PrivacyGuides: Two from Trail of Bits, and a third from a Mozilla auditor.

Anyway, we’ve spent enough time on this thread dealing with disinformation, lies, and circular arguments. I love privacy and the privacy community, but it’s seeming clear that we moved far beyond anything productive - feature suggestions, security questions, etc - into speculation and wasting time.

Note that we started this thread after we went through the PrivacyGuides criteria for email providers, three independent audits, recommendations in other privacy guides and lists, and more. It’s disappointing to see this thread reject well-made, generous, and truly private software.

---

## Post 168 by @amilich — 2023-05-11T18:13:54Z

We never collected any of the data mentioned. In fact, the article literally has a clarification at the top explaining this.

Skiff started as a few engineers who loved privacy building products. We’ve now become a real company with almost a million users. It’s shocking to see the bad faith in the entire community.

BTW, the US CANNOT force tech companies to install backdoors. There is absolutely no precedent to this, we’ve quite literally asked multiple legal teams - including the team that defended Apple against the FBI - about this, and so it’s completely wrong to say it here.

I don’t “agree to disagree” - a lot of what’s above is just wrong.

---

## Post 169 by @amilich — 2023-05-11T18:14:24Z

We’ve published an APK for people to download without the Play Store, but notifications don’t work. That should address other concerns on this thread as well.

---

## Post 170 by @moonwriting — 2023-05-11T18:52:38Z

> [@amilich](#):
>
> We’ve _never_ used trackers. Never using Firebase analytics, Facebook trackers, or anything else.

If this is true, then how do you explain [this εxodus report](https://reports.exodus-privacy.eu.org/en/reports/com.skemailmobileapp/latest/)? If you aren’t using these analytics tools, they why they have been listed there? Also, I would still like to know your justification for your permission requirements. Currently, your app needs more than double compared to Proton or Tutanota. Why is that?

---

## Post 171 by @pusrsc — 2023-05-11T20:00:50Z

> We’ve also published an APK for users who don’t use Google Play.

> We’ve published an APK for people to download without the Play Store, but notifications don’t work. That should address other concerns on this thread as well.

Okay. Please share the link. It is not publicly available on GitHub right now.

> On transparency, this is completely wrong. I’ve publicly and personally commented on almost every single discussion with my full name: twitter com/milichab, reddit com/r/skiff, Discord, LinkedIn, etc. We are _extremely transparent_ . Check out our blog, where all of our team members are also listed: [Skiff – Updates](skiff com/blog).

Andrew, I don’t think you’re being fair here. I’m talking about your website, and it is not reasonable to expect that I go hide-and-seek across Twitter, Reddit, Discord, LinkedIn and hundreds of blog pages to find something that should be on [skiff.com/about:](http://skiff.com/about:)

1. Location of the company
2. People in charge of company - CEO, CTO and COO.

> We do yearly audits. The last few years was done by Trail of Bits.

Please provide link.

> I disagree on the point about the US completely. The EU and UK have far more concerning proposals regarding end-to-end encryption right now. How could you deny or reject that? What happened to Tutanota in Germany is not speculation. What “could” happen to us is speculation not based on any legal fact. I don’t see BitWarden, Brave, Signal, or other privacy apps as having made a “wrong choice.” Quite the opposite.

> BTW, the US CANNOT force tech companies to install backdoors. There is absolutely no precedent to this, we’ve quite literally asked multiple legal teams - including the team that defended Apple against the FBI - about this, and so it’s completely wrong to say it here.

It happened with Lavabit. It almost happened with Apple. Probably only went public because of them being Apple. Would have been forced to hand over keys if it went through federal court. Also, the point of secret courts is that they are secret. Isn’t that something you worry about just a little?

Aside from that, it would be helpful for me personally, if Skiff could please:

1. Publish transparency report link on front page of main website.
2. Add option to download APK on download page.
3. Add link to audit, perhaps next to whitepaper on front page.
4. Create ‘about’ page with information about company and leadership.
5. Clean up privacy policy and TOS even more.
6. Publish all apps on F-Droid.

Thanks again for your time.

---

## Post 172 by @amilich — 2023-05-11T21:53:25Z

We’re working on the About us page right now. I completely agree it needs to be there - we aren’t hiding anything about us or the company! We just rebuilt the site in March and haven’t added it yet. That’s a great expectation for a privacy-first service to have, and I don’t disagree with it at all.

I hope we can have this page out in the next week.

I don’t think the Lavabit case is representative; the Apple case and Signal’s legal work seems far more relevant. BTW, we’ve spoken to legal teams about the Lavabit case, and many of the issues were legal blunders that they made that turned into contempt cases - that was what prompted the company to shut down ([https://www.washingtonpost.com/news/volokh-conspiracy/wp/2014/04/16/fourth-circuit-affirms-lavabit-contempt-finding/](https://www.washingtonpost.com/news/volokh-conspiracy/wp/2014/04/16/fourth-circuit-affirms-lavabit-contempt-finding/)).

Anyway:

1. We can add an About Us page in the next week with much more information
2. Add a transparency page on the data that could be shared with law enforcement
3. Link to [GitHub - trailofbits/publications: Publications from Trail of Bits](https://github.com/trailofbits/publications) - noting the 2 audits
4. The APK is in our public GitHub, but notifications don’t work, so we don’t default to it

I’m not sure what the issues are in the TOS or privacy policy. As I wrote above, I actually think we collect less information than some other recommended email/collaboration/file storage services.

---

## Post 173 by @amilich — 2023-05-11T21:55:58Z

Yes. Flipper is a debugging tool that is unused in production builds but included in the APK. We simply have to add the configuration to stop it from being bundled. Unfortunately, it is added as a debugging tool in React Native by default: [React Native Support | Flipper](https://fbflipper.com/docs/features/react-native/) (edit - adding code reference: [GitHub - facebook/flipper: A desktop debugging platform for mobile developers.](https://github.com/facebook/flipper); note Flipper is completely open-source and _not_ an analytics platform, and it’s also unused in the Skiff Mail app).

Firebase, as I wrote above, is used to send Push notifications, which Signal used to use. There are pros/cons of different push notification services, but we _do not_ use Firebase analytics. That’s quite clear from our Privacy Policy as well.

Exodus does not report on any running code, network activity, or anything else - just the class names it can find in the bundle.

What permissions are you particularly looking at?

Fingerprint/biometric have been added to prepare for hardware key/biometric usage, which we rolled out. App badge, wifi state, network state, vibrate, and settings seem to be for basic app setup.

---

## Post 174 by @anon31041004 — 2023-05-12T02:25:46Z

Do you have plan for publishing the apps on F-droid ? At least provide the download link for apk in this page : [Download - Read more](https://skiff.com/download)

---

## Post 175 by @amilich — 2023-05-12T03:58:56Z

We do plan to. We have not today because of the issue I wrote above, which is that notifications don’t work. I think that makes it really hard to use our apps as an email provider. For most users, using the web app as a PWA will be a better option because Skiff Mail works with browser notifications. The APK is here: [GitHub - skiff-org/skiff-org.github.io: Skiff releases, APKs, desktop apps, and whitepaper.](https://github.com/skiff-org/skiff-org.github.io).

We might add it to the downloads page but I still think using browser-based is as good an alternative for people with degoogled phones. What do you think of that option?

---

## Post 176 by @anon31041004 — 2023-05-12T06:54:49Z

You can check notifications periodically (for example every 10 minutes) in the background. It won’t drain much battery.

However, I do understand that some users may find the lack of push notifications to be a significant inconvenience.

Additionally, some users may prefer using the app over the PWA because of certain advantages that apps offer, such as better offline functionality and tighter integration with the operating system. This may be especially important for users who rely heavily on email for work or other important tasks.

---

## Post 177 by @anon31041004 — 2023-05-12T07:05:44Z

Here’s the direct link to apk :

[https://github.com/skiff-org/skiff-org.github.io/raw/main/assets/apk/Skiff%20Mail%20-%20v39.0.0.apk](https://github.com/skiff-org/skiff-org.github.io/raw/main/assets/apk/Skiff%20Mail%20-%20v39.0.0.apk)

---

## Post 178 by @amilich — 2023-05-12T21:38:11Z

That’s a good point. That would probably work alright. Offline mode will work on the native app or APK, even without Firebase for push.

---

## Post 179 by @amilich — 2023-05-12T21:38:22Z

Note that we do update the version numbers and version 41 will be latest shortly.

---

## Post 180 by @anon31041004 — 2023-05-13T03:49:59Z

Trying to create an account over tor:

 ![SmartSelect_20230513-093621_Tor Browser](//forum-uploads.privacyguidesusercontent.com/original/2X/6/65d5a7163f4f1321f5fccc5a56a841620060d0ed.jpeg)

Captcha isn’t loading even after allowing it.

Also Skiff takes longer time to load over Tor than any other providers.

I think Skiff should be optimized for networks like Tor , I2P and Lokinet.

---

## Post 181 by @amilich — 2023-05-13T05:53:57Z

We do have Tor/Lokinet users - I’m not sure what’s wrong here, but login and using the app should be fine. It’s possible that depending on the exit node, the traffic is being regarded as more or less suspicious by hcaptcha.

---

## Post 182 by @amilich — 2023-05-14T06:34:22Z

More updates:

- We’re adding an “About us” page now
- We’ve revised our privacy policy to reflect that no data is collected from [app.skiff.com](http://app.skiff.com), and only Matomo is used on [skiff.com](http://skiff.com)
- We added bulk export to any inbox, built right into the app (there’s no separate “export” app you have to install)
- The Android APK is publicly available on our GitHub

Anything else? @jonah or maybe @dngray please let me know. We’d love to be listed, but the changes have also improved our product a lot so thanks for that help.

---

## Post 183 by @anon31041004 — 2023-05-14T15:57:51Z

Awesome ! Thanks for listening to our feedbacks.

---

## Post 184 by @amilich — 2023-05-15T18:15:48Z

Another big update: The Skiff Windows app is out today, and it’s completely open-source.

[skiff.com/downloads](http://skiff.com/downloads)

> **[GitHub - skiff-org/skiff-windows-app: Skiff's Windows app for privacy-first, end-to-end...](https://github.com/skiff-org/skiff-windows-app)**
>
> Skiff's Windows app for privacy-first, end-to-end encrypted Mail, Drive, Calendar, and Pages.

---

## Post 185 by @amilich — 2023-05-19T02:39:03Z

Any other feedback or progress on the pull request?

---

## Post 186 by @dngray — 2023-05-21T15:26:45Z

I don’t think a [“web view”](https://github.com/skiff-org/skiff-windows-app/blob/884418fa414ee3a60cbc4681f56ccdaf7cafb33d/skiffWindowsApp/Skiff%20Desktop/MainWindow.xaml.cs#L25) is really what people mean when they mean open source.

I would be keen to see [`../../libs/skiff-crypto`](https://github.com/skiff-org/skiff-mail/blob/2986073f1983a8505273580a489551bc1aa28e71/skiff-mail-web/tsconfig.json#L23) though .

---

## Post 187 by @amilich — 2023-05-23T15:55:09Z

I completely, completely disagree. It’s quite important to know what code you are running in a native app. Running a WebView is much safer than running an Electron app ([https://www.cvedetails.com/vulnerability-list/vendor\_id-17824/product\_id-44696/Electronjs-Electron.html](https://www.cvedetails.com/vulnerability-list/vendor_id-17824/product_id-44696/Electronjs-Electron.html) - these are only OPEN CVEs), or a poorly built native app.

I think the message that using a WebView as a core web component is bad is completely the opposite of what our security engineers and reviewers believe.

Skiff-crypto is here: [GitHub - skiff-org/typed-envelopes: Typed AEAD Envelopes](https://github.com/skiff-org/typed-envelopes).

---

## Post 188 by @amilich — 2023-05-23T15:56:06Z

FYI, we released [Skiff –&nbsp;About us - Read more](https://skiff.com/about-us) and [Skiff –&nbsp;Transparency - Read more](https://skiff.com/transparency).

---

## Post 189 by @amilich — 2023-05-23T16:36:02Z

I’ve just published `skiff-crypto` directly in the `skiff-mail` repo: [GitHub - skiff-org/skiff-apps: Privacy-first, end-to-end encrypted Mail, Pages, Drive, and Calendar.](https://github.com/skiff-org/skiff-mail).

Any other feedback for us? At this point, I’m pretty much at a loss as to why we’ve continued to be treated with hostility on the forum, when we’ve gone above and beyond to satisfy all criteria, adapt our product based on feedback, and work on our entire brand and public presence based on feedback.

Are the criteria you’ve set genuine? Do you have any real feedback for us? We’ve had a ton of organic adoption and support, so it’s continued to be so puzzling to see this hostility.

---

## Post 190 by @anonymous53 — 2023-05-23T17:39:36Z

Hi, I’m a lay user, not a technical one. I have read all the discussion and find it sincere, serious and useful, without hostility.

As a lay user I was unable to find the external audit report on the GitHub link.

> [@pusrsc](#):
>
> Add link to audit, perhaps next to whitepaper on front page.

> [@amilich](#):
>
> [GitHub - trailofbits/publications: Publications from Trail of Bits](https://github.com/trailofbits/publications)

Perhaps the encouragement among those involved in the debate will diminish by pointing out the exact link in the document. This is a request that has been made many times.

I share the questions raised by other people in this discussion, and as a user of Skiff, the behavior of the company on this topic, at times, created me suspicions.

I would also like clarification on Sendgrid links in the email received after creating an account. It was an unpleasant first experience to see a link in the body of the email and another when passing the mouse over.

A request as a user: about how the external content proxy works in the email. It can be a useful addition. I couldn’t find enough information.

I thank Skiff members for improving the product.

I would also like to request the site in Spanish and Portuguese, it has been difficult to recommend the product to colleagues and family members when faced with a site only in English, even if the browser used indicates one of the languages mentioned above.

---

## Post 191 by @amilich — 2023-05-23T17:56:02Z

Thanks for checking on this, it’s really helpful! Couple notes:

- We haven’t published the full audit report. This is consistent in the industry - for example, Proton Mail does not publish full audit reports, but documentation that the audit was complete. This is exactly what we’ve done as well.
- We’re using Sendgrid to unsubscribe from the product updates right now. We’re actually switching it to an in-app toggle button this week.
- I know we need many more languages - it takes a lot of time, but we are committed to doing it soon.
- Anything in particular you are wondering about external content proxying? You can see it via network requests, but happy to ask our engineering team.

We are committed to making Skiff the best and most private email provider. I completely understand the frustration above creates more tension in this discussion than is necessary. The frustration on our part is not from the feedback - that part we benefit a lot from and can improve. The frustration comes from misleading or incorrect criteria. Check out the first post, where we actually went from this GitHub discussion ([https://github.com/privacyguides/privacyguides.org/discussions/1363](https://github.com/privacyguides/privacyguides.org/discussions/1363)) to make a ton of improvements to be ready for PrivacyGuides because it’s very reputable.

So, after a year of making improvements and satisfying the criteria, it’s demoralizing to feel like the criteria change on every post, or that we are treated with different criteria (check out one comment on [Notesnook (Evernote Alternative) - #46 by TorLover9](https://discuss.privacyguides.net/t/notesnook-evernote-alternative/174/46) as an example). We have been coming at every conversation with good faith, but it takes so much time to deal with changing criteria or assumptions of bad faith.

---

## Post 192 by @anon46880256 — 2023-05-23T18:23:55Z

> [@amilich](#):
>
> Proton Mail does not publish full audit reports

I’m seeing links to audit reports on [An Open Source Privacy Company | Proton](https://proton.me/community/open-source)

---

## Post 193 by @anonymous53 — 2023-05-23T18:35:47Z

### Privacy[¶](https://www.privacyguides.org/en/email/#privacy)

We prefer our recommended providers to collect as little data as possible.

**Minimum to Qualify:**  
…

- _Must not be hosted in the US due to_ [ECPA](https://en.wikipedia.org/wiki/Electronic_Communications_Privacy_Act#Criticism) which has [yet to be reformed](https://epic.org/ecpa/).

> [@nishil](#):
>
> [NO] ​Must not be hosted in the US due to ECPA which has yet to be reformed

As soon as possible I describe my doubts better. Thank you so much!

---

## Post 194 by @ph00lt0 — 2023-05-23T19:00:42Z

Perhaps criteria should be called minimum to qualify to avoid this confusion.

Skiff introduced a lot of new questions that were never an issue before, because others did already what we like to see or now do.

I can get the frustration from Skiffs team in spending a lot of time and still not getting listed.

The main requirement for listing is basically that it is the best option or equally as good. So Skiff got themselves in a competition with Tutanota and Proton which are highly dedicated companies who have been working on email security and privacy for a long time. Something that is hard to meet. Especially when using third parties for quite many things as we have seen in the above discussion.

The community here will keep comparing Skiff and hold them to the standards set by those two players because they are leading in this field. Anything Skiff does different that, we deem worse for privacy will therefore be an issue. There are many tools on the website that are not perfect, I name drop Nextcloud, which wouldn’t be listed if more profound options would be available. When this changes this also lifts the bar for them. Criteria are just a written out thing right now to explain why some thing didn’t get listed and others did. So yes this is very dynamic.

This is what I have been trying to explain many times to Skiff but the responses haven’t been understanding so far. I don’t easily give up.

---

## Post 195 by @sierra6 — 2023-05-23T19:52:04Z

I am new to the privacy space and have no technical background so most of what is discussed in this thread is over my head. I do appreciate the feedback from the forum members and the response from Andrew, it does appear both are operating in good faith.

Right now I am exploring my options for what I consider phase 1, getting away from Google/Microsoft. This means looking at an all in one solution like Proton Unlimited or piecing together a combination of Mullvad VPN + Skiff + ??. My plan is to use the free options of each for a few months to see which I like best from a user perspective and also learn more about each from the privacy perspective. This forum has been helpful for that. (I realize there are more advanced options including self hosting but that is something I plan on looking at down the road, baby steps)

I did have 2 questions about Skiff, either for Andrew or maybe a forum member could answer.

1. Can Skiff see the contents of my emails or files uploaded/saved to the drive? My threat level is minimal, just an average citizen who would like to keep his personal records secure and private.

2. My second question was about Firebase and Facebook flipper but see that those were addressed above. Runner up question, does Skiff track or keep logs of my location, IP address, or any other metadata that can be sold to brokers?

Sorry for the rookie questions but it would help me and possibly anyone else in my shoes who lurks this forum.

---

## Post 196 by @amilich — 2023-05-23T19:55:17Z

I totally understand. What area do you think is insufficient so far? I disagree that our responses haven’t been understanding - we’ve made a ton of updates and clarifications at every step on the thread.

---

## Post 197 by @amilich — 2023-05-23T19:56:43Z

1. No - nothing at all. Even file types are E2EE - plus folder names, all file/folder contents, Skiff Pages contents, and much more. See [Skiff –&nbsp;Transparency - Read more](https://skiff.com/transparency).
2. No. No IP address collection, no location collection, no metadata collection, and data is NEVER sold or shared. We’re removing the records of any Firebase/Flipper code, but they are both completely unused.

One other note: I was reviewing tests on Internet.nl, which seem to be used on other forums and threads.

Skiff: [Website test: skiff.com](https://internet.nl/site/skiff.com/2106387/#) (97%)  
[Mailbox.org](http://Mailbox.org): [Website test: mailbox.org](https://internet.nl/site/mailbox.org/2106390/) (89%)  
Proton: [Website test: proton.me](https://internet.nl/site/proton.me/2106388/) (66%)

Anyway, I would like to know what more people are looking for!

---

## Post 198 by @amilich — 2023-05-23T19:57:59Z

Also, what third parties are you referring to? I don’t think we do, at all. The only ones mentioned in this thread are:

- Cloudflare + Hcaptcha for DDOS/bot protection - standard practice.
- Zendesk for customer support - quite common.
- Sendgrid for unsubscribe lists - this is changing to in-app today, but hasn’t been a big concern?

---

## Post 199 by @anon31041004 — 2023-05-23T23:53:16Z

Isn’t Cloudflare only used for [skiff.com](http://skiff.com) ?

---

## Post 200 by @amilich — 2023-05-24T01:24:21Z

Cloudflare is not an analytics tool, it is a security, infrastructure, and CDN product and is used in that capacity.

---

## Post 201 by @ph00lt0 — 2023-05-24T07:36:53Z

I am postive about your replies this time @amilich

> [@amilich](#):
>
> - Cloudflare + Hcaptcha for DDOS/bot protection - standard practice.
> - Zendesk for customer support - quite common.

These two are also used by Proton at least (hcaptcha and Zendesk).

I know you don’t agree with me on this one. But I suggest you still:

- Get rid of the marketing company used for dmarc violation monitoring
- Update your articles on the website and ask for advice from someone that actually understands GDPR. (seek out to [IAPP](https://iapp.org/) i.e.) I won’t be too harsh on this any longer, proton lately has also shown incomptetences when it comes to writing factual articles for marketing. It just does not look good on you.
- Remove the outdaded ECDHE-ARIA256-GCM-SHA384 cipher support from [inbound-smtp.skiff.com](http://inbound-smtp.skiff.com). (yes tutanota still has AES256-GCM-SHA384 and also should be phased out.)
- Remove DH-2048 as key exchange parameter from [inbound-smtp.skiff.com](http://inbound-smtp.skiff.com) use `secp384r1` , `secp256r1` , `x448` , or `x25519` `secp384r1` , `secp256r1` , `x448` , or `x25519` instead.
- And I still hope although doubt you will: stop sending product updates to people who never signed up for it. I understand this has implications but that’s the consequence I think you should take. GDPR here in EU required many to drop sending marketing emails and companies have to collect consent ethically on beforehand. I don’t think this should be different for you.

---

## Post 202 by @ph00lt0 — 2023-05-24T14:17:25Z

> [@amilich](#):
>
> One other note: I was reviewing tests on Internet.nl, which seem to be used on other forums and threads.
> 
> Skiff: [Website test: skiff.com](https://internet.nl/site/skiff.com/2106387/#) (97%)

Realized I should have replied to this also. This is indeed a good place to test and I would recommend to so so, however you now used the test for the website, not for email :wink: . Although surely both are relevant to you. The percentages are also a bit misleading and I don’t like them all too much cuz internet.nl values the usage of ipv6 very highly. If you do not support it it’s not so significant for security and privacy. Just focus on getting the rest all green like for [proton.me](https://internet.nl/mail/proton.me/934183/) unlike [Skiff](https://internet.nl/mail/skiff.com/934188/).

---

## Post 203 by @amilich — 2023-05-24T19:15:33Z

Fair points. Definitely still things to improve. But, isn’t Skiff at 85% vs. [proton.me](http://proton.me) at 75%?

---

## Post 204 by @amilich — 2023-05-24T19:17:34Z

I completely understand the marketing articles issues you cited. This is a weakness for most companies overall and is below our standards. I will see what we can do, but please know for sure that the marketing writers are not the ones writing or determining any policies - they are tasked with making complex topics digestible.

I will see what we can do on ciphers.

We did change the policy for marketing/product updates, and we added a setting in-app to fully opt-out as well! That should have been clarified above a few times as well. You can go to settings → notifications and toggle off.

I can also see what we can do on the dmarc policy monitoring. I think this point is still debatable because dmarc violation uses public data, but it is worth a conversation.

Overall, thank you for taking the time to help us out! This thread has inspired a ton of technical changes on our team, as well as many upcoming positive updates - and even hiring a new team member.

---

## Post 205 by @jonah — 2023-05-24T23:28:16Z

> [@anonymous53](#):
>
> - _Must not be hosted in the US due to_ [ECPA](https://en.wikipedia.org/wiki/Electronic_Communications_Privacy_Act#Criticism) which has [yet to be reformed](https://epic.org/ecpa/).

I’m going to propose removing this criteria. The criticism of the ECPA is that it doesn’t protect email communications _enough_, but we already consider unencrypted communications stored with service providers to be unprotected anyways, so I’m not sure why we care whether the ECPA protects emails stored on a remote server or not. With mandatory zero-knowledge encryption, we don’t have to rely on laws protecting that data.

> <https://github.com/privacyguides/privacyguides.org/pull/2169>
>
> Changes proposed in this PR:
> 
> - Remove criteria which states that email provid…ers must be hosted outside the US.
> 
> This is discussed somewhat in https://discuss.privacyguides.net/t/skiff-mail-email-provider/11411. It's also [unclear](https://epic.org/ecpa/) whether the ECPA actually applies to emails anyways, I'm not aware of it being used in any relevant privacy attacks by the government...
> 
> The way this criteria is currently worded also makes it sound like the ECPA is a *bad* thing, in fact it would be *good* if the protections within the ECPA applied to email, but this has not been conclusively tested in case law. Worst case scenario it doesn't apply, and I'm not sure how that makes the US worse than anywhere else; best case scenario the protections within the ECPA *do* apply, which would actually be bonus points for the US.
> 
> Anyways, because we now require zero-knowledge encryption for all providers, I'm not really convinced that jurisdiction issues play a super huge part in what we should be listing 🤷‍♂️ 
> 
> https://epic.org/ecpa/
> 
> 
> 
> 
> - [x] I have disclosed any relevant conflicts of interest in my post.
> - [x] I agree to grant Privacy Guides a perpetual, worldwide, non-exclusive, transferable, royalty-free, irrevocable license with the right to sublicense such rights through multiple tiers of sublicensees, to reproduce, modify, display, perform, relicense, and distribute my contribution as part of this project.
> - [x] I am the sole author of this work. 
> - [x] I agree to the [Community Code of Conduct](https://www.privacyguides.org/en/code_of_conduct/).

---

## Post 206 by @anon30510143 — 2023-05-24T23:49:49Z

yes fully agree.

---

## Post 207 by @dngray — 2023-05-25T05:36:15Z

> [@jonah](#):
>
> I’m going to propose removing this criteria. The criticism of the ECPA is that it doesn’t protect email communications _enough_, but we already consider unencrypted communications stored with service providers to be unprotected anyways, so I’m not sure why we care whether the ECPA protects emails stored on a remote server or not.

Yes, this is from before we had a requirement that all providers must be zero knowledge. It’s also why I put in [Remove Startmail, as it's not zero-knowledge by dngray · Pull Request #2166 · privacyguides/privacyguides.org · GitHub](https://github.com/privacyguides/privacyguides.org/pull/2166)

---

## Post 208 by @Ganther — 2023-05-26T11:26:02Z

> [@amilich](#):
>
> Overall, thank you for taking the time to help us out! This thread has inspired a ton of technical changes on our team, as well as many upcoming positive updates - and even hiring a new team member.

One minor question. I can’t find anything about your site about what a “short alias” is. Everything else on your “Pricing” page is pretty self explanatory. I don’t suppose you could put a question mark that shows a hover with some info or something like that?

---

## Post 209 by @amilich — 2023-05-26T16:37:48Z

Good idea, can do that. It’s a 4-5 character alias (like [john@skiff.com](mailto:john@skiff.com)). Those aliases are much more sought after, so we don’t want them to just go to bots or people who might try to resell them!

---

## Post 211 by @anon30510143 — 2023-05-26T20:41:04Z

There’s already a PR on GitHub to add it:

> <https://github.com/privacyguides/privacyguides.org/pull/2108>
>
> Changes proposed in this PR:
> 
> - Recommend Skiff Mail
> 
> ~~Obviously they don't… meet our criteria yet, so this is waiting on the changes from https://discuss.privacyguides.net/t/skiff-mail-email-provider/11411/111, but I think those will eventually be made so I'll get started on writing this now.~~
> 
> 
> 
> 
> - [x] I have disclosed any relevant conflicts of interest in my post.
> - [x] I agree to grant Privacy Guides a perpetual, worldwide, non-exclusive, transferable, royalty-free, irrevocable license with the right to sublicense such rights through multiple tiers of sublicensees, to reproduce, modify, display, perform, relicense, and distribute my contribution as part of this project.
> - [x] I am the sole author of this work. 
> - [x] I agree to the [Community Code of Conduct](https://www.privacyguides.org/en/code_of_conduct/).

---

## Post 212 by @Equinox — 2023-05-26T20:44:14Z

I appreciate your feedback on this, didn’t know it was already on the pull-request in GitHub, great to hear that! :tada:

---

## Post 213 by @amilich — 2023-05-27T00:35:36Z

I do think we meet the criteria now… anything else you want us to post or clarify? We’ve fixed the marketing email issues (see screenshot).

We also put up an annotated security model to make it more easily digestible: [Skiff –&nbsp;Security Whitepaper - Read more](https://skiff.com/security-model) and are working on a lot more documentation.

 ![Screenshot 2023-05-26 at 5.34.47 PM](//forum-uploads.privacyguidesusercontent.com/original/2X/9/9442200d3c3d1265c11466178d76dbbf4a0fb1de.png)

---

## Post 214 by @anonymous53 — 2023-05-27T02:35:14Z

English is not my native language. Therefore, if my speech seems aggressive, arrogant, or obscure, I ask you to forgive me.

> [@amilich](#):
>
> We’re using Sendgrid to unsubscribe from the product updates right now.

When I created the account I received the marketing emails containing what I believe are tracking links from Sendgrid. This frightened me, because my own private and secure encrypted email provider, at first contact, sent me a marketing with opening-click tracking.

For me, it is “okay” to receive marketing about the product, as long as my click IS NOT tracked in any way.

See, the product offers protection against tracking external content (image), but sent me a tracking “pixel”.

> [@amilich](#):
>
> Sendgrid for unsubscribe lists

> [@amilich](#):
>
> We’ve fixed the marketing email issues

I’ll check it out soon. In any case, in the first place, Skiff must ask for permission to send the marketing emails, rather than offering a opt-out option.

Preferably without suspicious link in the images, or overlapping some button related to another Skiff product, which is being shown within the email.

* * *

Another point I want to address is this tracking protection and blocking external content. I searched the site, despite this, I did not find enough information.

What happens when I activate the automatic loading of external content? What does the proxy protect me from, exactly? Does it take out tracking content, such as Proton, and hides my IP address? What security do I have when not blocking the loading of external content, when I received an image with tracking from Skiff?

> [@amilich](#):
>
> Anything in particular you are wondering about external content proxying? You can see it via network requests

I want to reiterate that I am a lay user, without technical knowledge, but concerned with security and privacy on the internet. Therefore, it is impossible for me to follow his advice, unfortunately. And I didn’t find any information accessible on the site about how this proxy works.

I did the research without being connected in an active session on my account in order to test what a possible future customer would see. But even in active session, when searching for the proxy, the information was insufficient for me.

As a customer, I would like to see something [similar to that](https://proton.me/pt-br/support/email-tracker-protection), direct information about how the resource works.

* * *

Finally, I [found this](https://skiff.com/have-i-been-hacked). How does it work? What data is sent - and where is it sent? What is the source of leaks? This resource needs transparency.

* * *

Finally, a possible request for appeal: Plans for universities, schools, non-profit institutions, and others.

I believe there is some potential for gain in this, whether it’s marketing, users, or money.

* * *

As a user, a remark. While the discussion here was useful for product improvement, manifestations like that in the Notesnook post can be harmful to the company’s image. I was able to read before she was hidden by moderation.

Andrew Milich, you did a good job of keeping this post alive. However, in the case of the Skiff Page, the requirement is simpler to be met - and simply was not, and the product could already be approved.

Other than that, I leave my thanks for the improvement in the product. I want there to be other private product options and Skiff has my vote in every way. Thank you for your willingness to improve the product by listening to feedback from members of this forum.

> [@jonah](#):
>
> I’m going to propose removing this criteria.

Given the removal of this criterion, with votes from other members of the Privacy Guides team, I believe there are few obstacles for Skiff Mail to finally be recommended as a private service. Good news! Good news!

---

## Post 215 by @amilich — 2023-05-27T03:33:10Z

Thanks for the detailed comment - a few clarifications:

- There is no auto opt-in. You’ll receive product updates to your newly created Skiff Mail inbox that are opt-out. This is standard for every email provider I have tested. The backup email updates have been changed to be opt-in. If you scroll up, we had fixed this for new accounts a few months ago, which was a good change.
- SendGrid rewrites images and link URLs but we never add tracking of any capacity. No image/link tracking has _ever_ been done.
- Yes, image proxying blocks your IP address and any other personal information, exactly how the Proton feature you linked to works. This is quite standard and important, or your IP could be shared with a third party.
- Blocking external content fully would shield the fact that the content - which could be an image, a GIF, a font, or a style sheet - was loaded at all. Often, loading an asset happens when opening an email, which makes this feature useful for hiding the fact that an email was opened.
- We actually do have a thorough blog on this: [Skiff - Private, encrypted, secure email - 10 GB free](https://skiff.com/blog/block-remote-content)
- The have-i-been-hacked page uses public breach data, mostly from [https://haveibeenpwned.com](https://haveibeenpwned.com). This was discussed on Twitter, and that site is an incredibly well respected resource among security researchers. No data from this page is ever collected or stored, which is clear in our privacy policy.
- We actually do have 50% discounts for students. We had this on our old website.

On Skiff Pages, I don’t know what you mean. Skiff has been audited 3 times and will be audited for a 4th time at some point in the next year. See: [Skiff –&nbsp;Transparency - Read more](https://skiff.com/transparency). I was responding to incorrect information that has always been incorrect. We did not launch our products without a complete security audit of our codebase, infrastructure, dev practices, and more. Given the customers we have, releasing an unaudited product would be against my personal ethics.

I think we are now the most viewed, most replied, and potentially the most voted-for thread on the forum - so I’m happy to keep clarifying any questions but also would like to know what impediments might exist!

---

## Post 216 by @anonymous53 — 2023-05-27T04:10:29Z

> [@amilich](#):
>
> We actually do have a thorough blog on this: [Block trackers and remote content on Skiff Mail - Read more](https://skiff.com/blog/block-remote-content)

That’s great!

> [@amilich](#):
>
> This is standard for every email provider I have tested.

> [@amilich](#):
>
> SendGrid rewrites images and link URLs but we never add tracking of any capacity. No image/link tracking has _ever_ been done.

No problem with the marketing email of the product itself, it was just an unpleasant surprise to pass the mouse to see another Skiff product and have “sendgrid click” with an extensive hash, etc.

It only happened in the Skiff and it was my first bad experience. I felt betrayed.

> [@amilich](#):
>
> he backup email updates have been changed to be opt-in.

I have been with the discussion since the first post. My account does not use backup email.

> [@amilich](#):
>
> The have-i-been-hacked page uses public breach data, mostly from [https://haveibeenpwned.com](https://haveibeenpwned.com). This was discussed on Twitter, and that site is an incredibly well respected resource among security researchers. No data from this page is ever collected or stored, which is clear in our privacy policy.

Perfect, perfect!  
It is valid to make a specific mention of this site feature in the privacy policy or on this same page, with this same explanation that you gave me. It is a shield of law that protects you.

> [@amilich](#):
>
> We actually do have 50% discounts for students. We had this on our old website.

I am thinking more about partnership with Universities and other institutions, something great. But, I believe this will come in the future, with the growth of the site and better location in other languages.

> [@amilich](#):
>
> On Skiff Pages, I don’t know what you mean.

> [@amilich](#):
>
> I was responding to incorrect information that has always been incorrect

I disagree with a few things, and consider that the comment on the Notesnook page was unpleasant and unnecessary. You are doing well here and the service is improving. About Skiff Pages, just one requirement - open source.

> [@amilich](#):
>
> Skiff has been audited 3 times and will be audited for a 4th time at some point in the next year.

```
Clients must be open-source.
Any cloud sync functionality must be E2EE.
Must support exporting documents into a standard format.
```

The audit is excellent. But the least is just open-source. I believe that Skiff Pages could have been being recommended long ago if it had been fulfilled.

Thanks for the answers, you have restored my trust in Skiff services.  
I will return to use and recommend the product among my partners.

---

## Post 217 by @amilich — 2023-05-27T04:18:27Z

Yes, I completely understand the open-source requirement. I think Skiff Pages will be open-source very soon. We fully open-sourced the editor here: [skiff-apps/libs/skiff-prosemirror at main · skiff-org/skiff-apps · GitHub](https://github.com/skiff-org/skiff-apps/tree/main/libs/skiff-prosemirror)

---

## Post 218 by @Sesifen — 2023-05-27T15:53:37Z

@amilich I’m currently switching from ProtonMail and looking for an alternative. What I’m looking for is an email service that cares enough to let me download Android app without the Google Play Store and receive notifications without the Google Play Services. So I want to ask if Skiff would work for me.

---

## Post 219 by @ch3k — 2023-05-27T18:41:17Z

On the topic of notifications, how are notifications currently handled on android? If using google’s push service, is google able to read the notifs? @amilich

---

## Post 220 by @moonwriting — 2023-05-27T20:23:02Z

Not sure about Skiff, but at least Tutanota checks both of your criteria.

---

## Post 221 by @privacy3765 — 2023-05-27T20:54:44Z

No notifications without google services for skiff and proton. Only Tutanota works.

---

## Post 222 by @amilich — 2023-05-28T06:27:35Z

This is something we hope to work on. You can download our APK from [skiff-org.github.io/assets/apk at main · skiff-org/skiff-org.github.io · GitHub](https://github.com/skiff-org/skiff-org.github.io/tree/main/assets/apk) (we need to update for the last 2 releases) but it does not have full notification support yet.

---

## Post 223 by @amilich — 2023-05-28T16:36:32Z

Note this is now up to date.

---

## Post 224 by @anon31041004 — 2023-05-28T22:33:16Z

v53.0 is a lot faster. Also thanks for adding support for multiple accounts.

---

## Post 225 by @amilich — 2023-05-28T23:38:51Z

That’s great to hear.

---

## Post 226 by @ch3k — 2023-05-29T15:07:18Z

@amilich do you guys have an endpoint for imap/smtp? I couldn’t get skiff to work with custom email clients

---

## Post 227 by @amilich — 2023-05-29T18:16:42Z

We don’t - because emails are end-to-end encrypted, we couldn’t easily expose and endpoint without having you run a bridge-type application.

If there are any specific features you want to see in the Skiff web or native clients, let me know.

---

## Post 228 by @InternetGhost — 2023-05-29T22:00:07Z

Would it be helpful to divide this discussion into two threads for Skiff Mail? One would be to discuss the actual requirements and track whether or how they are met. The other would be to talk about general feedback or questions.

It seems like a lot of the comments being made are concerns that don’t tie back to the requirements for being listed on Privacy Guides. As open as the Skiff team has been, I think it would be helpful for them to have clear communication on the requirements specifically and not have the thread bogged down with other criticism, valid or not. At the end of the day, all privacy tools have tradeoffs. That’s why the PG team has criteria to meet rather than weighing each tool on its own.

---

## Post 229 by @amilich — 2023-05-30T04:19:36Z

I completely agree.

I believe unequivocally that all the requirements are met. There are a few small good practice changes that could be made - such as tightening up some language in marketing articles, and the remaining points from the internet.nl discussion above, but they are shared by listed email services (Proton/Tuta). So, at this point, I don’t know what more is needed.

---

## Post 230 by @hrtang — 2023-05-30T23:19:50Z

I’ve been testing Skiff for quite some time now. And as @Equinox pointed out, I am really impressed by their willingness to keep improving. I am particularly impressed by how much they engage with their users and help them out in the Discord community.

I also don’t understand why this thread is being dragged out so much. If Skiff fulfills the criteria, adding them would only be beneficial for all people who care about privacy.

---

## Post 231 by @nishil — 2023-05-31T18:23:03Z

Hi @jonah and @dngray,

What can we do to help with the [open PR](https://github.com/privacyguides/privacyguides.org/pull/2108) to add [skiff.com](http://skiff.com) as an email provider? I believe all outstanding issues have been addressed. Please correct me if I am wrong here, and we’ll get it addressed.

We really appreciate all the honest feedback from you both and the overall community. It undoubtedly has made Skiff better. We have a few other updates in the coming future that I think will be widely appreciated.

We don’t believe that merging this PR will be the end of engaging with this community. We plan to remain active to stay close to our core users and making sure we are delivering a strong privacy product everyday.

If we agree that all criteria is met, can we merge the PR and open a new topic for ongoing discussion? (We think the ongoing conversations and feedback has been overall productive and we’d like to continue; however, I want to make sure that the core concerns related to listing are addressed.)

Thanks for the consideration!

---

## Post 232 by @amilich — 2023-06-01T17:54:43Z

Also, we’ve now open-sourced and published skiff-crypto and skiff-ui (MIT licensed)

> **[skiff-apps/libs/skiff-crypto at main · skiff-org/skiff-apps](https://github.com/skiff-org/skiff-apps/tree/main/libs/skiff-crypto)**
>
> Privacy-first, end-to-end encrypted Mail, Pages, Drive, and Calendar. - skiff-org/skiff-apps

> **[GitHub - skiff-org/skiff-ui: React components for the Skiff UI Design System](https://github.com/skiff-org/skiff-ui)**
>
> React components for the Skiff UI Design System

Really would appreciate some input from the PG team to understand what’s going on with the open PR.

---

## Post 233 by @anon31041004 — 2023-06-03T12:37:33Z

Wow ! Great Job Andrew :clap:

---

## Post 234 by @amilich — 2023-06-04T19:54:49Z

Hey all - want to keep this thread alive and still waiting on any updates to understand what’s going on. Here are a few more changes on the Skiff side

- Skiff Mail is now approved by Apple to be a default mail app on iOS - yet another vote of confidence. This took about a year to get through! Link here - [https://apps.apple.com/us/app/skiff-mail/id1619168801](https://apps.apple.com/us/app/skiff-mail/id1619168801)
- We’ve published a Code Sandbox and even more detailed README for `skiff-crypto` - check out [@skiff-org/skiff-crypto - npm](https://www.npmjs.com/package/@skiff-org/skiff-crypto?activeTab=readme) with asymmetric/symmetric crypto tutorials, object versioning, hashing, and more
- We published a more interactive security model - [Skiff –&nbsp;Security Whitepaper - Read more](https://skiff.com/security-model) - with lots of diagrams and a detailed walkthrough. This page is still being copy edited.
- On the points above about product updates, you can now toggle them off in [Skiff - Private, encrypted, secure email - 10 GB free](https://app.skiff.com/mail/inbox?settingTab=notifications) for all existing users.

Any further questions for the Skiff team?

---

## Post 235 by @brivacy — 2023-06-04T20:25:51Z

When we will get a skiff mail app in linux and make it native using gtk4 or qt and support for snap and flatpak is very important whether you have .rpm and .Deb. Please do it soon. Love your app and after protonmail i find skiff is the second most attractive and good looking mail service with security enabled.  
And is there a plan to upgrade to pq crypo in future.

---

## Post 236 by @amilich — 2023-06-04T23:10:23Z

Any suggestions for making Skiff even better? We definitely have a lot of requests for a Linux app (here is our feature request board, BTW - [https://skiff.canny.io/feature-requests](https://skiff.canny.io/feature-requests)), so that’s already something we are thinking about actively.

---

## Post 237 by @ch3k — 2023-06-05T12:01:29Z

Auto-sending read items to trash after a certain period of time, as well as an option to auto-clear trash after the chosen period of time would be useful for keeping inboxes de-cluttered as well as for a privacy benefit.

Ideally, there could also be an option to whitelist certain emails from this.

---

## Post 238 by @amilich — 2023-06-06T16:53:36Z

Does anyone from the PG team want to do a Jitsi/Discord/Signal call and discuss any criteria that we’re still missing? Would love to know what the status is so we can keep the thread moving and make sure we are on the right track.

I’m available at [andrew@skiff.com](mailto:andrew@skiff.com) or happy to set a time in the thread and have community members join too.

---

## Post 239 by @xe3 — 2023-06-08T00:22:43Z

I just read through this entire thread. I have nothing to contribute to the technical discussion.

I wasn’t particularly familiar with Skiff beyond the name/basics before this thread, and I haven’t used or tested Skiff and I don’t really have a personal interest or strong opinion on the topic.

But I just wanted to chime in to say that after reading through this conversation, I respect you and your team’s continued willingness to engage in good faith and in the open, and the receptiveness to constructive criticism, considering that I am certain this conversation has at times been exasperating and possibly disheartening.

---

## Post 240 by @dngray — 2023-06-08T05:31:41Z

So looks like the major things have been fixed:

1. I was able to export a whole folder of emails not one by one. A zip file was produced with all the .eml messages.

2. Using recovery email only for recovery only seems to also be resolved for [new accounts](https://discuss.privacyguides.net/t/skiff-mail-email-provider/11411/108) so that looks good.

3. It does not appear that SES is being used as a backup anymore either, which is good.

4. The [transparency page](https://skiff.com/transparency) at least now makes some mention of the audits and when they took place. I assume the issue with providing them, or a letter of attestation is that it needed to be negotiated when the audit took place which is now not possible. An extra column there in that table perhaps describing the scope should be possible though.

5. Now that source code has been released we can also mention that too. @amilich I think it would be a good idea to produce a blog article on that. You’ve mentioned it in the marketing email with a link to [@skiff-org/skiff-crypto - npm](https://www.npmjs.com/package/@skiff-org/skiff-crypto). For major announcements like that I’d probably always make sure there’s some mention of it on the blog.

---

## Post 241 by @Niek-de-Wilde — 2023-06-08T09:06:24Z

We are currently looking over everything once again. It is looking good so far. We will post the decision in a few days.

---

## Post 242 by @amilich — 2023-06-08T16:42:35Z

Awesome, thank you! Please let me know if you have any additional feedback. On the Skiff Mail source code, we’re working on the same developments of putting up a Code Sandbox, making the repo easy to run (it’s not easy to run right now), putting up NPM packages for parts or all of it (like the editor), and then blog.

---

## Post 243 by @amilich — 2023-06-08T16:43:01Z

Again, happy to keep working on any part that you think would be helpful. I’ve only been posting to know what more we should do to improve.

---

## Post 244 by @amilich — 2023-06-09T15:26:42Z

For our next audit, we’re going to work on getting it published and/or getting a letter of attestation.

---

## Post 245 by @anon28734771 — 2023-06-10T14:57:56Z

I just switched from Proton to Skiff, and I want to share my experience.

I downloaded the Skiff Mail app, and I can say that the UX and UI are superior to any other privacy-focused email service apps, but I have some criticism.

1. It would be awesome if the app could update itself or just notify the user with a notification when there is a new version.
2. I would like to see a different notification implementation that doesn’t rely on a user having Google Play Services installed.

When I registered, I was greeted with $10 worth of credits, which is awesome, but it requires your card information to use them, and I think this is to prevent abuse, so it’s fine. But what’s not fine is that you can only use these credits for the Pro plan.

---

## Post 246 by @amilich — 2023-06-10T18:58:04Z

Thanks for the feedback, these changes all make a lot of sense. Non-Google notifications are very frequently requested.

On credits, that is also right… although credits will soon work with crypto plans, and you can use any wallet to pay for that. You can also use credits on the more expensive Business plan too.

---

## Post 247 by @anon28734771 — 2023-06-11T07:44:47Z

@amilich If you guys keep listening to user feedback and focus on privacy, security, and ethics, then you will be miles ahead of Proton. I switched to the Skiff ecosystem completely, and I really believe in you guys. Proton pissed me off enough times over the years that it was time to switch.

---

## Post 248 by @amilich — 2023-06-11T16:52:28Z

Glad you’ve had a good experience! We really do spend a ton of time on community and feedback. If you have any requests, feel free to also add [https://skiff.canny.io/feature-requests](https://skiff.canny.io/feature-requests) or in the thread.

---

## Post 249 by @anon31041004 — 2023-06-12T13:13:35Z

I’m unable to access any skiff services from yesterday. Having to use VPN.

Cloudflare Ray ID : 7d5a6e20db202a98

---

## Post 250 by @anon31041004 — 2023-06-12T13:14:51Z

It would be really beneficial for anonymity if we could use different display name for each alias.

---

## Post 251 by @amilich — 2023-06-12T17:02:12Z

Looking into it

---

## Post 252 by @anon28734771 — 2023-06-12T17:15:11Z

@amilich I noticed that I can’t login to web mail with JIT disabled. I have to enable it. JIT is very insecure, and a lot of vulnerabilities come from it. Could you guys take a look at this?

Here is the error message: It looks like there’s a temporary connectivity issue. Please try again in a couple of minutes.

---

## Post 253 by @anon28734771 — 2023-06-12T17:18:29Z

And are there any plans for a family plan? That would be cheaper than Proton’s family plan, because that one is costly. I would really like to bring my family from Gmail to Skiff.

---

## Post 254 by @NewUser — 2023-06-13T00:41:02Z

> [@anon28734771](#):
>
> I noticed that I can’t login to web mail with JIT disabled.

I created an exception for [app.skiff.com](http://app.skiff.com) to at least restrict it to just the single site that I’m obviously trusting in the first place.

Still I can’t get notifications to work in the PWA anyway. The app doesn’t ask for permission to send notifications at all. I’m hoping they can address the lack of notifications in their Android app ASAP. All it takes is regular polling like something like K9 Mail does.

---

## Post 255 by @amilich — 2023-06-13T06:45:34Z

I believe the issue is with webasm usage. What browser are you using? Chromium browsers I do not think this issue exists.

---

## Post 256 by @amilich — 2023-06-13T06:46:02Z

The Skiff Pro plan allows up to 6 members and should have very similar or more benefits. It’s also cheaper - $96/year instead of $240!

---

## Post 257 by @amilich — 2023-06-13T06:46:11Z

This is fixed BTW!

---

## Post 258 by @anon28734771 — 2023-06-13T06:50:30Z

I noticed it when I used up my credits on the Pro plan. This is pretty amazing functionality.

---

## Post 259 by @anon28734771 — 2023-06-13T06:53:36Z

I use Vanadium, which comes with GrapheneOS. It has a per-site JIT toggle, and JIT is disabled by default to greatly reduce the attack surface and chance of exploitation because of how insecure JIT is.

I think the same would happen when trying to login from Safari with Lockdown mode enabled on iOS.

Ahead-Of-Time (AOT) is a much more secure alternative to Just-In-Time (JIT).

---

## Post 260 by @anon31041004 — 2023-06-13T08:03:01Z

Yeah .. Thanks for that.

---

## Post 261 by @NewUser — 2023-06-13T09:48:02Z

> [@anon28734771](#):
>
> I use Vanadium, which comes with GrapheneOS

I’m using Vanadium also. Have you managed to get notifications to work if you allow JIT?

---

## Post 262 by @amilich — 2023-06-13T22:55:39Z

Blog is out: [Skiff - Private, encrypted, secure email - 10 GB free](https://skiff.com/blog/skiff-crypto-open-source). I need to update the date to be today, just realized it was copied from an old blog template.

---

## Post 263 by @amilich — 2023-06-15T06:29:36Z

Hey all, one more update - we’re launching the Skiff Crypto documentation tomorrow too:

> **[Skiff Crypto library](https://skiff.com/skiff-crypto/)**
>
> Learn everything there is to know about Skiff's crypto library and integrate easy-to-use cryptography into your product.

> **[Launching Skiff Crypto](https://medium.com/@skiffworld/launching-skiff-crypto-b95f7f0696b0)**
>
> Skiff is a privacy-first workspace that empowers you to communicate and collaborate with freedom. Building our end-to-end encrypted…

We’ll be doing the same for more of our codebase shortly.

If there’s anything I can do regarding questions from the PG team, please let me know.

---

## Post 264 by @ComplexSimplicity — 2023-06-16T14:04:12Z

Skiff seems like a cool newcomer, especially regarding Protons inability to solve problems within their applications.

What is Skiffs; answer to/version of, this Protonmail setup:  
External email → Simplelogin alias → (PGP+generic subject field) → Protonmail alias → Protonmail inbox

Thanks in advance

---

## Post 265 by @anon28734771 — 2023-06-16T16:34:57Z

@amilich Please make Android apps available under “releases” in GitHub.

A lot of us use Obtainium to obtain and update our apps or use RSS feeds to get notified about new releases and update manually.

---

## Post 266 by @amilich — 2023-06-16T16:37:38Z

Oh, great idea.

---

## Post 267 by @anon28734771 — 2023-06-16T17:05:53Z

I’ve been trying to use the Skiff Mail app through Tor for 10 minutes with no success. Skiff needs to do some work on being usable over Tor.

---

## Post 268 by @anon28734771 — 2023-06-16T17:27:51Z

@amilich After trying for more than half an hour, I can say that the Skiff Mail app is unusable over Tor.

---

## Post 269 by @amilich — 2023-06-16T17:29:31Z

What platform are you on?

We’ve been working on this and had some success. But, some Tor exit nodes are blocked by either hcaptcha (signup) or may have issues.

---

## Post 270 by @amilich — 2023-06-16T17:30:46Z

I think we have a great solution :slight_smile:

For as little as $2 per year, you can get a custom domain through Skiff where we will privately register it for you within minutes. You can then have unlimited alisaes on that domain.

Instead of going through alias → PGP → other alias, mail will simply be encrypted with your Skiff account public keys - _including the subject_ - and go to your inbox. Skiff Mail’s client blocks trackers (if you enable remote content blocking) and proxies all image requests to hide your IP and all other identifying data.

---

## Post 271 by @anon28734771 — 2023-06-16T17:33:50Z

I’m using Skiff Mail’s Android app, and I’m routing my traffic trough Tor with Orbot.

I switched my Tor circuit (which switches exit node too) a lot of times and still no success.

By the way, I’m already logged in to my account, it just doesn’t load my emails.

 ![IMG_20230616_203629](//forum-uploads.privacyguidesusercontent.com/original/2X/f/f93e588004d8b57ce7a3fff9350023b38c137f6a.jpeg)

---

## Post 273 by @amilich — 2023-06-16T19:45:05Z

Helpful to know. And this loads if not?

---

## Post 274 by @anon28734771 — 2023-06-18T09:27:56Z

Okay, so I have another complaint. I picked up a Pro plan with my $10 worth of credits. Then I saw that you can downgrade, so I did that to save $6 of my credits, and now I noticed that $4 are gone from my bank account, and I wasn’t aware that I will be paying with my real money, not credits.

(I contacted support for a refund)

---

## Post 275 by @anon28734771 — 2023-06-18T10:17:37Z

> [@amilich](#):
>
> Helpful to know. And this loads if not?

That logo just keeps spinning forever and doesn’t load emails.

---

## Post 276 by @anon28734771 — 2023-06-18T10:25:37Z

> [@amilich](#):
>
> This is something we hope to work on. You can download our APK from [skiff-org.github.io/assets/apk at main · skiff-org/skiff-org.github.io · GitHub](https://github.com/skiff-org/skiff-org.github.io/tree/main/assets/apk) (we need to update for the last 2 releases) but it does not have full notification support yet.

When can we expect these APKs to be under “releases” on GitHub?

---

## Post 277 by @fibo — 2023-06-18T16:15:03Z

I’ve been using Skiff for a few weeks now. While I did encounter a few bugs, the overall experience is fine.  
But I believe that the speed of the platform might prevent users from migrating. For instance, downloading email attachments takes a significant amount of time, especially for relatively larger files (e.g., 10MB).

I also appreciate efforts made by Skiff to improve security and privacy and listening to the community.

If there was a vote to decide whether to list Skiff or not, I would have voted for it to be included.

---

## Post 278 by @anon28734771 — 2023-06-18T17:02:52Z

> [@fibo](#):
>
> If there was a vote to decide whether to list Skiff or not, I would have voted for it to be included.

You can vote, it already has 16 votes.

---

## Post 279 by @amilich — 2023-06-18T18:42:31Z

Thank you! I can look into attachment downloading, that is really helpful to know. What other speed issues do you have? We’ve tried to make Mail a lot faster recently.

As Lukas said, you can vote at the top :slight_smile:

---

## Post 280 by @amilich — 2023-06-18T18:48:35Z

Let me try adding the latest one now (I believe v59.0).

---

## Post 281 by @amilich — 2023-06-18T18:50:00Z

I created a tag and release, but all you really want is the APK file instead of the entire repo. Does this still help?

---

## Post 282 by @anon28734771 — 2023-06-18T19:46:36Z

APK file should be under assets in that release ([Release android-v59.0 · skiff-org/skiff-org.github.io · GitHub](https://github.com/skiff-org/skiff-org.github.io/releases/tag/android-v59.0)). As of now, there is no APK file under assets.

Here you can see an APK file under assets: [Release v3.0.14 · ProtonMail/proton-mail-android · GitHub](https://github.com/ProtonMail/proton-mail-android/releases/tag/3.0.14)

---

## Post 283 by @amilich — 2023-06-18T21:30:27Z

Done! Thank you :slight_smile:

> **[Release Skiff Mail - Android - v59.0 · skiff-org/skiff-org.github.io](https://github.com/skiff-org/skiff-org.github.io/releases/tag/skiff-mail-android-v59.0)**
>
> Skiff Mail Android v59.0 APK published.

---

## Post 284 by @fibo — 2023-06-18T22:40:28Z

Thanks I really appreciate that Skiff listens to users and improve the service according to the feedbacks.  
For the transfer speeds, I had troubles while downloading attachments and files from the Drive.

I voted, I think Skiff really deserve to be listed.

---

## Post 285 by @amilich — 2023-06-19T05:26:58Z

Thank you :slight_smile:

We just improved upload speeds to Drive a month or so ago. We haven’t applied the same changes to download yet (downloading files in parallel).

---

## Post 286 by @anon28734771 — 2023-06-19T08:30:59Z

![Screenshot_20230619-113003](//forum-uploads.privacyguidesusercontent.com/original/2X/b/beee9294da324ad69b336964184823d6bbd6a430.png)

It appears pretty buggy in Obtainium, but it works! Thanks.

---

## Post 287 by @amilich — 2023-06-19T17:37:14Z

Cool! Let me know what bugs we should fix.

---

## Post 288 by @anon28734771 — 2023-06-20T13:13:29Z

Everything works fine. I would just suggest taking a look at how other projects do releases on GitHub.

A few things that I could suggest are to have a repository for an Android app or for all the apps with source code and a guide on how to compile the app or apps, and to have an APK in releases on the same repository. Each release would obviously have an up-to-date APK, and it should inform users on what changed.

We can again take Proton Mail as an example: [Release v3.0.14 · ProtonMail/proton-mail-android · GitHub](https://github.com/ProtonMail/proton-mail-android/releases/tag/3.0.14)  
It tells you the version, it tells you what’s new in this version, and there is an APK file under assets.

---

## Post 289 by @amilich — 2023-06-20T16:49:26Z

Yeah, I agree. We’re moving towards a monorepo for Skiff apps so the release configuration could be messy.

---

## Post 290 by @anon28734771 — 2023-06-21T00:09:41Z

By the way, Skiff Mail’s Android app still doesn’t work when using Tor.

And when trying to log in on [https://app.skiff.com](https://app.skiff.com) with JIT disabled, it gives this error: “It looks like there’s a temporary connectivity issue. Please try again in a couple of minutes.”

---

## Post 291 by @amilich — 2023-06-21T00:31:33Z

Yes, I think the JIT issue we’ve pinned down. Basically, I believe some browsers do not run webassembly with JIT disabled. Some (chromium) do. We use some webassembly for cryptography because it tends to be very fast. The plan is to fallback on non-wasm dependencies if they cannot be loaded. We haven’t implemented it yet.

---

## Post 292 by @anon30510143 — 2023-06-21T01:03:17Z

I know that Safari disables WASM in lockdown mode as well as JIT in lockdown mode.

---

## Post 293 by @amilich — 2023-06-21T02:05:54Z

I think this is the issue. I think Chromium treats wasm differently.

---

## Post 294 by @eudyp — 2023-06-21T05:03:23Z

I am a lover of privacy, and although there seems to be a lot of misunderstanding in this series of discussions, it seems that a consensus has been reached in the end.

I’d like to extend my thanks to the privacy guide team for their persistence and to Andrew Milich for their willingness to adjust.

It’s refreshing to see this user-friendly approach finally come into fruition, which earns my approval.

Furthermore, I’m considering transitioning from being a paid Proton user to Skiff.

---

## Post 295 by @anon28734771 — 2023-06-21T08:11:35Z

> [@eudyp](#):
>
> Furthermore, I’m considering transitioning from being a paid Proton user to Skiff.

That’s what I did. Switching to an email provider that actually listens to its users is just refreshing.

---

## Post 296 by @anon28734771 — 2023-06-21T10:09:46Z

> [@anon28734771](#):
>
> By the way, Skiff Mail’s Android app still doesn’t work when using Tor.

What’s interesting is that it always works in a web browser.

---

## Post 297 by @anon28734771 — 2023-06-23T08:46:39Z

@amilich does Skiff offer refunds? I contacted support, and they told me tu unsubscribe, so I did, but I didn’t get any messages for 2–3 days about my refund.

---

## Post 298 by @amilich — 2023-06-23T16:33:23Z

What is your ticket number? I can take a look

---

## Post 299 by @anon28734771 — 2023-06-23T16:55:50Z

Ticket number: 12649

---

## Post 300 by @Anonymous49 — 2023-06-23T22:24:02Z

I have been watching this discussion from the start. What is missing for PG to list skiff? I think they made a remarkable job to comply with the criteria with the only exception I disagree about marketing emails.

---

## Post 301 by @anon28734771 — 2023-06-24T09:02:13Z

I have absolutely no idea why Skiff Mail isn’t added already.

---

## Post 302 by @Equinox — 2023-06-24T16:09:54Z

@Niek-de-Wilde said 16 days ago that in a few days a decision will be posted. Yes, it’s taking a longtime, especially when you see other services getting approved and added in a matter of few days… However, just wanted to point out that the pull request got edited 4 days ago, and it looks like it will be approved. So, that is great! [https://github.com/privacyguides/privacyguides.org/pull/2108](https://github.com/privacyguides/privacyguides.org/pull/2108)

---

## Post 303 by @anon28734771 — 2023-06-24T17:13:43Z

Do you guys plan to make Skiff Mail app available on F-Droid? There are two ways to do this:

1. Making the app available in a main F-Droid repository (this would require having non-Google notifications).

2. Hosting your own third-party F-Droid repository.

---

## Post 304 by @amilich — 2023-06-24T20:20:55Z

The only changes I see here are grammatical. @jonah is there anything you need for the PR?

---

## Post 305 by @anon28734771 — 2023-06-25T22:35:06Z

I just tried out the Skiff Mail PWA, and the name of the PWA is “react-client” instead of something like “Skiff Mail”. Is this intentional or a mistake?

---

## Post 306 by @amilich — 2023-06-26T04:19:14Z

We haven’t really configured it as a PWA. It’s not meant to be used as a PWA. What platform? We prefer to have native apps on basically every platform.

---

## Post 307 by @Laitinlok — 2023-06-26T05:57:37Z

Facebook also uses legitimate interest to sell data in EU so definitely not private at all.

---

## Post 308 by @anon28734771 — 2023-06-26T08:37:07Z

> [@amilich](#):
>
> What platform?

Android.

> [@amilich](#):
>
> We prefer to have native apps on basically every platform.

Any reason why? Or is this just a preference?

---

## Post 309 by @amilich — 2023-06-26T17:39:15Z

Got it.

Yes, the difference is quite substantial - the native APK/Android app have a completely different UI, more features, native integrations (file upload/download, mailto: link opening, and more).

I’d really appreciate if anyone from the PG team could update on any questions or what’s going on with the PR. Just noting that we’re at 6 months, 300 replies, and almost 15k views on this thread!

---

## Post 310 by @anon28734771 — 2023-06-26T18:05:43Z

> [@amilich](#):
>
> Yes, the difference is quite substantial - the native APK/Android app have a completely different UI, more features, native integrations (file upload/download, mailto: link opening, and more).

Okay, I’m replacing that “PWA” with the native app.

> [@amilich](#):
>
> I’d really appreciate if anyone from the PG team could update on any questions or what’s going on with the PR. Just noting that we’re at 6 months, 300 replies, and almost 15k views on this thread!

Yeah, this is getting insane.

---

## Post 311 by @hrtang — 2023-06-26T19:36:57Z

Can’t believe this thread is still going on. lol.

---

## Post 312 by @anon30510143 — 2023-06-26T22:02:37Z

We do it in our free time, so people get busy and don’t necessarily have time to work on the site. On GitHub, each PR requires at least 2 approvals by team members. There’s one already, and I suggested a few changes. I could force those changes but I wanted to make sure Jonah was ok with it first. Not a fan of just editing/merging someone else’s PR without getting their approval first :sweat_smile:

---

## Post 313 by @amilich — 2023-06-26T23:00:47Z

Appreciate it. No rush, of course.

If anything it just means people really respect the PG process and approval :slight_smile:

---

## Post 314 by @NewUser — 2023-06-27T01:50:27Z

Any chance of getting a timeline on notifications in the Android app?

I know you’ve said before that it would require building a replacement for Google Play Services but that isn’t what we are looking for or expecting. All we need is for the app to poll the server every so often like other email apps do (eg. K9 Mail).

---

## Post 315 by @amilich — 2023-06-27T05:44:25Z

The app does poll for new emails, but it doesn’t send notifications yet. I don’t think it is it that much work.

---

## Post 316 by @anon28734771 — 2023-06-27T09:26:19Z

> [@NewUser](#):
>
> All we need is for the app to poll the server every so often like other email apps do (eg. K9 Mail).

What do you mean by we? Signal has polling and the battery life is absolute garbage. I would rather have a better notifications implementation.

---

## Post 317 by @Ganther — 2023-06-27T12:48:46Z

> [@amilich](#):
>
> We prefer to have native apps on basically every platform.

Is this why I have to install extra software when I install the Skiff desktop app?

I tried installing Skiff in Sandboxie-Plus, and then I’m asked to install “Microsoft.NETCore.app” and after I do so, Skiff crashes on startup.

---

## Post 318 by @amilich — 2023-06-27T16:45:24Z

The Windows desktop app uses the WebView2 framework on Windows to render some content. I haven’t heard about many crashes yet but can start looking into it.

---

## Post 319 by @NewUser — 2023-06-28T02:53:27Z

> [@anon28734771](#):
>
> What do you mean by we? Signal has polling and the battery life is absolute garbage. I would rather have a better notifications implement

Signal needs to poll constantly because it is an instant messenger. Email doesn’t need that sort of frequency (K9 Mail has never been considered a battery burden for example). Although personally I don’t have any battery problems with Signal.

I actually would prefer notifications to be implemented and notifications via intermittent polling is the fastest route to achieve that. I don’t believe there is any other foss android app that has implemented a replacement for Google Play Services that does not involve polling of some sort. Tutanota went for a unique approach but it still effectively is polling - see [How Tutanota replaced Google’s FCM with their own notification system | F-Droid - Free and Open Source Android App Repository](https://f-droid.org/2018/09/03/replacing-gcm-in-tutanota.html)

I think expecting Skiff to do anything beyond some sort of polling solution is misguided. I hope Skiff dedicate their coding resources to more realistic projects and simply provide standard polling type notifications that can be achieved relatively simply.

---

## Post 320 by @amilich — 2023-06-30T01:23:24Z

I could also open up a PR if you think that would be easier. It seems like we’re in the last stretch so I don’t want to step on Jonah’s PR toes, but let me know if this would help the team.

---

## Post 321 by @sarah7777 — 2023-07-01T15:42:25Z

Skiff is pretty amazing now but they still have one dark pattern inside their Email.

You can’t export SENT emails.  
They added the export ability for inbox, but not for sent emails.

I’ve reported it a month ago but it seems to get ignored

---

## Post 322 by @amilich — 2023-07-01T19:11:36Z

This isn’t a dark pattern- it’s a feature that will come soon. We are working on total inbox export by folder/label etc. Nothing gets ignored, but we do have a small team so we can’t ship everything as quickly as we want to. We still have a lot of improvements to make.

---

## Post 323 by @fibo — 2023-07-02T15:21:33Z

I’m excited and can’t wait for Drive improvements.

---

## Post 324 by @Anonymous49 — 2023-07-03T15:09:58Z

Please, stop calling everything dark pattern or spyware blindly. Every feature costs money and time. You may critique the approach the companies follow, but dark pattern is just an exaggeration.

---

## Post 325 by @root — 2023-07-03T17:32:10Z

I don’t think they knew what exactly is a dark pattern.

---

## Post 326 by @amilich — 2023-07-03T20:05:52Z

I just would like to know how we can get the PR [Add Skiff Mail by jonaharagon · Pull Request #2108 · privacyguides/privacyguides.org · GitHub](https://github.com/privacyguides/privacyguides.org/pull/2108) back on track

---

## Post 327 by @Ganther — 2023-07-03T20:53:36Z

I think at this point it’s just a matter of waiting for the PG team to have the time to add it.

My understanding is that Skiff now passes all the requirements. Skiff doesn’t have non-Google notifications but neither does Proton so I don’t think that will be an issue, for example.

The one thing that is making me consider switching from Proton to Skiff is the fact that your developers are ten times faster. Seriously, I can’t even fathom how slow Proton is at adding the most basic stuff. They have been around for 10 years now and it feels like nothing has changed from one year to another.

Some of the limitations of the free version of Skiff seems kind of harsh though. Only 2 filters?? Only 5 folders?Proton in practice offers unlimited filtering, which is something I really like. You have them beaten when it comes to folders however.

You may want to consider a 1 dollar per month tier with unlimited filters and folders and nothing else. I’d sign up for that. I don’t really need more storage space, 10 gigs for email is already more than enough. IMO there isn’t really a tier specifically aimed at email users and that’s where I think a 1 dollar email tier might come in handy. Basically, a tier for those of us that will never use Skiff for anything but email.

Lastly, any future plans for a Skiff VPN?

---

## Post 328 by @xe3 — 2023-07-03T21:31:07Z

> [@Ganther](#):
>
> Proton in practice offers unlimited filtering, which is something I really like. You have them beat when it comes to folders however.

What do you mean by ‘unlimited filtering _in practice_’? The protonmail website states 1 filter with the free plan, but I’m guessing you mean something more creative by ‘in practice’

> [@Ganther](#):
>
> any future plans for a Skiff VPN?

What is the benefit of your e-mail provider also being your VPN provider? I don’t understand the comparative advantage to bundling a VPN with these unrelated services compared with standalone VPN and e-mail/cloud storage?

I understand the appeal of bundling various things like Mail+Office+Calendar+Contacts since there is some synergy in bundling these services, but a VPN is in my eyes more of a standalone service that doesn’t benefit from being bundled together with other services.

---

## Post 329 by @Ganther — 2023-07-03T21:35:23Z

> [@xe3](#):
>
> What do you mean by ‘unlimited filtering _in practice_’? The protonmail website states 1 filter with the free plan, but I’m guessing you mean something more creative by ‘in practice’

You can have one filter with lots of if statements in it. If it’s from Gmail accounts it goes into folder 1, if it’s from Hotmail it goes into folder 2, usw.

> [@xe3](#):
>
> What is the benefit of your e-mail provider also being your VPN provider? I don’t understand the comparative advantage to bundling a VPN with these unrelated services compared with standalone VPN and e-mail/cloud storage?

I was just curious. That is all.

Personally I’m very happy with the VPN I’m using at the moment. Just wondered if they were planning on expanding to literally everything Proton is doing or if they are happy with their current lineup.

---

## Post 330 by @amilich — 2023-07-03T23:59:52Z

That’s fair. But, the lowest priced plan is $3 per month, which is higher than $1, but it does have all of those benefits. Filtering should also get a lot more powerful soon.

---

## Post 331 by @Ganther — 2023-07-04T08:22:25Z

Indeed that there is a 3 dollar tier with those features, but it also includes extra storage space which, as an email-only user, is completely useless to me. 10 gigs of emails is in practice unlimited gigs of emails.

For comparison, Posteo has a 1 € tier which is 1/3 the cost if you’re an email only user like me.

I get that you may not want to price it that low, as it might draw away users from the higher tiers. But it may also incentivize free users to pay for the extra filtering/folders.

Maybe if you add more premium only features it would be more appealing to pay a small fee for those?

---

## Post 332 by @ph00lt0 — 2023-07-04T10:39:36Z

> [@ph00lt0](#):
>
> Some quotes from the website that are pure misinformation:
> 
> > Under privacy laws like the General Data Protection Regulation (GDPR) in the European Union and the California Consumer Privacy Act (CCPA) in the United States, websites are required to obtain explicit consent from users before collecting and processing their personal data, including information collected through tracking cookies. ([What is device and browser fingerprinting? - Read more](https://skiff.com/blog/device-browser-fingerprinting-protection))
> 
> This is not true at all. The GDPR doesn’t even mention tracking cookies. Big misconception. All tracking methods are equally treated. It basically suggests that it may not be illegal, while it definetly is. This ‘privacy’ company just repeats bullshit arguments from the ad business.

Let me highlight once more that Skiff still spreads false information from the ad industry. This gives leverage to this false argument and is really really wrong. I cannot stress that how important it is that we do not tolerate these kinds of strange outcasts from privacy friendly businesses.

Skiff also still claims to be GDPR complaint while legally this impossible. They are misinforming their customers who may sign up believing them to be complaint. This could in theory result in fines for those businesses using Skiff. Without legal representation Skiff is not suitable for EU market.

Edit for reference:

> **[Do you use MailChimp? Bavarian DPA holds that its use was unlawful under GDPR...](https://www.scl.org/12230-do-you-use-mailchimp-bavarian-dpa-holds-that-its-use-was-unlawful-under-gdpr/)**
>
> Martin Sloan reports on a decision from one of the German data protection authorities has cast doubt over whether use of the popular email marketing platform by EU organisations MailChimp is lawful under GDPR. The decision emphases the importance...

---

## Post 333 by @amilich — 2023-07-04T16:29:03Z

This is completely false. I don’t even know what the point of your comment is? Skiff is GDPR compliant. We’ve hired lawyers that have EU offices so we _can_ have local counsel if needed. I truly cannot understand the point of your comment at all. What is false and wrong? What are you referencing as information from the “ad industry”? Skiff has absolutely nothing to do with advertising.

I’m happy to correct anything you think could be clearer on our blog. Why not take a constructive tone?

Blogs are intended to provide resources for like-minded community members. Learning about browser fingerprinting is extremely valuable. Take a constructive approach and send a specific paragraph or sentence you want changed. Posting unrelated articles just isn’t helpful to us. Have you read through the thousands of pages on [Brave’s latest news | Brave](https://brave.com/blog/) and [The Proton Blog - News from the front lines of privacy and security | Proton](https://proton.me/blog) and drawn the same conclusions?

The only constructive point you brought up was sending product update emails. This has been changed months ago, so I really don’t know what you’re talking about.

---

## Post 334 by @amilich — 2023-07-04T16:30:51Z

I honestly don’t think Posteo is a service that we are trying to emulate with this plan. Skiff offers a complete end-to-end encrypted workspace with far more features, native apps, capabilities, team/business use, and more. Posteo also does not offer builtin E2EE.

Generally I do not think software capabilities scale with price, but this might be an example where it does. For $3/month on Skiff (versus $1.10 per month on Posteo), you get 4 end-to-end encrypted products with many more capabilities, as well as 6 accounts to share a custom domain and your paid features.

---

## Post 335 by @dngray — 2023-07-05T17:34:30Z

> [@amilich](#):
>
> I honestly don’t think Posteo is a service that we are trying to emulate with this plan. Skiff offers a complete end-to-end encrypted workspace with far more features, native apps, capabilities, team/business use, and more. Posteo also does not offer builtin E2EE.

Indeed, I wrote a quite detailed description about that here: [https://discuss.privacyguides.net/t/best-secure-email-service/12933/2](https://discuss.privacyguides.net/t/best-secure-email-service/12933/2)

---

## Post 336 by @ph00lt0 — 2023-07-06T07:48:29Z

I wrote many times now that the arguments for allowing fingerprinting under privacy are completely false. This is infromation craeted by the ad industry. I am not saying you are part of them but you have distributed that bullshit without having any understanding of what you are actually saying with great harm. Fingerprinting is not any more legal than tracking cookies. This is just wrong and not valuable at all because the infromation is false and misleading. There is no difference in the law at all. I said it so many times so time for a constructive messaging has been wasted long ago when you called me out for not having knowledge on this matter, while you are the one spreading misinformation.

No you are not GDPR compliant any laywer you have hired who told you this you should fire! I would recommned you to actually get a better insights, because all you say is not true at all. You need a legal entity on paper or a contracted representation office at least in order to have some sort of compliance. They should also be listed in your privacy policy as point of contact. You do not have this as of now. There is no EU establishment. Read more here: [IAPP](https://iapp.org/news/a/representatives-under-art-27-of-the-gdpr-all-your-questions-answered/)

---

## Post 337 by @anon32044721 — 2023-07-06T12:26:27Z

@dngray I don’t see you are making any point.

> [@ph00lt0](#):
>
> It also might be good to point out that GDPR compliant doesn’t really mean anything:

You made it clear that GDPR doesn’t mean anything, which, by extension, means your argument about non-GDPR compliance doesn’t mean anything either. Yet, you go back and forth.

Let me ask you just one thing: Are you a lawyer who works with GDPR?

---

## Post 338 by @ph00lt0 — 2023-07-06T13:20:01Z

GDPR doesn’t mean anything? What? Where?  
You must be mis understood.

No I am not a lawyer but I work in business information security risk management with lawyers and privacy experts. I was a researcher at an university on this topic before.

Besides I don’t think you need to be a lawyer to be more knowledge than the allegedly by Skiff hired lawyers in this topic.

Moreover note that I backed my comments with articles of the association of privacy professionals IAPP. I am not sure what js your complain?

The GDPR is a very easy law to read actually. I can recommend to do so. Obviously there are unclear parts but there are several judgements from the CJEU and local authorities to clear up confusions here.

Besides legal representation f.x. in many EU countries it has been ordered that storing personal data in the USA is actually a non compliance in most cases. See [noyb win: First major fine (€ 1 million) for using Google Analytics](https://noyb.eu/en/noyb-win-first-major-fine-eu-1-million-using-google-analytics)

---

## Post 339 by @anon32044721 — 2023-07-06T15:52:14Z

This you? If so, what are you arguing about? You have rendered your own effort invalid and meaningless.

> [@ph00lt0](#):
>
> It also might be good to point out that GDPR compliant doesn’t really mean anything:

And this, a good businessman would avoid making such a extreme statement. “ONLY”?

> [@ph00lt0](#):
>
> However, interestingly the website of Skiff is only spreading misinformation.

Once again, based on your own argument, GDPR compliance doesn’t mean anything. Furthermore, you argued about seeking legal advice. Since you are not a lawyer, with the choice of your language, I guess we shouldn’t be too convinced that your understanding of GDPR is 100% correct.

> [@ph00lt0](#):
>
> No you are not GDPR compliant any laywer you have hired who told you this you should fire! I would recommned you to actually get a better insights, because all you say is not true at all. You need a legal entity on paper or a contracted representation office at least in order to have some sort of compliance.

You can’t seem to sort out your own logic. Your statements are mixed with emotions. They make me wonder about your objectives here.

---

## Post 340 by @ph00lt0 — 2023-07-06T16:06:57Z

There is no such thing as being GDPR compliant like a sticker, label or certification. It does not exist. That is true and you are correct. It however is very clear that Skiff is not aware of the things I wrote above. I personally believe them not to be able to serve EU customers, and I would advice agaist using them for EU (in current state). This in my opinion makes the statement of Skiff harmful and that is what I complain about. Hope you can follow the logic now.

I believe your comments to be questioning my expertise, which is fine, but I wonder what gives you the authority to do so? If you actually have good counter arguments I would be very interrested so we can have a meaningful discussion about this rather than you just questioning me. Thanks.

Also to be clear: I do not have any objectives here in terms of business. I only care about PG doing a good filtering and I don’t mind to stear up the discussion about things I find odd. I am not saying Skiff shouldn’t be listed. But I do think a company like this should be held accountable for their statements.

---

## Post 341 by @anon32044721 — 2023-07-06T16:25:37Z

Again, the effort in your latest conclusion is constructed on “Skiff is not GDPR compliant”.

> [@ph00lt0](#):
>
> No you are not GDPR compliant any laywer you have hired who told you this you should fire!

At the same time… logic issue?

> [@ph00lt0](#):
>
> It also might be good to point out that GDPR compliant doesn’t really mean anything:

It’s pretty hard to convince others that you have a better understanding of the law, especially considering how much more complicated it is compared to this small thread.

---

## Post 342 by @ph00lt0 — 2023-07-06T16:35:38Z

Yeah the statement can never be true in either case but still it could lead to issues for those who believe it and take it as a given. That I find problematic. Imagine a SME signs up think they are all compliant because they just believed the comment of Skiff and trusted them. They get unlucky and someone complains at the authority or starts a law suit. Who will get the fine? It is not Skiff as processor, it is the SME, because they are the data controller.

Worse for Skiff would be when EU citizens start complaining at the authorities as users. Because Skiff targetting the EU as a market is subject to the GDPR. My understanding is that this could have legal implications for them. I will say I don’t think this is very likely, but there is always a chance.

I know it is hard to make people understand that you actually know the regulation, but please share your perspective! If you have a different view or reading of the GDPR it would be interreting as I said. I may be very direct to Skiff at this point (it has been a long journey) but I am definitlely willing to listen if you know of any cases that can counter this.

---

## Post 343 by @privacyguided — 2023-07-06T18:48:57Z

I made my checkout on skiff as a new user.

I saw no information about free account termination, but the already passed recommendations’ has highights on this site. (my method is to serach the terms pages for _inactivity, day, week, month, year_ keywords… no result). Do you have any policy of this kind?

The pages for registering are in a bit odd order, and i think too restricted for an advanced user:  
–At one point, there is the step, where i should save my recovery code, the code is copiable, but also button to the next step forces me to download that in a PDF form, and by that i am forced to write that to disk, instead of copying it in ram to encrypti it in a way, e.g. . Inside that from there is a line for recovery emailaddress, what is empty, but  
–Next step: i am foced to add a recovery mail address, when i just copied my code, and downloaded the document, without this in it.  
– after loggin in i was able to send emails without even confirming my account with the recovery mail (in opposite e.g. outlook).  
(If i just missed parts and options sorry, i was kida distracted when made that reg.)

Personally i would take the risk what comes with not having a recovery email against being forced to manage an other account.  
Even if forced or not, the recovery email question is in the wrong side of the recovery document creation’s logically. Sadly i had issues ith incoming emails so i was unable to check when would recovery address get the mail.

But i really like the service’s possibilities, i almost perfect for my needs!

---

## Post 344 by @amilich — 2023-07-06T23:08:09Z

That is very fair, I think the recovery flow could be much better. The current design is similar to how a recovery kit might work for a password manager. On account termination, accounts are never terminated!

---

## Post 345 by @amilich — 2023-07-07T06:27:33Z

@jonah just sending a quick ping, let me know if I can help with the PR or anything else in any way. I understand you’ve been busy but want to help get the small nits fixed if I can.

---

## Post 346 by @hrtang — 2023-07-07T23:30:03Z

> [@privacyguided](#):
>
> Personally i would take the risk what comes with not having a recovery email against being forced to manage an other account.

Hmm. Nothing is going to be perfect for privacy-focus products right now. Privacy-focus products should be the trend the next couple years, and you can only hope that they will become better (Skiff is clearly the one). I also don’t think it’s easy to build a great product with e2ee.

Also, Skiff is featured in this video lately: [https://www.youtube.com/watch?v=tq91QWWSmyg&t=27s](https://www.youtube.com/watch?v=tq91QWWSmyg&t=27s)

A pretty solid discussion there.

---

## Post 347 by @hrtang — 2023-07-07T23:30:51Z

Also, it seems the review of Skiff as recommendation is still going? LOL. :joy:

---

## Post 348 by @mika — 2023-07-08T14:41:34Z

> [@hrtang](#):
>
> Also, it seems the review of Skiff as recommendation is still going? LOL.

It’s honestly absurd at this point. I don’t use Skiff, I’m not associated with Skiff, but the Skiff folks in this thread have been beyond patient and helpful so it’s hard to understand why there is what appears to be an indefinite delay with near radio silence from PG.

It’s been over 6 months! Either add it as a recommendation or reject it with a reason.

---

## Post 349 by @ph00lt0 — 2023-07-08T18:35:36Z

I don’t see you issue. PG is a volunteer run project that tries to have highs standards and takes time to evaluate new suggestions. What exactly is your problem with that?

It isn’t the first product that is in discussion for a while. Also nobody is required to list them?

---

## Post 350 by @hrtang — 2023-07-08T21:30:19Z

> [@ph00lt0](#):
>
> It isn’t the first product that is in discussion for a while. Also nobody is required to list them?

It’s totally fair to take time and have a high standard. But it’s kind of absurd to take so long without a reason to not recommend or recommend.

This thread is more than 6 months old and Skiff folks have been really helpful. They are certainly not the blocker.

---

## Post 351 by @Niek-de-Wilde — 2023-07-09T06:49:12Z

As phoolto kindly pointed out, we are a volunteer project which means we do all our work in our free time, without making a single dollar off it.

A project at the size of PG has alot of different facets that require attention, may it be new products on the market, or adding new langagues to our site so folks who do not speak english can improve their privacy as well.

A product as complex as an email provider needs a lot of attention, and I applaud Skiff for working so hard to get listed, I really do.

At this point they are pretty much assured to become listed, they just need to have a little more patience for while we ready things.

Look at notesnook for example, they have had an open forun thread since october last year, and only got added last month.

---

## Post 352 by @jonah — 2023-07-10T17:30:03Z

Status: In Progress → Done

> **[Add Skiff Mail (#2108) · privacyguides/privacyguides.org@e90fd23](https://github.com/privacyguides/privacyguides.org/commit/e90fd2377d7541ae7599e7352606b903122c6174)**
>
> Co-Authored-By: mfwmyfacewhen <94880365+mfwmyfacewhen@users.noreply.github.com>
> Co-Authored-By: Daniel Nathan Gray <48640805+dngray@users.noreply.github.com>

---

## Post 353 by @jonah — 2023-07-10T17:30:06Z



---

## Post 354 by @jonah — 2023-07-10T17:33:50Z

Since this is a pretty active thread here, I’ll remind everyone that suggestion threads get locked when suggestions are added to the site.

- If you think the Skiff Mail listing should be changed on the website, you can create a new thread in the Site Development category to discuss another change.
- If you want to discuss the privacy or security of Skiff Mail here, you can create a new thread in the Privacy category on the forum.
  - If you want to reply to an existing post in _this_ topic, you can still quote posts from this topic in your new topic. You may also consider DM’ing the poster.

- If you have another question about Skiff Mail or need support, contact Skiff directly.
