[HN Gopher] ProtonMail Is Down
       ___________________________________________________________________
        
       ProtonMail Is Down
        
       Author : digitalsanctum
       Score  : 133 points
       Date   : 2022-07-11 15:04 UTC (7 hours ago)
        
 (HTM) web link (protonstatus.com)
 (TXT) w3m dump (protonstatus.com)
        
       | mattanimation wrote:
       | good thing I just bought a 24 month pro sub last week...
        
         | lizardactivist wrote:
         | It sure was an excellent purchase -- one of the most secure
         | services available world-wide, operated in the EU with strong
         | privacy and completely outside US jurisdiction.
         | 
         | You weren't able to collect your emails for a brief 5 minutes,
         | but you'll live.
        
           | martin8412 wrote:
           | Switzerland is not in the EU.
        
             | [deleted]
        
           | rdevnull wrote:
           | Hello from Switzerland :) We are not in the EU not just
           | "technically" but as a fact. None of these agreement covers
           | the exchange of private emails or metadata with the EU.
        
       | 2Gkashmiri wrote:
       | 2 things to ask.
       | 
       | 1. why don't people selfhost email more? mailinabox is pretty
       | painless to set up and would give you infinitely more
       | security/privacy whatever you want. 2. why is email
       | deliverability still an issue? why do you need to use third party
       | email tools to ensure your email doesn;t go to spam? i am not
       | concerned with newsletters/ads/ that sort of thing but a
       | replacement to gmail/protonmail??
       | 
       | i have personally gone with miab like last year and beyond the
       | first few weeks of gmail putting my emails into spam(then having
       | to inform the other user to unspam it), things have been
       | painless. i get to occasionally spin up the ssh to update the
       | server but its fine. backblaze b2 backups ensure i am somewhat
       | safe(er). can it be better? yes. is it ready to be used in
       | production, aka a replacement to your regular paid/free email?
       | you be the judge but i am sold on this idea
        
         | gobip wrote:
         | You replied question 2 with question 1: we don't self host
         | email, -because- of deliverability issues.
        
           | 2Gkashmiri wrote:
           | why are they in the first place?
        
             | tick_tock_tick wrote:
             | Spammers
        
             | waynesonfire wrote:
             | - because google would prefer you use gmail so they can
             | train their data models on you
             | 
             | - google would also prefer to have a monopoly on all email
             | so that g-suite is necessary to reach your customers.
             | 
             | - because your IP address was at one point an e-mail spam
             | server, but, that only really matters because of the above
             | two reasons. Any nit, however irrelevant, will be used used
             | to beat you into using gmail.
        
             | skadamat wrote:
             | Deliverability is an issue in both directions:
             | 
             | - when you send emails from MyWebsite.com, you want to make
             | sure that Hotmail, Yahoo, Gmail, Proton Mail, etc users get
             | your email.
             | 
             | - when you receive emails to your hi@mywebsite.com email,
             | you don't want spam
             | 
             | V1 of email providers ostensibly solved this problem using
             | lots of data as well as "supervised" machine learning (e.g.
             | you telling the provider that a specific email is spam).
             | 
             | Self-hosting seems awesome if you're only handing out the
             | email to a few people (probably a few hundred max?), you
             | don't think it will be widely shared, and it's a slightly
             | unique email that makes it hard for a script to guess (e.g.
             | "hello@mywebsite.com" will be easily guessed but
             | "john2@mywebsite.com" may not be)
        
         | justsomehnguy wrote:
         | You can self-host email all you want if you intend only to
         | receive. If you want to be received, by O365/Gmail - that's
         | another story.
        
         | technothrasher wrote:
         | > why is email deliverability still an issue?
         | 
         | Mostly what I've found as the main issue here is that popular
         | blacklists will blacklist entire IP blocks instead of
         | individual IPs, so you have to not only have a clean IP but
         | also be on at least a /24 with all clean IPs. This can be hard
         | to manage when relying on outside hosting. And unfortunately,
         | trying to get around it by using a cheap/free relay like Amazon
         | SES or SendGrid doesn't work, as they fail to keep their IPs
         | clean (if they're even trying).
        
       | lom wrote:
       | Was down 5 minutes ago, but is now working again for me
        
       | LeoPanthera wrote:
       | I've been having trouble with iCloud all day too. (Try Apple ID >
       | Password and Security on your iOS device). It surely can't be
       | related.
        
         | bilkow wrote:
         | A minute ago StackOverflow was also throwing "Oops! Something
         | Bad Happened!" to me on many different pages. I wonder if
         | that's somehow related or just a coincidence.
        
       | [deleted]
        
       | devmunchies wrote:
       | Has to be related to this maintenance announced a couple days
       | ago[1]
       | 
       | > _" We're conducting a short database intervention on Sunday,
       | July 10th, 2022, between 9:00 - 10:00 am GMT+2. During this time,
       | users will be unable to access all Proton services for 2-4
       | minutes. We apologize for the inconvenience."_
       | 
       | [1]: https://twitter.com/ProtonSupport/status/1545698028895584257
        
       | ugjka wrote:
       | Down hard
        
         | futuretaint wrote:
         | its like blackhawk down but w/ proton mail.
        
           | ugjka wrote:
           | I mean the connection drops immediately, unlike the other
           | times when it spins forever
        
       | cyberpunk wrote:
       | I mean, no one cares if accessing mail is down, but it looks like
       | their MX is down, the status page reports incoming mail has a
       | 'partial' outage.
       | 
       | I don't care if I can't access my email for a while.
       | 
       | I very much care if email sent to me isn't received. They should
       | just be dumping all mail received at their MX's to maildirs or
       | something if it's this bad and process them properly later.
       | Losing data is not ok.
        
         | cmeacham98 wrote:
         | SMTP is literally built with this scenario in mind. As long as
         | their servers aren't incorrectly reporting a success the sender
         | will (or at least should) retry.
        
         | [deleted]
        
       | Ancapistani wrote:
       | Sorry about that.
       | 
       | I just moved the domain for my small business over to ProtonMail
       | (where I already hosted my personal email). The fact that I did
       | that guaranteed that it would go down. :)
        
         | browda wrote:
         | I was logged-in -- and composing a message -- a few minutes
         | ago. First there was that cannot reach backup server message
         | followed by a bunch (don't you just love technical jargon?) of
         | messages saying "Could not..." and then lost the message when
         | the site itself apparently went down. (Well, Firefox was
         | seriously unhappy...) I was ready to blame my ISP again but no,
         | this one is on proton mail. (It's pingable and traceroute is
         | happy.)
         | 
         | I'm really glad that we didn't move our business over...
        
       | [deleted]
        
       | Trias11 wrote:
       | Slower login, but works
        
       | DavideNL wrote:
       | " _Proton Mail mobile apps are are now operational again, and so
       | is Proton Calendar._ "
       | 
       | https://nitter.net/ProtonSupport
       | 
       | also RSS feed:
       | 
       | https://nitter.net/ProtonSupport/rss
        
       | amatecha wrote:
       | Rather ironically, the site they link to for the incident status
       | updates ( https://status.protontech.ch/incidents/195 ) is not
       | loading for me: "The connection has timed out"
        
       | motohagiography wrote:
       | Irony is the people most likey affected by a protonmail outage
       | would be political staffers and strategic PR firms who would
       | suddenly need to use messengers subject to disclosure.
       | 
       | As someone taken out by the Rogers outage last week, I'd be
       | concerned the infrastructure of western powers may be too fragile
       | to project power in a seriously contested conflict.
        
       | Jaepa wrote:
       | I'm kind of curious what the source of the outage is.
       | 
       | It looks like most of their services are down, including their
       | incident status page1. The number of things I can think of that
       | so many different services & are not a massively catastrophic
       | failure is pretty small. Though that may be a lack of imagination
       | on my part.
       | 
       | 1: https://status.protontech.ch/incidents/195
        
         | krn wrote:
         | > The number of things I can think of that so many different
         | services & are not a massively catastrophic failure is pretty
         | small.
         | 
         | Like, for instance, a simple DNS or BGP misconfiguration that
         | takes the entire network down?
         | 
         | Cloudflare (June 2022):
         | 
         | https://news.ycombinator.com/item?id=31823132
         | 
         | OVH (October 2021):
         | 
         | https://news.ycombinator.com/item?id=28849319
         | 
         | Facebook (October 2021):
         | 
         | https://news.ycombinator.com/item?id=28752131
         | 
         | Google (June 2019):
         | 
         | https://news.ycombinator.com/item?id=20077421
        
           | 29083011397778 wrote:
           | We don't know for certain, but you may have missed Rogers [0]
           | - which brought down cell phones (every function but wifi),
           | debit transactions, and 911 services.
           | 
           | [0] https://en.m.wikipedia.org/wiki/2022_Rogers_Communication
           | s_o...
        
           | tick_tock_tick wrote:
           | No ones it too big to not fuck up BGP or DNS from time to
           | time.
        
         | guerrilla wrote:
         | Maybe it's the same hard drive problem a lot of others
         | (including HN) had.
        
         | 0xbadcafebee wrote:
         | Doesn't have to be catastrophic failure. Most people just
         | assume that such services are architected properly to be HA,
         | but they usually aren't. They also aren't operated as HA
         | usually, so things like a config change are rolled out globally
         | to everything at once, and then everything breaks and they
         | can't roll back, and you have total outage. Very common.
         | 
         | ...and of course, they might not be down at all, it might just
         | be (example) a route from the west coast got fucked in a BGP
         | table so the west coast can't access it, and if that's where
         | the majority of their users are that's all the comments you'll
         | see.
        
           | sllabres wrote:
           | A bit nitpicking but even with a proper implemented HA
           | solution there would be a service interruption.
        
           | confounded wrote:
           | What is HA?
        
             | detaro wrote:
             | high availability
        
             | Pryde wrote:
             | High Availability
        
         | IG_Semmelweiss wrote:
         | I'm seeing their status page up now.
         | 
         | But they are down hard otherwise.
        
           | jjtheblunt wrote:
           | maybe the status page is therefore also down, misleadingly
           | showing its last pre-down state
        
         | willis936 wrote:
         | They have another status page that currently reports everything
         | is up (it isn't).
         | 
         | https://status.proton.me/
        
           | LeifCarrotson wrote:
           | And another that says that some systems (many systems) are
           | experiencing issues/in a state of "partial outage":
           | 
           | https://protonstatus.com/
        
           | KineticArms wrote:
           | "An error occurred on client"
        
         | 0xbadcafebee wrote:
         | https://protonstatus.com/incidents/195#update-201       45
         | minutes ago : Our engineering team is working on a database
         | performance issue which is impacting Proton services
         | 
         | Relational database woes. :( Probably re-indexing or slow
         | queries or something. This is why companies with an RDBMS as a
         | SPOF need a good DBA.
        
       | badrabbit wrote:
       | I thought it was my phone or vpn, I restarted it many times.
       | Where would I be without HN :-)
        
         | Aardwolf wrote:
         | 3 days ago, not very far!
         | 
         | https://news.ycombinator.com/item?id=32023848 [Hacker News was
         | down]
        
           | willis936 wrote:
           | Geez if both were down at the same time I might have no
           | option but to touch grass.
        
         | vaylian wrote:
         | funny that you say that: "HN is up again"
         | https://news.ycombinator.com/item?id=32026571 2 days ago
        
         | john-radio wrote:
         | > Where would I be without HN :-)
         | 
         | Reading the regular news like an idiot!
        
       | usr1106 wrote:
       | Just remember, clicking on refresh and searching the net what is
       | going on want make the problem go anyway faster. Few of us
       | urgently depend on email just this hour. An even if you do
       | setting your alarm to some suitable interval and just doing
       | something else is much more productive. Just act like the Arab
       | cliche taxi driver who takes the hands of the steering wheel when
       | it gets tight and say Allah will steer (No insult to anyone, I
       | have never visited any Arab country. Probably the story is not
       | true anyway, but a nice anecdote to accept things you cannot
       | change.)
       | 
       | When hackernews was down recently I wanted to report it as big
       | news in our company chat. But it was rather late here and I had
       | already closed all work stuff for the weekend. So I first slept
       | and when I woke up everything was working again. Oh yeah, I
       | missed to share the scoop with my colleagues, but I guess I'll
       | manage without any damage to my professional reputation.
       | 
       | Edit: Reading post-mortem afterwards is a different story. If
       | it's well written instead of some corporate communications
       | emptyspeak one can learn something. No mistake happens only once.
        
         | gruez wrote:
         | >Few of us urgently depend on email just this hour.
         | 
         | I agree that you shouldn't be manically refreshing your email
         | every 5 minutes, but my mail service being down for a few hours
         | would definitely be a major inconvenience if I needed to get a
         | 2fa code during that time. Same if I needed to look at my email
         | to view my tickets for an upcoming event.
        
           | favourable wrote:
           | It's a misfeature using e-mail for 2FA login codes. TOTP is
           | far more reliable. Any service doing e-mail only 2FA should
           | be called out and questioned. Never assume a user has access
           | to their email at all times.
        
             | usr1106 wrote:
             | Right, I must admit I had never heard of email being used
             | for 2FA codes. Is that some kind of standardized protocol
             | or something completely homegrown?
             | 
             | In the far past (and still today with 2 banks) I use
             | hardware/smartcard based solutions. But everything vaguely
             | IT world seems to use TOTP. They typically advertise it as
             | Google Autenticator, but I use different FOSS
             | implementations on both PC and phone and they have worked
             | 100% smoothly.
        
           | usr1106 wrote:
           | That sounds like an fragile setup if you depend on a single
           | email account to get 2FA codes. I have them configured
           | typically on my office workstation (reachable remotely if
           | everything works), on my laptop, on my phone, and I have the
           | static backup codes in my password manager which is also
           | distributed over several indpendent machines.
           | 
           | Of course if you have to respond to incoming tickets within a
           | guaranteed short timeframe that gets a problem if nothing can
           | come in.
           | 
           | Make your risk assessment in advance: Can I live without it
           | for a while, in the worst case even until I have an
           | alternative provider? If so then just do so when an outage
           | happens. If that's not acceptable for your case you need to
           | have an independent backup before the first outage.
        
       | Eddy_Viscosity2 wrote:
       | I'm on it now, must be back up?
        
         | hamaluik wrote:
         | Still down for me :(
        
         | Eddy_Viscosity2 wrote:
         | Correction, its down.
        
         | IG_Semmelweiss wrote:
         | Agreed. I'm back up too
        
       ___________________________________________________________________
       (page generated 2022-07-11 23:02 UTC)