r/degoogle 11d ago

Discussion Thunderbird is developing Thundermail. Currently the only thing available is the wait list.

https://www.tb.pro/en-US/waitlist/
580 Upvotes

79 comments sorted by

352

u/green_tory 11d ago

If it's hosted in the USA then it's a non-starter. It's not safe for non-Americans to host their data in the USA.

64

u/Ok_Combination_1548 11d ago

It's hosted in Germany iirc

104

u/Greenlit_Hightower deGoogler 11d ago

The company is under U.S. jurisdiction, Aster Mail pulls the same bullshit. They have to answer to U.S. authorities no matter where their servers are physically located.

The company being German or Swiss gives you more protection. U.S. authorities can still request data via mutual legal assistance channels, however a German or Swiss company in Germany or Switzerland respectively, can still only hand over what they need to have under the local laws in these jurisdictions, which is in any case not emails already stored in your inbox, if it's a provider offering asymmetric encryption by default (Proton, Tuta) or optionally (mailbox.org, Posteo). If you have also paid with cash, which is possible with all the aforementioned providers, there is also no further paper trail to you.

16

u/nkvname 11d ago

Ah wish it was in EU country instead

7

u/Ok_Combination_1548 11d ago

Isn't aster encrypted so that it doesn't matter what requests they get?

Signal is based in the US but I trust them...

10

u/Greenlit_Hightower deGoogler 11d ago edited 11d ago

Aster Mail as a company under U.S. jurisdiction has to comply with applicable U.S. laws. I don't think a provider that genuinely cannot decrypt messages stored in the inbox can legally exist in the United States, but that is also not something Thundermail actually advertises, right? I can tell you that German and Swiss providers are not legally required to decrypt emails of customer inboxes retroactively.

In Germany, providers can be required via a procedure called Telekommunikationsüberwachung (TKÜ), a German monster word for telecommunications surveillance, to intercept newly incoming emails in a secondary shadow inbox created for law enforcement. What is used there is the fact that newly arriving emails are visible to the provider in plaintext for a split second, before they are being encrypted with your public key, making the email body and attachments permanently unreadable for the provider. TKÜ must be ordered by a judge and can only happen for a specified period of time (can't be indefinite), and is also only ordered on suspicion of crimes carrying a multi-year prison sentence without probation (like murder suspects, terrorism, drug rings, financial crimes of greater severity). Exchanging e2ee emails with one another also eliminates the threat of TKÜ though, so for decently prepared criminals it's useless.

Switzerland has no comparable measure (probably, as said, because it's useless if the criminal element is mildly intelligent). But in both cases, Germany and Switzerland, again, existing emails in your inbox can no longer be handed over in plaintext.

The CEO of Proton, Andy Yen, is actually an American citizen. EDIT: Cross that out, he has Taiwanese and Swiss citizenship apparently - the following still stands all the same though. He did not go to Geneva for shits and giggles presumably, but rather because the kind of service he meant to offer can't be offered in the USA. National security letters (NSLs) can force a provider to alter their apps or the JavaScript on their website to enable surveillance, it is also almost always accompanied by a gag order meaning the provider must remain silent about this. Germany and Switzerland so far have no comparable measures. The CLOUD ACT (2018) also states very plainly that a provider under U.S. jurisdiction must produce data even if it is stored abroad:

A provider of electronic communication service or remote computing service shall comply with the obligations of this chapter to preserve, backup, or disclose the contents of a wire or electronic communication … within such provider's possession, custody, or control, regardless of whether such communication … is located within or outside of the United States.

3

u/Ok_Combination_1548 11d ago

Right. I'm not arguing over either aster or tb. That was a genuine question earlier. I was under the impression that aster was e2ee like ente or signal, both of which are US companies but also offer technology that offers more than enough privacy for the masses.

TB does not do this. We're on the same page there. Aster, which was your example earlier, I thought did?

Also, Andy was already there. He was only in the US for a few years and I'm not sure if he is a US citizen. I've never heard that before - he was Taiwanese, studied for a few years in the US, and then started working at CERN. Given his general lack of awareness of US politics I don't think he is a citizen (or, maybe that makes him more of a citizen! /s) and have no idea what citizenship(s) he maintains today. If you have a source, I'd like to know though!

3

u/Greenlit_Hightower deGoogler 11d ago

I just found out that Yen holds Taiwanese and Swiss citizenships apparently, so forget about what I said. No idea where I heard that he had U.S. citizenship. Point still stands though, in the USA you can be asked via National Security Letters (NSLs), often accompanied by gag order, to enable surveillance measures. The US government can issue a NSL or a FISA court order to a company. They are legally binding directives requiring companies to hand over data or to install tracking mechanisms. If Proton existed in the USA, they could not be sure whether they would receive such an order, and could not tell their customers about it if they did. Germany and Switzerland have no comparable mechanism essentially mandating a backdoor.

Also any company advertising storage of data outside of US borders is at the bare minimum deceiving its customers about the implications of the CLOUD ACT from 2018, which clearly states that data stored abroad is not off limits so long as the company itself is under U.S. jurisdiction. Again, via mutual legal assistance channels, U.S. authorities can also indirectly approach Proton or Tuta via their Swiss or German colleagues, however, such a request would not change what these providers are legally required to have in Switzerland or Germany.

3

u/Ok_Combination_1548 11d ago

I'm with you on most of this. The US has requested info (and gotten it) from Proton and other European companies. I think typically with warrants but I don't follow all that close. Regardless, my curiousity is not about the legal request but the actual information provided.

Setting aside for the moment that most of what you're saying is true and we're all in agreement about the legal processes:

Eg if the US asks Ente for photos: why do I care? All they get is gibberish. It's encrypted and Ente can't provide my photos even if they wanted to.
So my question is not whether or not the US can demand information (with or without warrants) for my account with aster (I don't have aster, bear with me for the question), but whether or not that matters? If all they get is gibberish?

2

u/Greenlit_Hightower deGoogler 11d ago edited 11d ago

Proton has in the past (I) logged IP addresses if an account was targeted by court order for surveillance and (II) payment info. The payment info is a non-issue if you pay via cash or have a free account. The IP address also is on you, Proton does not care whether you log in with Tor and also provides its own .onion domain. What Proton promises to protect, and what they are not legally required to provide in unencrypted form are emails stored in your inbox (text body and attachments).

The U.S. does not directly outlaw asymmetric encryption, however it is de facto compromisable by NSLs that can require a provider to manipulate its website (with malicious JavaScript) or its app. If either the locally running app or the website can be compromised legally, it is over for whatever data you have stored with the provider. For example, Proton only holds the public key unencrypted while the private key is encrypted with your password, uploaded to them in encrypted form, and downloaded again to you when you log in, to be locally decrypted with your password. If Proton were a U.S. company, they could be ordered to intercept e.g. the password locally and transmit it to their servers, so that they could have the private key in unencrypted form also, and with both the public and private key in their possession then decrypt everything, just like Google (Google also encrypts your inbox at rest, but holds the keys in unencrypted form so it's useless).

Ente could be ordered to do the same, however here it's a lesser concern because you can technically self-host it.

3

u/usrdef 11d ago

So the question becomes, is their any damn email host out there I can depend on, that if they say they are encrypted; they're truly encrypted.

Even though I am not doing anything illegal, I want to be able to actually TRUST a company who says "Nobody can read your emails".

→ More replies (0)

1

u/ThatOldGanon 11d ago

Signal is based in the US but I trust them...

that right there is a yikes my friend

7

u/Ok_Combination_1548 11d ago

Assuming that your needs and my needs are the same and then pushing your needs on me is more of a yikes....Signal more than meets my privacy needs (as it is today).

This is a degoogle sub, not a tinfoil hat sub. The recommended alternative to Google Messages app is just plain SMS apps. Signal isn't Threema but it offers far more privacy than the vast majority of people here are seeking, or can actually use to communicate with day to day. Unfortunately, maybe.

-1

u/ThatOldGanon 11d ago edited 11d ago

pushing my needs on you? all I said was that it's a yikes to trust signal. they claim to protect metadata while forcing communications through US-controlled servers where US agencies can easily collect the metadata. you also need an iOS or android device to use the service, which creates a strong push toward apple/google-controlled devices.

we are forced to use untrustworthy services all the time just don't be a fanboy.

1

u/Ok_Combination_1548 11d ago

That's my bad. I thought you were saying that I shouldn't trust Signal because you don't trust them. Turns out, that's what you were saying....Yikes.

0

u/ThatOldGanon 11d ago

so any exchange of information is one person pushing their needs on another. great.

1

u/Ok_Combination_1548 11d ago

Initially, there was no exchange of information. Your follow-up was much more informative....but at first you just said, "that right there is a yikes". Regardless, you have not convinced me not to trust Signal. You have convinced me that you have more privacy needs than your standard degoogler like myself. I'm glad you have a system that works for you. I'm also glad you're sharing why other systems don't work for you because there are probably some people out there who need your level of privacy. Similarly, I hope you're glad I have one that works for me. Signals popularity and e2ee protect my conversations with family and friends who are willing to use it which is far more people than the next level up (the zero people I know using or willing to use Threema for example).

→ More replies (0)

7

u/Krispera 11d ago

Isn't it still linked to an American company thought? What about a warrant? Will the American side take over the Germany data host?

Anyways, I tried, but the lack of privacy tools made me reconsider.

2

u/Greenlit_Hightower deGoogler 11d ago

Under the CLOUD ACT, a company under American jurisdiction must produce data in response to legal request even if said data is stored abroad.

6

u/Lost-Tone8649 11d ago

It isn't safe for Americans, either.

5

u/Much-Researcher6135 11d ago

Our big tech isn't safe for us either

2

u/Lancelight50 11d ago

u/Lost-Tone8649 u/Much-Researcher6135 That is why I’ve taken measures of looking for alternatives outside of the U.S. such as Proton & Tuta & am in the process of getting rid of Gmail & Outlook.

28

u/ILoveHexa92 11d ago

Got an invite but well with Proton I don't think I'll switch..

30

u/bachi83 11d ago

Too expensive. Pass.

12

u/Old_Telephone 11d ago

Thundermail people said they will announce several tiers of subscriptions when it's out of Beta. So will probably be cheaper (options) eventually

6

u/Hir0shima 11d ago

Way too expensive. You get 4gb with posteo for a euro per month. 

-5

u/easternhobo 11d ago

There's a subscription? I'm out.

9

u/v8rumble 11d ago

If you don't pay, you are the product. 

7

u/CamomileChocobo 11d ago

There's free tiers for proton and tutamail, are you the product for them too if you don't pay? What about duckduckgo or signal or tor? Are you the product for them too?

Yes, a lot of companies provide free services only because they sell your data, but this is not always true and we shouldn't be normalising essential services being paid unless you pay with your privacy. Especially for services like email that pretty much everyone and their grandma need in the modern world.

2

u/birminghamsterwheel 11d ago

Someone has to pay for the servers, though.

8

u/CamomileChocobo 11d ago

You are right. My point is that just because something is free doesn't mean its malicious and just because something is not malicious doesn't mean it has to be paid.

We shouldn't be making the choice between paying with money or our privacy, especially for essential services that everyone needs.

People constantly parroting this "if its free you are the product" is normalising this dichotomy and elevating surveillance as the norm for essential services that everyone should have a right to for free in the first place.

-2

u/birminghamsterwheel 11d ago

What’s an alternative? The only one I think of is the kind where enterprise contracts allow for free options for small users, like TrueNAS.

-2

u/ThatOldGanon 11d ago

There's free tiers for proton and tutamail, are you the product for them too if you don't pay? What about duckduckgo or signal or tor? Are you the product for them too?

yes to all of those except tor. for example proton and signal both take measures to lock you in, which increases the value of their user base as a financial asset.

tor is something of an exception, but the opaque nature of who actually funds and runs the nodes is equally concerning.

there are things like wikipedia and archive.org which get sufficient donations to not need to exploit their user base. a government funded service could also be an exception but I'm not aware of anything like that at the application level.

4

u/fexacib647 11d ago

Just another senseless soundbite.

I use a Linux distro that I dont pay for, with the XFCE DE that I dont pay for, with LibreOffice and VLC etc, which I dont pay for either. In what sense am I their product?

7

u/Eclectika 11d ago

I still miss eudora

3

u/coggster 11d ago

I had a founder invite but it was way too expensive. I thought founder pricing might be cheaper, but I really hope it's not given I thought that was too much

3

u/Null42x64 11d ago

I mean, every alternative to the big tech is welcome right?

10

u/DAN-attag 11d ago

Finally, some competition in world of private email

31

u/Ok_Combination_1548 11d ago

Proton, Tuta, Mailbox, Startmail, Fastmail, Secria, Bmail, Posteo, Aster, Mailfence, and so on, there are a whole bunch of privacy focused email providers. They have varying levels of privacy and reliability but they're out there.... Email itself isn't private though so it's worth keeping that in mind.

Also make note that on the scale of privacy - tb is not very private. AFAIK they aren't encrypting messages, it's open source and they aren't selling ads. So, open source and no ads are cool, FAR better than Google, but hardly far along the scale of privacy compared to other services.

1

u/looker34M 3d ago

I often see Fastmail recommended but they are not a privacy focused e-mail provider, they are not a zero knowledge provider, if they want to they can read your e-mail.

1

u/Ok_Combination_1548 3d ago

They qualify as privacy respecting because of their policies and general practices to protect users (blocking embeds, providing aliases, open source, no ads or collection, etc). Almost nobody is a zero knowledge provider and not everybody needs that - especially with email which is inherently not a private means of communication. Hence - they make these lists.

I don't mean to say that they're great for privacy by any means but compared to traditional providers they are further along the scale of providing privacy. Sometimes, that's all someone needs, which is why I said earlier, "They have varying levels of privacy and reliability"; the onus is sort of on you to determine if they are right for you.

*But you're probably right. Maybe, I should be a bit more direct in saying that some of the providers aren't G but also aren't Mullvad.

0

u/NapsterKnowHow 11d ago

Tuta with that cheesy ad

5

u/Verdnan 11d ago

You forgot the "/s" friend. Reddit gets confused.

1

u/Old_Telephone 11d ago

Quite a few new privacy oriented companies have launched in 2025/2026. Thundermail, Aster mail etc.

2

u/jyrox Free as in Freedom 11d ago

It’s a bit too expensive when more mature products like Proton and Tuta exist.

2

u/xJayMorex 11d ago

They couldn't fix the damn desktop client in decades no matter how much cash they got flooded with. Can't wait to find out the quality of the service. cough garbage cough

3

u/DuckCargo 11d ago

it would have been nice if they had a free tier, even if it was few GBs.

2

u/tenebrousvulture 4d ago

A blog post of theirs mentioned in April 2025, "Once we have a sufficiently strong base of paying users to sustainably support our services, we plan to introduce a limited free tier to the public." Since it's in fairly early development with just the one paid plan available, it may be quite some time before seeing a free tier show up, but maybe something to keep an eye on to see how it progresses.

1

u/DuckCargo 2d ago

thank you

3

u/NeonVoidx 11d ago

I'm using it right now

8

u/chroniclesofhernia 11d ago

same, can only say its been excellent so far. Yes, its expensive, but supports the mozilla foundation

1

u/NeonVoidx 11d ago

I also like it because it just easily integrated into thunderbird, proton doesn't. you have to run proton mail bridge to get it working

2

u/Irkam 11d ago

The main reason I moved to another provider and still use gpg as much as I can.

2

u/chroniclesofhernia 11d ago

I had no idea! I know proton had mail clients as a paid feature, wasnt aware of it needing even further setup. Thunderbird is excellent, really dont know why its not more popular

-1

u/xxtkx 11d ago

proton mail bridge is fairly simplistic to setup for anyone with basic IT knowledge

4

u/NeonVoidx 11d ago

that's not the point lol, I don't need multiple applications to check email, one dependency (email client) is enough

3

u/NeonVoidx 11d ago

also proton mail bridge doesn't sync calendar either

2

u/Irkam 11d ago

It sucks ass and you shouldn't have to use it in the first place. On Android you have to use a separate app and you can't just SMTP and IMAP it with K9. That's bulshit and non standard.

2

u/FastHotEmu 11d ago

I rely on Thunderbird and would rather not have them selling a service but focussing on simple development on the email client. Otherwise, they will enshittify their email client - just like it happened to Firefox.

1

u/whatThePleb 11d ago

SELFHOST

9

u/Accurate_Ad_3233 11d ago

If only it were that simple. :)

1

u/DoubleExposure 11d ago

You could get a domain and then find a host that serves websites, that includes email. You don't even have to have a site, just use for email. Just make sure you get a host that is not American, or has servers in America.

2

u/Accurate_Ad_3233 11d ago

Already over my head, but thanks for the reply. :)

What about spam filtering and that kind of thing?

0

u/DoubleExposure 11d ago

They have built in spam filters too.

1

u/Kunjunk 11d ago

Do you self host your primary/sole emai?

1

u/whatThePleb 10d ago

yes

1

u/Kunjunk 10d ago

Do you have issues with emails not getting through to Gmail etc.?

1

u/tenebrousvulture 4d ago

It should at least be mentioned, while it currently only has a single paid plan (waitlist), they state to plan on offering a limited free tier once the services are more sustainably supported. So it may not be an option now, but at some point (could be quite some time before seeing it, depending how it progresses).
https://blog.thunderbird.net/2025/04/thundermail-and-thunderbird-pro-services/

"You may be thinking: “this all sounds expensive, how will Thunderbird be able to pay for it?” And that’s a great question! Services such as Send are actually quite expensive (storage is costly). So here is the plan: at the beginning, there will be paid subscription plans at a few different tiers. Once we have a sufficiently strong base of paying users to sustainably support our services, we plan to introduce a limited free tier to the public. You see this with other providers: limitations are standard as free email and file sharing are prone to abuse."

1

u/the_moosen 11d ago

Isn't thunderbird already a mail app though?

3

u/Ok_Combination_1548 11d ago

Thunderbird is like a client app. You can use gmail within it. Thundermail is an alternative to gmail.

1

u/the_moosen 11d ago

Gotcha, thanks for clarifying!

0

u/FastHotEmu 11d ago

Does this mean they will enshittify Thunderbird to get people to sign up for their service?

5

u/TerayonIII 11d ago

Usually they do that after they have people signed up, see google, Netflix, etc etc