Remix.run Logo
Rootshell: A new E2EE email service hosted in Iceland(rootshell.is)
28 points by sc0rt 3 hours ago | 21 comments
sandeepkd 7 minutes ago | parent | next [-]

Quick question for the author in case they are here

> encryption key is derived from the password > One can use the passphrase in case password is lost

What does this really means? is the password encrypted with these pass phrases instead of being hashed?

sandeepkd 3 minutes ago | parent [-]

nvm, looks like the encryption key is derived from password, stored on the server side encrypted with these passphrases

dpoloncsak 2 hours ago | parent | prev | next [-]

I know it's in it's infancy here, but if it's a solo passion project I'd consider open-sourcing it so the E2EE can be verified.

If you plan on launching this as a monetized project of some sort, I, as a potential customer, would suffice for audits but I'm sure they can get pricey.

I'll give it a shot either way, just my two cents

sc0rt 23 minutes ago | parent [-]

I'm just a new user like everyone else commenting here. I should have been clear about that with a comment in the original post, sorry. I think x.com/rootshell0 looks like they have an X account but idk

guessmyname 36 minutes ago | parent | prev | next [-]

> Key bundle missing — please try again

I’m trying to create an account to test this service. I get this error message, what does it mean? Why is the error message so short to the point where I (the user) don’t know what to do next? Why can’t software developers learn how to communicate better with their non-tech users? And this is coming from someone with a 30+ years career in software engineering.

edit: after hitting the button “I’ve saved my recovery phrase - continue” multiple times and getting the same repeated error message, it finally worked but then the API returned “error: Registration failed”. And at this point I give up. This is why many projects, even at Big Tech companies, fail: too much friction for new users, or too many features, or too many options to choose from.

felooboolooomba 13 minutes ago | parent [-]

Hang in there mate. I've called the Whambulance.

sc0rt 32 minutes ago | parent | prev | next [-]

I am just a user who signed up for this same as everyone else here. I cannot answer any of the technical questions, but I did find an X account that looks like it is for this email server, x.com/rootshell0 Sorry I can't be more help!

ASalazarMX 2 hours ago | parent | prev | next [-]

I'd like to know more about the operator, besides them being from USA. Having the data in Iceland sounds great, but we should be wary of any new service designed specifically to attract confidential conversations.

sc0rt 30 minutes ago | parent [-]

Maybe x.com/rootshell0 is their X account? I wish I could tell you more.

mike-cardwell an hour ago | parent | prev | next [-]

You defeated https://www.emailprivacytester.com straight off. Which is more than most new email services. You seem to be relying on CSP entirely for this, but it works.

daneel_w 27 minutes ago | parent | next [-]

I gave your service a test, seeing all buttons in gray, and could not figure out if the service was broken, if my browser was broken, or if my e-mail client (Betterbird) was doing something good. Then I remembered that I use LuLu[1] to deny it all network access besides reaching my private e-mail server. Not ideal, I've learned to live with the caveats, but I do suppose it really does get the job done of stopping in-mail tracking.

[1] https://objective-see.org/products/lulu.html

mike-cardwell an hour ago | parent | prev | next [-]

You declare HSTS preload, but you are not in the preload list. You can not be added to the preload list at https://hstspreload.org/ because www.rootshell.is exists but has an invalid certificate.

Your MX TLS configuration supports various anon ciphers. These should be disabled.

Your DANE is broken. Try any of a number of freely available online validators.

mike-cardwell an hour ago | parent | prev [-]

Weirdly, if I click Load Images, all I get is a load more CSP errors and the image fetches don't happen.

Bender 2 hours ago | parent | prev | next [-]

Nice, the more stand alone non corporate email providers the better. You have it on a good host. I've never tried to email from their CIDR blocks, curious how it works out.

MikeKusold 2 hours ago | parent | prev | next [-]

I thought this was going to be related to the excellent libghostty based iOS terminal client: https://github.com/kitknox/rootshell

nubinetwork 31 minutes ago | parent | prev | next [-]

Why is it called root shell?

guessmyname 24 minutes ago | parent [-]

Because it is a shell for the root user [1].

Or at least the app’s logo is the root user symbol: a number sign [2]

Normal users typically get a $ prompt, while the superuser (root) gets a # prompt [3]

[1] https://wiki.debian.org/Root

[2] https://en.wikipedia.org/wiki/Number_sign

[3] https://unix.stackexchange.com/a/291733

cryo32 an hour ago | parent | prev | next [-]

I’m never hosting or dealing with any companies in Iceland. I had a run in with a hosting company there who was DoS attacking us from compromised nodes. I emailed them and they told me to get a letter from a local lawyer telling them to stop and they’ll look at it. In the end we contacted our DC provider and they dumped all traffic from their entire blocks.

A year later same attitude from a different one hosting a web site for Covid misinformation which was against their own AUP.

pixel_popping 2 hours ago | parent | prev | next [-]

Excellent! Simple and functional UI, Thank you for this.

ChrisArchitect 17 minutes ago | parent | prev | next [-]

Not to be confused with rootshell: macOS terminal emulator built with libghostty with powerful features https://news.ycombinator.com/item?id=48390029

paulnpace an hour ago | parent | prev [-]

Another company tried the Iceland root, and after growing steadily and without reporting issues (at least I never saw anything reported) just shut down one day.