| ▲ | superq 5 hours ago | |||||||
EU data regions are based on the insanely flawed idea that data is: * a physical thing that can only live in one place * not copyable * can be 'contained'. The whole thing reeks of bureaucratic 'best practices' that just aren't. Even worse than that, trying to keep email restricted to the EU (or anywhere else) means that you effectively wouldn't be able to communicate with anyone in a different region, which is kinda the whole point. Why not just make your own internet next? and then you can disconnect from everyone else who is trying to hack you. Just pull your network plug. Email itself is hopelessly insecure by design anyway. Not just metadata when you are E2EE everything inside the envelope, but even basic vulns like downgrade attacks are simple because it's literally a violation of the RFCs (so you're not spec-compliant) to require TLS or any other encryption.. Why? because requiring modern crypto might interfere with deliverability and backwards compatibility. The real, deeper reason is that email is from a kinder, simpler time (well, at least simpler) and the design goals were never updated to keep up with the times. Email is what we have. Just understand its flaws and then use other tools where you can. And who cares where your email lives - it's too easy to break anyway. | ||||||||
| ▲ | preisschild 4 hours ago | parent [-] | |||||||
This is not an EU law anyways, this is snakeoil companies acting like having their data located in the EU will change who has access to it and will make it "GDPR compliant" (it wont since the CLOUD ACT still applies) | ||||||||
| ||||||||