Hacker News new | ask | show | jobs
by burrows 1576 days ago
We can do a risk profile for an email with a custom domain versus a gmail domain.

Do we need to differentiate between custom email domain with self-hosted mail server and custom email domain with gmail?

If I self-host the mail server then I’ll have a machine running on digital ocean or ec2 and this machine will accept connections from the Internet. I think this machine should be included in the assessment. So now the risk of a custom email domain depends on when/how I apply patches and how ssh access is configured?

1 comments

That is like a fraction of a fraction of a fraction of people with own domains.

I don't think that's relevant, at all.

Could you please clarify your point? I don’t understand the comment as is.
That we don't need to differentiate on that level.

We'd first have to differentiate people that write their password on post-its in an open environment. People that have the same password on all services etc.