12 minute read

Last week I didn’t release any post on hardening macOS — sorry about that. I thought my witchcraft with network security was over; reality shows I was wrong. This AitM stuff drains my time, and I’m not the guy who releases weak stuff.

If you’re curious: I’m about to release a browser extension for all major platforms — Chromium, Firefox, and Safari — to help protect users. Mid or end of March 2026.

_Apart from that: today we talk communications. For a Cy[b ph]erpunk like myself, talking about communications is walking on eggshells. The risks are being too verbose and being too opinionated. If there’s anything like “talking politics at the pub” within the security scene, well — talking about communications is a great way to start a fight. And no, I don’t want to do politics._

So this will be a weird post. I’m telling you upfront.

Previous posts on this series

The postman always reads twice

Before we talk about tools, let’s establish something uncomfortable: email was never designed to be private. It was designed to be delivered. The privacy part was an afterthought — and it shows.

When you send an email, it hops between servers. Each hop is an opportunity. Your client sends it to your provider’s server. Your provider’s server talks to the recipient’s provider’s server. The recipient’s client picks it up. At each step, someone with access to those servers can read your message. Whether they do is a matter of policy, law, and opportunity — none of which you control.

This is not paranoia. This is how SMTP works. It has worked this way since 1982.

With that cheerful thought in mind, let’s talk about your options.

Email clients: the tool you actually touch

Your email client is the interface between you and your messages. It doesn’t determine who can read your email on the server side — that’s your provider’s job — but it determines how you interact with your mail, whether encryption is practical, and whether you’ll actually use it.

The main contenders on macOS:

Client Platform GPG support Cost Notes
Apple Mail macOS/iOS Plugin required (paid) Free Excellent UX, deep Apple integration
Canary Mail macOS/iOS Native, free Free/Pro Apple Mail-like experience, my choice
Thunderbird Linux/macOS/Windows Native Free Solid, cross-platform, telemetry uninspected
Outlook macOS/Windows Supported Microsoft 365 Good on Windows, loses context on Mac

Apple Mail is the obvious choice for most Apple users. The experience is excellent, the integration with the rest of your devices is seamless, and it does everything you’d expect. The only limitation worth mentioning: GPG support requires a paid plugin. If you don’t need GPG, this isn’t a limitation at all — it’s probably the right choice for you.

Thunderbird I used it for years. It’s solid, open source, cross-platform, and handles GPG natively. I’ll be honest: I’ve never properly audited its telemetry, which is a gap I’m not proud of. But if you’re on Linux — which, if you’re running a pentest setup on Arch, you are — Thunderbird is your realistic option. Not because it’s perfect, but because it works and nothing else competes.

Outlook deserves a more nuanced take than it usually gets. On Windows, in a Microsoft-heavy environment, it’s genuinely good. It works. The GPG support exists, even if it was cumbersome for a while. On Mac, it’s a nice-looking application that makes less sense the more you think about it. The G-Suite and other cross-platform alternatives exist. The Outlook mobile apps on iOS and Android are mediocre. And if you’re honest with yourself, you probably end up using webmail anyway. Good, but you have to want it.

Canary Mail is my choice. It looks and feels like Apple Mail, supports encryption natively without extra cost, and works consistently across macOS and iOS. The reason I didn’t choose Apple Mail is simple: when I made my decision, I wanted GPG support without paying extra. Canary gave me that. It’s not a dramatic choice — it’s a pragmatic one.

A note on multi-platform setups: if you run macOS and Linux, as I do, you’ll end up with Canary on the Mac and Thunderbird on Linux. Not because one is better — because that’s what the ecosystem gives you.

Email providers: the contract you sign with your data

Your client is the tool. Your provider is the contract. You can have the most privacy-conscious client in existence, but if your provider reads your email on the server side, you’re decorating a glass room.

Google has built one of the most impressive productivity suites in existence. The engineering is genuine, the tools are excellent, and some of the third-party integrations built on top of G-Suite are genuinely clever. I have a Gmail account. Several, actually. Like most people.

The trade-off is equally genuine: Google knows everything about you. Everything. Your email, your calendar, your location, your searches, your documents. They are an American company, subject to the Patriot Act — which means a government request for your data doesn’t require your knowledge or consent. This isn’t conspiracy theory. It’s US law. Choose accordingly.

Microsoft makes excellent software. Office is a formidable suite. VSCode is one of the best editors available — and it’s free, which is almost suspicious. F# is a beautiful language. The list goes on.

As an email provider, however, my answer is no. Years ago, Microsoft accessed an employee’s mailbox before terminating them — a move that, regardless of scale, said something about the culture. Setting up a Microsoft 365 organisation is an exercise in patience that borders on self-harm. And the American jurisdiction problem applies here too, in full.

Apple tries harder than the other two on privacy, and the effort is visible. Hide My Email is a genuinely useful feature — the idea of generating disposable aliases to protect your real address is sound practice. The execution, however, has limits: five aliases only, and — the detail that stings — disabling an alias doesn’t stop mail from arriving on it. For serious compartmentalisation, five aliases isn’t enough. For casual use, it’s fine.

Proton is based in Switzerland. The Swiss jurisdiction is not subject to the Patriot Act, and Proton has fought legal battles to protect user data. Client-side encryption means that Proton, technically, cannot read your email — the decryption happens on your device. It has grown into a full ecosystem: mail, VPN, calendar, drive, password manager. The VPN, if you’re on a higher tier, is among the best available.

The downside: Proton will charge you for anything beyond the basics, and the tiers escalate quickly. It’s not free if you want to use it seriously. Dear Patriot Act — not today.

Tuta is German. Hannover, specifically — subject to GDPR and German privacy law, which goes further than most. Like Proton, it offers client-side encryption. Unlike Proton, it is uncompromising to the point of being brutal: lose your recovery key, lose everything. No reset. No support ticket that saves you. This is a feature, not a bug — but it requires that you know what you’re doing. If you’ve read this far in this series, you probably do.

Note to self: being so nice to everyone will bring me a slow, painful death. Note for the reader: As you may see, I tried to supply you with a factual and non-opinionated review of the main email providers out there. Nothing new, but how can someone write anything new when trying to be nice to the world?

What I plan to do

When I find some time, I will spin up a VPS on 1984.hosting. Put a serious OpenBSD box. An even serious-er MTA. Send all logs to /dev/null. And forget about all this.

A note for my Italian readers

Italy has a thing called PECPosta Elettronica Certificata, or Certified Electronic Mail. It sounds serious. It has “certified” in the name. The government made it mandatory for professionals, businesses, and public administration. You pay for it annually. There are accredited providers. There are regulations. There are audits. There is an entire bureaucratic ecosystem built around it.

That is the theory. In practical terms, after years of Italian-ity, this is my reading: cousinocracy. In Italy, the cousin is a deity-like character. You write superb websites and want to be paid accordingly? Your customers will always have a cousin who does the same for half the price. You’re a great electrician? Well, your customer’s cousin is surely better than you. And when it comes to politics — sorry to say it bluntly, but blunt I am — politicians usually do favours for their cousins. Perhaps because they owe them a lot. Like their seat.

What does it actually do? It certifies that your email was delivered. That’s it. The content travels in plaintext. No encryption. No integrity protection. No confidentiality whatsoever. It’s a glorified read receipt — the digital equivalent of sending a letter via registered post, except the postman can read everything inside, photocopy it, and nobody considers this a problem.

Meanwhile, PGP has been freely available since 1991. It actually encrypts your content. It works internationally. It costs nothing. Phil Zimmermann almost went to prison for releasing it, because governments understood that real encryption was a threat to their ability to snoop. Italy looked at all of this, looked at decades of cryptographic progress, and decided: no thanks. We’ll build our own thing, make it mandatory by law, hand the market to a handful of accredited providers, and call it security.

The result is a system that protects nobody’s privacy, generates revenue for a cosy oligopoly of providers, and gives Italian professionals the warm feeling of compliance without any of the actual security. Brilliant, really. In the most depressing way possible.

If you ever needed a textbook example of security theater institutionalised by law, benvenuti in Italia.

For what it’s worth: find the cheapest provider. They all do the same nothing.

PGP: the standard nobody loves and everyone uses

PGP — Pretty Good Privacy — has been the de facto standard for email encryption since 1991. It’s not the most elegant solution. The key management is arcane, the web of trust is effectively dead, and the user experience hasn’t aged particularly well. But it works, it’s interoperable, and — crucially — it’s what your counterpart probably supports, if they support anything at all.

In practice, PGP gives you two tools: encryption and signing. Encryption hides the content of your message from anyone without the recipient’s private key. Signing proves that the message came from you and hasn’t been tampered with. They are different operations, and you don’t always need both.

A word on using them: resist the temptation to encrypt and sign everything by default. It sounds like the maximally secure approach, but in practice it means entering your passphrase on every message. Which means either a weak passphrase — because you’re entering it fifty times a day — or a saved passphrase somewhere that isn’t your password manager. Neither is what you want. Use encryption and signing when they matter. That’s what they’re for.

Canary Mail, for what it’s worth, handles this well — it asks you explicitly what you want to do with each message, on both macOS and iOS. That pain is a feature.

Are there better alternatives? Technically, yes.

Age is a modern encryption tool — simpler, cleaner, better algorithms. But it’s designed for files and data, not email. No equivalent ecosystem.

S/MIME is the enterprise alternative — certificate-based rather than web-of-trust-based, better integrated into corporate email clients. Requires a CA, costs money, and is more closed than PGP.

Signal Protocol is cryptographically superior for messaging — perfect forward secrecy, double ratchet algorithm. But it’s for chat, not email.

The honest answer: PGP is the standard not because it’s the best, but because it’s the one your counterpart might actually have. In encryption, as in so many things, interoperability beats theoretical perfection.

Chat: you don’t choose your app — your contacts do

I’ll be honest: I’m not a chat person. Chat is an invasion. It’s an abuse of your time, dressed up as convenience. If you DM me, don’t expect a prompt answer. Or a kind one. But I will answer.

With that established: the landscape is what it is.

Signal is the pragmatic choice. End-to-end encrypted by default, open source, audited, minimal metadata collection. The Signal Protocol is genuinely good cryptography. The usability is acceptable. Enough people use it to make it useful — which, in secure messaging, is the critical variable.

WhatsApp is end-to-end encrypted, technically. It also belongs to Meta, which has demonstrated, repeatedly and comprehensively, that your privacy is not the product they’re selling — you are. The encryption protects the content in transit. The metadata, the social graph, the usage patterns — those are a totally different matter.

Telegram has a reputation for privacy that significantly exceeds its actual privacy properties. Standard chats are not end-to-end encrypted — they’re encrypted in transit, stored on Telegram’s servers. Only “Secret Chats” are end-to-end encrypted, and most people never use them. The recent legal troubles of its founder add context that each reader can weigh for themselves.

SimpleX Chat is, technically, the best answer in this space. No user identifiers — no phone number, no username. Decentralised. You can run your own relay server. Metadata minimisation that takes the problem seriously. Audited and open source. I mention it in my manual as the right answer to the question nobody around you is asking. I use it. So does one other person I know.

This is the fundamental problem with secure messaging: it requires both parties to participate. You can make the right choice and find yourself talking to nobody. The most secure messaging app in the world is useless if your contacts are on WhatsApp.

The times of Messenger are over. The fragmentation is total. Pick Signal for the people who’ll use it, and make your peace with the rest.

Conclusion

Next time, we go deeper — and further from the keyboard. No tools, no configurations, no checklists. Just behaviour. The human factor is the one layer no software can harden for you, and the one layer most guides conveniently ignore.

Until then: stay paranoid, but have fun.