Welcome to the mailbox user forum
 

Login errors

Felix Kaspar mailbox Support shared this problem 8 hours ago
Published

Hello everyone,

We’d like to provide some context regarding the current login issues, as two separate causes have coincided here. First, there was a technical glitch in our infrastructure yesterday that temporarily prevented some of our customers from logging in. The cause of this glitch has been resolved, and we apologize for any inconvenience this may have caused. We will provide more details about the exact circumstances here in due course.

Second, there is currently a separate issue affecting older browser versions: In conjunction with the latest update to the webmail client, a JavaScript error may occur in browsers that do not fully support certain modern web technologies. This error can also prevent the login process from completing successfully. This may also affect the mailbox PWA (Progressive Web App). On smartphones, the PWA relies on the device’s browser and its web technologies for certain functions. Therefore, an outdated browser can also cause the described problems when using the PWA.

To resolve the situation as quickly as possible, we have initially rolled back the update in question. We want to give all users who may encounter the JavaScript error due to an older browser version 14 days to update their browser.

To resolve the situation as quickly as possible, we have temporarily rolled back the update in question. By doing so, we aim to give all users who may be experiencing the JavaScript error due to an older browser version 14 days to update their browser. We will then roll out the update again. We sincerely apologize for the inconvenience caused and for the confusion resulting from the timing of these two separate errors.

Best regards

Replies (3)

photo
1

I can login (Vivaldi, latest), but cannot use Meet:

{"code":"invalid_tariff_id","message":"JWT contained unknown tariff_id"}
And what I can see in the JWT:

"tariff_id":"MAIL"
I'm on the standard plan.

This comment is in trash! Restore
photo
1

I strongly urge you to reconsider this plan. It is unacceptable to make updates that result in blocking access to the services for many users, just because you have an arbitrary change to make to something that up until now has been working perfectly well, clearly showing you know little enough about the users of your service as to push breaking changes without consideration for us. What you are proposing is to give us a slight reprieve, but no real choice in the matter, and this leaves a very bad taste.

What you should be doing is looking at ways to make your planned changes work for everyone, not just cut off service for those who are unwilling or unable to make the switch you arbitrarily require of us. I'm willing to work with you on this to get to a resolve that will work for everyone concerned, and am sure that others will be too.

But if you are determined to continue on this course of action knowing that it will block access for a number of your users, and with no alternative but to bend to your will offered for those of us whose service is now under threat, I shall have no option but to move my business elsewhere and recommend others to do the same. Inflexibility towards its customers is a terrible trait for a company to have.

This comment is in trash! Restore
photo
1

Hi B.,

Thank you very much for your detailed feedback. We understand that such a change is frustrating for affected users, especially if the browser they’ve been using has worked without any issues so far.

However, our decision to discontinue support for these older browsers is not arbitrary. The browser versions in question are software that has been at end-of-life (EOL) for quite some time and is no longer supported by their respective manufacturers. In particular, security updates are no longer provided for these versions.

This means that continuing to support such browsers is not merely a matter of technical compatibility. Using a browser that is no longer supported can pose a significant security risk, as known security vulnerabilities may no longer be patched. As a provider of a security-critical service, we therefore cannot and do not wish to support this situation indefinitely.

It is expressly not our goal to exclude users from our service unnecessarily. Where possible and reasonable, we therefore strive to establish transition periods and make the transition as predictable as possible. In the long term, however, we cannot offer a solution based on outdated software that is no longer supported by the manufacturer.

We regret that this necessary change will require additional effort on your part, and we hope you understand that, in the interest of the security of our services and our users, we cannot continue to support software versions that are outdated.

With kind regards


---

Felix Kaspar
Teamlead
mailbox Support

Useful Links:

d9e15a7fee470fb66af17115c3a43886

This comment is in trash! Restore
photo
1

Hello Felix, thank you for your reply. I understand the problem from your point of view, but would like to point out that my main browser is still receiving security updates from its manufacturer and has had its EOL date extended several times because they understand that there is still a sizable number of active users running it, which is exactly the attitude any sensible service provider ought to take, and especially good in their case considering they make absolutely no money from me and the product is free. And please note that another browser I tried on iOS, which failed in exactly the same way as my desktop, was not outdated, is still under active maintenance by the manufacturer, and my device meets its minimum requirements. So what am I to do in that situation?

This leaves me no choice but to go through a series of updates and migrations I would rather not do if possible (and cannot even do in the case of iOS), or to take my business elsewhere, which to be perfectly honest is looking like the more attractive option as things currently stand. I'm not averse to making changes in my own time, but being forced to do them really grates on me.

This fanatical necessity to be secure at all costs without any flexibility or choice afforded to the end user is such a huge problem of our times and I truly believe it is leading to bad outcomes being preferred for technology's sake instead of the people that have to use it. I am a responsible adult and would like to be treated as such, and given the option to make my own decisions about how and when security should be prioritised in my life, a decision I am perfectly competent to make.

This comment is in trash! Restore
photo
photo
1

Hi Felix. Thank you for this update! More specifics and nuance may be helpful for everyone. You wrote:

"Second, there is currently a separate issue affecting older browser versions: In conjunction with the latest update to the webmail client, a JavaScript error may occur in browsers that do not fully support certain modern web technologies. This error can also prevent the login process from completing successfully. This may also affect the mailbox PWA (Progressive Web App). On smartphones, the PWA relies on the device’s browser and its web technologies for certain functions. Therefore, an outdated browser can also cause the described problems when using the PWA."

  1. You may to be conflating "older browser versions" with "more private and secure" browsers. Some browsers are more locked down than others by design, or by user modification. If the latest update from Open-Xchange doesn't support fully up to date, hardened browsers, that could be a problem for a lot of us. "Most mailbox customers use X browser, so just make the switch and get over it" will not be a welcomed or helpful response.
  2. You have not named which specific "modern web technologies" the latest OX update is pushing on mailbox customers. Why not share the technical details regarding this change? I, for one, would like to know.
  3. My inability to view and edit my own encrypted documents crippled a core mailbox functionality (if indeed it was related to the update). Messing with customers ability to access their private work is a deal-breaker which deserves more investigation and explanation from the team.

I'm glad mailbox rolled back the latest update. Things appear to be working again. However, mailbox has some explaining to do over the next 14 days.

This comment is in trash! Restore
photo
1

Hi Maximus,

Thank you very much for your feedback. Those are three very important points.

1. Let me clarify: This isn’t about “certain modern web technologies”—that was poorly worded. It’s actually the other way around: the older JavaScript versions in browsers that reached their end-of-life (EOL) several years ago have caused a conflict in OX, making it impossible to log in. However, based on your description, the error occurred on a current, specially hardened browser. It would be very helpful if you could send me the name and version of the browser—feel free to email it to helpdesk@mailbox.org if you’d rather not post it here. So this isn’t about forcing users to switch to insecure browsers, but rather about the fact that outdated browsers triggered the error.

2. That wording was incorrect. The fact is that old JavaScript versions in browsers that reached their end-of-life (EOL) several years ago caused a conflict in OX, making it impossible to log in because certain requests were not forwarded correctly.

3. We’re still investigating whether there’s a connection to the update. So far, no other users have reported this behavior to us, and we haven’t been able to reproduce it yet. Here, too, it would be very helpful if you could tell us which browser you’re using and its version.

With kind regards


---

Felix Kaspar
Teamlead
mailbox Support

Useful Links:

d9e15a7fee470fb66af17115c3a43886

This comment is in trash! Restore
photo
Leave a Comment
 
Attach a file
You can't vote. Please authorize!