Live data from Hacker News

Fastmail offers EU data region

fastmail.com

41–50 of 98 posts

Re: Fastmail offers EU data region

#43
post #9

EU data regions are a reflexive action by companies that try to hold on to their EU customers (and more and more are leaving, surprisingly the larger ones seem to be leading here). Realize that as long as you are still hosted on US owned infrastructure or that if there are US (or: five-eyes) owned companies anywhere in the stack your data can still be forcibly pulled and often without you being aware that this happen…

That’s true and Fastmail runs on AWS. But it’s a start and a “feature” many have requested for years. It’s funny because the HQ and I believe their workforce is located in Australia.

Re: Fastmail offers EU data region

#44

If what you need is a guarantee that your data remains only in the EU, we don’t have that, and we’d rather tell you directly than let you assume otherwise. Is there an alternative that really keeps data in the EU? (And not only in the sense it serves a sales promotion)

I do not know any EU-only, but ProtonMail is in Switzerland.

Re: Fastmail offers EU data region

#45
post #9

EU data regions are a reflexive action by companies that try to hold on to their EU customers (and more and more are leaving, surprisingly the larger ones seem to be leading here). Realize that as long as you are still hosted on US owned infrastructure or that if there are US (or: five-eyes) owned companies anywhere in the stack your data can still be forcibly pulled and often without you being aware that this happen…

Yeah, this does absolutely not solve the CLOUD Act issues. However, it is good to look at what the ramifications of the CLOUD Act is for e-mail:

- The US could request your data. You probably shouldn't use e-mail for anything sensitive anyway for many reasons. E-Mail was traditionally not encrypted and I think that many servers still allow plain-text communication. The protocols are old and there are all kinds of downgrade attacks. Aside from that, even if your service does not fall under the CLOUD Act, you are probably f*cked anyway, because most people you communicate with are using services that fall under the CLOUD Act.

- The US can force the provider to block your account. The workarounds are: regularly backup your e-mail (easy for services that offer IMAP) and, most importantly, use a domain with an extension that is not under the control of a US (or probably five eyes) registrar.

Use an E2E-encrypted messenger with perfect forward secrecy, etc. for most personal communication.

Re: Fastmail offers EU data region

#46
post #31
post #9

EU data regions are a reflexive action by companies that try to hold on to their EU customers (and more and more are leaving, surprisingly the larger ones seem to be leading here). Realize that as long as you are still hosted on US owned infrastructure or that if there are US (or: five-eyes) owned companies anywhere in the stack your data can still be forcibly pulled and often without you being aware that this happen…

> your data can still be forcibly pulled and often without you being aware that this happened as a german i feel the urge to point out that this technically also applies to european companies... With more hurdles for the US, but still technically applicable

True, I think the calculus is more about who you think is more trustworthy than what tools they have to damage you.

Re: Fastmail offers EU data region

#47

If what you need is a guarantee that your data remains only in the EU, we don’t have that, and we’d rather tell you directly than let you assume otherwise. Is there an alternative that really keeps data in the EU? (And not only in the sense it serves a sales promotion)

[deleted]

Re: Fastmail offers EU data region

#48
post #33
post #9

EU data regions are a reflexive action by companies that try to hold on to their EU customers (and more and more are leaving, surprisingly the larger ones seem to be leading here). Realize that as long as you are still hosted on US owned infrastructure or that if there are US (or: five-eyes) owned companies anywhere in the stack your data can still be forcibly pulled and often without you being aware that this happen…

How does Apple handle it?

Why would apple care? Eu is what a quarter of their business? And where exactly will those people move? They're locked into the Apple infra.

Re: Fastmail offers EU data region

#49

Posted on the previous submission for this: it’s a good start, but from the article: If what you need is a guarantee that your data remains only in the EU, we don’t have that, and we’d rather tell you directly than let you assume otherwise.

Wow they completely missed the ball on why people want reassurances that their data stays in the EU

I think they just know what they can and can't guarantee.

Re: Fastmail offers EU data region

#50

If what you need is a guarantee that your data remains only in the EU, we don’t have that, and we’d rather tell you directly than let you assume otherwise. Is there an alternative that really keeps data in the EU? (And not only in the sense it serves a sales promotion)

Depends on the definition and your threat model but to make a very large story short; it’s email, others have copies (your gmail friends?). Metadata is public by default the body can be encrypted and encrypted at rest (comes with many limitations) and that’s the highest level of security you can realistically achieve.

If that works fine if not, use another method of comm. Email wasn’t designed to be secure.

Post reply on HN