Live data from Hacker News

The FastMail Security Mindset

blog.fastmail.com

11–20 of 301 posts

Re: The FastMail Security Mindset

#11
post #10

Wow what a coincidence — I switched from Gmail to Fastmail exactly 1 year ago today. I couldn't be happier. I mostly use native clients, but the Web client is a joy to use, and everything I've observed about Fastmail gives me confidence in their service. I never used the Gmail-exclusive features like labels, so switching was pretty easy. I highly recommend it to anyone considering it. Keep up the good work, guys.

I'm considering switching (in fact I just registered for the FastMail trial). I'm especially interested in the ability to use catchall addresses with a custom domain, which would allow me to give out an address like , and thus determine who shared my email address if I start receiving spam at that address. This is partly possible with Gmail, as you can use addresses like , but not all sites support emails with a + in…

I'm not suggesting (at all) that you use them over FastMail, but GSuite also supports catch-all email addresses.

Re: The FastMail Security Mindset

#12
post #10

Wow what a coincidence — I switched from Gmail to Fastmail exactly 1 year ago today. I couldn't be happier. I mostly use native clients, but the Web client is a joy to use, and everything I've observed about Fastmail gives me confidence in their service. I never used the Gmail-exclusive features like labels, so switching was pretty easy. I highly recommend it to anyone considering it. Keep up the good work, guys.

I'm considering switching (in fact I just registered for the FastMail trial). I'm especially interested in the ability to use catchall addresses with a custom domain, which would allow me to give out an address like , and thus determine who shared my email address if I start receiving spam at that address. This is partly possible with Gmail, as you can use addresses like , but not all sites support emails with a + in…

I use aliases (FastMail's term for custom addresses that go to the same inbox) for that reason. They work very well, and I've never had any problems setting up a new one on the fly.

Re: The FastMail Security Mindset

#13

Wow what a coincidence — I switched from Gmail to Fastmail exactly 1 year ago today. I couldn't be happier. I mostly use native clients, but the Web client is a joy to use, and everything I've observed about Fastmail gives me confidence in their service. I never used the Gmail-exclusive features like labels, so switching was pretty easy. I highly recommend it to anyone considering it. Keep up the good work, guys.

How's the spam filter compared to Gmail?

Re: The FastMail Security Mindset

#14
Any lawyers care to comment on this claim of theirs?

It has been pointed out to us that since we have our servers in the US, we are under US jurisdiction. We do not believe this to be the case.

https://blog.fastmail.com/2013/10/07/fastmails-servers-are-i...

As a non-lawyer I would expect the US to be able to serve their host with a warrant to get whatever data the judge said they could have.

Re: The FastMail Security Mindset

#15
post #10

Wow what a coincidence — I switched from Gmail to Fastmail exactly 1 year ago today. I couldn't be happier. I mostly use native clients, but the Web client is a joy to use, and everything I've observed about Fastmail gives me confidence in their service. I never used the Gmail-exclusive features like labels, so switching was pretty easy. I highly recommend it to anyone considering it. Keep up the good work, guys.

I'm considering switching (in fact I just registered for the FastMail trial). I'm especially interested in the ability to use catchall addresses with a custom domain, which would allow me to give out an address like , and thus determine who shared my email address if I start receiving spam at that address. This is partly possible with Gmail, as you can use addresses like , but not all sites support emails with a + in…

I have my mail hosted at Zoho and they support this.

Edit: Simply throwing this out there in case Fastmail doesn't and you're looking for alternatives. Not shilling for Zoho.

Re: The FastMail Security Mindset

#16
post #13

Wow what a coincidence — I switched from Gmail to Fastmail exactly 1 year ago today. I couldn't be happier. I mostly use native clients, but the Web client is a joy to use, and everything I've observed about Fastmail gives me confidence in their service. I never used the Gmail-exclusive features like labels, so switching was pretty easy. I highly recommend it to anyone considering it. Keep up the good work, guys.

How's the spam filter compared to Gmail?

I switched to FastMail from Gmail a few months ago and haven’t had any issues with spam.

Re: The FastMail Security Mindset

#17
post #3
post #2

> Just as important as what we do do is what we don’t. For example, we don’t do full message encryption (e.g. PGP) in the browser. In theory it means you “don’t have to trust us”. However in reality, every time you open your email you would be trusting the code delivered to your browser. If the server were compromised, it could easily be made to return code that intercepted and sent back your password next time you l…

For most providers, like Protonmail, the decryption password is the same as your login password. I'm curious what scenario you see allowing someone other than the provider to get access to your mailbox but not also your decryption key.

The decryption password is not the same as the login password for ProtonMail. Logging in at minimum requires entering your username, your login password, and your mailbox password.

The result is security at rest, which fastmail does not have. ProtonMail's web app is open-source, and can be deployed locally if you wish to remove the chance of an evil app deployment.

If you use the official deployment, an evil update can obtain your mailbox password, in which case the the adversary (that is, the one capable of pushing the update) observe a security level equivalent to if security at rest was not implemented. However, even in this case, the data on the mail-servers is still protected from everyone else, so while a single adversary has observed a security level identical to that of fastmail (i.e. no security at rest), everyone else still observes a secured mailbox.

Not having security at rest is, in my opinion, dangerous.

Re: The FastMail Security Mindset

#18
post #2

> Just as important as what we do do is what we don’t. For example, we don’t do full message encryption (e.g. PGP) in the browser. In theory it means you “don’t have to trust us”. However in reality, every time you open your email you would be trusting the code delivered to your browser. If the server were compromised, it could easily be made to return code that intercepted and sent back your password next time you l…

ProtonMail's web client is open source, and can be deployed locally if you wish to avoid scenarios where an evil application is deployed.

Their native apps are unfortunately not open source, though.

Re: The FastMail Security Mindset

#19
post #10

Wow what a coincidence — I switched from Gmail to Fastmail exactly 1 year ago today. I couldn't be happier. I mostly use native clients, but the Web client is a joy to use, and everything I've observed about Fastmail gives me confidence in their service. I never used the Gmail-exclusive features like labels, so switching was pretty easy. I highly recommend it to anyone considering it. Keep up the good work, guys.

I'm considering switching (in fact I just registered for the FastMail trial). I'm especially interested in the ability to use catchall addresses with a custom domain, which would allow me to give out an address like , and thus determine who shared my email address if I start receiving spam at that address. This is partly possible with Gmail, as you can use addresses like , but not all sites support emails with a + in…

I switched about 6 months ago. I love having the catchall address although I had that when google managed my custom email domain as well. The web interface is really fast as it does operations in the background so it is really responsive, even at times when your internet connection is spotty. The only real downside is that the phone app (at least the android one) wasn't that good, I currently just use IMAP and k9 mail instead which works well enough.

I did use inbox before (and I still get some email to my gmail account) and it does have nice features like snooze that I miss. But on the whole I am happy with my choice to use fast mail.

I should also add that I seem to get slightly more junk mail than I did before, but it is close and hard to tell, I have not had a real email marked as spam yet, which did happen from time to time with gmail, so this isn't a complaint, just an observation.

Re: The FastMail Security Mindset

#20
post #3
post #2

> Just as important as what we do do is what we don’t. For example, we don’t do full message encryption (e.g. PGP) in the browser. In theory it means you “don’t have to trust us”. However in reality, every time you open your email you would be trusting the code delivered to your browser. If the server were compromised, it could easily be made to return code that intercepted and sent back your password next time you l…

For most providers, like Protonmail, the decryption password is the same as your login password. I'm curious what scenario you see allowing someone other than the provider to get access to your mailbox but not also your decryption key.

That's definitely not the default with Protonmail. They'll allow you to change it to that if you really want to though.

On mine at least, proton prompts me for username and password, then 2 factor auth, then the decryption code.

Post reply on HN