Live data from Hacker News

The FastMail Security Mindset

blog.fastmail.com

41–50 of 301 posts

Re: The FastMail Security Mindset

#42
post #10

Wow what a coincidence — I switched from Gmail to Fastmail exactly 1 year ago today. I couldn't be happier. I mostly use native clients, but the Web client is a joy to use, and everything I've observed about Fastmail gives me confidence in their service. I never used the Gmail-exclusive features like labels, so switching was pretty easy. I highly recommend it to anyone considering it. Keep up the good work, guys.

I'm considering switching (in fact I just registered for the FastMail trial). I'm especially interested in the ability to use catchall addresses with a custom domain, which would allow me to give out an address like , and thus determine who shared my email address if I start receiving spam at that address. This is partly possible with Gmail, as you can use addresses like , but not all sites support emails with a + in…

I haven't had any downsides at all, for my use cases. I've heard from a few folks that lack of "labels" is a bummer (if you rely on them in Gmail), and their mobile clients aren't quite as good (though I've never used them).

Re: The FastMail Security Mindset

#43
post #10

Earlier quoted context omitted.

I'm considering switching (in fact I just registered for the FastMail trial). I'm especially interested in the ability to use catchall addresses with a custom domain, which would allow me to give out an address like , and thus determine who shared my email address if I start receiving spam at that address. This is partly possible with Gmail, as you can use addresses like , but not all sites support emails with a + in…

I do precisely this with Fastmail and it works a treat. Setting up Fastmail with a custom domain was a joy, I can easily filter based on the To address, and you can setup a wildcard identity so you can trivially send email from whatever name you like at your domain. To me the only downside is the mobile app isn't quite as polished as Gmail. It doesn't work offline, and I notice occasional bugs or awkwardnesses. But i…

> To me the only downside is the mobile app isn't quite as polished as Gmail. It doesn't work offline, and I notice occasional bugs or awkwardnesses. But it's still very usable, and I much prefer the Fastmail web interface to Gmail.

But FastMail supports other clients, right? I don't want to be forced to use their web interface or their app; I'm happy with the Apple-written Mail apps.

Re: The FastMail Security Mindset

#44
This is an entry in FastMail's series of Advent Calendar blog posts that they do every year. I'm glad to see them continue the tradition this year, and it's valuable to get this level of insight into a company that I trust with my mail. If you're interested in seeing more, check this year's first Advent Calendar post which has links to their calendars from 2014, 2015, and 2016, which are all worth reading if you're a FastMail customer or just interested in how running a mail hosting company works: https://blog.fastmail.com/2017/12/01/fastmail-advent-2017/

Re: The FastMail Security Mindset

#45

Wow what a coincidence — I switched from Gmail to Fastmail exactly 1 year ago today. I couldn't be happier. I mostly use native clients, but the Web client is a joy to use, and everything I've observed about Fastmail gives me confidence in their service. I never used the Gmail-exclusive features like labels, so switching was pretty easy. I highly recommend it to anyone considering it. Keep up the good work, guys.

Been using them for a few years now and they're great. Some things I like: - plays nice with mbsync - sane system: real folders, not labels - customer service with an IRL person - identities feature

Out of curiosity, why do you consider folders to be sane, and labels not?

To me I always found labels to be the exact same as a folder, but not bound to a single instance. Ie, it is everything a folder has, and more. What am I missing?

Re: The FastMail Security Mindset

#46
post #40

Wow what a coincidence — I switched from Gmail to Fastmail exactly 1 year ago today. I couldn't be happier. I mostly use native clients, but the Web client is a joy to use, and everything I've observed about Fastmail gives me confidence in their service. I never used the Gmail-exclusive features like labels, so switching was pretty easy. I highly recommend it to anyone considering it. Keep up the good work, guys.

The only thing that keeps me switching away from Gmail is loosing the actual email address.

Fastmail can both send and receive your gmail address (even proxying through Google's SMTP server). So it's easy to switch over gradually, and quietly keep your existing address indefinitely

Re: The FastMail Security Mindset

#47
post #40

Wow what a coincidence — I switched from Gmail to Fastmail exactly 1 year ago today. I couldn't be happier. I mostly use native clients, but the Web client is a joy to use, and everything I've observed about Fastmail gives me confidence in their service. I never used the Gmail-exclusive features like labels, so switching was pretty easy. I highly recommend it to anyone considering it. Keep up the good work, guys.

The only thing that keeps me switching away from Gmail is loosing the actual email address.

Why not POP forward? You can also set a custom From...I use a custom domain instead of my old gmail because I was tired of hopping from juno to yahoo to gmail to fastmail.

Re: The FastMail Security Mindset

#48
post #43

Earlier quoted context omitted.

I do precisely this with Fastmail and it works a treat. Setting up Fastmail with a custom domain was a joy, I can easily filter based on the To address, and you can setup a wildcard identity so you can trivially send email from whatever name you like at your domain. To me the only downside is the mobile app isn't quite as polished as Gmail. It doesn't work offline, and I notice occasional bugs or awkwardnesses. But i…

> To me the only downside is the mobile app isn't quite as polished as Gmail. It doesn't work offline, and I notice occasional bugs or awkwardnesses. But it's still very usable, and I much prefer the Fastmail web interface to Gmail. But FastMail supports other clients, right? I don't want to be forced to use their web interface or their app; I'm happy with the Apple-written Mail apps.

Yes, they support SMTP and IMAP just fine. In fact, they're one of the few providers that actually support IMAP push with iOS's Mail: https://blog.fastmail.com/2016/12/21/what-we-talk-about-when...

Re: The FastMail Security Mindset

#49
post #10

Earlier quoted context omitted.

I'm considering switching (in fact I just registered for the FastMail trial). I'm especially interested in the ability to use catchall addresses with a custom domain, which would allow me to give out an address like , and thus determine who shared my email address if I start receiving spam at that address. This is partly possible with Gmail, as you can use addresses like , but not all sites support emails with a + in…

I have my mail hosted at Zoho and they support this. Edit: Simply throwing this out there in case Fastmail doesn't and you're looking for alternatives. Not shilling for Zoho.

Looks interesting. It seems (from a quick look) like it tries to be a replacement for a lot of Google products, including Docs. It's nice to see that Google and Microsoft have smaller competitors in this area.

Personally, I'm only interested in email. But thanks for letting me know about other options!

Re: The FastMail Security Mindset

#50
post #33

Earlier quoted context omitted.

ProtonMail's web client is open source, and can be deployed locally if you wish to avoid scenarios where an evil application is deployed. Their native apps are unfortunately not open source, though.

Deploying a browser Javascript application locally does not automatically protect you from serverside malicious Javascript; you have to know a lot more about how the application is structured to know whether it's even helpful.

Deploying any application locally puts you entirely at mercy of whoever wrote it, and those that know how to abuse it. That holds true for any type of application.

However, in this context, deploying this particular self-contained application locally protects against the hypothetical attack where a genuine application is later modified to turn malicious. It is relatively easy to look for and identify any execution of server-side content.

To prove that an application is not intentionally malicious, you would have to inspect the source. To prove that an application cannot be malicious, directly or indirectly, intentionally a not, you will need full formal verification of the application. And that verification only holds if you have formal verification of what it runs on.

Post reply on HN