Live data from Hacker News

The FastMail Security Mindset

blog.fastmail.com

61–70 of 301 posts

Re: The FastMail Security Mindset

#61
I see the usual comment about Fastmail (comparison to Gmail, ProtonMail, web interface, spam filtering performance, servers in the US, ...) but still nothing about the TOS, which seems more important to me

So here it is again:

- Fastmail can immediately cancel your account for any reason: "The Service Provider may terminate your access to any part or all of the Service and any related service(s) at any time, with or without cause, with or without notice, effective immediately, for any reason whatsoever, with or without providing any refund of any payments."

- Fastmail can disclose your info/data if it thinks it's in the interest of the company: "The Service Provider will not monitor, edit, or disclose any personal information about you [...] unless required or allowed by law, or where the Service Provider has a good faith belief that such action is necessary to: [...] (2) protect and defend the rights or property of the Service Provider; [...] (4) act to protect the interests of its members or others [...]

By comparison, mailbox.org TOS are much better.

Also mailbox.org offers GPG encryption, which Fastmail doesn't (AFAIK).

Re: The FastMail Security Mindset

#62
post #3

Earlier quoted context omitted.

For most providers, like Protonmail, the decryption password is the same as your login password. I'm curious what scenario you see allowing someone other than the provider to get access to your mailbox but not also your decryption key.

That's definitely not the default with Protonmail. They'll allow you to change it to that if you really want to though. On mine at least, proton prompts me for username and password, then 2 factor auth, then the decryption code.

One password is now the default for new ProtonMail accounts. For accounts that were created before this authentication was released, you will remain on 2 password until you update it in your settings.

Re: The FastMail Security Mindset

#63
I only see FastMail and ProtonMail mentioned on Hacker News, never in real life.

To those who made the switch away from free,conventional mail services like Gmail and Outlook, what was the appeal ? What's your case for making the switch ?

Re: The FastMail Security Mindset

#64
I was a very happy FastMail customer until a hacker asked them to reset my password. After _incorrectly_ answering a handful of questions asked by the FastMail support, the recovery email address was changed and a password reset link sent. From there, the hacker attempted password resets on other services.

Initially, FastMail was dismissive that this was a simple "mix-up" and didn't disable access to the hacker for 7.5 hours after my report.

To their credit, FastMail gave me a list of the email accessed and the message headers of the messages the hacker sent from my account (and then deleted -- unrecoverable).

Until and unless FastMail addresses the human factor of security, their technical security mindset is of secondary importance.

Re: The FastMail Security Mindset

#65
post #10

Wow what a coincidence — I switched from Gmail to Fastmail exactly 1 year ago today. I couldn't be happier. I mostly use native clients, but the Web client is a joy to use, and everything I've observed about Fastmail gives me confidence in their service. I never used the Gmail-exclusive features like labels, so switching was pretty easy. I highly recommend it to anyone considering it. Keep up the good work, guys.

I'm considering switching (in fact I just registered for the FastMail trial). I'm especially interested in the ability to use catchall addresses with a custom domain, which would allow me to give out an address like , and thus determine who shared my email address if I start receiving spam at that address. This is partly possible with Gmail, as you can use addresses like , but not all sites support emails with a + in…

> which would allow me to give out an address like , and thus determine who shared my email address if I start receiving spam at that address.

I've been doing this for over 15 years, but with a much simpler setup: I just forward it to another account, which for the last 10-ish years has been an @gmail address. The mails show up in my Gmail inbox as From: the original sender and To: the custom domain.

As a caution: don't forward a top-level domain. You'll get all kinds of dictionary-style spam attacks and it becomes flooded with noise. Instead, use a sub-domain, so you get for example .

Re: The FastMail Security Mindset

#66

I only see FastMail and ProtonMail mentioned on Hacker News, never in real life. To those who made the switch away from free,conventional mail services like Gmail and Outlook, what was the appeal ? What's your case for making the switch ?

I use ProtonMail for the simple reason that there is less of a chance they are selling my data and building up a user profile of me for advertisers to target.

Re: The FastMail Security Mindset

#67
post #64

I was a very happy FastMail customer until a hacker asked them to reset my password. After _incorrectly_ answering a handful of questions asked by the FastMail support, the recovery email address was changed and a password reset link sent. From there, the hacker attempted password resets on other services. Initially, FastMail was dismissive that this was a simple "mix-up" and didn't disable access to the hacker for 7…

Dear Fastmal, I am a happy customer, but very concerned by this report. Would you mind to comment?

Re: The FastMail Security Mindset

#68
post #67
post #64

I was a very happy FastMail customer until a hacker asked them to reset my password. After _incorrectly_ answering a handful of questions asked by the FastMail support, the recovery email address was changed and a password reset link sent. From there, the hacker attempted password resets on other services. Initially, FastMail was dismissive that this was a simple "mix-up" and didn't disable access to the hacker for 7…

Dear Fastmal, I am a happy customer, but very concerned by this report. Would you mind to comment?

[deleted]

Re: The FastMail Security Mindset

#69
post #65
post #10

Earlier quoted context omitted.

I'm considering switching (in fact I just registered for the FastMail trial). I'm especially interested in the ability to use catchall addresses with a custom domain, which would allow me to give out an address like , and thus determine who shared my email address if I start receiving spam at that address. This is partly possible with Gmail, as you can use addresses like , but not all sites support emails with a + in…

> which would allow me to give out an address like , and thus determine who shared my email address if I start receiving spam at that address. I've been doing this for over 15 years, but with a much simpler setup: I just forward it to another account, which for the last 10-ish years has been an @gmail address. The mails show up in my Gmail inbox as From: the original sender and To: the custom domain. As a caution: do…

> As a caution: don't forward a top-level domain.

Nice tip, I'll implement that for my setup. I had to stop a catchall on a TLD for the reason you mention and it'll be trivial to switch to a sub-domain. Thanks.

Re: The FastMail Security Mindset

#70

I only see FastMail and ProtonMail mentioned on Hacker News, never in real life. To those who made the switch away from free,conventional mail services like Gmail and Outlook, what was the appeal ? What's your case for making the switch ?

I did switch after just another chilling story about person losing his gmail account because of some machine learning security system false positive. There is essentially 0 user support from google in such cases.

And paid custom domain in google suite costs exactly the same as fastmail.

Plus email is fastmails primary business and I am their real customer.

I loved their product and their support.

Post reply on HN