Live data from Hacker News

The FastMail Security Mindset

blog.fastmail.com

81–90 of 301 posts

Re: The FastMail Security Mindset

#81

Wow what a coincidence — I switched from Gmail to Fastmail exactly 1 year ago today. I couldn't be happier. I mostly use native clients, but the Web client is a joy to use, and everything I've observed about Fastmail gives me confidence in their service. I never used the Gmail-exclusive features like labels, so switching was pretty easy. I highly recommend it to anyone considering it. Keep up the good work, guys.

The only thing that I complain about with Fastmail is the lack of ability to use the calendar outside of the web UI. The email side is fantastic.

Maybe try again; I use the calendar with Mac and GNOME native calendar programs just fine

Re: The FastMail Security Mindset

#82
post #64

I was a very happy FastMail customer until a hacker asked them to reset my password. After _incorrectly_ answering a handful of questions asked by the FastMail support, the recovery email address was changed and a password reset link sent. From there, the hacker attempted password resets on other services. Initially, FastMail was dismissive that this was a simple "mix-up" and didn't disable access to the hacker for 7…

That is a very weird thing to do, and easily fixed. Just do an average of log-ins per day/week, and do not accept any reset passwords (from customer support) before that avg time has elapsed (+ an uncertainty) since the last time you checked the email.

How come they accepted the reset? Were you not logging in your account?

Re: The FastMail Security Mindset

#83
post #80
post #64

I was a very happy FastMail customer until a hacker asked them to reset my password. After _incorrectly_ answering a handful of questions asked by the FastMail support, the recovery email address was changed and a password reset link sent. From there, the hacker attempted password resets on other services. Initially, FastMail was dismissive that this was a simple "mix-up" and didn't disable access to the hacker for 7…

Did you also have 2fa?

No, I did not. And I certainly should have.

However, 2fa would not have prevented the problem. The problem is twofold -- 1) account recovery (using email, SMS, or anything other than a secret key) is an effective attack vector. Especially SMS. 2) a human who will change the account recovery settings (in my case, FM changing the account recovery email address).

Re: The FastMail Security Mindset

#84

I see the usual comment about Fastmail (comparison to Gmail, ProtonMail, web interface, spam filtering performance, servers in the US, ...) but still nothing about the TOS, which seems more important to me So here it is again: - Fastmail can immediately cancel your account for any reason: "The Service Provider may terminate your access to any part or all of the Service and any related service(s) at any time, with or…

No, that TOS was amended several months ago, to among other things, get rid of that clause about termination for any reason. "We used to be able to terminate your account at any time and for any reason. Now, we can only do so if you: fail to comply with the Terms and Conditions; if we are required to by law; or if your account is inactive for an extended period of time." [0] [1]

[0] https://blog.fastmail.com/2017/09/11/tos-update/

[1] https://www.fastmail.com/about/tos.html

Re: The FastMail Security Mindset

#85

I only see FastMail and ProtonMail mentioned on Hacker News, never in real life. To those who made the switch away from free,conventional mail services like Gmail and Outlook, what was the appeal ? What's your case for making the switch ?

I had to send more than 500 emails / day. So i switched over to FastMail.

It works well, and i like having unlimited aliases that i can kill at any moment. But there's no way of disabling deleting messages. I wanted to be extra sure i wouldn't loose any messages and what support said was basically "just don't delete them and you are all set".

What is worse, they accept the default deleting of messages of some email clients. Gmail won't allow deleting from a POP email client, which is much saner in my view.

Re: The FastMail Security Mindset

#86
post #27
post #10

Earlier quoted context omitted.

I'm considering switching (in fact I just registered for the FastMail trial). I'm especially interested in the ability to use catchall addresses with a custom domain, which would allow me to give out an address like , and thus determine who shared my email address if I start receiving spam at that address. This is partly possible with Gmail, as you can use addresses like , but not all sites support emails with a + in…

Im curious how FastMail and ProtonMail are comparison wise?

Do not forget about tutanota.com. I prefer them to protonmail since they're much cheaper and feature wise are pretty much the same.

Re: The FastMail Security Mindset

#87
post #64

I was a very happy FastMail customer until a hacker asked them to reset my password. After _incorrectly_ answering a handful of questions asked by the FastMail support, the recovery email address was changed and a password reset link sent. From there, the hacker attempted password resets on other services. Initially, FastMail was dismissive that this was a simple "mix-up" and didn't disable access to the hacker for 7…

That is a very weird thing to do, and easily fixed. Just do an average of log-ins per day/week, and do not accept any reset passwords (from customer support) before that avg time has elapsed (+ an uncertainty) since the last time you checked the email. How come they accepted the reset? Were you not logging in your account?

I was logging into my account. I discovered and reported the incident within 45 minutes of the compromise.

Re: The FastMail Security Mindset

#88
post #3

Earlier quoted context omitted.

For most providers, like Protonmail, the decryption password is the same as your login password. I'm curious what scenario you see allowing someone other than the provider to get access to your mailbox but not also your decryption key.

The decryption password is not the same as the login password for ProtonMail. Logging in at minimum requires entering your username, your login password, and your mailbox password. The result is security at rest, which fastmail does not have. ProtonMail's web app is open-source, and can be deployed locally if you wish to remove the chance of an evil app deployment. If you use the official deployment, an evil update c…

That's wrong. You no longer need a third password in protonmail. All you need to have, in order to login, is the username and a password. If you've 2FA enabled, you need the 2FA code of-course.

Re: The FastMail Security Mindset

#89
post #58

Earlier quoted context omitted.

Deploying any application locally puts you entirely at mercy of whoever wrote it, and those that know how to abuse it. That holds true for any type of application. However, in this context, deploying this particular self-contained application locally protects against the hypothetical attack where a genuine application is later modified to turn malicious. It is relatively easy to look for and identify any execution of…

No, it does not. You've missed my point. Deploying a browser JS application locally would help you if you could be sure that the application never loaded any additional Javascript from the server during execution. But browser JS applications can in fact do that, and so local deployment does not help as much as you think it does.

Yes you would probably need to play with headers.

Re: The FastMail Security Mindset

#90
The simple reason I haven't switched email providers: all my online accounts, as well as many offline ones, are tied to my gmail account.

Yes, I can set up forwarding, but that defeats the purpose of switching providers IMO (for me, the purpose would be to move away from Google completely). I don't want Google to read any of my emails period, so forwarding is not a sufficient solution.

Post reply on HN