Live data from Hacker News

The FastMail Security Mindset

blog.fastmail.com

91–100 of 301 posts

Re: The FastMail Security Mindset

#91
post #52

Wow what a coincidence — I switched from Gmail to Fastmail exactly 1 year ago today. I couldn't be happier. I mostly use native clients, but the Web client is a joy to use, and everything I've observed about Fastmail gives me confidence in their service. I never used the Gmail-exclusive features like labels, so switching was pretty easy. I highly recommend it to anyone considering it. Keep up the good work, guys.

Interesting. I switched a little over a year ago too. I like not being the product but find the web client painful. Specifically: 1. No Send and Archive 2. Sending is slooow. E.g. compose email, hit Send, wait several seconds, go back to Inbox. Gmail is instantaneous. 3. Hitting Reply is SLOOOOW to bring up the Reply pane. Fastmail does a POST that takes from 500ms to 5000ms (usually on the lower end but even that is…

A few years on, muting a thread is the #1 feature I miss from gmail

Re: The FastMail Security Mindset

#92
post #83
post #80

Earlier quoted context omitted.

Did you also have 2fa?

No, I did not. And I certainly should have. However, 2fa would not have prevented the problem. The problem is twofold -- 1) account recovery (using email, SMS, or anything other than a secret key) is an effective attack vector. Especially SMS. 2) a human who will change the account recovery settings (in my case, FM changing the account recovery email address).

Hmm you think they would have bypassed your 2fa as well? I wonder if FM can comment on that - it would be concerning. The "sms backdoor" is the same with gmail, etc. unless you explicitly disable it.

Re: The FastMail Security Mindset

#93

I see the usual comment about Fastmail (comparison to Gmail, ProtonMail, web interface, spam filtering performance, servers in the US, ...) but still nothing about the TOS, which seems more important to me So here it is again: - Fastmail can immediately cancel your account for any reason: "The Service Provider may terminate your access to any part or all of the Service and any related service(s) at any time, with or…

> - Fastmail can immediately cancel your account for any reason: "The Service Provider may terminate your access to any part or all of the Service and any related service(s) at any time, with or without cause, with or without notice, effective immediately, for any reason whatsoever, with or without providing any refund of any payments." Other than the last clause about "without providing any refund", I would expect t…

>Other than the last clause about "without providing any refund", I would expect this from any service provider

that's certainly not the case for office365, for example. https://www.microsoft.com/online/mosa/MOSA2014Agr(NA)(ENG)(N... . same with gsuite. https://gsuite.google.com/intl/en_in/terms/2013/1/premier_te...

>and I'd certainly never want to run a service that didn't have this in its terms.

that may make sense if it was for a free trial, or it was for a cat sharing app, but I certainly would not want my business to be dependent on a service that can be yanked away from me at any time.

Re: The FastMail Security Mindset

#94
post #65
post #10

Earlier quoted context omitted.

I'm considering switching (in fact I just registered for the FastMail trial). I'm especially interested in the ability to use catchall addresses with a custom domain, which would allow me to give out an address like , and thus determine who shared my email address if I start receiving spam at that address. This is partly possible with Gmail, as you can use addresses like , but not all sites support emails with a + in…

> which would allow me to give out an address like , and thus determine who shared my email address if I start receiving spam at that address. I've been doing this for over 15 years, but with a much simpler setup: I just forward it to another account, which for the last 10-ish years has been an @gmail address. The mails show up in my Gmail inbox as From: the original sender and To: the custom domain. As a caution: do…

The problem with this is SPF reject domains. Which means your legitimately forwarded email will simply disappear into the void. Hosting your domain at something like fastmail will not have this problem.

Re: The FastMail Security Mindset

#95

The simple reason I haven't switched email providers: all my online accounts, as well as many offline ones, are tied to my gmail account. Yes, I can set up forwarding, but that defeats the purpose of switching providers IMO (for me, the purpose would be to move away from Google completely ). I don't want Google to read any of my emails period, so forwarding is not a sufficient solution.

Isn't vendor lock in great? :) This is why I started using my own domain for emails a long time ago. Still have some stuff on my gmail, but I've mostly broken free.

Re: The FastMail Security Mindset

#96

Wow what a coincidence — I switched from Gmail to Fastmail exactly 1 year ago today. I couldn't be happier. I mostly use native clients, but the Web client is a joy to use, and everything I've observed about Fastmail gives me confidence in their service. I never used the Gmail-exclusive features like labels, so switching was pretty easy. I highly recommend it to anyone considering it. Keep up the good work, guys.

> "Wow what a coincidence — I switched from Gmail to Fastmail exactly 1 year ago today."

Same, in fact I just got my renewal notice over the weekend, which means either yesterday or today was the day I turned Gmail off for good.

> "I couldn't be happier. I mostly use native clients, but the Web client is a joy to use, and everything I've observed about Fastmail gives me confidence in their service."

I vastly prefer Fastmail's web client to any modern native client, though Claws mail comes close if only for its abundantly configurable interface. I really enjoy the extras with Fastmail too; the Notes and Files apps are perfect for quick access from any device. The fact that their iPhone app is a near perfect mirror of the desktop web client helps too.

> "I never used the Gmail-exclusive features like labels, so switching was pretty easy. I highly recommend it to anyone considering it."

Coming from over a decade of IMAP folders, I hated Gmail labels and found them awkward. Fastmail uses folders and I'm in my happy place with them.

I never thought I'd pay for email service beyond hosting my own, but Fastmail is definitely worth it to me.

Re: The FastMail Security Mindset

#97
post #92
post #83

Earlier quoted context omitted.

No, I did not. And I certainly should have. However, 2fa would not have prevented the problem. The problem is twofold -- 1) account recovery (using email, SMS, or anything other than a secret key) is an effective attack vector. Especially SMS. 2) a human who will change the account recovery settings (in my case, FM changing the account recovery email address).

Hmm you think they would have bypassed your 2fa as well? I wonder if FM can comment on that - it would be concerning. The "sms backdoor" is the same with gmail, etc. unless you explicitly disable it.

What is the sms backdoor?

Re: The FastMail Security Mindset

#98
post #51

I use FastMail and love it, but I've noticed that if I use SMTP, it leaks my IP address in the email headers, whereas using the web client does not.

That's how RFC2822 defines the email headers. That's not a leak, that's just how email works. When you send from the web app it uses that client as the originator.

Re: The FastMail Security Mindset

#99
post #64

I was a very happy FastMail customer until a hacker asked them to reset my password. After _incorrectly_ answering a handful of questions asked by the FastMail support, the recovery email address was changed and a password reset link sent. From there, the hacker attempted password resets on other services. Initially, FastMail was dismissive that this was a simple "mix-up" and didn't disable access to the hacker for 7…

Just curious...was this incident before or after they re-architected their authentication system? I believe that was done last July[1]. The new system is really nice, now implementing separate app-specific passwords as well as new emergency recovery mechanisms. I wonder if they updated their internal support policies with respect to assisted account recovery when they implemented the new system...seems like they should have made the bar higher...

[1]: https://blog.fastmail.com/2016/07/25/two-step-verification-a...

Re: The FastMail Security Mindset

#100
post #52

Wow what a coincidence — I switched from Gmail to Fastmail exactly 1 year ago today. I couldn't be happier. I mostly use native clients, but the Web client is a joy to use, and everything I've observed about Fastmail gives me confidence in their service. I never used the Gmail-exclusive features like labels, so switching was pretty easy. I highly recommend it to anyone considering it. Keep up the good work, guys.

Interesting. I switched a little over a year ago too. I like not being the product but find the web client painful. Specifically: 1. No Send and Archive 2. Sending is slooow. E.g. compose email, hit Send, wait several seconds, go back to Inbox. Gmail is instantaneous. 3. Hitting Reply is SLOOOOW to bring up the Reply pane. Fastmail does a POST that takes from 500ms to 5000ms (usually on the lower end but even that is…

Interesting, I've only ever run into these kinds of speed issues on the iOS client. I've found the web client (and usually the mobile client) loads a large inbox (hundreds to thousands of messages) much, much faster than Gmail; in fact, that was one of the first things in testing that told me I'd like using it.

I will say that Gmail handles threading better, as you said. Fastmail goes for a more traditional native-client-like approach; it didn't take long for me to switch back to that paradigm, but someone who has only ever known Gmail would definitely see it as a pain point.

Post reply on HN