Live data from Hacker News

The FastMail Security Mindset

blog.fastmail.com

131–140 of 301 posts

Re: The FastMail Security Mindset

#131

Earlier quoted context omitted.

I tried out ProtonMail for just a little bit around the time I switched, and personally I found the focus on security and encryption to be at the expense of user experience.

If I recall correctly, ProtonMail was using RoundCube as the webmail interface when I was looking for a service. RoundCube was the reason I left my previous e-mail provider, so I had to give it a pass. Though now their website is showing a rather nice web UI, perhaps they've switched to a new one since then?

We have never used RoundCube in the project's history. You must be thinking of someone else.

Re: The FastMail Security Mindset

#132
post #52

Earlier quoted context omitted.

Interesting. I switched a little over a year ago too. I like not being the product but find the web client painful. Specifically: 1. No Send and Archive 2. Sending is slooow. E.g. compose email, hit Send, wait several seconds, go back to Inbox. Gmail is instantaneous. 3. Hitting Reply is SLOOOOW to bring up the Reply pane. Fastmail does a POST that takes from 500ms to 5000ms (usually on the lower end but even that is…

Interesting, I've only ever run into these kinds of speed issues on the iOS client. I've found the web client (and usually the mobile client) loads a large inbox (hundreds to thousands of messages) much, much faster than Gmail; in fact, that was one of the first things in testing that told me I'd like using it. I will say that Gmail handles threading better, as you said. Fastmail goes for a more traditional native-cl…

The FM web client loads messages faster, but is slower to use in my experience. I’d rather pay a one-time loading cost up front for an app experience that feels native-ish and snappy like Gmail vs having the app feel laggy when I do mainline use cases like send email or compose a reply.

Re threading I’ve had email for 25 years now and def. feel Gmail’s approach is superior, if only because you don’t have to scroll so freaking much!

Re: The FastMail Security Mindset

#133
post #30

Earlier quoted context omitted.

I'm not suggesting (at all) that you use them over FastMail, but GSuite also supports catch-all email addresses.

Indeed - but replying from an arbitrary address is one big downside of G Suite’s implementation. In FastMail you can add [0]@example.com as an identity. Selecting this when composing an email allows you to edit the localpart entirely. Similarly, when replying to an email sent to your catch-all and you have an @ identity for the hostname FastMail will automatically set your from address for you. In Gmail (with G Suite…

Selecting this when composing an email allows you to edit the localpart entirely. Similarly, when replying to an email sent to your catch-all and you have an @ identity for the hostname FastMail will automatically set your from address for you.

I didn't know that, but it's fantastic news! I was doing things the awkward "gmail" way.

Re: The FastMail Security Mindset

#134
post #64

I was a very happy FastMail customer until a hacker asked them to reset my password. After _incorrectly_ answering a handful of questions asked by the FastMail support, the recovery email address was changed and a password reset link sent. From there, the hacker attempted password resets on other services. Initially, FastMail was dismissive that this was a simple "mix-up" and didn't disable access to the hacker for 7…

Good morning. I'm going to be here to answer specific questions, and I owe you a personal response to this as well, which I'm about to start working on!

There is no doubt that in this specific case our human factor screwed up, and I'm really sorry about that.

First I'm going to post the standard response that our team has written for any new support tickets that come in about this today, then write my own personal apology and response here.

---

Thanks for getting in touch with us about the report on Hacker News about our security procedures.

As we say in our recent post about security at https://blog.fastmail.com/2017/12/05/the-fastmail-security-m..., security is a process, not a checkbox. We do our best to be continually improving and upgrading our security procedures, and offering our security-minded customers the most robust, industry-standard options possible.

However, we have been less diligent about forcing older accounts to upgrade their security settings. With a range of possible security option states, customer support is occasionally placed in a position to make a judgement call. As the post indicates, the incident in question happened immediately after a major round of security changes. There’s no way around it; someone made an exception they shouldn't have.

Social engineering is always one of our biggest concerns. As any number of well-known break-ins have demonstrated, the "best" security hack is often to sidestep it. Since that incident, we have taken substantially more aggressive steps to close off avenues of attack and human review. We are constantly trying to narrow the number of accounts that even can go to a human for review, and for those that must go to a human to provide as much notice as possible to the account owner before possibly allowing the attacker to have access. For instance, some cases take 24 hours before the reset password goes into effect. If you are a legitimate account owner, this has the often frustrating side effect of locking you out of your account for 24 hours. But, if you have been attacked, this gives you the opportunity to keep the attacker out.

Thank you for sharing your concern with us, and I hope we’ve addressed yours.

Re: The FastMail Security Mindset

#135
post #13

Wow what a coincidence — I switched from Gmail to Fastmail exactly 1 year ago today. I couldn't be happier. I mostly use native clients, but the Web client is a joy to use, and everything I've observed about Fastmail gives me confidence in their service. I never used the Gmail-exclusive features like labels, so switching was pretty easy. I highly recommend it to anyone considering it. Keep up the good work, guys.

How's the spam filter compared to Gmail?

When I was using fastmail, I got lots of spam and I couldn't figure out how to get less. The spam was the reason I stopped using it and went back to gmail primarily. (This was a year or 1.5 ago.) I liked everything else about their service, though.

Re: The FastMail Security Mindset

#136

Earlier quoted context omitted.

If I recall correctly, ProtonMail was using RoundCube as the webmail interface when I was looking for a service. RoundCube was the reason I left my previous e-mail provider, so I had to give it a pass. Though now their website is showing a rather nice web UI, perhaps they've switched to a new one since then?

We have never used RoundCube in the project's history. You must be thinking of someone else.

Thanks for the clarification, must indeed be mixing you up with another service!

Re: The FastMail Security Mindset

#137
post #64

I was a very happy FastMail customer until a hacker asked them to reset my password. After _incorrectly_ answering a handful of questions asked by the FastMail support, the recovery email address was changed and a password reset link sent. From there, the hacker attempted password resets on other services. Initially, FastMail was dismissive that this was a simple "mix-up" and didn't disable access to the hacker for 7…

Just wondering, is your FastMail login email the same email as what you typically use?

Re: The FastMail Security Mindset

#138
post #92
post #83

Earlier quoted context omitted.

No, I did not. And I certainly should have. However, 2fa would not have prevented the problem. The problem is twofold -- 1) account recovery (using email, SMS, or anything other than a secret key) is an effective attack vector. Especially SMS. 2) a human who will change the account recovery settings (in my case, FM changing the account recovery email address).

Hmm you think they would have bypassed your 2fa as well? I wonder if FM can comment on that - it would be concerning. The "sms backdoor" is the same with gmail, etc. unless you explicitly disable it.

[deleted]

Re: The FastMail Security Mindset

#139
post #64

I was a very happy FastMail customer until a hacker asked them to reset my password. After _incorrectly_ answering a handful of questions asked by the FastMail support, the recovery email address was changed and a password reset link sent. From there, the hacker attempted password resets on other services. Initially, FastMail was dismissive that this was a simple "mix-up" and didn't disable access to the hacker for 7…

Good morning. I'm going to be here to answer specific questions, and I owe you a personal response to this as well, which I'm about to start working on! There is no doubt that in this specific case our human factor screwed up, and I'm really sorry about that. First I'm going to post the standard response that our team has written for any new support tickets that come in about this today, then write my own personal ap…

This can be enough for me to consider leaving depending on how it's fixed.

This response says absolutely nothing about how the vulnerability is prevented in the future. It's just a bunch of vague promises and mumbo jumbo. What specific procedures are in place to prevent it? At a minimum, I expect to see something specific like when you guys almost lost your domain because of Gandi [1].

And even then, can I have an option to select absolutely no human intervention possible? Having any human intervention is simply not acceptable.

I already have multiple ways of recovering my account, and I never, ever want human assistance on this. I use a password manager, and I will never, ever need FastMail assistance on login.

[1]: https://blog.fastmail.com/2014/04/10/when-two-factor-authent...

Re: The FastMail Security Mindset

#140
post #64

I was a very happy FastMail customer until a hacker asked them to reset my password. After _incorrectly_ answering a handful of questions asked by the FastMail support, the recovery email address was changed and a password reset link sent. From there, the hacker attempted password resets on other services. Initially, FastMail was dismissive that this was a simple "mix-up" and didn't disable access to the hacker for 7…

> I was a very happy FastMail customer until a hacker asked them to reset my password. After _incorrectly_ answering a handful of questions asked by the FastMail support, the recovery email address was changed and a password reset link sent. From there, the hacker attempted password resets on other services. When did this happen?

July 2016
Post reply on HN