Live data from Hacker News

The FastMail Security Mindset

blog.fastmail.com

151–160 of 301 posts

Re: The FastMail Security Mindset

#151
post #64

I was a very happy FastMail customer until a hacker asked them to reset my password. After _incorrectly_ answering a handful of questions asked by the FastMail support, the recovery email address was changed and a password reset link sent. From there, the hacker attempted password resets on other services. Initially, FastMail was dismissive that this was a simple "mix-up" and didn't disable access to the hacker for 7…

Now to write a more detailed response. If this winds up out of order later, I first posted: https://news.ycombinator.com/item?id=15856609 Again, ghouse, I'm really really sorry about what happened to your account. It was wrong and we screwed up. As other comments have already noted, it was during the transition to a new security system which was designed precisely to remove the human factor from decision making. I'm…

What I'm hearing is that the human aspect remains and there is absolutely no prevention of this happening in the future.

The other response contains weasel words like "For instance, _some cases_ take 24 hours before the reset password goes into effect". Why "some cases"? Why isn't it all cases?

I think we as customers deserve complete transparency on this and know what prevention will be in place.

Re: The FastMail Security Mindset

#152

Earlier quoted context omitted.

Thanks for the clarification, must indeed be mixing you up with another service!

You might be thinking up riseup.net. They use Roundcube, they target a similar audience, and both have a cryptopunk-ish slant.

I had a quick look -- I was thinking of Posteo. I think they aren't aiming for the exact same customer segment, but I think of both as a small Central European service that values privacy.

Re: The FastMail Security Mindset

#153

Earlier quoted context omitted.

Exactly which employees in your organization have the ability to alter recovery email settings? How many of those employees are there? In what fashion do you audit and track the activities of those employees? What training are these employees given to avoid social engineering? What firm provides the courseware? What's the escalation process for complicated, non-no-brainer reset situations? If a support person isn't a…

Wow, that's a lot of questions, and I can't answer all of them without creating security risks! Our absolute focus is on minimizing the human factors. In the past year and a bit since that incident, we have improved our escalation policies and support training, as well as let some support staff go. But more importantly, we now have an automated account recovery system which can be used to verify ownership of the acco…

Which of these questions can you not answer without creating security risks? I didn't ask you anything about your automated system.

Is it possible under any set of circumstances for your human employees to alter accounts? If the automated system fails, are accountholders out of luck?

Re: The FastMail Security Mindset

#154
post #92
post #83

Earlier quoted context omitted.

No, I did not. And I certainly should have. However, 2fa would not have prevented the problem. The problem is twofold -- 1) account recovery (using email, SMS, or anything other than a secret key) is an effective attack vector. Especially SMS. 2) a human who will change the account recovery settings (in my case, FM changing the account recovery email address).

Hmm you think they would have bypassed your 2fa as well? I wonder if FM can comment on that - it would be concerning. The "sms backdoor" is the same with gmail, etc. unless you explicitly disable it.

Our account recovery process won't allow you through at all if you lose your password, and your 2FA, and your recovery key, then you're not getting that account back.

Re: The FastMail Security Mindset

#155
post #52

Wow what a coincidence — I switched from Gmail to Fastmail exactly 1 year ago today. I couldn't be happier. I mostly use native clients, but the Web client is a joy to use, and everything I've observed about Fastmail gives me confidence in their service. I never used the Gmail-exclusive features like labels, so switching was pretty easy. I highly recommend it to anyone considering it. Keep up the good work, guys.

Interesting. I switched a little over a year ago too. I like not being the product but find the web client painful. Specifically: 1. No Send and Archive 2. Sending is slooow. E.g. compose email, hit Send, wait several seconds, go back to Inbox. Gmail is instantaneous. 3. Hitting Reply is SLOOOOW to bring up the Reply pane. Fastmail does a POST that takes from 500ms to 5000ms (usually on the lower end but even that is…

> 2. Sending is slooow. E.g. compose email, hit Send, wait several seconds, go back to Inbox. Gmail is instantaneous.

Gmail is optimistic about it, while we’re actually sending the message before confirming to you that it’s been sent. (There are sound technical/historical reasons why it’s done the way it is; it’s not trivial to change.)

Once the JMAP spec stabilises (hopefully by the next IETF meeting in March), our web UI will switch to using JMAP, and then I think that sending messages will be done in the background. Not certain, I’m not the one that’s been doing the JMAPification of the FastMail web UI.

> 3. Hitting Reply is SLOOOOW to bring up the Reply pane. Fastmail does a POST that takes from 500ms to 5000ms (usually on the lower end but even that is noticeable. On the rare occasion it's longer it's incredibly frustrating).

This is definitely fixed with JMAP. In a JMAP world the client takes care of creating drafts, parsing MIME messages, defanging potentially malicious HTML, &c. rather than the server as our current implementation does.

> 4. […] In Fastmail the keyboard shortcuts only act on the most recent message in the thread.

Not true: use n/p to focus the appropriate message (same as in Gmail), then r et al. will apply to that particular message.

> 5. When viewing an email that is a response to another email, Gmail collapses the initial email and lets you expand it with an ellipsis. Fastmail does no such thing, which means you need to scroll (and scroll and scroll...) when looking up through long threads

FastMail does collapse the messages that have been read. You can expand individual messages by clicking on them or pressing e (provided you’re using n/p to switch between them), or Shift+e to expand all (Alt+Shift+e collapses all). In consequence of these things, I’m not sure what the issue you’re pointing out is; if you can provide more info we can look into improving it.

You may find it helpful to look at https://www.fastmail.com/help/receive/kbshortcuts.html.

---

For web UI work, we’ve been focusing on Topicbox and JMAP this year rather than FastMail; Topicbox has been a simpler staging ground for various improvements that we intend to bring to FastMail (mostly internal tooling stuff—I’ll be writing a bit about it later in our Advent series), and JMAP will enable various long-desired features (e.g. snooze, delayed/undo send). Next year will see more effort put into the FastMail web UI; my favourite item that we have planned (and I called dibs on implementing most of it!) is service workers for offline support and substantially improved performance (building on top of JMAP’s improvements).

Re: The FastMail Security Mindset

#156

Earlier quoted context omitted.

You might be thinking up riseup.net. They use Roundcube, they target a similar audience, and both have a cryptopunk-ish slant.

I had a quick look -- I was thinking of Posteo. I think they aren't aiming for the exact same customer segment, but I think of both as a small Central European service that values privacy.

[deleted]

Re: The FastMail Security Mindset

#157

Earlier quoted context omitted.

Good morning. I'm going to be here to answer specific questions, and I owe you a personal response to this as well, which I'm about to start working on! There is no doubt that in this specific case our human factor screwed up, and I'm really sorry about that. First I'm going to post the standard response that our team has written for any new support tickets that come in about this today, then write my own personal ap…

This can be enough for me to consider leaving depending on how it's fixed. This response says absolutely nothing about how the vulnerability is prevented in the future. It's just a bunch of vague promises and mumbo jumbo. What specific procedures are in place to prevent it? At a minimum, I expect to see something specific like when you guys almost lost your domain because of Gandi [1]. And even then, can I have an op…

Also, could you please add ability to get a phone call (instead of text message) to receive recovery options?

That way I can setup my grandparents' phone number or something obscure as yet another recovery option.

And then, please let me lock down any possibility of your support staff screwing up.

Re: The FastMail Security Mindset

#158

I see the usual comment about Fastmail (comparison to Gmail, ProtonMail, web interface, spam filtering performance, servers in the US, ...) but still nothing about the TOS, which seems more important to me So here it is again: - Fastmail can immediately cancel your account for any reason: "The Service Provider may terminate your access to any part or all of the Service and any related service(s) at any time, with or…

> - Fastmail can immediately cancel your account for any reason: "The Service Provider may terminate your access to any part or all of the Service and any related service(s) at any time, with or without cause, with or without notice, effective immediately, for any reason whatsoever, with or without providing any refund of any payments." Other than the last clause about "without providing any refund", I would expect t…

In almost all cases, we're very happy to provide refunds - particularly early in a subscription period. We also automatically refund if we believe accounts were opened with stolen credit details (happens more often than we would like despite all the checks in place at payment time).

Re: The FastMail Security Mindset

#159
post #64

I was a very happy FastMail customer until a hacker asked them to reset my password. After _incorrectly_ answering a handful of questions asked by the FastMail support, the recovery email address was changed and a password reset link sent. From there, the hacker attempted password resets on other services. Initially, FastMail was dismissive that this was a simple "mix-up" and didn't disable access to the hacker for 7…

Good morning. I'm going to be here to answer specific questions, and I owe you a personal response to this as well, which I'm about to start working on! There is no doubt that in this specific case our human factor screwed up, and I'm really sorry about that. First I'm going to post the standard response that our team has written for any new support tickets that come in about this today, then write my own personal ap…

Hi Bron. I'm a customer of both Fastmail and GSuite, and I have enjoyed your service for a few years now. I still use Fastmail for some things, like sieve, and very much will continue paying just for the ongoing development of open-standard email like JMAP. But there are definitely a few things that I can't shake when I learned about them that very much pertains to the security mindset that prevents me from moving my primary emails onto Fastmail.

Security paradigms have been steadily moving beyond a hard-boundary-soft-center, to a defense-in-depth, distrust-your-own-services model. I was alarmed to learn last year, for example, that you use OpenVPN with fixed symmetric keys (--secret) rather than TLS with any forward secrecy (--tls-auth) for VPN between your NYI and AMS datacenters. https://blog.fastmail.com/2016/12/19/secure-datacentre-inter...

Presumably, running datalinks like this means you would have to have perfect trust in your long term key management and rotation. Is that something you plan on improving in the future?

Similarly -- I stumbled on this entirely by accident after your blog post about moving datacenters -- that your head of security ops & infrastructure tweeted "I will probably root my phone soon because Samsung's emoji set is worse than not having convenient OTA updates" https://twitter.com/robn/status/919194089920311296

I don't want to conflate anything -- a tweet on an engineer's own time about their personal devices isn't by itself a security problem. But it does reflect on the security mindset. If you had a BYOD policy, and this phone did end up being flashed to Lineage and be 3 patch levels behind (esp with Android's track record of RCE-via-media CVEs), this could definitely become a weakness on your entire infrastructure, and thereby on all of us as customers.

This is the type of thing I couldn't shake after learning about it. Of course, trust has to be placed somewhere. You have to be able to place trust on your ops and your infrastructure, but that's also a process, not a checkbox. People and devices can be trusted a little less in the overall security system, to provide redundant security. Could you clarify your position on how your staff is trained about the human weak points, security as a lifestyle if you're security and ops, and how your security mindset incorporates defense in depth?

Re: The FastMail Security Mindset

#160
post #148

Earlier quoted context omitted.

Now to write a more detailed response. If this winds up out of order later, I first posted: https://news.ycombinator.com/item?id=15856609 Again, ghouse, I'm really really sorry about what happened to your account. It was wrong and we screwed up. As other comments have already noted, it was during the transition to a new security system which was designed precisely to remove the human factor from decision making. I'm…

> a 24 hour lockout to allow the owner to notice an attempt on their account. I've been pretty careful to ensure that I don't lock myself out of my account (multiple U2F keys, strong password saved in password manager with backups) But if a determined attacker kicks this off just as I'm stepping on a flight from Sydney to London, 24 hours isn't going to be enough. (I should add also - I'm a mostly happy Fastmail cust…

You can't even get to the 24 hour lockout unless you've successfully passed the security checks.

We add the 24 hour lockout as an additional level of protection for 2fa accounts (even though they've given two factors of recovery by then) or if we can't confirm that you are resetting from a computer which has successfully logged in to that account before.

Post reply on HN