Live data from Hacker News

The FastMail Security Mindset

blog.fastmail.com

181–190 of 301 posts

Re: The FastMail Security Mindset

#181
post #148

Earlier quoted context omitted.

> a 24 hour lockout to allow the owner to notice an attempt on their account. I've been pretty careful to ensure that I don't lock myself out of my account (multiple U2F keys, strong password saved in password manager with backups) But if a determined attacker kicks this off just as I'm stepping on a flight from Sydney to London, 24 hours isn't going to be enough. (I should add also - I'm a mostly happy Fastmail cust…

For an attacker to exploit this, they will have to know that you are going on such a trip. This means that attackers who don't know much about you already are less likely to bother, and also raises the bar for even the focus attackers. Nothing is foolproof, but many things can be useful.

If a well-resourced attacker was targeting me specifically, it wouldn't be too difficult for them to find out about my short-to-medium term travel plans. A bit of social engineering with the airlines could tell them exactly which flight I'm on.

They could also compromise other people who need to know my plans and don't have the same security practises as me.

I think about this stuff and minimise as best I can, but my account security shouldn't be dependant on it.

Re: The FastMail Security Mindset

#182

Earlier quoted context omitted.

Hi Bron. I'm a customer of both Fastmail and GSuite, and I have enjoyed your service for a few years now. I still use Fastmail for some things, like sieve, and very much will continue paying just for the ongoing development of open-standard email like JMAP. But there are definitely a few things that I can't shake when I learned about them that very much pertains to the security mindset that prevents me from moving my…

If an Android phone connecting to the company’s WiFi or the user’s email and whatnot is enough to compromise the infrastructure, then the company has bigger problems. I’ve worked in companies with liberal BYOD policies for portable devices, but also tasted really restricted environments and such environments are basically highly regulated security theaters. Users do stupid things of course and in corporations it’s wo…

> PS: your mention of that Twitter account is creepy.

With no context, I agree. But I'm not exactly stalking engineers here - there was literally a direct link to that twitter from the Fastmail updates mailing list that went out, when customers were notified of the NYI datacenter move. Made me do a double take.

Re: The FastMail Security Mindset

#183
post #64

I was a very happy FastMail customer until a hacker asked them to reset my password. After _incorrectly_ answering a handful of questions asked by the FastMail support, the recovery email address was changed and a password reset link sent. From there, the hacker attempted password resets on other services. Initially, FastMail was dismissive that this was a simple "mix-up" and didn't disable access to the hacker for 7…

Now to write a more detailed response. If this winds up out of order later, I first posted: https://news.ycombinator.com/item?id=15856609 Again, ghouse, I'm really really sorry about what happened to your account. It was wrong and we screwed up. As other comments have already noted, it was during the transition to a new security system which was designed precisely to remove the human factor from decision making. I'm…

I use Fastmail and I like it but this is extremely disturbing. I appreciate you being relatively candid with us, but it doesn’t change the fact that you allowed a customer’s account to be compromised by the most basic attack out there.

Complexity and vulnerability go hand-in-hand. A product providing a critical service like email should be opt-in to any form of recovery not requiring pure secrets provided directly by the user (or provided to an already logged-in user for this specific purpose). Failing that, there should at least be an opt-out for such dangerous recovery methods.

I’m going to watch this thread and your blog for a while, and I hope you can provide some real assurances for security-minded technical folks like me for whom email really is the “keys to the kingdom”. Failing that, I may have to look for another email provider.

Re: The FastMail Security Mindset

#184
post #64

I was a very happy FastMail customer until a hacker asked them to reset my password. After _incorrectly_ answering a handful of questions asked by the FastMail support, the recovery email address was changed and a password reset link sent. From there, the hacker attempted password resets on other services. Initially, FastMail was dismissive that this was a simple "mix-up" and didn't disable access to the hacker for 7…

This is death. Your email provider absolutely cannot under any circumstances have this vulnerability. Wow. Just the idea that there's a human in the process making subjective decisions about security questions and answers that can, on their own recognizance, change a recovery email address. Forget the immediate mistake that one rep made, and go down a couple levels deeper into the company policy design mistakes at pl…

> This is death.

Even allowing for some hyperbole, I think this is an overreaction. I agree that they made a mistake, but we only know of one user it affected. They didn't leak an entire database of user data or expose a vulnerability for which the attack can be automated.

You've commented many times that email is inherently insecure and that (IIRC the conclusion precisely) there is little point in focusing on securing it. Instead, use a secure messaging system such as Signal. Email just isn't going to be secure. Fastmail seems to put more effort into their security than most mail providers. For example, the proxied images [0] sound fantastic and they address a threat that affects almost every email user daily.

[0] https://blog.fastmail.com/2014/09/16/better-security-and-pri...

Re: The FastMail Security Mindset

#185
post #97
post #92

Earlier quoted context omitted.

Hmm you think they would have bypassed your 2fa as well? I wonder if FM can comment on that - it would be concerning. The "sms backdoor" is the same with gmail, etc. unless you explicitly disable it.

What is the sms backdoor?

Sim swapping:

http://www.fraud.org/sim_swapping_alert

Re: The FastMail Security Mindset

#186

Earlier quoted context omitted.

This is death. Your email provider absolutely cannot under any circumstances have this vulnerability. Wow. Just the idea that there's a human in the process making subjective decisions about security questions and answers that can, on their own recognizance, change a recovery email address. Forget the immediate mistake that one rep made, and go down a couple levels deeper into the company policy design mistakes at pl…

> This is death. Even allowing for some hyperbole, I think this is an overreaction. I agree that they made a mistake, but we only know of one user it affected. They didn't leak an entire database of user data or expose a vulnerability for which the attack can be automated. You've commented many times that email is inherently insecure and that (IIRC the conclusion precisely) there is little point in focusing on securi…

The inherent insecurity of e-mail doesn't change the fact that popping someone's email account means popping most of their services. Therefore it makes sense to hold e-mail providers to a higher standard than a median company.

Furthermore, while we only know 1 user affected, in the rest of the thread, Fastmail has been cagey at best about answering what they feel the process is now, let alone what it was back when this incident occurred.

Re: The FastMail Security Mindset

#187
post #10

Wow what a coincidence — I switched from Gmail to Fastmail exactly 1 year ago today. I couldn't be happier. I mostly use native clients, but the Web client is a joy to use, and everything I've observed about Fastmail gives me confidence in their service. I never used the Gmail-exclusive features like labels, so switching was pretty easy. I highly recommend it to anyone considering it. Keep up the good work, guys.

I'm considering switching (in fact I just registered for the FastMail trial). I'm especially interested in the ability to use catchall addresses with a custom domain, which would allow me to give out an address like , and thus determine who shared my email address if I start receiving spam at that address. This is partly possible with Gmail, as you can use addresses like , but not all sites support emails with a + in…

I've been a FastMail customer for about four years and overall I'm really pleased with their service. Like you I have my own domain, previously used Gmail, and provide custom email addresses to every site I register with. Interesting to see who has sold my email or may have been hacked when a rogue email ends up in my inbox (hi, Sunspel!).

I have one issue with FastMail that I didn't have with Gmail. Every few days/weeks I'll get a wave of backspatter from someone spoofing my domain to spam. I've researched and it doesn't look like there's anything I can do about this. Most of the backspatter ends up in my spam folder, but not all of it does. I don't know if Gmail automatically removed backspatter -- not even sending it to my spam folder -- or if this only started after I transferred my domain.

Re: The FastMail Security Mindset

#188
post #174

Earlier quoted context omitted.

This is death. Your email provider absolutely cannot under any circumstances have this vulnerability. Wow. Just the idea that there's a human in the process making subjective decisions about security questions and answers that can, on their own recognizance, change a recovery email address. Forget the immediate mistake that one rep made, and go down a couple levels deeper into the company policy design mistakes at pl…

You're aware this is how the vast majority of email providers legacy operated right? (And sadly a few still do) E.g. in this case likely a 2 point auth system (security question and e.g. payment details (last four of latest payment meth/etc)) Seems you're shocked that a lower tier support agent can auth this kind of request when the reality for most email hosts is that they can. They(likely a new employee) got social…

FastMail isn't some random legacy email provider. It's a premium one that bills itself as secure. It's not some free mailbox you got with your budget domain registrar. Hence, it's reasonable to hold them to a higher standard rather than fatalistically observing that the median email provider sucks.

Re: The FastMail Security Mindset

#189
FastMail is tempting. I'm currently moving over to hosting my own E-mail, since Gmail is failing to deliver a significant number of important inbound E-mails to my account, rejecting them as spam (and fails to deliver almost all of my wife's E-mail). I could be convinced to pay for E-mail, but I'm concerned with customer support and the "black box" nature of online services. For something as important as E-mail, I grudgingly feel I finally need to bite the bullet and do it myself.

Re: The FastMail Security Mindset

#190
post #188
post #174

Earlier quoted context omitted.

You're aware this is how the vast majority of email providers legacy operated right? (And sadly a few still do) E.g. in this case likely a 2 point auth system (security question and e.g. payment details (last four of latest payment meth/etc)) Seems you're shocked that a lower tier support agent can auth this kind of request when the reality for most email hosts is that they can. They(likely a new employee) got social…

FastMail isn't some random legacy email provider. It's a premium one that bills itself as secure. It's not some free mailbox you got with your budget domain registrar. Hence, it's reasonable to hold them to a higher standard rather than fatalistically observing that the median email provider sucks.

I know, still don't buy his outrage.

I think the response would be far less exaggerated for a HN sponsored company.

By legacy provider I don't mean a 2010 cpanel reseller, I mean the majority of current providers outside of the big four. Especially anything with concurrent web hosting.

Again this isn't excusing their incompetence, just disagreeing with the severity of his response, especially given theirs.

Post reply on HN