Earlier quoted context omitted.
I'm considering switching (in fact I just registered for the FastMail trial). I'm especially interested in the ability to use catchall addresses with a custom domain, which would allow me to give out an address like , and thus determine who shared my email address if I start receiving spam at that address. This is partly possible with Gmail, as you can use addresses like , but not all sites support emails with a + in…
I've been a FastMail customer for about four years and overall I'm really pleased with their service. Like you I have my own domain, previously used Gmail, and provide custom email addresses to every site I register with. Interesting to see who has sold my email or may have been hacked when a rogue email ends up in my inbox (hi, Sunspel!). I have one issue with FastMail that I didn't have with Gmail. Every few days/w…
The FastMail Security Mindset
191–200 of 301 posts
Re: The FastMail Security Mindset
#192Earlier quoted context omitted.
If the automated system fails and you have 2fa, then it gets escalated to the two most senior members of the security team. In some cases we haven't had sufficient information on the account to ever verify that account's owner, and they never got their account back. Some users refuse to give us enough information to allow us to later positively identify them - so yes, those people will be out of luck if they lose the…
At this point, you should write a blog post to address the myriad of concerns popping up in this thread.
Re: The FastMail Security Mindset
#193Earlier quoted context omitted.
This can be enough for me to consider leaving depending on how it's fixed. This response says absolutely nothing about how the vulnerability is prevented in the future. It's just a bunch of vague promises and mumbo jumbo. What specific procedures are in place to prevent it? At a minimum, I expect to see something specific like when you guys almost lost your domain because of Gandi [1]. And even then, can I have an op…
Also, could you please add ability to get a phone call (instead of text message) to receive recovery options? That way I can setup my grandparents' phone number or something obscure as yet another recovery option. And then, please let me lock down any possibility of your support staff screwing up.
It also brings issues of its own. Home phones are hard to block number on, and it could be used to troll people in the middle of their night. We need to consider those risks too - it's not a simple and obvious win.
Re: The FastMail Security Mindset
#194Earlier quoted context omitted.
If an Android phone connecting to the company’s WiFi or the user’s email and whatnot is enough to compromise the infrastructure, then the company has bigger problems. I’ve worked in companies with liberal BYOD policies for portable devices, but also tasted really restricted environments and such environments are basically highly regulated security theaters. Users do stupid things of course and in corporations it’s wo…
> PS: your mention of that Twitter account is creepy. With no context, I agree. But I'm not exactly stalking engineers here - there was literally a direct link to that twitter from the Fastmail updates mailing list that went out, when customers were notified of the NYI datacenter move. Made me do a double take.
Cheers.
Re: The FastMail Security Mindset
#195Earlier quoted context omitted.
> To me the only downside is the mobile app isn't quite as polished as Gmail. It doesn't work offline, and I notice occasional bugs or awkwardnesses. But it's still very usable, and I much prefer the Fastmail web interface to Gmail. But FastMail supports other clients, right? I don't want to be forced to use their web interface or their app; I'm happy with the Apple-written Mail apps.
> But FastMail supports other clients, right? I don't want to be forced to use their web interface or their app; I'm happy with the Apple-written Mail apps. It does, but at least for me the problem is using my separate forwarding-only e-mail address instead of fastmail.com as the sender. As far as I see, I need the native app for this.
Re: The FastMail Security Mindset
#196Earlier quoted context omitted.
At this point, you should write a blog post to address the myriad of concerns popping up in this thread.
We're working on that! It may not be finished today.
I respect that, as CEO, you're genuinely responding to your customers in this thread instead of fobbing it off to someone else.
Hopefully, this can all be explained, resolved, and /or remedied in good time.
Re: The FastMail Security Mindset
#197Earlier quoted context omitted.
Interesting. I switched a little over a year ago too. I like not being the product but find the web client painful. Specifically: 1. No Send and Archive 2. Sending is slooow. E.g. compose email, hit Send, wait several seconds, go back to Inbox. Gmail is instantaneous. 3. Hitting Reply is SLOOOOW to bring up the Reply pane. Fastmail does a POST that takes from 500ms to 5000ms (usually on the lower end but even that is…
> 2. Sending is slooow. E.g. compose email, hit Send, wait several seconds, go back to Inbox. Gmail is instantaneous. Gmail is optimistic about it, while we’re actually sending the message before confirming to you that it’s been sent. (There are sound technical/historical reasons why it’s done the way it is; it’s not trivial to change.) Once the JMAP spec stabilises ( hopefully by the next IETF meeting in March), our…
Re: The FastMail Security Mindset
#198I was a very happy FastMail customer until a hacker asked them to reset my password. After _incorrectly_ answering a handful of questions asked by the FastMail support, the recovery email address was changed and a password reset link sent. From there, the hacker attempted password resets on other services. Initially, FastMail was dismissive that this was a simple "mix-up" and didn't disable access to the hacker for 7…
This is death. Your email provider absolutely cannot under any circumstances have this vulnerability. Wow. Just the idea that there's a human in the process making subjective decisions about security questions and answers that can, on their own recognizance, change a recovery email address. Forget the immediate mistake that one rep made, and go down a couple levels deeper into the company policy design mistakes at pl…
The offerings over at https://protonmail.com/signup have been nagging me to give it a try.
I now have a reason to try and switch. I'll lose functionality found in fastmail but gain a lot in security.
Re: The FastMail Security Mindset
#199Earlier quoted context omitted.
If I recall correctly, ProtonMail was using RoundCube as the webmail interface when I was looking for a service. RoundCube was the reason I left my previous e-mail provider, so I had to give it a pass. Though now their website is showing a rather nice web UI, perhaps they've switched to a new one since then?
We have never used RoundCube in the project's history. You must be thinking of someone else.
I ask because that is what I want. I want my account to autodestruct if compromised and when recovered I want to be assured that all my personal data has been safeguarded by effectively throwing away the key into the depths of Mordor.
Re: The FastMail Security Mindset
#200Earlier quoted context omitted.
> 2. Sending is slooow. E.g. compose email, hit Send, wait several seconds, go back to Inbox. Gmail is instantaneous. Gmail is optimistic about it, while we’re actually sending the message before confirming to you that it’s been sent. (There are sound technical/historical reasons why it’s done the way it is; it’s not trivial to change.) Once the JMAP spec stabilises ( hopefully by the next IETF meeting in March), our…
Any plans for a PWA for the mobile version? I use the app on Android, but I recently tried just loading the site in Firefox (Beta/58/Quantum), and I think it runs faster, plus it doesn't have keyboard/autocorrect issues.
(BTW, the Android app is in the process of being revamped to use the now-sufficiently-capable WebView, which will fix certain issues like the keyboard problems you mention. Not sure what progress is on that.)
FastMail’s web interface is already practically a PWA (from a few years before that term was invented), lacking only the ability to start offline (it copes with transient network connections pretty well), and use of the Web Notifications API (which we’ll probably support at some point, but not use in the app because it provides only a subset of the native functionality we currently use).