Live data from Hacker News

The FastMail Security Mindset

blog.fastmail.com

201–210 of 301 posts

Re: The FastMail Security Mindset

#201

Earlier quoted context omitted.

This is death. Your email provider absolutely cannot under any circumstances have this vulnerability. Wow. Just the idea that there's a human in the process making subjective decisions about security questions and answers that can, on their own recognizance, change a recovery email address. Forget the immediate mistake that one rep made, and go down a couple levels deeper into the company policy design mistakes at pl…

I've been a fastmail customer for a bit over a year and I agree. The offerings over at https://protonmail.com/signup have been nagging me to give it a try. I now have a reason to try and switch. I'll lose functionality found in fastmail but gain a lot in security.

Unless you have a set of objectives that are very different from what I consider "as secure as e-mail gets", please consider GSuite and not Protonmail. (I don't speak for 'tptacek, but I'm pretty sure he'd agree.)

As a corollary: if you really care, use Signal for stuff you can't say over e-mail. Whatsapp's fine too. But they solve a very different security problem than the one you need e-mail to solve, which is mostly "don't leak my emails" and also "don't reset my password for attackers who ask nicely".

Re: The FastMail Security Mindset

#202
post #178

Earlier quoted context omitted.

If the automated system fails and you have 2fa, then it gets escalated to the two most senior members of the security team. In some cases we haven't had sufficient information on the account to ever verify that account's owner, and they never got their account back. Some users refuse to give us enough information to allow us to later positively identify them - so yes, those people will be out of luck if they lose the…

I agree with hitekker, I'm feeling pretty nervous about being a FastMail customer right now and will start looking for a more secure alternative now. The main reason I moved to FastMail is because I stopped trusting Google to keep my mail secure.

Google is the gold standard for email account service. Nobody in the industry does a better job at that one thing than Google does.

Re: The FastMail Security Mindset

#203
post #13

Earlier quoted context omitted.

How's the spam filter compared to Gmail?

It is worse than GMail. It tends to come in waves, there can be weeks where I barely get any spam in my inbox and then there is sometimes a couple of messages per day. I guess marking spam (Fastmail also uses a naive-bayes-based filter) and/or servers being added to a blacklist stops those waves. I don't recall the opposite (false positives) ever happening. I would say the numbers are generally small enough that it d…

You can also tweak your spam score threshold in settings.

Re: The FastMail Security Mindset

#204
post #191

Earlier quoted context omitted.

I've been a FastMail customer for about four years and overall I'm really pleased with their service. Like you I have my own domain, previously used Gmail, and provide custom email addresses to every site I register with. Interesting to see who has sold my email or may have been hacked when a rogue email ends up in my inbox (hi, Sunspel!). I have one issue with FastMail that I didn't have with Gmail. Every few days/w…

By backspatter, do you mean things like message bounce alerts? Or replies from the people who received spam messages spoofed from your address?

Backscatter is (I think) when the target server of a spam mail bounces the email back to me, the rightful owner of the domain, typically because the address is not valid (though I sometimes also get out-of-office messages or mailbox full errors).

It works like this: the spammer forges their headers to make it look like the from address is under my domain. My domain has DKIM/SPF set up, so a good recipient will compare the email to the authentication records, see they don't match, and then trash the email. But there are still a lot of mail servers out there that don't have that set up, so they accept the email as valid, process it, then return it to me when the account doesn't exist on their server. Like I said, annoying, but not a lot I can do other than set up rules to trash messages with a subject of "Undelivered Mail Returned to Sender."

Re: The FastMail Security Mindset

#205
post #64

I was a very happy FastMail customer until a hacker asked them to reset my password. After _incorrectly_ answering a handful of questions asked by the FastMail support, the recovery email address was changed and a password reset link sent. From there, the hacker attempted password resets on other services. Initially, FastMail was dismissive that this was a simple "mix-up" and didn't disable access to the hacker for 7…

"FastMail has always been an engineering-focused company, from the top down. As such there is a strong culture of no-bullshit, and an intense dislike of security theatre."

After OP comment, that's hilarious. And yes, I am a fastmail user as well. How long will it take to an "engineering-focused company" to understand that humans are humans?

Re: The FastMail Security Mindset

#206
post #64

I was a very happy FastMail customer until a hacker asked them to reset my password. After _incorrectly_ answering a handful of questions asked by the FastMail support, the recovery email address was changed and a password reset link sent. From there, the hacker attempted password resets on other services. Initially, FastMail was dismissive that this was a simple "mix-up" and didn't disable access to the hacker for 7…

[deleted]

Re: The FastMail Security Mindset

#207
post #181

Earlier quoted context omitted.

For an attacker to exploit this, they will have to know that you are going on such a trip. This means that attackers who don't know much about you already are less likely to bother, and also raises the bar for even the focus attackers. Nothing is foolproof, but many things can be useful.

If a well-resourced attacker was targeting me specifically, it wouldn't be too difficult for them to find out about my short-to-medium term travel plans. A bit of social engineering with the airlines could tell them exactly which flight I'm on. They could also compromise other people who need to know my plans and don't have the same security practises as me. I think about this stuff and minimise as best I can, but my…

If a "well-resourced attacker" was targeting you specifically, you're toast. Period.

Re: The FastMail Security Mindset

#208

Earlier quoted context omitted.

Any plans for a PWA for the mobile version? I use the app on Android, but I recently tried just loading the site in Firefox (Beta/58/Quantum), and I think it runs faster, plus it doesn't have keyboard/autocorrect issues.

We’re still planning all the details around service workers and the likes, but we intend to continue our tradition of having as much as possible in the normal web app, instead of in the app wrappers (the app being mostly just a wrapper around the web interface). (BTW, the Android app is in the process of being revamped to use the now-sufficiently-capable WebView, which will fix certain issues like the keyboard proble…

I will say having a native wrapper will be worth it even if all it does is allow the quiet hours feature.

(That feature, your use of Source San Pro, and the fact that the calendar always starts with the current week was what sold me on your service.)

Thanks for the info on the future WebView version.

Re: The FastMail Security Mindset

#209
post #64

I was a very happy FastMail customer until a hacker asked them to reset my password. After _incorrectly_ answering a handful of questions asked by the FastMail support, the recovery email address was changed and a password reset link sent. From there, the hacker attempted password resets on other services. Initially, FastMail was dismissive that this was a simple "mix-up" and didn't disable access to the hacker for 7…

[deleted]

Re: The FastMail Security Mindset

#210

Earlier quoted context omitted.

This is death. Your email provider absolutely cannot under any circumstances have this vulnerability. Wow. Just the idea that there's a human in the process making subjective decisions about security questions and answers that can, on their own recognizance, change a recovery email address. Forget the immediate mistake that one rep made, and go down a couple levels deeper into the company policy design mistakes at pl…

I've been a fastmail customer for a bit over a year and I agree. The offerings over at https://protonmail.com/signup have been nagging me to give it a try. I now have a reason to try and switch. I'll lose functionality found in fastmail but gain a lot in security.

You have been a customer for over a year but based on someone else's anecdote you feel the need to post a signup link for a competitor?
Post reply on HN