Live data from Hacker News

The FastMail Security Mindset

blog.fastmail.com

221–230 of 301 posts

Re: The FastMail Security Mindset

#221
post #191

Earlier quoted context omitted.

By backspatter, do you mean things like message bounce alerts? Or replies from the people who received spam messages spoofed from your address?

Backscatter is (I think) when the target server of a spam mail bounces the email back to me, the rightful owner of the domain, typically because the address is not valid (though I sometimes also get out-of-office messages or mailbox full errors). It works like this: the spammer forges their headers to make it look like the from address is under my domain. My domain has DKIM/SPF set up, so a good recipient will compar…

Did you also setup DMARC? I've had good luck with that to reduce the amount of backscatter. Although some recipients don't check it, those that do will fast fail anything coming in that doesn't pass SPF or DKIM.

Re: The FastMail Security Mindset

#222
post #212

Earlier quoted context omitted.

Sure! Signal and WhatsApp are good at having private conversations. Email is very tough to add private conversation capability to, for a variety of reasons. What you do need your mail provider (and by extension your DNS provider) to do is to not give up access to an attacker who asks nicely, because for most services, email access is account takeover. This makes discussions about email security confusing, because mos…

I get the impression that when non-security people talk about "security" these days it's almost always in the context of preventing government surveillance. So even though Google has a great track record of keeping hackers from taking over your accounts, the news stories about them cooperating with governments makes them seem less "secure" to some people. What's weird is when it leads to a fallacy where people trust…

This is irrational. It might be a complicated question if the foreign-jurisdiction alternatives were more secure, rather than drastically less secure. But since that's not the case, switching from Google Mail actually gets you the worst of both worlds: a mail service that is materially less secure, operating in a jurisdiction where there are literally no rules preventing USG-level adversaries from exploiting it.

Re: The FastMail Security Mindset

#223
post #64

I was a very happy FastMail customer until a hacker asked them to reset my password. After _incorrectly_ answering a handful of questions asked by the FastMail support, the recovery email address was changed and a password reset link sent. From there, the hacker attempted password resets on other services. Initially, FastMail was dismissive that this was a simple "mix-up" and didn't disable access to the hacker for 7…

Now to write a more detailed response. If this winds up out of order later, I first posted: https://news.ycombinator.com/item?id=15856609 Again, ghouse, I'm really really sorry about what happened to your account. It was wrong and we screwed up. As other comments have already noted, it was during the transition to a new security system which was designed precisely to remove the human factor from decision making. I'm…

'I'm an Australian, and I'm a great fan of our "100 points of ID" system, which is designed to remove the human factor from identifying people.'

According the page you linked, a birth certificate and bank statement (or even a 'Document issued by or registered corporations.') would be enough. So if I get your birth certificate and have an Australian corporation, I can issue a letter saying you're a customer for a year. So I have 100 points and can pretend to be you?

That doesn't seem secure at all. The birth certificate has no photo (or, if it does, it won't be useful except to determine ethnicity), and the document from a registered corporation can be trivially faked.

Re: The FastMail Security Mindset

#224

Earlier quoted context omitted.

I haven't had that experience — I have it hooked up as CalDAV to my mac and iphone's native clients.

Hmm, maybe I'm just doing it wrong.

I found the Fastmail calendar to be far more reliable and compatible than Gmail.

Re: The FastMail Security Mindset

#225
post #213

Earlier quoted context omitted.

Could you share some info/links on what makes it the Gold Standard?

They have one of the largest information security teams in the world, that team includes what is probably the best corporate vulnerability research team in the world. They're one of a small number of companies that is actively defining modern TLS and thus modern transport encryption; their operations and security teams are almost certainly the world's most sophisticated users of TLS. They ship the most secure browser…

So it's because Google has deep/best skills in security? It automatically applies and makes all their products more secure than everyone else's, even if their design is weakened as a result of their business model? e.g. Does Google's 1st class security team + unencrypted emails + tracking makes it more secure than a company like Proton Mail that's focused on providing Secure mail?

Does that make the claims that Protonmail is more secure than Gmail false? - https://protonmail.com/blog/protonmail-vs-gmail-security/

Re: The FastMail Security Mindset

#226
post #201

Earlier quoted context omitted.

Unless you have a set of objectives that are very different from what I consider "as secure as e-mail gets", please consider GSuite and not Protonmail. (I don't speak for 'tptacek, but I'm pretty sure he'd agree.) As a corollary: if you really care, use Signal for stuff you can't say over e-mail. Whatsapp's fine too. But they solve a very different security problem than the one you need e-mail to solve, which is most…

Just gonna drive by mention https://landing.google.com/advancedprotection/ , which is a physical-2fa-security-key-only version of gmail. To my knowledge it also disallows mail forwarding, and the account recovery procedure in the event of losing both second factors is intended to be a long process that involves proof of identity and multiple attempts to notify the account owner. (I work on gmail, but I'm not intimate…

Yep. I don’t recommend it by default (most people I work with use GSuite in a work context, so recovery is normally administrator-mediated), but the fact that this exists is pretty awesome.

Re: The FastMail Security Mindset

#227
post #217
post #215

Earlier quoted context omitted.

Can you think of some info/links that would suggest the opposite?

I'm not looking to discredit the claim, I'm genuinely curious to learn about what they've done to earn the Gold Standard from @tptacek Google were previously reading our emails for Ad purposes and some of their employees are still able to read our Emails, their privacy policy also indictates they will hand over our emails if requested by law enforcement which suggests it's weaker than protonmail.com end-to-end encryp…

I'm genuinely curious to learn

I get and am not questioning that. It's just that your curiosity doesn't seem to have motivated you to do a first pass of, I don't want to call it 'research', but just basic poking around on the topic. You want links and info from some dude on the internet because what he says contradicts stuff you know from... something a vendor said about their product.

It's a totally sensible question but it's not some particularly arcane mystery to dig into. In tptacek's case, in a jiffy, you can bring up the 60-odd comments of his that mention 'Gmail' and get a reasonable idea of what he thinks of it and why. And if you think he's got it wrong, you can say, hey, tptacek, I think you're full of poop when you said [...]. And then maybe you can hash it out and one or both of you will learn something. But 'Citation, please', especially on trivially searchable topics mostly says 'I'm kind of curious, but I don't really care'. The person you're asking probably isn't going to care either.

Re: The FastMail Security Mindset

#228

Earlier quoted context omitted.

I get the impression that when non-security people talk about "security" these days it's almost always in the context of preventing government surveillance. So even though Google has a great track record of keeping hackers from taking over your accounts, the news stories about them cooperating with governments makes them seem less "secure" to some people. What's weird is when it leads to a fallacy where people trust…

This is irrational. It might be a complicated question if the foreign-jurisdiction alternatives were more secure, rather than drastically less secure . But since that's not the case, switching from Google Mail actually gets you the worst of both worlds: a mail service that is materially less secure, operating in a jurisdiction where there are literally no rules preventing USG-level adversaries from exploiting it.

Agreed. Don't throw the baby out with the bathwater.

Re: The FastMail Security Mindset

#229
post #225

Earlier quoted context omitted.

They have one of the largest information security teams in the world, that team includes what is probably the best corporate vulnerability research team in the world. They're one of a small number of companies that is actively defining modern TLS and thus modern transport encryption; their operations and security teams are almost certainly the world's most sophisticated users of TLS. They ship the most secure browser…

So it's because Google has deep/best skills in security? It automatically applies and makes all their products more secure than everyone else's, even if their design is weakened as a result of their business model? e.g. Does Google's 1st class security team + unencrypted emails + tracking makes it more secure than a company like Proton Mail that's focused on providing Secure mail? Does that make the claims that Proto…

Sorry, I missed an important sentence.

${All the things I said previously}. And, Google Mail is one of their flagship products.

Most of what is on that ProtonMail page is nonsensical. The claim that is relevant to the discussion here --- that ProtonMail has a "smaller attack surface" and is thus structurally more secure than Google Mail --- assumes significant facts not in evidence.

See downthread for my response to the claim that using a mail services outside the US somehow insulates you from NSA snooping.

Re: The FastMail Security Mindset

#230
post #227
post #217

Earlier quoted context omitted.

I'm not looking to discredit the claim, I'm genuinely curious to learn about what they've done to earn the Gold Standard from @tptacek Google were previously reading our emails for Ad purposes and some of their employees are still able to read our Emails, their privacy policy also indictates they will hand over our emails if requested by law enforcement which suggests it's weaker than protonmail.com end-to-end encryp…

I'm genuinely curious to learn I get and am not questioning that. It's just that your curiosity doesn't seem to have motivated you to do a first pass of, I don't want to call it 'research', but just basic poking around on the topic. You want links and info from some dude on the internet because what he says contradicts stuff you know from... something a vendor said about their product. It's a totally sensible questio…

I was hoping there was a quick resource of someone having done a deep analysis dive into advanced techniques Gmail does that makes it more secure than everyone else but judging by tptacek's response it sounds like it's because they have the best security team and by extension all products they make are naturally more secure.

If all we have are the same claim being repeated with the only way to learn about what makes Gmail the most secure email provider is having to trawl through 1000's of comments. It means Gmail is always going to perceived as more secure even when they may not be, because relatively no-one is going to trawl through 1000's of comments to make an informed assessment otherwise.

Post reply on HN