Earlier quoted context omitted.
By backspatter, do you mean things like message bounce alerts? Or replies from the people who received spam messages spoofed from your address?
Backscatter is (I think) when the target server of a spam mail bounces the email back to me, the rightful owner of the domain, typically because the address is not valid (though I sometimes also get out-of-office messages or mailbox full errors). It works like this: the spammer forges their headers to make it look like the from address is under my domain. My domain has DKIM/SPF set up, so a good recipient will compar…
The FastMail Security Mindset
221–230 of 301 posts
Re: The FastMail Security Mindset
#222Earlier quoted context omitted.
Sure! Signal and WhatsApp are good at having private conversations. Email is very tough to add private conversation capability to, for a variety of reasons. What you do need your mail provider (and by extension your DNS provider) to do is to not give up access to an attacker who asks nicely, because for most services, email access is account takeover. This makes discussions about email security confusing, because mos…
I get the impression that when non-security people talk about "security" these days it's almost always in the context of preventing government surveillance. So even though Google has a great track record of keeping hackers from taking over your accounts, the news stories about them cooperating with governments makes them seem less "secure" to some people. What's weird is when it leads to a fallacy where people trust…
Re: The FastMail Security Mindset
#223I was a very happy FastMail customer until a hacker asked them to reset my password. After _incorrectly_ answering a handful of questions asked by the FastMail support, the recovery email address was changed and a password reset link sent. From there, the hacker attempted password resets on other services. Initially, FastMail was dismissive that this was a simple "mix-up" and didn't disable access to the hacker for 7…
Now to write a more detailed response. If this winds up out of order later, I first posted: https://news.ycombinator.com/item?id=15856609 Again, ghouse, I'm really really sorry about what happened to your account. It was wrong and we screwed up. As other comments have already noted, it was during the transition to a new security system which was designed precisely to remove the human factor from decision making. I'm…
According the page you linked, a birth certificate and bank statement (or even a 'Document issued by or registered corporations.') would be enough. So if I get your birth certificate and have an Australian corporation, I can issue a letter saying you're a customer for a year. So I have 100 points and can pretend to be you?
That doesn't seem secure at all. The birth certificate has no photo (or, if it does, it won't be useful except to determine ethnicity), and the document from a registered corporation can be trivially faked.
Re: The FastMail Security Mindset
#224Re: The FastMail Security Mindset
#225Earlier quoted context omitted.
Could you share some info/links on what makes it the Gold Standard?
They have one of the largest information security teams in the world, that team includes what is probably the best corporate vulnerability research team in the world. They're one of a small number of companies that is actively defining modern TLS and thus modern transport encryption; their operations and security teams are almost certainly the world's most sophisticated users of TLS. They ship the most secure browser…
Does that make the claims that Protonmail is more secure than Gmail false? - https://protonmail.com/blog/protonmail-vs-gmail-security/
Re: The FastMail Security Mindset
#226Earlier quoted context omitted.
Unless you have a set of objectives that are very different from what I consider "as secure as e-mail gets", please consider GSuite and not Protonmail. (I don't speak for 'tptacek, but I'm pretty sure he'd agree.) As a corollary: if you really care, use Signal for stuff you can't say over e-mail. Whatsapp's fine too. But they solve a very different security problem than the one you need e-mail to solve, which is most…
Just gonna drive by mention https://landing.google.com/advancedprotection/ , which is a physical-2fa-security-key-only version of gmail. To my knowledge it also disallows mail forwarding, and the account recovery procedure in the event of losing both second factors is intended to be a long process that involves proof of identity and multiple attempts to notify the account owner. (I work on gmail, but I'm not intimate…
Re: The FastMail Security Mindset
#227Earlier quoted context omitted.
Can you think of some info/links that would suggest the opposite?
I'm not looking to discredit the claim, I'm genuinely curious to learn about what they've done to earn the Gold Standard from @tptacek Google were previously reading our emails for Ad purposes and some of their employees are still able to read our Emails, their privacy policy also indictates they will hand over our emails if requested by law enforcement which suggests it's weaker than protonmail.com end-to-end encryp…
I get and am not questioning that. It's just that your curiosity doesn't seem to have motivated you to do a first pass of, I don't want to call it 'research', but just basic poking around on the topic. You want links and info from some dude on the internet because what he says contradicts stuff you know from... something a vendor said about their product.
It's a totally sensible question but it's not some particularly arcane mystery to dig into. In tptacek's case, in a jiffy, you can bring up the 60-odd comments of his that mention 'Gmail' and get a reasonable idea of what he thinks of it and why. And if you think he's got it wrong, you can say, hey, tptacek, I think you're full of poop when you said [...]. And then maybe you can hash it out and one or both of you will learn something. But 'Citation, please', especially on trivially searchable topics mostly says 'I'm kind of curious, but I don't really care'. The person you're asking probably isn't going to care either.
Re: The FastMail Security Mindset
#228Earlier quoted context omitted.
I get the impression that when non-security people talk about "security" these days it's almost always in the context of preventing government surveillance. So even though Google has a great track record of keeping hackers from taking over your accounts, the news stories about them cooperating with governments makes them seem less "secure" to some people. What's weird is when it leads to a fallacy where people trust…
This is irrational. It might be a complicated question if the foreign-jurisdiction alternatives were more secure, rather than drastically less secure . But since that's not the case, switching from Google Mail actually gets you the worst of both worlds: a mail service that is materially less secure, operating in a jurisdiction where there are literally no rules preventing USG-level adversaries from exploiting it.
Re: The FastMail Security Mindset
#229Earlier quoted context omitted.
They have one of the largest information security teams in the world, that team includes what is probably the best corporate vulnerability research team in the world. They're one of a small number of companies that is actively defining modern TLS and thus modern transport encryption; their operations and security teams are almost certainly the world's most sophisticated users of TLS. They ship the most secure browser…
So it's because Google has deep/best skills in security? It automatically applies and makes all their products more secure than everyone else's, even if their design is weakened as a result of their business model? e.g. Does Google's 1st class security team + unencrypted emails + tracking makes it more secure than a company like Proton Mail that's focused on providing Secure mail? Does that make the claims that Proto…
${All the things I said previously}. And, Google Mail is one of their flagship products.
Most of what is on that ProtonMail page is nonsensical. The claim that is relevant to the discussion here --- that ProtonMail has a "smaller attack surface" and is thus structurally more secure than Google Mail --- assumes significant facts not in evidence.
See downthread for my response to the claim that using a mail services outside the US somehow insulates you from NSA snooping.
Re: The FastMail Security Mindset
#230Earlier quoted context omitted.
I'm not looking to discredit the claim, I'm genuinely curious to learn about what they've done to earn the Gold Standard from @tptacek Google were previously reading our emails for Ad purposes and some of their employees are still able to read our Emails, their privacy policy also indictates they will hand over our emails if requested by law enforcement which suggests it's weaker than protonmail.com end-to-end encryp…
I'm genuinely curious to learn I get and am not questioning that. It's just that your curiosity doesn't seem to have motivated you to do a first pass of, I don't want to call it 'research', but just basic poking around on the topic. You want links and info from some dude on the internet because what he says contradicts stuff you know from... something a vendor said about their product. It's a totally sensible questio…
If all we have are the same claim being repeated with the only way to learn about what makes Gmail the most secure email provider is having to trawl through 1000's of comments. It means Gmail is always going to perceived as more secure even when they may not be, because relatively no-one is going to trawl through 1000's of comments to make an informed assessment otherwise.