Live data from Hacker News

The FastMail Security Mindset

blog.fastmail.com

231–240 of 301 posts

Re: The FastMail Security Mindset

#231
post #64

I was a very happy FastMail customer until a hacker asked them to reset my password. After _incorrectly_ answering a handful of questions asked by the FastMail support, the recovery email address was changed and a password reset link sent. From there, the hacker attempted password resets on other services. Initially, FastMail was dismissive that this was a simple "mix-up" and didn't disable access to the hacker for 7…

Now to write a more detailed response. If this winds up out of order later, I first posted: https://news.ycombinator.com/item?id=15856609 Again, ghouse, I'm really really sorry about what happened to your account. It was wrong and we screwed up. As other comments have already noted, it was during the transition to a new security system which was designed precisely to remove the human factor from decision making. I'm…

Please consider adding a option to never ever allow recovering of the account without password, similar to how gandi does it.

My email account / domain is my central hub for all my accounts. All of them can be taken over through fastmail (with the exception of my domain and other extremely crucial services) if an attacker happens to obtain access to it. I want to have the security that this attack can not happen to me.

Re: The FastMail Security Mindset

#232

Earlier quoted context omitted.

Now to write a more detailed response. If this winds up out of order later, I first posted: https://news.ycombinator.com/item?id=15856609 Again, ghouse, I'm really really sorry about what happened to your account. It was wrong and we screwed up. As other comments have already noted, it was during the transition to a new security system which was designed precisely to remove the human factor from decision making. I'm…

'I'm an Australian, and I'm a great fan of our "100 points of ID" system, which is designed to remove the human factor from identifying people.' According the page you linked, a birth certificate and bank statement (or even a 'Document issued by or registered corporations.') would be enough. So if I get your birth certificate and have an Australian corporation, I can issue a letter saying you're a customer for a year…

We don't use the 100 points of ID system of course, because we're an online service. The 100 points of ID is something that's used in person to decide whether you can open a new bank account using that name.

The concept behind the 100 points of ID is that there's a fixed standard and it's not a per-time decision made by a human, it's a consistent set of rules applied without fear or favour.

Re: The FastMail Security Mindset

#233
post #30

Earlier quoted context omitted.

I'm not suggesting (at all) that you use them over FastMail, but GSuite also supports catch-all email addresses.

Indeed - but replying from an arbitrary address is one big downside of G Suite’s implementation. In FastMail you can add [0]@example.com as an identity. Selecting this when composing an email allows you to edit the localpart entirely. Similarly, when replying to an email sent to your catch-all and you have an @ identity for the hostname FastMail will automatically set your from address for you. In Gmail (with G Suite…

Speaking of which, do you know of any mail client (on iOS or Mac) that supports this? I am using the web interface for replying on most emails because of exactly this feature

Re: The FastMail Security Mindset

#234
post #217
post #215

Earlier quoted context omitted.

Can you think of some info/links that would suggest the opposite?

I'm not looking to discredit the claim, I'm genuinely curious to learn about what they've done to earn the Gold Standard from @tptacek Google were previously reading our emails for Ad purposes and some of their employees are still able to read our Emails, their privacy policy also indictates they will hand over our emails if requested by law enforcement which suggests it's weaker than protonmail.com end-to-end encryp…

Elsewhere in the thread I mentioned advanced protection[0]. Gmail/Google is also the only company to my knowledge that gives you a warning like this one[1], and it was certainly the first to do so.

A lot of this comes down to your threat model. If you are most worried about

Unless your threat model is "The NSA gives my hosting provider a court order" or "an employee of my hosting provider goes rogue", its pretty clear that GMail is categorically the best option. And in those two cases, its not clear that there are significantly better options.

[0]: https://landing.google.com/advancedprotection/

[1]:https://techcrunch.com/2017/03/24/what-to-do-about-those-gov...

Re: The FastMail Security Mindset

#235

Earlier quoted context omitted.

This can be enough for me to consider leaving depending on how it's fixed. This response says absolutely nothing about how the vulnerability is prevented in the future. It's just a bunch of vague promises and mumbo jumbo. What specific procedures are in place to prevent it? At a minimum, I expect to see something specific like when you guys almost lost your domain because of Gandi [1]. And even then, can I have an op…

At a minimum, normally when speaking of the other big mail providers, you wouldn’t get an explanation on a public forum at all. Especially because technical folks like us don’t know to communicate well, words can be misinterpreted, etc. It’s actually not a good strategy to respond to such concerns in public. Also in my opinion, people that make threats of leaving in public unless certain demands are met usually have…

Oh, and also, I use my own domain on top of having a backup of my emails.

What this means is that if all recovery options are not working and I'm actually locked out, I can fix it.

I own the domain, I own my past emails, I can still get emails. Maybe I'll lose some emails for a day, but that's it. If I want to prove my identity to FastMail, I can also prove that I own the domain.

But the point is, getting locked out of something as important as email is not gonna happen due to my screw-up. It's more likely for a support loophole to screw me over.

Re: The FastMail Security Mindset

#236
post #213

Earlier quoted context omitted.

Could you share some info/links on what makes it the Gold Standard?

They have one of the largest information security teams in the world, that team includes what is probably the best corporate vulnerability research team in the world. They're one of a small number of companies that is actively defining modern TLS and thus modern transport encryption; their operations and security teams are almost certainly the world's most sophisticated users of TLS. They ship the most secure browser…

s/They/Apple/g

Err... This could of been said about Apple Inc a few weeks ago then they go and have the root password issue.

Re: The FastMail Security Mindset

#237

Earlier quoted context omitted.

Exactly which employees in your organization have the ability to alter recovery email settings? How many of those employees are there? In what fashion do you audit and track the activities of those employees? What training are these employees given to avoid social engineering? What firm provides the courseware? What's the escalation process for complicated, non-no-brainer reset situations? If a support person isn't a…

Wow, that's a lot of questions, and I can't answer all of them without creating security risks! Our absolute focus is on minimizing the human factors. In the past year and a bit since that incident, we have improved our escalation policies and support training, as well as let some support staff go. But more importantly, we now have an automated account recovery system which can be used to verify ownership of the acco…

[deleted]

Re: The FastMail Security Mindset

#238
post #230
post #227

Earlier quoted context omitted.

I'm genuinely curious to learn I get and am not questioning that. It's just that your curiosity doesn't seem to have motivated you to do a first pass of, I don't want to call it 'research', but just basic poking around on the topic. You want links and info from some dude on the internet because what he says contradicts stuff you know from... something a vendor said about their product. It's a totally sensible questio…

I was hoping there was a quick resource of someone having done a deep analysis dive into advanced techniques Gmail does that makes it more secure than everyone else but judging by tptacek's response it sounds like it's because they have the best security team and by extension all products they make are naturally more secure. If all we have are the same claim being repeated with the only way to learn about what makes…

trawl through 1000's of comments. It means Gmail is always going to perceived as more secure even when they may not be, because relatively no-one is going to trawl through 1000's of comments to make an informed assessment otherwise.

60ish is not 1000s. 69ish if you add the 9 about Protonmail. The guy posts on HN so much you can fairly safely go to https://hn.algolia.com and type author:tptacek [topic of interest] and find out what he thinks about it. If there was, inexplicably, a comic universe about HN mutants, he'd be The Citation.

Re: The FastMail Security Mindset

#239
post #64

I was a very happy FastMail customer until a hacker asked them to reset my password. After _incorrectly_ answering a handful of questions asked by the FastMail support, the recovery email address was changed and a password reset link sent. From there, the hacker attempted password resets on other services. Initially, FastMail was dismissive that this was a simple "mix-up" and didn't disable access to the hacker for 7…

Now to write a more detailed response. If this winds up out of order later, I first posted: https://news.ycombinator.com/item?id=15856609 Again, ghouse, I'm really really sorry about what happened to your account. It was wrong and we screwed up. As other comments have already noted, it was during the transition to a new security system which was designed precisely to remove the human factor from decision making. I'm…

The blog post was in 2014. This security bypass happened in 2016.

I think what we're witnessing here is that despite best intentions and past experience, humans are going to be humans. I actually felt good after reading that blog post in 2014 thinking that you guys are going to be better than most companies here.

Nope.

But I think a lesson can be learned here. The lesson is simply that humans are the weakest link. As much as you might try to add process and try to minimize, the best is having zero human capability at all. So when tptacek asks _who_ has ability to change things about an account, we really do want to know. Because those people are the weakest links. (don't mean naming names, but understanding who in general has those powers)

I mentioned elsewhere. I own my domain. I backup my emails. It's way more likely for a FastMail human loophole to screw me over than for me to need human assistance on login (which is never).

Re: The FastMail Security Mindset

#240
post #64

I was a very happy FastMail customer until a hacker asked them to reset my password. After _incorrectly_ answering a handful of questions asked by the FastMail support, the recovery email address was changed and a password reset link sent. From there, the hacker attempted password resets on other services. Initially, FastMail was dismissive that this was a simple "mix-up" and didn't disable access to the hacker for 7…

I've been a long-term customer of them, but I'm continually under-whelmed by them.

They admit, if you push them, that they economize on front-line support. I think what you relate is a consequence of that.

In a previous thread, I went on a massive whinge-fest about how they had "sun-setted" the one-time $15 payment member account that I set up for my father and that they had previously advertised using the words "never expires". I stand by that because they were in breach of contract.

On the other hand, I don't think they are charging enough really. I would probably be prepared to pay more than I do if I had confidence that they weren't using low-skilled labor for front-line support.

Post reply on HN