Live data from Hacker News

The FastMail Security Mindset

blog.fastmail.com

281–290 of 301 posts

Re: The FastMail Security Mindset

#281
post #178

Earlier quoted context omitted.

I agree with hitekker, I'm feeling pretty nervous about being a FastMail customer right now and will start looking for a more secure alternative now. The main reason I moved to FastMail is because I stopped trusting Google to keep my mail secure.

Google is the gold standard for email account service. Nobody in the industry does a better job at that one thing than Google does.

I've just switched away from Chrome (because I'd like to support Firefox) and am a FastMail customer.

But I've started to think about moving back to Chrome for "high security mail".

My private mail is pretty bland and uninteresting, so I don't care too much about not using GMail there, but for my Apple account, Google account, Microsoft account etc. it might be a good idea to compartmentalize those "high value" things from everyday mail and go to GMail with the Advanced Protection Program (so no access from smartphone or iPad, I guess).

And looking at their web site I've learned that GSuite Business is affordable and allows adding domains hosted elsewhere. Good.

What do people think about this?

But then the next step: what about losing my domain? My registrar is a reputable German domain hoster, but certainly no Google. On the other hand, Google doesn't register domains, but has "domain partners" like "domaindiscount24" (that I've never heard of before), so I guess not much to win there.

Re: The FastMail Security Mindset

#282

Earlier quoted context omitted.

A strict content security policy in an http-equiv meta tag is a much simpler and more effective way to accomplish this.

That will break the app if it wasn't written for it. It doesn't change the argument, though. I'm arguing that it is relatively easy to deal with within the limits of what can be dealt with. If a strict content security policy can be applied, it just gets even easier.

I'd say that a csp is the only reasonable way to verify for a non-trivial app. A deep audit of every line of the app plus the whole dependency graph (that must be repeated on the diffs for every update) is not how I would define 'relatively easy'.

And yes, I know it will break if not written for it--I'm saying that coding to fit a strict csp is the only way to have a verifiably secure js app. Without it, you're in the jungle.

Re: The FastMail Security Mindset

#283
post #84

I see the usual comment about Fastmail (comparison to Gmail, ProtonMail, web interface, spam filtering performance, servers in the US, ...) but still nothing about the TOS, which seems more important to me So here it is again: - Fastmail can immediately cancel your account for any reason: "The Service Provider may terminate your access to any part or all of the Service and any related service(s) at any time, with or…

No, that TOS was amended several months ago, to among other things, get rid of that clause about termination for any reason. "We used to be able to terminate your account at any time and for any reason. Now, we can only do so if you: fail to comply with the Terms and Conditions; if we are required to by law; or if your account is inactive for an extended period of time." [0] [1] [0] https://blog.fastmail.com/2017/09/…

Indeed the TOS has been changed on 1st of october ! I haven't noticed it, has an email been sent to notify the users ?

Anyway it's much better now (except for the disclosure, which hasn't been changed). Thanks !

Re: The FastMail Security Mindset

#284

I see the usual comment about Fastmail (comparison to Gmail, ProtonMail, web interface, spam filtering performance, servers in the US, ...) but still nothing about the TOS, which seems more important to me So here it is again: - Fastmail can immediately cancel your account for any reason: "The Service Provider may terminate your access to any part or all of the Service and any related service(s) at any time, with or…

> - Fastmail can immediately cancel your account for any reason: "The Service Provider may terminate your access to any part or all of the Service and any related service(s) at any time, with or without cause, with or without notice, effective immediately, for any reason whatsoever, with or without providing any refund of any payments." Other than the last clause about "without providing any refund", I would expect t…

>> - Fastmail can immediately cancel your account for any reason: "The Service Provider may terminate your access to any part or all of the Service and any related service(s) at any time, with or without cause, with or without notice, effective immediately, for any reason whatsoever, with or without providing any refund of any payments."

> Other than the last clause about "without providing any refund", I would expect this from any service provider, and I'd certainly never want to run a service that didn't have this in its terms.

You expect from any service that they can cancel your account for any reason ?!? We must not have the same set of requirements. Anyway the point is not relevant anymore as they have changed the TOS (it's much better now).

Re: The FastMail Security Mindset

#285

Earlier quoted context omitted.

> - Fastmail can immediately cancel your account for any reason: "The Service Provider may terminate your access to any part or all of the Service and any related service(s) at any time, with or without cause, with or without notice, effective immediately, for any reason whatsoever, with or without providing any refund of any payments." Other than the last clause about "without providing any refund", I would expect t…

In almost all cases, we're very happy to provide refunds - particularly early in a subscription period. We also automatically refund if we believe accounts were opened with stolen credit details (happens more often than we would like despite all the checks in place at payment time).

Please also consider to reduce your disclosure rights. As it is currently written in the TOS, it's too broad.

Re: The FastMail Security Mindset

#286

Earlier quoted context omitted.

> - Fastmail can immediately cancel your account for any reason: "The Service Provider may terminate your access to any part or all of the Service and any related service(s) at any time, with or without cause, with or without notice, effective immediately, for any reason whatsoever, with or without providing any refund of any payments." Other than the last clause about "without providing any refund", I would expect t…

>> - Fastmail can immediately cancel your account for any reason: "The Service Provider may terminate your access to any part or all of the Service and any related service(s) at any time, with or without cause, with or without notice, effective immediately, for any reason whatsoever, with or without providing any refund of any payments." > Other than the last clause about "without providing any refund", I would expec…

> You expect from any service that they can cancel your account for any reason

Yes, absolutely. "We reserve the right to refuse service to anyone." I expect to be able to do that for any service I run, and I expect others to be able to do the same.

I also expect that doing so lightly, without a very well-justified reason, would get reported on and lead to a massive backlash. So, in practice, I expect such a clause to be used as, effectively, 'if you try to find a "creative" way to weasel your way out of our specific terms like "don't be disruptive, don't spam, etc", such that your activity meets the letter of the ToS but not the spirit, we'll kick you off anyway". Personally, if I were writing a ToS, I'd write the relevant term along those lines instead.

Re: The FastMail Security Mindset

#287

Earlier quoted context omitted.

I used Fastmail for a few years. I switched last spring due to two interactions through support channels that left me really despising the apparent company culture, attitudes about intellectual honesty, and general jerkishness. You're probably considering switching based on your mail needs, so this might not apply to you, however: In addition to mail, Fastmail also advertises[1] their plans come with their FastMail F…

> However, I learned from the CEO's comments in my support ticket that they're apparently overprovisioned and don't expect everyone to actually use the storage included with their plans. Isn't that true for every file hosting service everywhere? Most people only use a fraction of their available storage, so there's no need to actually provision enough space for everyone to use 100% of their quota. Doing so would be a…

[deleted]

Re: The FastMail Security Mindset

#288

Earlier quoted context omitted.

We don't use the 100 points of ID system of course, because we're an online service. The 100 points of ID is something that's used in person to decide whether you can open a new bank account using that name. The concept behind the 100 points of ID is that there's a fixed standard and it's not a per-time decision made by a human, it's a consistent set of rules applied without fear or favour.

"We don't use the 100 points of ID system of course, because we're an online service. Right, but you said you're a 'great fan' of it. My reading of the wikipedia description that you linked suggests that the system is wholly inadequate (mainly as you can satisfy the 100 points without photo ID). So I'd like to know: are you really a fan of that system (the particulars of its rules), or just a fan of the idea behind i…

Tell me how you bootstrap photo ID in your country, and I'll tell you whether I think photo ID means anything.

In our case, we don't care at all what you look like, just that you're the same person we were talking to earlier - and ideally that you're the owner of the method being used to pay, though that's not always true or necessary. So the photo is meaningless to us.

Besides: who is looking at the photo and confirming that it's the same person as the one in front of them? Yep, an human. The whole point of this discussion is stopping the human making human-factor judgement calls.

Re: The FastMail Security Mindset

#289
post #217
post #215

Earlier quoted context omitted.

Can you think of some info/links that would suggest the opposite?

I'm not looking to discredit the claim, I'm genuinely curious to learn about what they've done to earn the Gold Standard from @tptacek Google were previously reading our emails for Ad purposes and some of their employees are still able to read our Emails, their privacy policy also indictates they will hand over our emails if requested by law enforcement which suggests it's weaker than protonmail.com end-to-end encryp…

I think you're conflating several different things here. Their vulnerability to hackers is not at all related to the extent to which they are willing to cooperate with the US Government or to exactly how their GMail ads work. You have to define exactly what your threat model is, and no service can really be the best at all of them. It's perfectly consistent with the worst interpretation of your other assertions that Google is still the gold standard for making sure that no hacker can ever compromise your GMail account, reset your passwords to your services, and hold your data and accounts on other services hostage.

Re: The FastMail Security Mindset

#290
post #238

Earlier quoted context omitted.

trawl through 1000's of comments. It means Gmail is always going to perceived as more secure even when they may not be, because relatively no-one is going to trawl through 1000's of comments to make an informed assessment otherwise. 60ish is not 1000s. 69ish if you add the 9 about Protonmail. The guy posts on HN so much you can fairly safely go to https://hn.algolia.com and type author:tptacek [topic of interest] and…

If there was, inexplicably, a comic universe about HN mutants, he'd be The Citation. This is getting weird. But I'll allow it.

[deleted]
Post reply on HN