Live data from Hacker News

FastMail’s servers are in the US – what this means for you

blog.fastmail.fm

11–20 of 175 posts

Re: FastMail’s servers are in the US – what this means for you

#12

Note the obvious caveat though: "There are of course other avenues available to obtain your data. Our colocation providers could be compelled to give physical access to our servers. Network capturing devices could be installed. And in the worst case an attacker could simply force their way into the datacentre and physically remove our servers." As the colocation providers are based in the U.S., they would be subject…

How likely is it that Fastmail data could be obtained without anybody at Fastmail noticing? And the key point is that Fastmail cannot be complied to keep such an attempt secret - which is not the case for a US company.

Re: FastMail’s servers are in the US – what this means for you

#13

Note the obvious caveat though: "There are of course other avenues available to obtain your data. Our colocation providers could be compelled to give physical access to our servers. Network capturing devices could be installed. And in the worst case an attacker could simply force their way into the datacentre and physically remove our servers." As the colocation providers are based in the U.S., they would be subject…

If they mount webcams and other sensors inside the cabinet, they could detect unexplained access to their servers. Not sure what it'd really accomplish. The colo provider would either say "tech mistakenly opened that cabinet" or "no comment". The only real defense is to assume any such access is a breach and have servers immediately overwrite FDE keys in RAM and power off - and if they were that committed, they would…

[deleted]

Re: FastMail’s servers are in the US – what this means for you

#14

The US government will just take their server. They don't care if you go out of business. Look at what they did to megaupload.com.

The point that they're trying to make, and which is true in the Megaupload case, is that they would know that this had happened and they would disclose the fact that it happened.

Re: FastMail’s servers are in the US – what this means for you

#15

So they are saying that they can never get a NSL to turn over information, but where are these servers? Who has the keys to the door of the server room? So maybe they don't get the NSL, but the people/group/company that is handling the servers might. This seems disingenuous. I could be wrong, but it feels like they are making claims that will dupe people into their service because they feel safe.

> So maybe they don't get the NSL, but the people/group/company that is handling the servers might. This seems disingenuous.

well they do say explicitly that, near the bottom. Hardly disingenuous.

Re: FastMail’s servers are in the US – what this means for you

#17
The personal location of the operators is probably the #1 most important security risk; location of customers, location of servers, and country of incorporation are also important.

It's much easier to compel operators to do something (through legal threats or potentially physical threats) than it is to do any active modifications to a complex system, undetectably. Passive ubiquitous monitoring is a concern because it's passive and thus hard to detect -- it's highly unlikely TAO can go after a large number of well-defended systems without getting caught. Obviously they'd be likely to hide their actions behind HACKED BY CHINESEEEE or something, but even then, it's relatively rare to have a complete penetration of a large site in a way which isn't end-user affecting, and rarer still for the site not to publicize it.

That said, if I wanted to compromise Fastmail, I'd either compromise a staffer or some of their administrative systems to impersonate staff.

Re: FastMail’s servers are in the US – what this means for you

#18

The US government will just take their server. They don't care if you go out of business. Look at what they did to megaupload.com.

This is the same megaupload where FBI agents took part in a raid on a house in a non-US country?

http://www.listener.co.nz/commentary/the-internaut/kim-dotco...

As I said in a response on our forum, if the stakes are high enough, no datacentre in the world is safe.

Bruce Schneier recommends protecting against terrorist attacks by improving emergency response capabilities - with the side benefit that your measures also help against natural disasters:

https://www.schneier.com/essay-292.html

(edit: that's not a great version of his point actually, https://www.schneier.com/blog/archives/2005/09/katrina_and_s... is more on point)

Similarly, our main focus for security is protecting against all forms of attackers, including common theft or misplacement of our servers. We consider that to be more valuable for the overall security of our users (including security against denial of service) than fighting an impossible fight.

FACT: if the three letter agencies in the USA want your data desperately enough, they will get it. With FastMail, they have a legal way to obtain it which is quite a lot of effort, but (hopefully) less expensive to them than taking our servers offline.

What they can't do, by Australian law, is require our cooperation in blanket surveillance on all our users.

Re: FastMail’s servers are in the US – what this means for you

#19

The only real benefit I see here is that your IP won't be easily revealed. That is, given a fastmail account, the e.g. FBI cannot quickly get your login IP, like they can with e.g. Outlook or Gmail. So, for just low-level anti-surveillance, SSL to fastmail might suffice instead of using Tor with Gmail. Unless you're using PGP or S/MIME, SMTP is still most often unencrypted.

I think the assumption is that FBI has to obey the law to produce evidence for prosecutions. NSA doesn't, particularly vs. "foreign".
Post reply on HN