Live data from Hacker News

FastMail’s servers are in the US – what this means for you

blog.fastmail.fm

31–40 of 175 posts

Re: FastMail’s servers are in the US – what this means for you

#31

The US government will just take their server. They don't care if you go out of business. Look at what they did to megaupload.com.

Absolutely. It is a powerful tactic. Impede or shut down their business, destroy their reputation, and then even if you can't do anything to them legally, you have still achieved the same ultimate damage.

And, my initial response to seeing this headline: "Oh, _yes_ you do."

Re: FastMail’s servers are in the US – what this means for you

#32

Hi, FastMail employee and author of (most of) that blog post here. Just so we're clear, the point of this post was not that we don't think the rules don't apply to us. Instead we're trying to make it clear where position on these things are. The topic of this thread is a sensationalist sound-bite, nothing more. I'm not going to go over the points again here because I'm pretty sure we said it all in the post (but ask…

I may have missed this elsewhere, but why are you're severs in the US at all?

Re: FastMail’s servers are in the US – what this means for you

#33

Hi, FastMail employee and author of (most of) that blog post here. Just so we're clear, the point of this post was not that we don't think the rules don't apply to us. Instead we're trying to make it clear where position on these things are. The topic of this thread is a sensationalist sound-bite, nothing more. I'm not going to go over the points again here because I'm pretty sure we said it all in the post (but ask…

Hi Rob, Has the headline on HN been updated? Because both you and brongondwana talk about it being sensationalist, where I see it as just being a summary of the most salient part of what you have to say. Do you have Australian legal advice to back up your conclusions? (I agree with them, but would like to make sure we're talking more than the "gist" of the law)

> Has the headline on HN been updated? Because both you and brongondwana talk about it being sensationalist, where I see it as just being a summary of the most salient part of what you have to say.

To my mind it was one of the least interesting parts of what we had to say. "Non-US company not bound by US law" - its hardly earth-shattering news. Would "Non-Senegalese company not bound by Senegal law" be as interesting?

EDIT: Sorry, it just occurred to me that it was changed already and you might have posted this afterwards. The original post headline was "FastMail claims they do not have to comply with National Security Letters". That's what we were referring to when we said it was "sensationalist".

> Do you have Australian legal advice to back up your conclusions? (I agree with them, but would like to make sure we're talking more than the "gist" of the law)

We've made our position public, and we're satisfied that its an accurate reflection of our position and our understanding of Australian law. You must not rely on it as a legal basis for anything though - get your own legal advice that applies specifically to your own circumstances!

Re: FastMail’s servers are in the US – what this means for you

#34
post #27

Earlier quoted context omitted.

Full disk encryption would be another option, with the key being obtained over a secure channel from servers hosted remotely before booting to the real system. Then, as long as they can detect whether the server asking for the key has been compromised, I think it should be pretty safe. (Not a security researcher though, I wouldn't bet money on it.)

Remotely detecting if the server is not compromised when you don't trust the physical surroundings is probably unsolvable. If your attackers are very motivated and have lots of resources, what's to prevent them from installing a ram bus signal analyzer during a scheduled/unscheduled downtime. This would be pretty hard to detect (absent an elaborate video monitoring setup), as a good analyzer should not impact the sys…

Hardware Security Modules (HSMs) are supposed to be able to resist that kind of attack, but given we currently have a duopoly of fairly government (US and EU/UK) connected HSM manufacturers, and they devices aren't suitable (price and capabilities) for general purpose computing, we're kind of out of luck.

A Free/Open HSM design would go a long way, along with more host-based trusted computing security (Intel SGX, etc.). But just physically controlling the surroundings is probably the only feasible option today.

Re: FastMail’s servers are in the US – what this means for you

#35
post #6

> There are of course other avenues available to obtain your data. Our colocation providers could be compelled to give physical access to our servers. Network capturing devices could be installed. And in the worst case an attacker could simply force their way into the datacentre and physically remove our servers. > These are not things we can protect against directly but again, we can make it extremely difficult for…

"This kind of frank disclosure should be highly rewarded." Yep, definitely. I think even more important than the information itself is the spirit of honesty and integrity that it demonstrates. This stands in stark contrast to the ambiguous slimeball statements issued by the likes of Google, Facebook, Apple, Microsoft, etc. When Big Brother comes knocking, which companies are going to take a risk to stand up for you?…

Note that G, FB, A and MS are not in a position where they can write such disclosure. I am not arguing with your main point, I applaud FastMail for taking a stand - it's just that USA companies must use "ambiguous slimeball statements" to at least appear clean (because they are not).

I would argue that if FastMail were an USA company their statements (if any) would be just as ambiguous as those of G, FB, A and MS.

Re: FastMail’s servers are in the US – what this means for you

#36

Hi, FastMail employee and author of (most of) that blog post here. Just so we're clear, the point of this post was not that we don't think the rules don't apply to us. Instead we're trying to make it clear where position on these things are. The topic of this thread is a sensationalist sound-bite, nothing more. I'm not going to go over the points again here because I'm pretty sure we said it all in the post (but ask…

I may have missed this elsewhere, but why are you're severs in the US at all?

https://news.ycombinator.com/item?id=6506626

Re: FastMail’s servers are in the US – what this means for you

#37

Note the obvious caveat though: "There are of course other avenues available to obtain your data. Our colocation providers could be compelled to give physical access to our servers. Network capturing devices could be installed. And in the worst case an attacker could simply force their way into the datacentre and physically remove our servers." As the colocation providers are based in the U.S., they would be subject…

If they mount webcams and other sensors inside the cabinet, they could detect unexplained access to their servers. Not sure what it'd really accomplish. The colo provider would either say "tech mistakenly opened that cabinet" or "no comment". The only real defense is to assume any such access is a breach and have servers immediately overwrite FDE keys in RAM and power off - and if they were that committed, they would…

There is some historical precedent for such methods. I believe one popular CDN (possibly Akamai?) has its nodes set up with sensors of some variety to discard sensitive data if the hardware is exposed to light.

Re: FastMail’s servers are in the US – what this means for you

#38
post #35

Earlier quoted context omitted.

"This kind of frank disclosure should be highly rewarded." Yep, definitely. I think even more important than the information itself is the spirit of honesty and integrity that it demonstrates. This stands in stark contrast to the ambiguous slimeball statements issued by the likes of Google, Facebook, Apple, Microsoft, etc. When Big Brother comes knocking, which companies are going to take a risk to stand up for you?…

Note that G, FB, A and MS are not in a position where they can write such disclosure. I am not arguing with your main point, I applaud FastMail for taking a stand - it's just that USA companies must use "ambiguous slimeball statements" to at least appear clean (because they are not). I would argue that if FastMail were an USA company their statements (if any) would be just as ambiguous as those of G, FB, A and MS.

> Note that G, FB, A and MS are not in a position where they can write such disclosure.

Yet could, e.g, Google Ireland Ltd do so, by some interesting twist of laws?

Re: FastMail’s servers are in the US – what this means for you

#39
> Australia does not have any equivalent to the US National Security Letter, so we cannot be forced to do something without being allowed to disclose it.

This is not true. The Australian Crime Commission has some of the most extensive secret coercive powers in the Western world.

http://www.austlii.edu.au/au/legis/cth/consol_act/acca200228...

I would suggest that either:

a) Fastmail is aware of this and is covertly spreading the word that it might be compromised; or

b) Fastmail needs better lawyers.

Re: FastMail’s servers are in the US – what this means for you

#40
post #38
post #35

Earlier quoted context omitted.

Note that G, FB, A and MS are not in a position where they can write such disclosure. I am not arguing with your main point, I applaud FastMail for taking a stand - it's just that USA companies must use "ambiguous slimeball statements" to at least appear clean (because they are not). I would argue that if FastMail were an USA company their statements (if any) would be just as ambiguous as those of G, FB, A and MS.

> Note that G, FB, A and MS are not in a position where they can write such disclosure. Yet could, e.g, Google Ireland Ltd do so, by some interesting twist of laws?

I don't think so, as the NSLs are received and acted upon by Google US. Of course, when operating in a country, you have to respect the legislation of that country. However, companies like Google are in a really tough spot on this one, which is why the NSA spying is so poisonous to US businesses and why you should fight against it.
Post reply on HN