The US government will just take their server. They don't care if you go out of business. Look at what they did to megaupload.com.
And, my initial response to seeing this headline: "Oh, _yes_ you do."
31–40 of 175 posts
The US government will just take their server. They don't care if you go out of business. Look at what they did to megaupload.com.
And, my initial response to seeing this headline: "Oh, _yes_ you do."
Hi, FastMail employee and author of (most of) that blog post here. Just so we're clear, the point of this post was not that we don't think the rules don't apply to us. Instead we're trying to make it clear where position on these things are. The topic of this thread is a sensationalist sound-bite, nothing more. I'm not going to go over the points again here because I'm pretty sure we said it all in the post (but ask…
Hi, FastMail employee and author of (most of) that blog post here. Just so we're clear, the point of this post was not that we don't think the rules don't apply to us. Instead we're trying to make it clear where position on these things are. The topic of this thread is a sensationalist sound-bite, nothing more. I'm not going to go over the points again here because I'm pretty sure we said it all in the post (but ask…
Hi Rob, Has the headline on HN been updated? Because both you and brongondwana talk about it being sensationalist, where I see it as just being a summary of the most salient part of what you have to say. Do you have Australian legal advice to back up your conclusions? (I agree with them, but would like to make sure we're talking more than the "gist" of the law)
To my mind it was one of the least interesting parts of what we had to say. "Non-US company not bound by US law" - its hardly earth-shattering news. Would "Non-Senegalese company not bound by Senegal law" be as interesting?
EDIT: Sorry, it just occurred to me that it was changed already and you might have posted this afterwards. The original post headline was "FastMail claims they do not have to comply with National Security Letters". That's what we were referring to when we said it was "sensationalist".
> Do you have Australian legal advice to back up your conclusions? (I agree with them, but would like to make sure we're talking more than the "gist" of the law)
We've made our position public, and we're satisfied that its an accurate reflection of our position and our understanding of Australian law. You must not rely on it as a legal basis for anything though - get your own legal advice that applies specifically to your own circumstances!
Earlier quoted context omitted.
Full disk encryption would be another option, with the key being obtained over a secure channel from servers hosted remotely before booting to the real system. Then, as long as they can detect whether the server asking for the key has been compromised, I think it should be pretty safe. (Not a security researcher though, I wouldn't bet money on it.)
Remotely detecting if the server is not compromised when you don't trust the physical surroundings is probably unsolvable. If your attackers are very motivated and have lots of resources, what's to prevent them from installing a ram bus signal analyzer during a scheduled/unscheduled downtime. This would be pretty hard to detect (absent an elaborate video monitoring setup), as a good analyzer should not impact the sys…
A Free/Open HSM design would go a long way, along with more host-based trusted computing security (Intel SGX, etc.). But just physically controlling the surroundings is probably the only feasible option today.
> There are of course other avenues available to obtain your data. Our colocation providers could be compelled to give physical access to our servers. Network capturing devices could be installed. And in the worst case an attacker could simply force their way into the datacentre and physically remove our servers. > These are not things we can protect against directly but again, we can make it extremely difficult for…
"This kind of frank disclosure should be highly rewarded." Yep, definitely. I think even more important than the information itself is the spirit of honesty and integrity that it demonstrates. This stands in stark contrast to the ambiguous slimeball statements issued by the likes of Google, Facebook, Apple, Microsoft, etc. When Big Brother comes knocking, which companies are going to take a risk to stand up for you?…
I would argue that if FastMail were an USA company their statements (if any) would be just as ambiguous as those of G, FB, A and MS.
Hi, FastMail employee and author of (most of) that blog post here. Just so we're clear, the point of this post was not that we don't think the rules don't apply to us. Instead we're trying to make it clear where position on these things are. The topic of this thread is a sensationalist sound-bite, nothing more. I'm not going to go over the points again here because I'm pretty sure we said it all in the post (but ask…
I may have missed this elsewhere, but why are you're severs in the US at all?
Note the obvious caveat though: "There are of course other avenues available to obtain your data. Our colocation providers could be compelled to give physical access to our servers. Network capturing devices could be installed. And in the worst case an attacker could simply force their way into the datacentre and physically remove our servers." As the colocation providers are based in the U.S., they would be subject…
If they mount webcams and other sensors inside the cabinet, they could detect unexplained access to their servers. Not sure what it'd really accomplish. The colo provider would either say "tech mistakenly opened that cabinet" or "no comment". The only real defense is to assume any such access is a breach and have servers immediately overwrite FDE keys in RAM and power off - and if they were that committed, they would…
Earlier quoted context omitted.
"This kind of frank disclosure should be highly rewarded." Yep, definitely. I think even more important than the information itself is the spirit of honesty and integrity that it demonstrates. This stands in stark contrast to the ambiguous slimeball statements issued by the likes of Google, Facebook, Apple, Microsoft, etc. When Big Brother comes knocking, which companies are going to take a risk to stand up for you?…
Note that G, FB, A and MS are not in a position where they can write such disclosure. I am not arguing with your main point, I applaud FastMail for taking a stand - it's just that USA companies must use "ambiguous slimeball statements" to at least appear clean (because they are not). I would argue that if FastMail were an USA company their statements (if any) would be just as ambiguous as those of G, FB, A and MS.
Yet could, e.g, Google Ireland Ltd do so, by some interesting twist of laws?
This is not true. The Australian Crime Commission has some of the most extensive secret coercive powers in the Western world.
http://www.austlii.edu.au/au/legis/cth/consol_act/acca200228...
I would suggest that either:
a) Fastmail is aware of this and is covertly spreading the word that it might be compromised; or
b) Fastmail needs better lawyers.
Earlier quoted context omitted.
Note that G, FB, A and MS are not in a position where they can write such disclosure. I am not arguing with your main point, I applaud FastMail for taking a stand - it's just that USA companies must use "ambiguous slimeball statements" to at least appear clean (because they are not). I would argue that if FastMail were an USA company their statements (if any) would be just as ambiguous as those of G, FB, A and MS.
> Note that G, FB, A and MS are not in a position where they can write such disclosure. Yet could, e.g, Google Ireland Ltd do so, by some interesting twist of laws?