Live data from Hacker News

FastMail’s servers are in the US – what this means for you

blog.fastmail.fm

61–70 of 175 posts

Re: FastMail’s servers are in the US – what this means for you

#62
post #53

Since the Silk Road bust we know the US LE is able to convince or force colocation providers to provide them with an image of a server. After that, pretty much any communication can be considered open to the NSA. I am not surprised that he does not clearly mentions this. So FM should move their servers out of the US even if that's inconvenient.

Actually we did clearly mention it: "Our colocation providers could be compelled to give physical access to our servers." But in the very next paragraph: "These are not things we can protect against directly but again, we can make it extremely difficult for these things to occur by using strong encryption and careful systems monitoring. Were anything like this ever to happen we would be talking about it very publical…

You could move the servers to a country with more respect for rule of law. That would be awesome!

Re: FastMail’s servers are in the US – what this means for you

#63

Earlier quoted context omitted.

Hi Rob, Has the headline on HN been updated? Because both you and brongondwana talk about it being sensationalist, where I see it as just being a summary of the most salient part of what you have to say. Do you have Australian legal advice to back up your conclusions? (I agree with them, but would like to make sure we're talking more than the "gist" of the law)

> Has the headline on HN been updated? Because both you and brongondwana talk about it being sensationalist, where I see it as just being a summary of the most salient part of what you have to say. To my mind it was one of the least interesting parts of what we had to say. "Non-US company not bound by US law" - its hardly earth-shattering news. Would "Non-Senegalese company not bound by Senegal law" be as interesting…

Just a tangential thought, but I can't imagine seizing Australian assets based in the US would make for a particularly comfortable diplomatic position to be in (although I suspect our current government doesn't care). To say nothing about the fact that we've already shown our hand (and upset most of our allies) by way of the Manning leaks, the Assange manhunt brought about largely by US political pressure, and, more recently, the NSA scandal.

I've mentioned it elsewhere but it's worth repeating here. Finding established case law dealing with foreign assets seized (possibly illegally) on US soil and the repercussions would make for an interesting exercise. I feel like there's one instance in particular that was especially noisome that happened recently, but I can't for the life of me remember what it was.

If you don't mind my asking, what contingencies do you have in place in the event of a seizure of hardware assets? It's unlikely, but the FBI has been known to take anything that vaguely looks like a server...

Re: FastMail’s servers are in the US – what this means for you

#64
post #34
post #27

Earlier quoted context omitted.

Remotely detecting if the server is not compromised when you don't trust the physical surroundings is probably unsolvable. If your attackers are very motivated and have lots of resources, what's to prevent them from installing a ram bus signal analyzer during a scheduled/unscheduled downtime. This would be pretty hard to detect (absent an elaborate video monitoring setup), as a good analyzer should not impact the sys…

Hardware Security Modules (HSMs) are supposed to be able to resist that kind of attack, but given we currently have a duopoly of fairly government (US and EU/UK) connected HSM manufacturers, and they devices aren't suitable (price and capabilities) for general purpose computing, we're kind of out of luck. A Free/Open HSM design would go a long way, along with more host-based trusted computing security (Intel SGX, etc…

Intel? It's alleged that Intel is in on it! Any NSA-proof solution must be based on chips designed and fabbed outside the US.

Re: FastMail’s servers are in the US – what this means for you

#65
post #57
post #6

> There are of course other avenues available to obtain your data. Our colocation providers could be compelled to give physical access to our servers. Network capturing devices could be installed. And in the worst case an attacker could simply force their way into the datacentre and physically remove our servers. > These are not things we can protect against directly but again, we can make it extremely difficult for…

"This kind of frank disclosure should be highly rewarded." With all due, Im sorry but, no. Had it come before the Snowden leaks, absolutely. But it didn't. After the event, facing a danger of customer loss or loss of confidence, it can only be seen as too late and defensive move. All these companies must have known something about these risks, yet remained in a passive conspiracy of silence. Not one stood up until Sn…

So Lavabit should have shutdown before the leaks?

What you say may be applicable to the big players, but not to the smaller ones.

Re: FastMail’s servers are in the US – what this means for you

#66
I know that my word doesn't mean much, but I have had the chance to talk to several of the guys working at Fastmail during their years at Opera Software. They are -serious- about mail and they are -serious- about privacy.

Next time I'm out shopping for email services, I will give my moeny to them! (And, to give something back for all the Tim Tams brongondwana brought with him to Norway ever time he was on a visit ;) )

Re: FastMail’s servers are in the US – what this means for you

#67

> Australia does not have any equivalent to the US National Security Letter, so we cannot be forced to do something without being allowed to disclose it. This is not true. The Australian Crime Commission has some of the most extensive secret coercive powers in the Western world. http://www.austlii.edu.au/au/legis/cth/consol_act/acca200228... I would suggest that either: a) Fastmail is aware of this and is covertly sp…

I would argue that section 29 is very narrow in its scope, and allows for disclosure once an investigation is completed, and allows for disclosure to an attorney, whereas my understanding of an NSL is that it can order pretty much anything it wants without limitation. That seems quite different to me. But then, I'm not lawyer. You're probably not either. Which is why I keep telling people to get their own legal advic…

I would hope you have lawyers who have consulted you on this? What do they say?

Re: FastMail’s servers are in the US – what this means for you

#68
post #51

Earlier quoted context omitted.

I understand your viewpoint, but I don't accept that as an excuse. Remember how quickly SOPA sank after the Silicon Valley establishment turned against it? Do you think the government is going to put the CEOs of some of America's most popular and profitable companies in jail for an act of civil disobedience that the majority of the country and the world would support wholeheartedly? SV is more powerful than it realiz…

SOPA was a single proposed piece of legislation proposed by corporate lobbyists, who are on an essentially level playing field with Silicon Valley. The NSA is a 60 year old spy agency at the heart of the national security infrastructure and government. You are comparing two entirely dissimilar things. Also, how exactly is the American national security state 'weakened and vulnerable'?

At the moment it is weakened and vulnerable compared to how it was a few years ago. It has not been destroyed or dismantled by Snowden's revelations, far from it, but it is a definite factor the NSA cannot ignore. Five years ago, no one would even think of shutting the NSA down over their abominable deeds, because their abominable deeds were not widely known.

At the moment, there are many people shouting for them to be shut down. Will it happen? Probably not. But at the moment, that is something for the NSA to worry about and to try to do damage control over. In that sense, they are certainly in a quite worse position.

Re: FastMail’s servers are in the US – what this means for you

#70

> Australia does not have any equivalent to the US National Security Letter, so we cannot be forced to do something without being allowed to disclose it. This is not true. The Australian Crime Commission has some of the most extensive secret coercive powers in the Western world. http://www.austlii.edu.au/au/legis/cth/consol_act/acca200228... I would suggest that either: a) Fastmail is aware of this and is covertly sp…

You don't need to even use the ACC, people for get that the 2005 counter-terrorism act[0][1] has provision for preventative detention without charge, and notably, made it a criminal act to tell anyone that you had been detained. Combined with a rather broad definition on what was terrorism and the ability of police to request information, documents and emails, this act seems to cover all of the functional aspects of the National security letters with even less oversight.

[0]http://www.ag.gov.au/NationalSecurity/Counterterrorismlaw/Pa... [1]https://en.wikipedia.org/wiki/Anti-Terrorism_Act_2005

Post reply on HN