Live data from Hacker News

FastMail’s servers are in the US – what this means for you

blog.fastmail.fm

81–90 of 175 posts

Re: FastMail’s servers are in the US – what this means for you

#81
post #75

Note the obvious caveat though: "There are of course other avenues available to obtain your data. Our colocation providers could be compelled to give physical access to our servers. Network capturing devices could be installed. And in the worst case an attacker could simply force their way into the datacentre and physically remove our servers." As the colocation providers are based in the U.S., they would be subject…

According to a FastMail representative: > We use encryption to make hard drives worthless if they are stolen or just misplaced. [1] [1] http://www.emaildiscussions.com/showpost.php?p=561920&postco... Anything that makes hard drives unreadable by thieves would probably also make them unreadable by any U.S. agency that seizes them. Unless of course NSA has already broken the algorithms used by the disk encryption softw…

...or if they use RSA at too low of a bit depth: https://news.ycombinator.com/item?id=6506120

Re: FastMail’s servers are in the US – what this means for you

#82

Hi, FastMail employee and author of (most of) that blog post here. Just so we're clear, the point of this post was not that we don't think the rules don't apply to us. Instead we're trying to make it clear where position on these things are. The topic of this thread is a sensationalist sound-bite, nothing more. I'm not going to go over the points again here because I'm pretty sure we said it all in the post (but ask…

Can you confirm you have never been contacted by US authorities (or Australian for that matter), and have never been placed under a non-disclosure order?

Re: FastMail’s servers are in the US – what this means for you

#83
post #74

Earlier quoted context omitted.

In the link he posted originally: "Penalty: 20 penalty units or imprisonment for one year."

Apparently that's about $3,400 ($170 x 20): https://en.wikipedia.org/wiki/Penalty_units A year of incarcerating someone is only worth $3,400 to the government? Strange, considering that if you're going to be pedantic about money, the cost of incarceration is surely at least one order of magnitude more than that.

It's not about how much it costs to do it, it's about the effect on the subject. $3,400 is a lot to a typical criminal.

Re: FastMail’s servers are in the US – what this means for you

#84
post #83

Earlier quoted context omitted.

Apparently that's about $3,400 ($170 x 20): https://en.wikipedia.org/wiki/Penalty_units A year of incarcerating someone is only worth $3,400 to the government? Strange, considering that if you're going to be pedantic about money, the cost of incarceration is surely at least one order of magnitude more than that.

It's not about how much it costs to do it, it's about the effect on the subject. $3,400 is a lot to a typical criminal.

We're talking about a particular subset of criminal/person that can afford a computer, has the knowledge and forethought to encrypt it, and is committing a type of crime/action which makes the state want to see the encrypted contents of said computer badly enough to invoke that law. I would think that someone in that subset could easily afford $3,400.

Re: FastMail’s servers are in the US – what this means for you

#85

Earlier quoted context omitted.

I would argue that section 29 is very narrow in its scope, and allows for disclosure once an investigation is completed, and allows for disclosure to an attorney, whereas my understanding of an NSL is that it can order pretty much anything it wants without limitation. That seems quite different to me. But then, I'm not lawyer. You're probably not either. Which is why I keep telling people to get their own legal advic…

Actually I am a lawyer. In the past I have even advised clients who received ACC notices (they are more common than most people would think). Needless to say I was staggered at the scope of the powers granted. Forget about transparency, justice and the rule of law. If you receive one of these you can be compelled to give evidence or documents in secret, without judicial oversight or public scrutiny.

I just checked upstairs. The advice we have is roughly:

- ACC has judicial oversight

- its unclear how this interacts with the Telecommunications (Intercept and Access) Act

With my boss throwing in:

- law is a giant mess

- until you have two extremely well-funded parties disagreeing vehemently about the interpretation, you'll never get a final answer

We're still happy with our publicly-stated position. You might disagree, and I'm not really in a position to argue with you. Its my corporate masters with their necks on the line, and they seem relaxed about it. That's good enough for me :)

Re: FastMail’s servers are in the US – what this means for you

#86

Earlier quoted context omitted.

It might also mean that many of our users believe in the same tradeoff that we do - that we're not overreacting to one low probability/high visibility risk by throwing out the incredibly good reliability we've had for years to shut everything down, ship it to a location with unknown reliability and spin it all back up again - complete with new IP addresses and all the headache that would cause tons of customers who h…

You're not representing your company very well. If you're going to be mean, you'd better be right. But in the scenario you describe, the solution is to move incrementally, one server at a time, not "shut everything down, ship it, then reboot everything simultaneously." FYI you have about 1.5 hours to edit your post. You may want to do that, because otherwise it will probably scare off most informed potential customer…

Do you have a realistic idea of how long that would take, and what the risks and costs involved are? How would we "move" the servers, without a significantly higher risk of the data being leaked? Assuming Europe, that's an 8 hour flight at the least.

I'm guessing people are assuming Europe as the bastion of all things good here. Certainly it's more affordable for hosting than Australia, and more reliably connected than anywhere else.

A more realistic scenario, if we had the budget for it, would be to buy a duplicate set of hardware, install it in the theoretical new location, duplicate all the data, grandfather everything running at NYI.

This would be a process that would take months or years of real time as well, plus quite a lot of admin time. Just duplicating all the email, well - I did it recently, I carried an almost full set of backups on encrypted hard disks from New York to Australia (the key was only ever in tmpfs on the host in New York, copied in over ssh inside a VPN link, and all copies nuked and the server rebooted and reinstalled before I left New York) Even filling those disks at the maximum IO rate we could sustain took over a week - and unpacking it at the other end would take as long again.

All this for theoretical security against one of very many risks we face. It is my considered opinion that we can get better return on our security investment (both time and money) in other ways than scrambling to get everything out of the USA.

And "emails being read by the US Government" is only one of very many security threats. We could make our users' emails VERY secure by putting all our servers in the shredder - it might reduce uptime and recoverability of data somewhat...

... so I'm hoping most informed potential customers understand that there are other risks in the world, and we balance our defenses amongst the various risks.

Throwing away everything that's good about our New York hosting in exchange for maybe being more secure against one particular risk is not a decision to make lightly, your assertions nonwithstanding.

Re: FastMail’s servers are in the US – what this means for you

#87
post #82

Hi, FastMail employee and author of (most of) that blog post here. Just so we're clear, the point of this post was not that we don't think the rules don't apply to us. Instead we're trying to make it clear where position on these things are. The topic of this thread is a sensationalist sound-bite, nothing more. I'm not going to go over the points again here because I'm pretty sure we said it all in the post (but ask…

Can you confirm you have never been contacted by US authorities (or Australian for that matter), and have never been placed under a non-disclosure order?

We have been contacted by US authorities in the past, and have referred them to the appropriate Australian authorities.

We have been contacted by Australian authorities in the past, and have worked with them in accordance with Australian law and our privacy policy, which you can read here: https://www.fastmail.fm/help/overview_privacy.html

Re: FastMail’s servers are in the US – what this means for you

#88

Earlier quoted context omitted.

> Has the headline on HN been updated? Because both you and brongondwana talk about it being sensationalist, where I see it as just being a summary of the most salient part of what you have to say. To my mind it was one of the least interesting parts of what we had to say. "Non-US company not bound by US law" - its hardly earth-shattering news. Would "Non-Senegalese company not bound by Senegal law" be as interesting…

Just a tangential thought, but I can't imagine seizing Australian assets based in the US would make for a particularly comfortable diplomatic position to be in (although I suspect our current government doesn't care). To say nothing about the fact that we've already shown our hand (and upset most of our allies) by way of the Manning leaks, the Assange manhunt brought about largely by US political pressure, and, more…

We currently have a complete copy of all user data in a secondary (non-US) data centre. In the event of a loss of our US-based servers, we would get this secondary copy up and running as quick as possible (likely in a reduced capacity) while sourcing new equipment and getting a new primary centre up as quickly as possible.

This would be a catastrophic event, no doubt about it, and there would be significant disruption for our users. But it wouldn't mean the end of FastMail.

Re: FastMail’s servers are in the US – what this means for you

#89
post #79

Earlier quoted context omitted.

> Has the headline on HN been updated? Because both you and brongondwana talk about it being sensationalist, where I see it as just being a summary of the most salient part of what you have to say. To my mind it was one of the least interesting parts of what we had to say. "Non-US company not bound by US law" - its hardly earth-shattering news. Would "Non-Senegalese company not bound by Senegal law" be as interesting…

"We've made our position public, and we're satisfied that its an accurate reflection of our position and our understanding of Australian law. You must not rely on it as a legal basis for anything though" I'm not sure if I see the value of you saying it, then. Why not get a lawyer to provide you with a position that can be relied upon?

Because its our advice. It was developed for us, taking our concerns into account. You need to get your own legal advice relevant to your own situation.

Or put another way, I don't think "Your Honour, FastMail's lawyer said it was ok" is valid defense for anyone except us.

Post reply on HN