Live data from Hacker News

FastMail’s servers are in the US – what this means for you

blog.fastmail.fm

91–100 of 175 posts

Re: FastMail’s servers are in the US – what this means for you

#91
post #79

Earlier quoted context omitted.

"We've made our position public, and we're satisfied that its an accurate reflection of our position and our understanding of Australian law. You must not rely on it as a legal basis for anything though" I'm not sure if I see the value of you saying it, then. Why not get a lawyer to provide you with a position that can be relied upon?

Because its our advice. It was developed for us, taking our concerns into account. You need to get your own legal advice relevant to your own situation. Or put another way, I don't think "Your Honour, FastMail's lawyer said it was ok" is valid defense for anyone except us.

Who said that that would be a defense we would use?

My point is that you have given advice, with the implication that it would soothe some of our concerns. And then, in the very next sentence, you've said, in effect, it's legally worthless.

So, how exactly does your own advice to us help in any way whatsoever?

Re: FastMail’s servers are in the US – what this means for you

#92
post #49

I found this article brutally honest. What they are saying is that (1) NSA snooping is more expensive for the NSA as they can't engage in blanket surveillance on all of their users, while keeping them silent, but on the other hand (2) you can't expect and shouldn't assume privacy, because if the NSA wants to listen on your traffic, they will. This in combination with FastMail being acquired by its former employees, c…

I think there's reason to believe that a targeting a person like Snowden would cause the U.S. to use the most extreme measures discussed in the post, such as seizing the servers.

The point is, they wouldn't need to, because the Australian Government would order us to turn over the data, and we would. Everybody wins (except theoretical-Snowden)

Mind you, theoretical-Snowden is already screwed at this point, regardless of where his mail is. No reason to believe any European country would be susceptible to pressure:

http://www.bbc.co.uk/news/world-latin-america-23174874

Or maybe there is.

Which comes back to the point I've been trying to make all along here. In the most serious extreme, nowhere in the world is "safe". In a less serious case, nobody's going to invade NYI with jackboots on. The window between those two cases is where being not-in-USA could theoretically save us from having our servers snatched (assuming said jackboots weren't willing to just wait for the Australian Government to order us to hand the data over)

Re: FastMail’s servers are in the US – what this means for you

#93

The US government will just take their server. They don't care if you go out of business. Look at what they did to megaupload.com.

There's a difference between going after a company that is obviously facilitating copyright infringement and is mainly used for that purpose vs. going after a respectable service provider. The latter would raise hell in the international relations between countries.

That's just a matter of perspective. Was Megaupload "obviously" facilitating copyright infringement any more than Google does?

Re: FastMail’s servers are in the US – what this means for you

#94

Earlier quoted context omitted.

Just a tangential thought, but I can't imagine seizing Australian assets based in the US would make for a particularly comfortable diplomatic position to be in (although I suspect our current government doesn't care). To say nothing about the fact that we've already shown our hand (and upset most of our allies) by way of the Manning leaks, the Assange manhunt brought about largely by US political pressure, and, more…

We currently have a complete copy of all user data in a secondary (non-US) data centre. In the event of a loss of our US-based servers, we would get this secondary copy up and running as quick as possible (likely in a reduced capacity) while sourcing new equipment and getting a new primary centre up as quickly as possible. This would be a catastrophic event, no doubt about it, and there would be significant disruptio…

We also have a second (1-2 week old at this point) backup set of most users' data sitting in boxes on my loungeroom floor. Encrypted of course. It came back in my suitcases from New York a week ago.

Bootstrapping from that would be significantly more painful though, and a lot more "gappy".

Re: FastMail’s servers are in the US – what this means for you

#95
As Australia is a member of the five eyes group, I do not see any added protection from FM being incorporated there rather than in the USA.

This is why I use a email service in Norway (runbox.com), which, as far as I know, is not sharing information by default.

Re: FastMail’s servers are in the US – what this means for you

#96
post #78

They don't need to seize the server. SMTP is plaintext and on a well known port number. I'm sure the NSA have a record of every email sent through the US in the last few years.

It is possible to encrypt SMTP connections with standard SSL/TLS technology. FastMail has been using opportunistic encryption on their incoming and outgoing SMTP servers for years. If you send an email to another service that does opportunistic encryption, and if both the sender and recipient uses SSL to access their mailboxes (as FastMail requires), the email will never be transmitted in plain text over the Internet…

The problem with such opportunistic encryption, is that you could insert a man in the middle which basically intercepts the traffic and modifies the handshake to exclude the STARTTLS extension.

With opportunistic SMTP encryption this will cause things to proceed in plain text. The sinister thing about this is that e-mails still flow, so it still works.

Re: FastMail’s servers are in the US – what this means for you

#97

Note the obvious caveat though: "There are of course other avenues available to obtain your data. Our colocation providers could be compelled to give physical access to our servers. Network capturing devices could be installed. And in the worst case an attacker could simply force their way into the datacentre and physically remove our servers." As the colocation providers are based in the U.S., they would be subject…

If they mount webcams and other sensors inside the cabinet, they could detect unexplained access to their servers. Not sure what it'd really accomplish. The colo provider would either say "tech mistakenly opened that cabinet" or "no comment". The only real defense is to assume any such access is a breach and have servers immediately overwrite FDE keys in RAM and power off - and if they were that committed, they would…

And we'd want to turn that off every time we got them to replace a hard disk...

I wonder how many "sorry, the hairtrigger anti-intrustion systems took the site down" outages it would take before people begged us to turn the sensitivity down.

Re: FastMail’s servers are in the US – what this means for you

#98

Earlier quoted context omitted.

Actually I am a lawyer. In the past I have even advised clients who received ACC notices (they are more common than most people would think). Needless to say I was staggered at the scope of the powers granted. Forget about transparency, justice and the rule of law. If you receive one of these you can be compelled to give evidence or documents in secret, without judicial oversight or public scrutiny.

I just checked upstairs. The advice we have is roughly: - ACC has judicial oversight - its unclear how this interacts with the Telecommunications (Intercept and Access) Act With my boss throwing in: - law is a giant mess - until you have two extremely well-funded parties disagreeing vehemently about the interpretation, you'll never get a final answer We're still happy with our publicly-stated position. You might disa…

Fair enough, I agree that these laws are a mess and you'll never get the final answer unless a disputed application of the Act is determined by the High Court.

But these laws have been active and in common use for over 10 years without a single public challenge. I also know that the ACC's interpretation of their own powers has been used to prevent suspects disclosing certain matters even to their own lawyers.

The fact that no high-profile judicial decisions have placed limits on what the ACC does indicates to me that the law is fairly settled in this area.

I just wanted to point out that the original statement "Australia does not have any equivalent to the US National Security Letter, so we cannot be forced to do something without being allowed to disclose it." does not seem well-founded.

Re: FastMail’s servers are in the US – what this means for you

#99

Earlier quoted context omitted.

You're not representing your company very well. If you're going to be mean, you'd better be right. But in the scenario you describe, the solution is to move incrementally, one server at a time, not "shut everything down, ship it, then reboot everything simultaneously." FYI you have about 1.5 hours to edit your post. You may want to do that, because otherwise it will probably scare off most informed potential customer…

Do you have a realistic idea of how long that would take, and what the risks and costs involved are? How would we "move" the servers, without a significantly higher risk of the data being leaked? Assuming Europe, that's an 8 hour flight at the least. I'm guessing people are assuming Europe as the bastion of all things good here. Certainly it's more affordable for hosting than Australia, and more reliably connected th…

You could also just create a second, completely separate setup in Europe running on a new domain. People who don't care about their @fastmail.fm domain or those use their own domain can move to the European setup.

Re: FastMail’s servers are in the US – what this means for you

#100
post #95

As Australia is a member of the five eyes group, I do not see any added protection from FM being incorporated there rather than in the USA. This is why I use a email service in Norway (runbox.com), which, as far as I know, is not sharing information by default.

The legal situation in Norway is... in flux at the moment. The Snowden revelations might stop information sharing from coming in, but Norway is looking like leapfrogging Australia pretty much with data retention (along with much of Europe):

http://theforeigner.no/pages/news/updated-parliament-passes-...

Norway isn't some magical safe haven from legal data requests. We receive law enforcement requests through the Norwegian system for mail.opera.com users (which, despite running on the same infrastructure, is operated under Norwegian law, not Australian - isn't life complex)

http://en.wikipedia.org/wiki/Telecommunications_data_retenti... tells a few interesting stories.

Australian law may indeed change, and we'll be compelled to update our policies to match. So far, we've avoided it.

http://www.smh.com.au/technology/technology-news/government-...

Post reply on HN