Live data from Hacker News

FastMail’s servers are in the US – what this means for you

blog.fastmail.fm

101–110 of 175 posts

Re: FastMail’s servers are in the US – what this means for you

#101
post #53

Since the Silk Road bust we know the US LE is able to convince or force colocation providers to provide them with an image of a server. After that, pretty much any communication can be considered open to the NSA. I am not surprised that he does not clearly mentions this. So FM should move their servers out of the US even if that's inconvenient.

Silk Road wasn't hosted in the US, in the documents it says they got the server image from another country.

Re: FastMail’s servers are in the US – what this means for you

#102
post #53

Since the Silk Road bust we know the US LE is able to convince or force colocation providers to provide them with an image of a server. After that, pretty much any communication can be considered open to the NSA. I am not surprised that he does not clearly mentions this. So FM should move their servers out of the US even if that's inconvenient.

What we also know from that is that it doesn't really matter where your servers are physically located.

Re: FastMail’s servers are in the US – what this means for you

#103
post #99

Earlier quoted context omitted.

Do you have a realistic idea of how long that would take, and what the risks and costs involved are? How would we "move" the servers, without a significantly higher risk of the data being leaked? Assuming Europe, that's an 8 hour flight at the least. I'm guessing people are assuming Europe as the bastion of all things good here. Certainly it's more affordable for hosting than Australia, and more reliably connected th…

You could also just create a second, completely separate setup in Europe running on a new domain. People who don't care about their @fastmail.fm domain or those use their own domain can move to the European setup.

Yes, we could. It's certainly an idea that's on our radar.

Re: FastMail’s servers are in the US – what this means for you

#104
post #91

Earlier quoted context omitted.

Because its our advice. It was developed for us, taking our concerns into account. You need to get your own legal advice relevant to your own situation. Or put another way, I don't think "Your Honour, FastMail's lawyer said it was ok" is valid defense for anyone except us.

Who said that that would be a defense we would use? My point is that you have given advice, with the implication that it would soothe some of our concerns. And then, in the very next sentence, you've said, in effect, it's legally worthless. So, how exactly does your own advice to us help in any way whatsoever?

Even if that post was written entirely by lawyers, that still wouldn't make it legally binding.

Re: FastMail’s servers are in the US – what this means for you

#105
post #75

Note the obvious caveat though: "There are of course other avenues available to obtain your data. Our colocation providers could be compelled to give physical access to our servers. Network capturing devices could be installed. And in the worst case an attacker could simply force their way into the datacentre and physically remove our servers." As the colocation providers are based in the U.S., they would be subject…

According to a FastMail representative: > We use encryption to make hard drives worthless if they are stolen or just misplaced. [1] [1] http://www.emaildiscussions.com/showpost.php?p=561920&postco... Anything that makes hard drives unreadable by thieves would probably also make them unreadable by any U.S. agency that seizes them. Unless of course NSA has already broken the algorithms used by the disk encryption softw…

Encrypted HDD won't help against cold boot attack.

Re: FastMail’s servers are in the US – what this means for you

#106
post #75

Earlier quoted context omitted.

According to a FastMail representative: > We use encryption to make hard drives worthless if they are stolen or just misplaced. [1] [1] http://www.emaildiscussions.com/showpost.php?p=561920&postco... Anything that makes hard drives unreadable by thieves would probably also make them unreadable by any U.S. agency that seizes them. Unless of course NSA has already broken the algorithms used by the disk encryption softw…

Encrypted HDD won't help against cold boot attack.

I doubt that an unexpected reboot and chassis intrusion (to install a compromized bootloader, for example) will go unnoticed by FastMail staff.

Re: FastMail’s servers are in the US – what this means for you

#107
post #78

Earlier quoted context omitted.

It is possible to encrypt SMTP connections with standard SSL/TLS technology. FastMail has been using opportunistic encryption on their incoming and outgoing SMTP servers for years. If you send an email to another service that does opportunistic encryption, and if both the sender and recipient uses SSL to access their mailboxes (as FastMail requires), the email will never be transmitted in plain text over the Internet…

The problem with such opportunistic encryption, is that you could insert a man in the middle which basically intercepts the traffic and modifies the handshake to exclude the STARTTLS extension. With opportunistic SMTP encryption this will cause things to proceed in plain text. The sinister thing about this is that e-mails still flow, so it still works.

There's a solution for this. Its called DANE. See http://tools.ietf.org/html/draft-ietf-dane-smtp

We're currently investigating it.

Re: FastMail’s servers are in the US – what this means for you

#108
post #66

I know that my word doesn't mean much, but I have had the chance to talk to several of the guys working at Fastmail during their years at Opera Software. They are -serious- about mail and they are -serious- about privacy. Next time I'm out shopping for email services, I will give my moeny to them! (And, to give something back for all the Tim Tams brongondwana brought with him to Norway ever time he was on a visit ;)…

If you want to just send timtams, that would be fine too. We seem to have run out of them in the office...

Re: FastMail’s servers are in the US – what this means for you

#109
post #104
post #91

Earlier quoted context omitted.

Who said that that would be a defense we would use? My point is that you have given advice, with the implication that it would soothe some of our concerns. And then, in the very next sentence, you've said, in effect, it's legally worthless. So, how exactly does your own advice to us help in any way whatsoever?

Even if that post was written entirely by lawyers, that still wouldn't make it legally binding.

Indeed.

So, the point remains: what value does this advice have over against the advice from Google, etc? It's a rhetorical question, by the way.

Re: FastMail’s servers are in the US – what this means for you

#110

Earlier quoted context omitted.

Actually I am a lawyer. In the past I have even advised clients who received ACC notices (they are more common than most people would think). Needless to say I was staggered at the scope of the powers granted. Forget about transparency, justice and the rule of law. If you receive one of these you can be compelled to give evidence or documents in secret, without judicial oversight or public scrutiny.

I just checked upstairs. The advice we have is roughly: - ACC has judicial oversight - its unclear how this interacts with the Telecommunications (Intercept and Access) Act With my boss throwing in: - law is a giant mess - until you have two extremely well-funded parties disagreeing vehemently about the interpretation, you'll never get a final answer We're still happy with our publicly-stated position. You might disa…

I read the blog post and was nearly persuaded that fastmail might be better in than US providers on some level of privacy.

But now reading this exchange I now see that your company doesn't actually know the Australian law any better than it knows the US law, and now I feel that fastmail might actually be WORSE than a US company in terms of privacy. Thanks for letting us know.

The title of this post should be changed to:

FastMail’s servers are in the US – what this means for you -> absolutely nothing.

Post reply on HN