Live data from Hacker News

FastMail’s servers are in the US – what this means for you

blog.fastmail.fm

121–130 of 175 posts

Re: FastMail’s servers are in the US – what this means for you

#121
post #78

Earlier quoted context omitted.

It is possible to encrypt SMTP connections with standard SSL/TLS technology. FastMail has been using opportunistic encryption on their incoming and outgoing SMTP servers for years. If you send an email to another service that does opportunistic encryption, and if both the sender and recipient uses SSL to access their mailboxes (as FastMail requires), the email will never be transmitted in plain text over the Internet…

The problem with such opportunistic encryption, is that you could insert a man in the middle which basically intercepts the traffic and modifies the handshake to exclude the STARTTLS extension. With opportunistic SMTP encryption this will cause things to proceed in plain text. The sinister thing about this is that e-mails still flow, so it still works.

There exists some Cisco network gear that intentionally breaks STARTLS commands in it's default configuration (and wasn't debugging _that_ on a piece of network gear a client owned but didn't know about a fun waste of several weeks…)

( http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/produc... for anyone who wants details… )

Re: FastMail’s servers are in the US – what this means for you

#122

Earlier quoted context omitted.

The problem with such opportunistic encryption, is that you could insert a man in the middle which basically intercepts the traffic and modifies the handshake to exclude the STARTTLS extension. With opportunistic SMTP encryption this will cause things to proceed in plain text. The sinister thing about this is that e-mails still flow, so it still works.

There's a solution for this. Its called DANE. See http://tools.ietf.org/html/draft-ietf-dane-smtp We're currently investigating it.

I don't suppose you got any numbers easily at hand about how much of your port 25 traffic negotiates a TLS encrypted connection?

Re: FastMail’s servers are in the US – what this means for you

#123

The US government will just take their server. They don't care if you go out of business. Look at what they did to megaupload.com.

This is the same megaupload where FBI agents took part in a raid on a house in a non-US country? http://www.listener.co.nz/commentary/the-internaut/kim-dotco... As I said in a response on our forum, if the stakes are high enough, no datacentre in the world is safe. Bruce Schneier recommends protecting against terrorist attacks by improving emergency response capabilities - with the side benefit that your measures als…

"As I said in a response on our forum, if the stakes are high enough, no datacentre in the world is safe."

The stakes being relevant to US that is.

Re: FastMail’s servers are in the US – what this means for you

#124
post #117
post #68

Earlier quoted context omitted.

At the moment it is weakened and vulnerable compared to how it was a few years ago. It has not been destroyed or dismantled by Snowden's revelations, far from it, but it is a definite factor the NSA cannot ignore. Five years ago, no one would even think of shutting the NSA down over their abominable deeds, because their abominable deeds were not widely known. At the moment, there are many people shouting for them to…

I dunno, if the US government can't figure out if it wants public healthcare by the end of this month, they are gonna have to sell off some of those datacentres to pay the national debt...

Not quite.

The US Government operates on an extralegal basis (ie they're willing to cross any line), and roughly 85%+ of all new debt is purchased by the Federal Reserve. What very specifically is not going to happen, is the shut down of the military industrial complex of which the NSA is such an integral part.

So long as the dollar (Federal Reserve Note I should say) remains the global reserve currency, the national debt is a trivial problem (as is paying the interest on it). The dollar is the real linchpin, to everything. All else is a sideshow of political gamesmanship.

Re: FastMail’s servers are in the US – what this means for you

#125
post #120

Earlier quoted context omitted.

I just checked upstairs. The advice we have is roughly: - ACC has judicial oversight - its unclear how this interacts with the Telecommunications (Intercept and Access) Act With my boss throwing in: - law is a giant mess - until you have two extremely well-funded parties disagreeing vehemently about the interpretation, you'll never get a final answer We're still happy with our publicly-stated position. You might disa…

Either way, it makes your service completely vulnerable to the government's interpretation of the law. If they force you to disclose your customers' data in secret tomorrow, or face jail time, I have no doubts what your choice will be. I'm not calling you a liar, btw, I just think you're naive/oblivious, and considering you just now discovered what ACC is and had to check with your lawyer (who isn't even sure how it…

> If they force you to disclose your customers' data in secret tomorrow, or face jail time, I have no doubts what your choice will be.

We have no doubts either. The privacy policy clearly states we will give your data to the Australian authorities if supplied with the proper supporting documentation.

I didn't just find out about the ACC, though I wasn't aware of the details. But I'm not a lawyer, just a sysadmin, so I don't need to be. The "its not clear" bit is simply that there are two laws that appear to be in contradiction with each other. Its never been tested in court. And thus, its not clear. But we have confidence that what our position is legally supportable or we wouldn't be here.

Re: FastMail’s servers are in the US – what this means for you

#128

There's one question they haven't answered: Why do they even need to have their servers in the US? Their blog post admits that there's a big chance that the US is spying on their customers. Given the fact that FastMail is a Norwegian/Australian company, why don't they just move their servers to e.g. Norway? I realize that even if the servers were in Norway, an email from a FastMail user to a gmail.com account would s…

We're no longer Norwegian :)

http://blog.fastmail.fm/2013/09/25/exciting-news-fastmail-st...

Re: FastMail’s servers are in the US – what this means for you

#129
post #35

Earlier quoted context omitted.

Note that G, FB, A and MS are not in a position where they can write such disclosure. I am not arguing with your main point, I applaud FastMail for taking a stand - it's just that USA companies must use "ambiguous slimeball statements" to at least appear clean (because they are not). I would argue that if FastMail were an USA company their statements (if any) would be just as ambiguous as those of G, FB, A and MS.

I understand your viewpoint, but I don't accept that as an excuse. Remember how quickly SOPA sank after the Silicon Valley establishment turned against it? Do you think the government is going to put the CEOs of some of America's most popular and profitable companies in jail for an act of civil disobedience that the majority of the country and the world would support wholeheartedly? SV is more powerful than it realiz…

SOPA was easy to turn against and I would argue, didn't cost anything to oppose. Fighting the NSA on warrantless wiretaps is a completely different animal in that there will be real money involved in fighting it. Potentially millions of dollars duking it out in court(s).

I think it's already been established that the NSA has HUGE financial resources (from the part that we can tell) and to top it all off, fighting the NSA on it's grounds would most likely pass through the FISA court. A court which in and of itself, is shrouded in secrecy.

Also, this: http://www.nbcnews.com/id/12727867/#.UlKlY2RtVOg

Re: FastMail’s servers are in the US – what this means for you

#130

Earlier quoted context omitted.

You're not representing your company very well. If you're going to be mean, you'd better be right. But in the scenario you describe, the solution is to move incrementally, one server at a time, not "shut everything down, ship it, then reboot everything simultaneously." FYI you have about 1.5 hours to edit your post. You may want to do that, because otherwise it will probably scare off most informed potential customer…

> You're not representing your company very well. > FYI you have about 1.5 hours to edit your post. You may want to do that, because otherwise it will probably scare off most informed potential customers who read it. (The above post was, curiously, edited very slightly before I was able to reply.) It's possible brongondwana is taking some of the discussion here personally, but most people invested emotionally in thei…

"I can only imagine just how incendiary such headlines might become: US Seizes Australian Servers in NSA/FBI/Scary-three-letter-name US Agency Sting Operation. That'd go over real well, especially among Commonwealth nations."

I think if that were to happen, it would be another nail in the coffin for the "US cloud".

From www2.itif.org/2013-cloud-computing-costs.pdf‎

"The U.S cloud computing industry stands to lose $22 to $35 billion over the next three years as a result of the recent revelations about the NDA's electronic surveillance programs"

Post reply on HN