Live data from Hacker News

FastMail’s servers are in the US – what this means for you

blog.fastmail.fm

131–140 of 175 posts

Re: FastMail’s servers are in the US – what this means for you

#131

There's one question they haven't answered: Why do they even need to have their servers in the US? Their blog post admits that there's a big chance that the US is spying on their customers. Given the fact that FastMail is a Norwegian/Australian company, why don't they just move their servers to e.g. Norway? I realize that even if the servers were in Norway, an email from a FastMail user to a gmail.com account would s…

We're no longer Norwegian :) http://blog.fastmail.fm/2013/09/25/exciting-news-fastmail-st...

Alright, but the point still remains: You could theoretically place your servers anywhere in the world, so why choose the US?

Re: FastMail’s servers are in the US – what this means for you

#132

Earlier quoted context omitted.

We're no longer Norwegian :) http://blog.fastmail.fm/2013/09/25/exciting-news-fastmail-st...

Alright, but the point still remains: You could theoretically place your servers anywhere in the world, so why choose the US?

Like what Bron mentioned above:

'Which comes back to the point I've been trying to make all along here. In the most serious extreme, nowhere in the world is "safe"'

Do you have any suggestions for countries that have excellent data connectivity, would successfully resist pressure from US/UK/X authorities to hand over our servers, and at the same time would not themselves want access to?

Re: FastMail’s servers are in the US – what this means for you

#133

Earlier quoted context omitted.

There's a solution for this. Its called DANE. See http://tools.ietf.org/html/draft-ietf-dane-smtp We're currently investigating it.

I don't suppose you got any numbers easily at hand about how much of your port 25 traffic negotiates a TLS encrypted connection?

A very naive estimate based on one day of logs from one server says over 75% of our incoming port 25 connections are encrypted. Although that says nothing about the quality of the cipher in use and the type of messages that come through, its still significantly higher than I would have expected.

I can see I'll be spending some time on this in the next few days!

Re: FastMail’s servers are in the US – what this means for you

#134

Earlier quoted context omitted.

Alright, but the point still remains: You could theoretically place your servers anywhere in the world, so why choose the US?

Like what Bron mentioned above: 'Which comes back to the point I've been trying to make all along here. In the most serious extreme, nowhere in the world is "safe"' Do you have any suggestions for countries that have excellent data connectivity, would successfully resist pressure from US/UK/X authorities to hand over our servers, and at the same time would not themselves want access to?

Norway, Iceland and Switzerland come to mind.

As for whether or not they want access to data: There's nothing wrong with governments accessing data if there's a court order in place and their request is part of an investigation. It's the automatic surveillance of everyone that NSA does that's a problem, and it's certainly not all countries that do that.

In the most serious extreme, nowhere in the world is "safe"

Sure, but there are levels of safety, and the US has turned out to have a low degree of safety for a Western country. The fact that you probably can't find a perfect country shouldn't be an excuse to pick a notoriously unsafe one.

Re: FastMail’s servers are in the US – what this means for you

#135

Hi, FastMail employee and author of (most of) that blog post here. Just so we're clear, the point of this post was not that we don't think the rules don't apply to us. Instead we're trying to make it clear where position on these things are. The topic of this thread is a sensationalist sound-bite, nothing more. I'm not going to go over the points again here because I'm pretty sure we said it all in the post (but ask…

I have a fastmail test account. The only reason I have not completely switched to FM is because your servers are in the US. I am in Europe.

Re: FastMail’s servers are in the US – what this means for you

#136

Earlier quoted context omitted.

Like what Bron mentioned above: 'Which comes back to the point I've been trying to make all along here. In the most serious extreme, nowhere in the world is "safe"' Do you have any suggestions for countries that have excellent data connectivity, would successfully resist pressure from US/UK/X authorities to hand over our servers, and at the same time would not themselves want access to?

Norway, Iceland and Switzerland come to mind. As for whether or not they want access to data: There's nothing wrong with governments accessing data if there's a court order in place and their request is part of an investigation. It's the automatic surveillance of everyone that NSA does that's a problem, and it's certainly not all countries that do that. In the most serious extreme, nowhere in the world is "safe" Sure…

We're already in Iceland - from http://blog.fastmail.fm/2012/07/03/a-story-of-leaping-second...

"We have a complete live-spare datacentre in Iceland. Eventually it will be a fully operational centre in its own right, but for now it’s running almost 100% in replica mode."

I'm not so sure about the safe-haveness of Switzerland these days. They already caved to the US, giving them access to banking info (what they're famous for... which leaves me wondering what Switzerland got in return):

  http://uk.reuters.com/article/2013/08/28/uk-switzerland-usa-tax-idUKBRE97R0CY20130828

Re: FastMail’s servers are in the US – what this means for you

#137
post #120

Earlier quoted context omitted.

Either way, it makes your service completely vulnerable to the government's interpretation of the law. If they force you to disclose your customers' data in secret tomorrow, or face jail time, I have no doubts what your choice will be. I'm not calling you a liar, btw, I just think you're naive/oblivious, and considering you just now discovered what ACC is and had to check with your lawyer (who isn't even sure how it…

> If they force you to disclose your customers' data in secret tomorrow, or face jail time, I have no doubts what your choice will be. We have no doubts either. The privacy policy clearly states we will give your data to the Australian authorities if supplied with the proper supporting documentation. I didn't just find out about the ACC, though I wasn't aware of the details. But I'm not a lawyer, just a sysadmin, so…

Laws that appear to be in contradiction with each other, never tested in court -- so, yeah, quite like the US legal situation, right?

Re: FastMail’s servers are in the US – what this means for you

#138
post #35

Earlier quoted context omitted.

"This kind of frank disclosure should be highly rewarded." Yep, definitely. I think even more important than the information itself is the spirit of honesty and integrity that it demonstrates. This stands in stark contrast to the ambiguous slimeball statements issued by the likes of Google, Facebook, Apple, Microsoft, etc. When Big Brother comes knocking, which companies are going to take a risk to stand up for you?…

Note that G, FB, A and MS are not in a position where they can write such disclosure. I am not arguing with your main point, I applaud FastMail for taking a stand - it's just that USA companies must use "ambiguous slimeball statements" to at least appear clean (because they are not). I would argue that if FastMail were an USA company their statements (if any) would be just as ambiguous as those of G, FB, A and MS.

I never understood this rationalization for what is essentially a corrupt behavior. People find excuses to keep the corrupt system going. I see it as a collective madness.

Those companies, being a huge influence on the internet culture and economy, a trend-setter, one might even say the internet gatekeepers - I think they not only should disclose and vehemently oppose any attempts on user rights, but it is their moral obligation to do so.

How is it that individuals and small parties are scrutinized and put down for a single misstep or a character flaw, while enterprises are forgiven, or worse - go unnoticed, for systematic violations of our rights.

Also, keep in mind, that being a big business like Google, inevitably puts you in a close proximity to government and politics. One thing is certain, they do not lobby on our behalf. Though they could. If Google and other giants had a moral compass resembling one of Lavabit or FastMail, perhaps PRISM would fail or never happen.

Re: FastMail’s servers are in the US – what this means for you

#139

Earlier quoted context omitted.

The problem with such opportunistic encryption, is that you could insert a man in the middle which basically intercepts the traffic and modifies the handshake to exclude the STARTTLS extension. With opportunistic SMTP encryption this will cause things to proceed in plain text. The sinister thing about this is that e-mails still flow, so it still works.

There's a solution for this. Its called DANE. See http://tools.ietf.org/html/draft-ietf-dane-smtp We're currently investigating it.

Interesting.

Meanwhile, does SMTP have something like HTTP Strict Transport Security? It would be nice for an impartial party to compile a list of mail servers that pledge to accept encrypted connections, and for sending MTAs to treat it as a connection failure if the destination is on that list but doesn't appear to support encryption.

Re: FastMail’s servers are in the US – what this means for you

#140
post #6

> There are of course other avenues available to obtain your data. Our colocation providers could be compelled to give physical access to our servers. Network capturing devices could be installed. And in the worst case an attacker could simply force their way into the datacentre and physically remove our servers. > These are not things we can protect against directly but again, we can make it extremely difficult for…

It's nice that they are frank about it, but it is also pretty clear that any company hosting in the US, even if they are based elsewhere, is less of an appealing option to the truly security conscious (or paranoid, depends on how you look at it). Sometimes these aren't necessarily the more technical people either.

The problem is that for most services, it is hard to tell where the company is from and where they are hosted, unless you're technical enough to run a traceroute. At StartHQ we've been trying to make that easier to find for non techies and the fact that FastMail host in the US became quickly apparent via their app profile page when we first added it: https://starthq.com/apps/fastmail - there was a pretty lively discussion on FB about it at the time as well.

Post reply on HN