Live data from Hacker News

FastMail’s servers are in the US – what this means for you

blog.fastmail.fm

141–150 of 175 posts

Re: FastMail’s servers are in the US – what this means for you

#141
post #138
post #35

Earlier quoted context omitted.

Note that G, FB, A and MS are not in a position where they can write such disclosure. I am not arguing with your main point, I applaud FastMail for taking a stand - it's just that USA companies must use "ambiguous slimeball statements" to at least appear clean (because they are not). I would argue that if FastMail were an USA company their statements (if any) would be just as ambiguous as those of G, FB, A and MS.

I never understood this rationalization for what is essentially a corrupt behavior. People find excuses to keep the corrupt system going. I see it as a collective madness. Those companies, being a huge influence on the internet culture and economy, a trend-setter, one might even say the internet gatekeepers - I think they not only should disclose and vehemently oppose any attempts on user rights, but it is their mora…

> moral obligation

Keep in mind that these companies' only obligations are to their shareholders.

Re: FastMail’s servers are in the US – what this means for you

#142

Earlier quoted context omitted.

Norway, Iceland and Switzerland come to mind. As for whether or not they want access to data: There's nothing wrong with governments accessing data if there's a court order in place and their request is part of an investigation. It's the automatic surveillance of everyone that NSA does that's a problem, and it's certainly not all countries that do that. In the most serious extreme, nowhere in the world is "safe" Sure…

We're already in Iceland - from http://blog.fastmail.fm/2012/07/03/a-story-of-leaping-second... "We have a complete live-spare datacentre in Iceland. Eventually it will be a fully operational centre in its own right, but for now it’s running almost 100% in replica mode." I'm not so sure about the safe-haveness of Switzerland these days. They already caved to the US, giving them access to banking info (what they're fa…

We have a complete live-spare datacentre in Iceland. Eventually it will be a fully operational centre in its own right

Let me know when that happens and I'll gladly sign up for your service :)

I'm not so sure about the safe-haveness of Switzerland these days. They already caved to the US, giving them access to banking info (what they're famous for... which leaves me wondering what Switzerland got in return):

I don't see how bank secrets have anything to do with Internet surveillance. There's a general tendency now both in the US and the EU to pressure tax havens such as Switzerland, Andorra, the Bahamas, etc. to give up their bank secrets so that corporations and rich individuals can't hide their income and avoid paying taxes. That seems fair enough, and I don't see a direct link between that and Internet surveillance.

Re: FastMail’s servers are in the US – what this means for you

#143
post #6

> There are of course other avenues available to obtain your data. Our colocation providers could be compelled to give physical access to our servers. Network capturing devices could be installed. And in the worst case an attacker could simply force their way into the datacentre and physically remove our servers. > These are not things we can protect against directly but again, we can make it extremely difficult for…

I agree that this is a nice gesture, but it's not a "frank disclosure". What did they disclose?

When they actually have a security breach and they promptly "[talk] about it very publicly", that will be something commendable. Right now we have words, not actions.

Though honestly I'd much rather have such words than not.

Re: FastMail’s servers are in the US – what this means for you

#144
post #141
post #138

Earlier quoted context omitted.

I never understood this rationalization for what is essentially a corrupt behavior. People find excuses to keep the corrupt system going. I see it as a collective madness. Those companies, being a huge influence on the internet culture and economy, a trend-setter, one might even say the internet gatekeepers - I think they not only should disclose and vehemently oppose any attempts on user rights, but it is their mora…

> moral obligation Keep in mind that these companies' only obligations are to their shareholders.

That refrain, while correct* as a matter of corporate law, increasingly sounds like our era's version of the Nuremberg defense.

Also, who is to say that moral behavior isn't in the long term interest of shareholders?

Re: FastMail’s servers are in the US – what this means for you

#145
post #64
post #34

Earlier quoted context omitted.

Hardware Security Modules (HSMs) are supposed to be able to resist that kind of attack, but given we currently have a duopoly of fairly government (US and EU/UK) connected HSM manufacturers, and they devices aren't suitable (price and capabilities) for general purpose computing, we're kind of out of luck. A Free/Open HSM design would go a long way, along with more host-based trusted computing security (Intel SGX, etc…

Intel? It's alleged that Intel is in on it! Any NSA-proof solution must be based on chips designed and fabbed outside the US.

Because chips fabbed in China would never be compromised?

Re: FastMail’s servers are in the US – what this means for you

#146
post #57
post #6

> There are of course other avenues available to obtain your data. Our colocation providers could be compelled to give physical access to our servers. Network capturing devices could be installed. And in the worst case an attacker could simply force their way into the datacentre and physically remove our servers. > These are not things we can protect against directly but again, we can make it extremely difficult for…

"This kind of frank disclosure should be highly rewarded." With all due, Im sorry but, no. Had it come before the Snowden leaks, absolutely. But it didn't. After the event, facing a danger of customer loss or loss of confidence, it can only be seen as too late and defensive move. All these companies must have known something about these risks, yet remained in a passive conspiracy of silence. Not one stood up until Sn…

How could they have talked about it if they never knew about because they were never in bed with the NSA?

You are assuming they were cooperating with the NSA behind the scenes like Google et al, but they are saying they were not and could not be compelled to do so by Australian Law.

Re: FastMail’s servers are in the US – what this means for you

#147
post #141
post #138

Earlier quoted context omitted.

I never understood this rationalization for what is essentially a corrupt behavior. People find excuses to keep the corrupt system going. I see it as a collective madness. Those companies, being a huge influence on the internet culture and economy, a trend-setter, one might even say the internet gatekeepers - I think they not only should disclose and vehemently oppose any attempts on user rights, but it is their mora…

> moral obligation Keep in mind that these companies' only obligations are to their shareholders.

Keep in mind that these companies' only obligations are to their shareholders

Your statement is mostly true but completely hollow. Just because your primary obligation is to your shareholders doesn't mean you go along with (arguably) illegal acts committed by your government that run counter to your users. Because if you do that long enough, your users will leave and you will have screwed your shareholders in an attempt to look out for your shareholders.

This is why your comment is hollow. Because it attempts to excuse any behavior that provides short-term gain regardless of mid-term or long-term pain.

Re: FastMail’s servers are in the US – what this means for you

#148
post #140
post #6

> There are of course other avenues available to obtain your data. Our colocation providers could be compelled to give physical access to our servers. Network capturing devices could be installed. And in the worst case an attacker could simply force their way into the datacentre and physically remove our servers. > These are not things we can protect against directly but again, we can make it extremely difficult for…

It's nice that they are frank about it, but it is also pretty clear that any company hosting in the US, even if they are based elsewhere, is less of an appealing option to the truly security conscious (or paranoid, depends on how you look at it). Sometimes these aren't necessarily the more technical people either. The problem is that for most services, it is hard to tell where the company is from and where they are h…

Less of an appealing option where?

If I don't trust (say) the Russian government, it is more secure to put my hosting in Russia? Nonsense.

Re: FastMail’s servers are in the US – what this means for you

#149
post #148
post #140

Earlier quoted context omitted.

It's nice that they are frank about it, but it is also pretty clear that any company hosting in the US, even if they are based elsewhere, is less of an appealing option to the truly security conscious (or paranoid, depends on how you look at it). Sometimes these aren't necessarily the more technical people either. The problem is that for most services, it is hard to tell where the company is from and where they are h…

Less of an appealing option where? If I don't trust (say) the Russian government, it is more secure to put my hosting in Russia? Nonsense.

I don't understand what you're trying to say with the Russian example.

You can for example trust the Finnish government not to look at your data or let other governments do the same. A number of companies here in Finland are emphasizing that point in their marketing nowadays.

Re: FastMail’s servers are in the US – what this means for you

#150
post #64

Earlier quoted context omitted.

Intel? It's alleged that Intel is in on it! Any NSA-proof solution must be based on chips designed and fabbed outside the US.

Because chips fabbed in China would never be compromised?

Sure, they might be, but what do I care what the Chinese govt knows about me? They're 10,000 miles away and I have no foreseeable plans to travel there. My own government, who I want to be free to criticize when they do something I disapprove of, that's something else.
Post reply on HN