Live data from Hacker News

FastMail’s servers are in the US – what this means for you

blog.fastmail.fm

161–170 of 175 posts

Re: FastMail’s servers are in the US – what this means for you

#161
post #106

Earlier quoted context omitted.

Encrypted HDD won't help against cold boot attack.

I doubt that an unexpected reboot and chassis intrusion (to install a compromized bootloader, for example) will go unnoticed by FastMail staff.

That was what my comment was addressing: What will they do if that happens? Suppose a machine goes offline for a minute then comes back. Datacenter says nothing or says "we have no records of a power issue" or something to that effect. Now what? If Fastmail's software didn't wipe the key from RAM, it may be already compromised. Do they shutdown that colo facility? If so, why are they in the US in the first place?

Re: FastMail’s servers are in the US – what this means for you

#162
post #6

> There are of course other avenues available to obtain your data. Our colocation providers could be compelled to give physical access to our servers. Network capturing devices could be installed. And in the worst case an attacker could simply force their way into the datacentre and physically remove our servers. > These are not things we can protect against directly but again, we can make it extremely difficult for…

"This kind of frank disclosure should be highly rewarded." Yep, definitely. I think even more important than the information itself is the spirit of honesty and integrity that it demonstrates. This stands in stark contrast to the ambiguous slimeball statements issued by the likes of Google, Facebook, Apple, Microsoft, etc. When Big Brother comes knocking, which companies are going to take a risk to stand up for you?…

Definitely. I am actually really worried about the effect of NSA Surveillance and data collection on industrial espionage. How does a small and growing company know that a big company/interest group that feels threatened by it won't get access to NSA data on the company by using their connections?

If Snowden, an individual contractor, can dive deep into the data how do we know that others are not doing the same for other purposes?

Re: FastMail’s servers are in the US – what this means for you

#163
While some describe this as "frank", I think to have that quality TFA would need to specify where the decryption keys are stored. Are they in the USA colo's too? (I realize I could probably figure this out myself if I could be arsed to do so, but why not just tell us?)

Re: FastMail’s servers are in the US – what this means for you

#164
post #43

Earlier quoted context omitted.

Dell (and possibly others) servers have chassis intrusion sensors that you can trap in software, and do with as you please.

This goes beyond chassis intrusion, though - the servers are set up to freak out if anyone even opens the cage to look at them.

Yeah, that is just bar room banter between nerds. I've stood next to unprotected racks of Akamai servers and nothing happened.

Nobody really builds systems where an HVAC engineer walking into your cage to move a cooling tile will cause an outage, they just love to talk about how they would build them.

Re: FastMail’s servers are in the US – what this means for you

#165

Earlier quoted context omitted.

I don't suppose you got any numbers easily at hand about how much of your port 25 traffic negotiates a TLS encrypted connection?

A very naive estimate based on one day of logs from one server says over 75% of our incoming port 25 connections are encrypted. Although that says nothing about the quality of the cipher in use and the type of messages that come through, its still significantly higher than I would have expected. I can see I'll be spending some time on this in the next few days!

Thanks for that. They're useful numbers for me, because I've got this plan…

My current side-project involves a RaspberryPi (sitting in my loungeroom on my home ADSL connection), iRedMail, full disk encryption, a handful of inexpensive VPS providers with APIs that allow automated provisioning (DigitalOcean, NineFold, and Hetzner – to spread out the jurisdictions) – with the RasPi opening a reverse SSH tunnel for ports 25 and 465. Add in a DNS provider with a useable API so the 'Pi can spin up and shut down VPSes itself and update MX records to suit, and VPS images configured to not log anything mail-related, and I think I've gone as far as I can to secure my end of all my email. Having physical control of the hardware/storage that my email relies on won't protect me against NSA level targeted-at-me snooping, or even local law enforcement with sufficient "probable cause" to get a judge to sign a search warrant, but at least I'll _know_ if someone grabs my server hardware. (Hmmm, I wonder if there's some NSL-type coercion that could be used against my partner to force her to let someone take/image my 'Pi while I'm not home, and not be allowed to tell me?)

Possible over-paranoid ideas include refusing port 25 smtp connections that wont negotiate a secured connection in response to a STARTLLS command, and possibly blacklisting mail originating from any of the 8 known PRISM collaborators. I like the _idea_ of ensuring none of my mail arrives from known-intercepted sources, but reality dictates otherwise since way too many of the people I really do want to communicate with are exclusively using gmail/yahoo for email (or worse still, have migrated largely to Facebook messaging instead of email).

Re: FastMail’s servers are in the US – what this means for you

#167
post #35

Earlier quoted context omitted.

Note that G, FB, A and MS are not in a position where they can write such disclosure. I am not arguing with your main point, I applaud FastMail for taking a stand - it's just that USA companies must use "ambiguous slimeball statements" to at least appear clean (because they are not). I would argue that if FastMail were an USA company their statements (if any) would be just as ambiguous as those of G, FB, A and MS.

I understand your viewpoint, but I don't accept that as an excuse. Remember how quickly SOPA sank after the Silicon Valley establishment turned against it? Do you think the government is going to put the CEOs of some of America's most popular and profitable companies in jail for an act of civil disobedience that the majority of the country and the world would support wholeheartedly? SV is more powerful than it realiz…

> Do you think the government is going to put the CEOs of some of America's most popular and profitable companies in jail for an act of civil disobedience

If you support the rule of law, you should expect and demand that if it comes to legal consequences that's exactly what will happen. You can fight the law in parallel and use the trial to challenge it, but expect the consequences anyway. Otherwise you're calling for the rich and powerful to be held to a different, weaker standard just because in this case you might like the outcome.

You can treat it as the lesser evil, acknowledging that they're already held to weaker standards and that happens to be useful here, but you'd still be helping to entrench a system which is ultimately bad for you unless you're also very rich.

Re: FastMail’s servers are in the US – what this means for you

#168

Earlier quoted context omitted.

I understand your viewpoint, but I don't accept that as an excuse. Remember how quickly SOPA sank after the Silicon Valley establishment turned against it? Do you think the government is going to put the CEOs of some of America's most popular and profitable companies in jail for an act of civil disobedience that the majority of the country and the world would support wholeheartedly? SV is more powerful than it realiz…

Unfortunately, Mark Zuckerberg, Eric Schmidt, and all of those other guys are surveillance poster boys. It's best just to not use their services, and vote with dollars.

Your vote is worth about five bucks a year to Facebook. Not really a huge deal, considering most people aren't concerned about surveillance and a very tiny fraction is concerned enough to give up social networks.

Re: FastMail’s servers are in the US – what this means for you

#169
post #117

Earlier quoted context omitted.

I dunno, if the US government can't figure out if it wants public healthcare by the end of this month, they are gonna have to sell off some of those datacentres to pay the national debt...

Not quite. The US Government operates on an extralegal basis (ie they're willing to cross any line), and roughly 85%+ of all new debt is purchased by the Federal Reserve. What very specifically is not going to happen, is the shut down of the military industrial complex of which the NSA is such an integral part. So long as the dollar (Federal Reserve Note I should say) remains the global reserve currency, the national…

Dollar being the global reserve currency is the real linchpin to everything, but right now US Government seems ready to undermine that with their squabbles over healthcare. I mean, the upcoming default wouldn't destroy the dollar, but it would somewhat reduce the role of dollar reserves and treasury bonds in global markets.

Re: FastMail’s servers are in the US – what this means for you

#170

Earlier quoted context omitted.

> Has the headline on HN been updated? Because both you and brongondwana talk about it being sensationalist, where I see it as just being a summary of the most salient part of what you have to say. To my mind it was one of the least interesting parts of what we had to say. "Non-US company not bound by US law" - its hardly earth-shattering news. Would "Non-Senegalese company not bound by Senegal law" be as interesting…

Just a tangential thought, but I can't imagine seizing Australian assets based in the US would make for a particularly comfortable diplomatic position to be in (although I suspect our current government doesn't care). To say nothing about the fact that we've already shown our hand (and upset most of our allies) by way of the Manning leaks, the Assange manhunt brought about largely by US political pressure, and, more…

NSA eagerness to intercept personal emails of Brazilian president and EU citizens shows that noone cares about comfortable diplomatic positions, they'd just do it anyways.
Post reply on HN