Earlier quoted context omitted.
Encrypted HDD won't help against cold boot attack.
I doubt that an unexpected reboot and chassis intrusion (to install a compromized bootloader, for example) will go unnoticed by FastMail staff.
FastMail’s servers are in the US – what this means for you
161–170 of 175 posts
Re: FastMail’s servers are in the US – what this means for you
#162> There are of course other avenues available to obtain your data. Our colocation providers could be compelled to give physical access to our servers. Network capturing devices could be installed. And in the worst case an attacker could simply force their way into the datacentre and physically remove our servers. > These are not things we can protect against directly but again, we can make it extremely difficult for…
"This kind of frank disclosure should be highly rewarded." Yep, definitely. I think even more important than the information itself is the spirit of honesty and integrity that it demonstrates. This stands in stark contrast to the ambiguous slimeball statements issued by the likes of Google, Facebook, Apple, Microsoft, etc. When Big Brother comes knocking, which companies are going to take a risk to stand up for you?…
If Snowden, an individual contractor, can dive deep into the data how do we know that others are not doing the same for other purposes?
Re: FastMail’s servers are in the US – what this means for you
#163Re: FastMail’s servers are in the US – what this means for you
#164Earlier quoted context omitted.
Dell (and possibly others) servers have chassis intrusion sensors that you can trap in software, and do with as you please.
This goes beyond chassis intrusion, though - the servers are set up to freak out if anyone even opens the cage to look at them.
Nobody really builds systems where an HVAC engineer walking into your cage to move a cooling tile will cause an outage, they just love to talk about how they would build them.
Re: FastMail’s servers are in the US – what this means for you
#165Earlier quoted context omitted.
I don't suppose you got any numbers easily at hand about how much of your port 25 traffic negotiates a TLS encrypted connection?
A very naive estimate based on one day of logs from one server says over 75% of our incoming port 25 connections are encrypted. Although that says nothing about the quality of the cipher in use and the type of messages that come through, its still significantly higher than I would have expected. I can see I'll be spending some time on this in the next few days!
My current side-project involves a RaspberryPi (sitting in my loungeroom on my home ADSL connection), iRedMail, full disk encryption, a handful of inexpensive VPS providers with APIs that allow automated provisioning (DigitalOcean, NineFold, and Hetzner – to spread out the jurisdictions) – with the RasPi opening a reverse SSH tunnel for ports 25 and 465. Add in a DNS provider with a useable API so the 'Pi can spin up and shut down VPSes itself and update MX records to suit, and VPS images configured to not log anything mail-related, and I think I've gone as far as I can to secure my end of all my email. Having physical control of the hardware/storage that my email relies on won't protect me against NSA level targeted-at-me snooping, or even local law enforcement with sufficient "probable cause" to get a judge to sign a search warrant, but at least I'll _know_ if someone grabs my server hardware. (Hmmm, I wonder if there's some NSL-type coercion that could be used against my partner to force her to let someone take/image my 'Pi while I'm not home, and not be allowed to tell me?)
Possible over-paranoid ideas include refusing port 25 smtp connections that wont negotiate a secured connection in response to a STARTLLS command, and possibly blacklisting mail originating from any of the 8 known PRISM collaborators. I like the _idea_ of ensuring none of my mail arrives from known-intercepted sources, but reality dictates otherwise since way too many of the people I really do want to communicate with are exclusively using gmail/yahoo for email (or worse still, have migrated largely to Facebook messaging instead of email).
Re: FastMail’s servers are in the US – what this means for you
#166Re: FastMail’s servers are in the US – what this means for you
#167Earlier quoted context omitted.
Note that G, FB, A and MS are not in a position where they can write such disclosure. I am not arguing with your main point, I applaud FastMail for taking a stand - it's just that USA companies must use "ambiguous slimeball statements" to at least appear clean (because they are not). I would argue that if FastMail were an USA company their statements (if any) would be just as ambiguous as those of G, FB, A and MS.
I understand your viewpoint, but I don't accept that as an excuse. Remember how quickly SOPA sank after the Silicon Valley establishment turned against it? Do you think the government is going to put the CEOs of some of America's most popular and profitable companies in jail for an act of civil disobedience that the majority of the country and the world would support wholeheartedly? SV is more powerful than it realiz…
If you support the rule of law, you should expect and demand that if it comes to legal consequences that's exactly what will happen. You can fight the law in parallel and use the trial to challenge it, but expect the consequences anyway. Otherwise you're calling for the rich and powerful to be held to a different, weaker standard just because in this case you might like the outcome.
You can treat it as the lesser evil, acknowledging that they're already held to weaker standards and that happens to be useful here, but you'd still be helping to entrench a system which is ultimately bad for you unless you're also very rich.
Re: FastMail’s servers are in the US – what this means for you
#168Earlier quoted context omitted.
I understand your viewpoint, but I don't accept that as an excuse. Remember how quickly SOPA sank after the Silicon Valley establishment turned against it? Do you think the government is going to put the CEOs of some of America's most popular and profitable companies in jail for an act of civil disobedience that the majority of the country and the world would support wholeheartedly? SV is more powerful than it realiz…
Unfortunately, Mark Zuckerberg, Eric Schmidt, and all of those other guys are surveillance poster boys. It's best just to not use their services, and vote with dollars.
Re: FastMail’s servers are in the US – what this means for you
#169Earlier quoted context omitted.
I dunno, if the US government can't figure out if it wants public healthcare by the end of this month, they are gonna have to sell off some of those datacentres to pay the national debt...
Not quite. The US Government operates on an extralegal basis (ie they're willing to cross any line), and roughly 85%+ of all new debt is purchased by the Federal Reserve. What very specifically is not going to happen, is the shut down of the military industrial complex of which the NSA is such an integral part. So long as the dollar (Federal Reserve Note I should say) remains the global reserve currency, the national…
Re: FastMail’s servers are in the US – what this means for you
#170Earlier quoted context omitted.
> Has the headline on HN been updated? Because both you and brongondwana talk about it being sensationalist, where I see it as just being a summary of the most salient part of what you have to say. To my mind it was one of the least interesting parts of what we had to say. "Non-US company not bound by US law" - its hardly earth-shattering news. Would "Non-Senegalese company not bound by Senegal law" be as interesting…
Just a tangential thought, but I can't imagine seizing Australian assets based in the US would make for a particularly comfortable diplomatic position to be in (although I suspect our current government doesn't care). To say nothing about the fact that we've already shown our hand (and upset most of our allies) by way of the Manning leaks, the Assange manhunt brought about largely by US political pressure, and, more…