Live data from Hacker News

FastMail’s servers are in the US – what this means for you

blog.fastmail.fm

111–120 of 175 posts

Re: FastMail’s servers are in the US – what this means for you

#111
post #66

I know that my word doesn't mean much, but I have had the chance to talk to several of the guys working at Fastmail during their years at Opera Software. They are -serious- about mail and they are -serious- about privacy. Next time I'm out shopping for email services, I will give my moeny to them! (And, to give something back for all the Tim Tams brongondwana brought with him to Norway ever time he was on a visit ;)…

If you want to just send timtams, that would be fine too. We seem to have run out of them in the office...

I'll get you timtams if you run the fire escape with us...

Re: FastMail’s servers are in the US – what this means for you

#112
post #57
post #6

> There are of course other avenues available to obtain your data. Our colocation providers could be compelled to give physical access to our servers. Network capturing devices could be installed. And in the worst case an attacker could simply force their way into the datacentre and physically remove our servers. > These are not things we can protect against directly but again, we can make it extremely difficult for…

"This kind of frank disclosure should be highly rewarded." With all due, Im sorry but, no. Had it come before the Snowden leaks, absolutely. But it didn't. After the event, facing a danger of customer loss or loss of confidence, it can only be seen as too late and defensive move. All these companies must have known something about these risks, yet remained in a passive conspiracy of silence. Not one stood up until Sn…

Before the Snowden leaks Fastmail was owned by Opera, it has since been bought by Fastmail staff.

http://blog.fastmail.fm/2013/09/25/exciting-news-fastmail-st...

Re: FastMail’s servers are in the US – what this means for you

#113
post #109
post #104

Earlier quoted context omitted.

Even if that post was written entirely by lawyers, that still wouldn't make it legally binding.

Indeed. So, the point remains: what value does this advice have over against the advice from Google, etc? It's a rhetorical question, by the way.

It's as useful as the degree to which you trust the company giving this advice. And that's always going to be the case regardless of who the company is and what they say.

Re: FastMail’s servers are in the US – what this means for you

#114

Earlier quoted context omitted.

If you want to just send timtams, that would be fine too. We seem to have run out of them in the office...

I'll get you timtams if you run the fire escape with us...

I'm afraid that if get fit and stuff I won't want them anymore! :'(

Re: FastMail’s servers are in the US – what this means for you

#115
post #6

> There are of course other avenues available to obtain your data. Our colocation providers could be compelled to give physical access to our servers. Network capturing devices could be installed. And in the worst case an attacker could simply force their way into the datacentre and physically remove our servers. > These are not things we can protect against directly but again, we can make it extremely difficult for…

The problem of this "disclosure" is that to the people writing the text the implications of Australian laws aren't clear, as seen in other thread here, started by westicle:

https://news.ycombinator.com/item?id=6506711

In short, don't expect that you can get any advantage from FastMail being Australian company -- you can even be worse off.

Re: FastMail’s servers are in the US – what this means for you

#116
There's one question they haven't answered: Why do they even need to have their servers in the US? Their blog post admits that there's a big chance that the US is spying on their customers. Given the fact that FastMail is a Norwegian/Australian company, why don't they just move their servers to e.g. Norway?

I realize that even if the servers were in Norway, an email from a FastMail user to a gmail.com account would still be read by the NSA (because it would pass through American servers), but email sent from FastMail to other email hosts in relatively safe countries would not be read by the NSA.

Re: FastMail’s servers are in the US – what this means for you

#117
post #68
post #51

Earlier quoted context omitted.

SOPA was a single proposed piece of legislation proposed by corporate lobbyists, who are on an essentially level playing field with Silicon Valley. The NSA is a 60 year old spy agency at the heart of the national security infrastructure and government. You are comparing two entirely dissimilar things. Also, how exactly is the American national security state 'weakened and vulnerable'?

At the moment it is weakened and vulnerable compared to how it was a few years ago. It has not been destroyed or dismantled by Snowden's revelations, far from it, but it is a definite factor the NSA cannot ignore. Five years ago, no one would even think of shutting the NSA down over their abominable deeds, because their abominable deeds were not widely known. At the moment, there are many people shouting for them to…

I dunno, if the US government can't figure out if it wants public healthcare by the end of this month, they are gonna have to sell off some of those datacentres to pay the national debt...

Re: FastMail’s servers are in the US – what this means for you

#119
As far as I know, Australian law is common law and would allow a judge to seal a warrant. So, fastmail's asertion that there is nothing like an NSL where they couldn't disclose a search is incorrect. I'm sure it is just lack of awareness, rather than intentional deception.

(Ianal, ianaa, but I am pretty sure I am correct on this point.)

Re: FastMail’s servers are in the US – what this means for you

#120

Earlier quoted context omitted.

Actually I am a lawyer. In the past I have even advised clients who received ACC notices (they are more common than most people would think). Needless to say I was staggered at the scope of the powers granted. Forget about transparency, justice and the rule of law. If you receive one of these you can be compelled to give evidence or documents in secret, without judicial oversight or public scrutiny.

I just checked upstairs. The advice we have is roughly: - ACC has judicial oversight - its unclear how this interacts with the Telecommunications (Intercept and Access) Act With my boss throwing in: - law is a giant mess - until you have two extremely well-funded parties disagreeing vehemently about the interpretation, you'll never get a final answer We're still happy with our publicly-stated position. You might disa…

Either way, it makes your service completely vulnerable to the government's interpretation of the law. If they force you to disclose your customers' data in secret tomorrow, or face jail time, I have no doubts what your choice will be.

I'm not calling you a liar, btw, I just think you're naive/oblivious, and considering you just now discovered what ACC is and had to check with your lawyer (who isn't even sure how it interacts with other laws), I wouldn't use your service to send any critical information. Ever.

Post reply on HN