Live data from Hacker News

The FastMail Security Mindset

blog.fastmail.com

121–130 of 301 posts

Re: The FastMail Security Mindset

#121

The simple reason I haven't switched email providers: all my online accounts, as well as many offline ones, are tied to my gmail account. Yes, I can set up forwarding, but that defeats the purpose of switching providers IMO (for me, the purpose would be to move away from Google completely ). I don't want Google to read any of my emails period, so forwarding is not a sufficient solution.

I think the only way is to start switching gradually. If you don't want Google to read your email, keeping it as the main accounts isn't really going to help.

If you do change, get a forwarding service or your own domain so that the same mistake doesn't happen again.

Re: The FastMail Security Mindset

#122
post #77
post #67

Earlier quoted context omitted.

Dear Fastmal, I am a happy customer, but very concerned by this report. Would you mind to comment?

I just forwarded this comment to their customer support. Let’s see what would be their comment.

Please tag me when they answer. (does HN have tags/notifications?)

Re: The FastMail Security Mindset

#123
post #47
post #40

Earlier quoted context omitted.

The only thing that keeps me switching away from Gmail is loosing the actual email address.

Why not POP forward? You can also set a custom From...I use a custom domain instead of my old gmail because I was tired of hopping from juno to yahoo to gmail to fastmail.

juno? Damn blast from the past there.

Re: The FastMail Security Mindset

#124
post #27

Earlier quoted context omitted.

Im curious how FastMail and ProtonMail are comparison wise?

I tried out ProtonMail for just a little bit around the time I switched, and personally I found the focus on security and encryption to be at the expense of user experience.

I’ve only tried ProtonMail’s iOS client, but have found it to be very easy to use.

Re: The FastMail Security Mindset

#125
post #2

> Just as important as what we do do is what we don’t. For example, we don’t do full message encryption (e.g. PGP) in the browser. In theory it means you “don’t have to trust us”. However in reality, every time you open your email you would be trusting the code delivered to your browser. If the server were compromised, it could easily be made to return code that intercepted and sent back your password next time you l…

You can use PGP then. However using PGP well turns out to be hard. You can to have the client local (and built by a trusted source), not a web client. You have to ensure you didn't forget your private key. You have to understand how it works and what the limits are to ensure that you don't accidentally break something. For what fastmail is doing providing PGP is the wrong answer: there is no way they can provide it s…

All of my email is encrypted using PGP on the way in. I can read it on my laptop, desktop and phone because I use Evolution, Mutt and K-9 Mail, all three of which support PGP and all three of which I can use with my Yubikey.

If you compromise my mailbox, you can't read any old or new email, and you can trigger as many password reset emails as you want, you wont be able to read them.

Re: The FastMail Security Mindset

#126
They should do PGP on the way in, for people who want it. It's trivial to set up. All they need to do is let people paste in a public PGP key and encrypt all incoming email with that key. Here's how I've been doing it for the last 7 years:

https://www.grepular.com/Automatically_Encrypting_all_Incomi...

Re: The FastMail Security Mindset

#127
post #77

Earlier quoted context omitted.

I just forwarded this comment to their customer support. Let’s see what would be their comment.

Please tag me when they answer. (does HN have tags/notifications?)

> does HN have tags/notifications?

No, but if you visit your Threads page (link at the top of every page) you can see any replies to any of your comments. There's nothing special that marks a new reply, though.

I have a habit of upvoting nearly every reply anyone makes to any comment of mine, as a way of thanking them for the comment. This also happens to help when I skim my Threads page, since it's easy to spot comments that still have the voting button(s).

Re: The FastMail Security Mindset

#128
post #64

I was a very happy FastMail customer until a hacker asked them to reset my password. After _incorrectly_ answering a handful of questions asked by the FastMail support, the recovery email address was changed and a password reset link sent. From there, the hacker attempted password resets on other services. Initially, FastMail was dismissive that this was a simple "mix-up" and didn't disable access to the hacker for 7…

That's very unacceptable, and enough to make me consider leaving Fastmail - I've used them happily for over 7 years and have recommended them to many people, but their support having the ability to do that is giving me pause.

Re: The FastMail Security Mindset

#129
post #67
post #64

I was a very happy FastMail customer until a hacker asked them to reset my password. After _incorrectly_ answering a handful of questions asked by the FastMail support, the recovery email address was changed and a password reset link sent. From there, the hacker attempted password resets on other services. Initially, FastMail was dismissive that this was a simple "mix-up" and didn't disable access to the hacker for 7…

Dear Fastmal, I am a happy customer, but very concerned by this report. Would you mind to comment?

Likewise. Social engineering is a big concern. I understand the risks of getting locked out of my account, but would much prefer a stricter system -- along with published guidelines on Fastmail's process for handling these cases.

Being able to persuade a customer service rep to provide access to an account (even if indirectly by changing a recovery email) should never be possible.

Re: The FastMail Security Mindset

#130
post #64

I was a very happy FastMail customer until a hacker asked them to reset my password. After _incorrectly_ answering a handful of questions asked by the FastMail support, the recovery email address was changed and a password reset link sent. From there, the hacker attempted password resets on other services. Initially, FastMail was dismissive that this was a simple "mix-up" and didn't disable access to the hacker for 7…

> I was a very happy FastMail customer until a hacker asked them to reset my password. After _incorrectly_ answering a handful of questions asked by the FastMail support, the recovery email address was changed and a password reset link sent. From there, the hacker attempted password resets on other services.

When did this happen?

Post reply on HN