Live data from Hacker News

Fastmail offers EU data region

fastmail.com

161–170 of 302 posts

Re: Fastmail offers EU data region

#161
post #9

EU data regions are a reflexive action by companies that try to hold on to their EU customers (and more and more are leaving, surprisingly the larger ones seem to be leading here). Realize that as long as you are still hosted on US owned infrastructure or that if there are US (or: five-eyes) owned companies anywhere in the stack your data can still be forcibly pulled and often without you being aware that this happen…

Does this still apply if there are separate legal entities for US & EU operations? Take Hetzner as an example. They have a separate US company to deal with their US data center. Would their EU servers be vulnerable to the CLOUD Act?

The relevant fact about Hetzner is that it's an EU company with US branch, not a US company with an EU branch.

Re: Fastmail offers EU data region

#162
post #93

Earlier quoted context omitted.

Requiring that you believe those companies that they won’t hand the keys over to the US at the first ask. Like, the critical problem with the AWS sovereign pitch is that you must believe that they won’t give the keys to the US, and they also won’t give the source code that’s hosted in the US to the government either for them to find vulnerabilities in. I don’t know if that’s good enough unless you just need the data…

The harder problem here is that any real EU sovereign platform would have to come with ironclad guarantees that it isn't going to be directly or indirectly sold to a US party. And when enough customers move that marketshare is affected the bags with money tempting shareholders will get larger and larger.

Isn’t that counterbalanced by the fact that the reason they exist in the first place is to be a sovereign platform?

I am assuming the reason companies switch to them is not price or tech. US cloud providers have the advantage on both.

Selling EU companies data would mean destroying trust over their main selling point, not to mention incur on EU wrath.

Feels like living one whistleblower away from doom.

I refer to fully EU clouds, parent list includes US clouds that do not need bags of money, Clouds Act in enough.

Re: Fastmail offers EU data region

#163

Earlier quoted context omitted.

Not nearly the same thing. Trump and his family have made billions. I cannot say the same of von der Leyen.

Which of those two leaders were elected by the people?

The European Parliament is elected by vote and has to ratify the chosen members of the EU council. The president of the council included.

Re: Fastmail offers EU data region

#164

Earlier quoted context omitted.

Sorry, I don't agree with that. The amount of corruption in the USA right now is simply off the scale.

It's not, you're just watching CNN too much.

or maybe you're watching Fox News too much?

Re: Fastmail offers EU data region

#165

EU folks, note the warnings threaded throughout this post: this is not currently any sort of panacea against US or AU data hosting risks, but it will make your data noticeably closer to home. Fastmail (Australia) merged with Pobox (Philadelphia) resulting in a complex tri-national law/risk surface when the EU is involved, so go in eyes wide open having read this in full. That everyone will overinterpret “EU data regi…

I think it's not unreasonable to see this as a first, positive, step.

It's certainly giving them some benefit of the doubt, but it doesn't seem unreasonable that, say, the EU server and the US backup will in some time be an EU server and an EU backup.

Re: Fastmail offers EU data region

#166
post #9

EU data regions are a reflexive action by companies that try to hold on to their EU customers (and more and more are leaving, surprisingly the larger ones seem to be leading here). Realize that as long as you are still hosted on US owned infrastructure or that if there are US (or: five-eyes) owned companies anywhere in the stack your data can still be forcibly pulled and often without you being aware that this happen…

True. Australia is part of the Five Eyes alliance. Fastmail is an Australian company. Australia also has the Assistance and Access Act - https://havenmessenger.com/blog/posts/australia-assistance-a... - which just stops shy of asking Australian tech companies, like Fastmail, to build backdoors into their products so that the government can "legally access" data from them. (When the law passed, Fastmail lost many clie…

> just stops shy of asking Australian tech companies, like Fastmail, to build backdoors into their products so that the government can "legally access" data from them

It stops just short of saying that you must do thispreemptively, but is pretty clear that you must do it if they ask you to.

Re: Fastmail offers EU data region

#167
post #124

Earlier quoted context omitted.

I started using tuta until I realised they don't support IMAP. Something to do with not guaranteeing encryption (which isn't even enabled by default) but has the convenient effect of locking you into their apps

IMAP can do TLS though (IMAPS). Did they say what's stopping them from using that (and requiring the encryption!)?

They didn't need to. When you start denying IAMP to your customer in the name of "encryption" at that point it becomes privacy theatre, instead of privacy, irrespective of how nobly activist their intensions are. It is probably slightly worse than a mail provider assuming they can't trust their users with encrypting their emails when needed.

Re: Fastmail offers EU data region

#168
post #115

If what you need is a guarantee that your data remains only in the EU, we don’t have that, and we’d rather tell you directly than let you assume otherwise. Is there an alternative that really keeps data in the EU? (And not only in the sense it serves a sales promotion)

https://mailbox.org/ Germany https://posteo.de/ Germany https://runbox.com/ Norway https://www.migadu.com/ Switzerland more: https://european-alternatives.eu/category/email-providers

Among these runbox is quite good and my friend has used migadu for a few years and likes it even though he says the "soft" limits still make him uncomfortable even though so far he has never hit them; so I guess that should be fine. Posteo doesn't support custom domains (I've used them and otherwise they are good). I wouldn't go with Proton ever. Mailo seems new - never heard of them. Would love to get a review.

mailbox.org can be avoided if you need to send and receive emails from domains where the mail admins might not be email admin savants and/or privacy activists (sometimes that's not a choice in case of Govt services etc and you may not live in a country when you can get those changes done). Also, if you ever face an issue and send them an email, expect the reply to come in weeks (if you are lucky) and that too a flippant (sometimes even terse) nothing-mail and then if you respond the cycle repeats until you give up.

Re: Fastmail offers EU data region

#169

Can't wait to verify my age before reading emails! In all seriousness though, what are the chances Fastmail won't require KYC at some point? I have sent them a support request with that question and got a non-answer. PS: Am a paying customer for like a decade

No one would know that other than Fastmail and regulators. But what I can say is keeping different emails for different purposes might be the way. Unless your domain also has none of your PII attached to you, neither is any of your email interactions. It's not ideal but I finally stopped fighting it and use few emails that offers both privacy and anonymity if I ever need that.

Re: Fastmail offers EU data region

#170

Earlier quoted context omitted.

True. Australia is part of the Five Eyes alliance. Fastmail is an Australian company. Australia also has the Assistance and Access Act - https://havenmessenger.com/blog/posts/australia-assistance-a... - which just stops shy of asking Australian tech companies, like Fastmail, to build backdoors into their products so that the government can "legally access" data from them. (When the law passed, Fastmail lost many clie…

> just stops shy of asking Australian tech companies, like Fastmail, to build backdoors into their products so that the government can "legally access" data from them It stops just short of saying that you must do this preemptively , but is pretty clear that you must do it if they ask you to.

And you can’t tell anyone if you do, on pain of jail.
Post reply on HN