Live data from Hacker News

Fastmail: Staff access to your data

fastmail.com

21–25 of 25 posts

Re: Fastmail: Staff access to your data

#21
Yes, though not routinely... but if you need help with something and we need to see your data for that, our support team will ask for your permission and then take a look for you.

Also: if we have credible evidence that your account has been misbehaving (e.g. spams, scams, etc with the headers that show they originated from your authenticated connection) then we'll investigate to see if you're a bad actor breaking our terms of service or just some poor soul who had their credentials stolen.

And if your account is the subject of an Australian warrant, and a judge has been convinced that there's cause to access your individual data, then we don't place ourselves above the law. We consider ourselves good citizens of the world, and that includes working with law enforcement where they have a warrant.

What we don't do is sell your data or profile you in order to allow you to be targeted by those wishing to exert undue influence based on knowledge gleaned from your private communications. That's the privacy that's being bought and sold by many in the current world, and leading to poor consequences. We stand firm against the sale and manipulation of people's private electronic memory.

We don't snoop on you, but we'll help you fix your account if you mess it up, and we'll get your access back if you forget your password (a friend of mine lost her entire email history when she forgot her password while using one of the heavy encryption services... oops. Security is about availability and integrity as well).

Our support team is on your side, because we only have one paymaster, and that's our customer.

Re: Fastmail: Staff access to your data

#22

Earlier quoted context omitted.

Any folder called precisely "forwebmaster" gets the content automatically deobfuscated when support view the account. There's probably an interesting blog post in how that's achieved in the JMAP middleware using a reverse index on each blob to allow you to download any attachment that's referenced by those messages as well... but I digress. The forwebmaster method (legacy names 'r' us) is very useful for debugging is…

thanks for the detailed explanation. Do you think it'd be feasible to add this to Fastmail's help page about Security?

Seems plausible - the support team is in the middle of a revamp of a bunch of the help pages - I'll pop them a ticket.

Re: Fastmail: Staff access to your data

#23
post #14

Earlier quoted context omitted.

> my limited understanding is that Australian law forbids secure-by-design encryption pipelines This understanding is wrong. Secure encryption is perfectly legal, tech media simply likes to overreact to laws without actually reading them. The underlying law that lead to this widespread misconception requires Australian companies to assist law enforcement in acquiring communications but only when it can be done in suc…

That doesn't sound secure. What that is describing is that third parties can easily intercept my data. It isn't a huge deal because email is by nature quite insecure; but if I cared about other people reading my emails the law is a bit of a problem. At some point these companies will probably leak data onto the public internet (if the Panama papers can leak, anything can). Secure by design includes ideas like the pip…

It isn't secure and I wasn't saying it was secure. What I was saying is that the law gives you no less technical protection than you had before the law.

Importantly, the law doesn't compel you to have any interception capabilities. If you publish open-source code with verified and reproducible builds, the government can't really ask you to do anything, as doing so would either alert the people they're targeting or compromise the security of people unrelated to the investigation.

And I don't think this is any different to anywhere else. The FBI for example has been able to gain access to encryption keys in the past so I see no reason why signing keys would be any different.

Re: Fastmail: Staff access to your data

#24

For all their policies, they're still subject to Australia's "NSL" equivalent that requires they disclose data to law enforcement without notifying you, and in the case of certain agencies, without a warrant. Their servers are also located in the US, so they're accessible to three-letter agencies as well. I recently switched to a German service. Data can still be silently disclosed but only if there's imminent danger…

Who’s this German provider and how do they compare in terms of pricing/features/UX to Fastmail?

I use mailbox.org but there's a list of others here: https://thatoneprivacysite.net/email-comparison/#simple-emai...

For me mailbox.org ended up being slightly cheaper.

In terms of features and UX I've found them comparable.

Re: Fastmail: Staff access to your data

#25

Yes, though not routinely... but if you need help with something and we need to see your data for that, our support team will ask for your permission and then take a look for you. Also: if we have credible evidence that your account has been misbehaving (e.g. spams, scams, etc with the headers that show they originated from your authenticated connection) then we'll investigate to see if you're a bad actor breaking ou…

Can you please consider improving the notes function of your product? I really want to have better fastmail integration in my life and not having to rely on a third party app for something as simple as notes would help a lot.
Post reply on HN