Live data from Hacker News

The FastMail Security Mindset

blog.fastmail.com

211–220 of 301 posts

Re: The FastMail Security Mindset

#211
post #201

Earlier quoted context omitted.

I've been a fastmail customer for a bit over a year and I agree. The offerings over at https://protonmail.com/signup have been nagging me to give it a try. I now have a reason to try and switch. I'll lose functionality found in fastmail but gain a lot in security.

Unless you have a set of objectives that are very different from what I consider "as secure as e-mail gets", please consider GSuite and not Protonmail. (I don't speak for 'tptacek, but I'm pretty sure he'd agree.) As a corollary: if you really care, use Signal for stuff you can't say over e-mail. Whatsapp's fine too. But they solve a very different security problem than the one you need e-mail to solve, which is most…

>"Whatsapp's fine too. But they solve a very different security problem than the one you need e-mail to solve,"

Can you elaborate on this? What security problem are they trying to solve?

Re: The FastMail Security Mindset

#212
post #201

Earlier quoted context omitted.

Unless you have a set of objectives that are very different from what I consider "as secure as e-mail gets", please consider GSuite and not Protonmail. (I don't speak for 'tptacek, but I'm pretty sure he'd agree.) As a corollary: if you really care, use Signal for stuff you can't say over e-mail. Whatsapp's fine too. But they solve a very different security problem than the one you need e-mail to solve, which is most…

>"Whatsapp's fine too. But they solve a very different security problem than the one you need e-mail to solve," Can you elaborate on this? What security problem are they trying to solve?

Sure! Signal and WhatsApp are good at having private conversations. Email is very tough to add private conversation capability to, for a variety of reasons. What you do need your mail provider (and by extension your DNS provider) to do is to not give up access to an attacker who asks nicely, because for most services, email access is account takeover.

This makes discussions about email security confusing, because most security professionals I know are thinking about a very different threat model (pop all of your services) than what a lot of people think about (confidentiality). Google is pretty good at not letting random people auth to GSuite as you. (Still turn off SMS recovery, though.)

Does that answer your question?

Re: The FastMail Security Mindset

#213
post #178

Earlier quoted context omitted.

I agree with hitekker, I'm feeling pretty nervous about being a FastMail customer right now and will start looking for a more secure alternative now. The main reason I moved to FastMail is because I stopped trusting Google to keep my mail secure.

Google is the gold standard for email account service. Nobody in the industry does a better job at that one thing than Google does.

Could you share some info/links on what makes it the Gold Standard?

Re: The FastMail Security Mindset

#214
post #201

Earlier quoted context omitted.

I've been a fastmail customer for a bit over a year and I agree. The offerings over at https://protonmail.com/signup have been nagging me to give it a try. I now have a reason to try and switch. I'll lose functionality found in fastmail but gain a lot in security.

Unless you have a set of objectives that are very different from what I consider "as secure as e-mail gets", please consider GSuite and not Protonmail. (I don't speak for 'tptacek, but I'm pretty sure he'd agree.) As a corollary: if you really care, use Signal for stuff you can't say over e-mail. Whatsapp's fine too. But they solve a very different security problem than the one you need e-mail to solve, which is most…

Just gonna drive by mention https://landing.google.com/advancedprotection/, which is a physical-2fa-security-key-only version of gmail. To my knowledge it also disallows mail forwarding, and the account recovery procedure in the event of losing both second factors is intended to be a long process that involves proof of identity and multiple attempts to notify the account owner.

(I work on gmail, but I'm not intimately familiar with this option, other than knowing that it exists and is intended for high value targets like celebrities and politicians).

Re: The FastMail Security Mindset

#215
post #213

Earlier quoted context omitted.

Google is the gold standard for email account service. Nobody in the industry does a better job at that one thing than Google does.

Could you share some info/links on what makes it the Gold Standard?

Can you think of some info/links that would suggest the opposite?

Re: The FastMail Security Mindset

#216
Another data point: I have had a FastMail account before Gmail before Opera and Kaggle. Why pay for email? when everything was free ...Yahoo, hotmail, etc. Word of mouth. Reputation. Though times were less sophisticated back then along with security; Fastmail kept up. I used my YubiKey with them way before gmail u2f fido support and they fostered my trust over the years keeping it clean and simple. Nothing is foolproof but at least I know their track record and commitments to their users despite dropping the ball in some cases. That said, I'm glad to read about the horror stories, provider alternatives and fastmail responses; hopefully we are all the better for it.

Re: The FastMail Security Mindset

#217
post #215
post #213

Earlier quoted context omitted.

Could you share some info/links on what makes it the Gold Standard?

Can you think of some info/links that would suggest the opposite?

I'm not looking to discredit the claim, I'm genuinely curious to learn about what they've done to earn the Gold Standard from @tptacek

Google were previously reading our emails for Ad purposes and some of their employees are still able to read our Emails, their privacy policy also indictates they will hand over our emails if requested by law enforcement which suggests it's weaker than protonmail.com end-to-end encryption:

> All emails are secured automatically with end-to-end encryption. This means even we cannot decrypt and read your emails. As a result, your encrypted emails cannot be shared with third parties.

If this is the case, how is Google being held as the Gold Standard?

Re: The FastMail Security Mindset

#218
post #212

Earlier quoted context omitted.

>"Whatsapp's fine too. But they solve a very different security problem than the one you need e-mail to solve," Can you elaborate on this? What security problem are they trying to solve?

Sure! Signal and WhatsApp are good at having private conversations. Email is very tough to add private conversation capability to, for a variety of reasons. What you do need your mail provider (and by extension your DNS provider) to do is to not give up access to an attacker who asks nicely, because for most services, email access is account takeover. This makes discussions about email security confusing, because mos…

I get the impression that when non-security people talk about "security" these days it's almost always in the context of preventing government surveillance.

So even though Google has a great track record of keeping hackers from taking over your accounts, the news stories about them cooperating with governments makes them seem less "secure" to some people.

What's weird is when it leads to a fallacy where people trust services that are less verified and tested in terms of security just because there isn't the association with government cooperation.

Re: The FastMail Security Mindset

#219

Earlier quoted context omitted.

Exactly which employees in your organization have the ability to alter recovery email settings? How many of those employees are there? In what fashion do you audit and track the activities of those employees? What training are these employees given to avoid social engineering? What firm provides the courseware? What's the escalation process for complicated, non-no-brainer reset situations? If a support person isn't a…

Wow, that's a lot of questions, and I can't answer all of them without creating security risks! Our absolute focus is on minimizing the human factors. In the past year and a bit since that incident, we have improved our escalation policies and support training, as well as let some support staff go. But more importantly, we now have an automated account recovery system which can be used to verify ownership of the acco…

Wow, that's a lot of questions, and I can't answer all of them without creating security risks

Questions like these are not unreasonable for a customer to ask a service provider with respect to identity management and protection of that customer’s proprietary and confidential information.

With respect to the first question “Exactly which employees have the ability to alter recovery email settings.” Not being able to have a prepared answer for this question suggests that you don’t have a formal policy or standard procedure around role based capabilities in your operation.

The second question is an extension of the first.

“In what fashion do you audit and track the activities of these employees?” Not being able to answer that question suggests that you don’t have an auditing process around employee actions with respect to account changes.

“What training are these employees given to avoid social engineering?” Not being able to answer this question suggests that you don’t have such training in place.

“What’s the escalation process for non-no-brainer reset situations?” If your processes are written down and staff are trained in them, a very simple description here would not create a security’s risk of any kind. Not doing so suggests that the process is not formally specified or is quite ad hoc.

“Are the support people who are enabled and entitled to lose the tickets incentivized to close the tickets as soon as possible?” It seems that your internal security posture would make that clear, and it is unclear how stating that correctness is more important than speed in user account modification poses a security risk.

I’ll pause here and summarize. Answering any of these questions is not going to pose a security risk unless such answers expose to your users reasonable measures that you are not taking or haven’t thought of.

Re: The FastMail Security Mindset

#220
post #213

Earlier quoted context omitted.

Google is the gold standard for email account service. Nobody in the industry does a better job at that one thing than Google does.

Could you share some info/links on what makes it the Gold Standard?

They have one of the largest information security teams in the world, that team includes what is probably the best corporate vulnerability research team in the world. They're one of a small number of companies that is actively defining modern TLS and thus modern transport encryption; their operations and security teams are almost certainly the world's most sophisticated users of TLS. They ship the most secure browser in the world (if it's not, it's a dead-even tie with Edge --- but, since Google outclasses every other major vendor in vulnerability research, I doubt it's really a tie) and thus have a far better understanding of browser security and the interaction between serverside applications and clientside JS/HTTP applications than any other company. They spend more per year on external vulnerability assessment than most startups do... for everything. They're a constant state-level adversary target and have, over the last decade, evolved a secops and monitoring team to match those adversaries.

How many engineering employees does Fastmail even have? How much better would each of them have to be than one of the best-paying security teams in the entire industry for them to match up?

I could go on, but to me, you don't really even have to think hard about this.

Post reply on HN