Live data from Hacker News

Fastmail offers EU data region

fastmail.com

211–220 of 305 posts

Re: Fastmail offers EU data region

#211
Maybe it’s a silly question, but how much of those “EU Region” makeups that were seeing are enforceable in reality?

In extreme cases the US DoJ can reach, let’s say the CEO/CTO arrest them or pick up family members in case of some sort of non-compliance in some criminal investigation.

I can imagine something like > US DoJ has some PoI with some account in Fastmail “EU region” > Fastmail says “sorry we’re GDPR” > US DoJ says “now” or… > Fastmail refuses

Then what?

Re: Fastmail offers EU data region

#212
post #211

Maybe it’s a silly question, but how much of those “EU Region” makeups that were seeing are enforceable in reality? In extreme cases the US DoJ can reach, let’s say the CEO/CTO arrest them or pick up family members in case of some sort of non-compliance in some criminal investigation. I can imagine something like > US DoJ has some PoI with some account in Fastmail “EU region” > Fastmail says “sorry we’re GDPR” > US D…

[deleted]

Re: Fastmail offers EU data region

#213

Earlier quoted context omitted.

Does this still apply if there are separate legal entities for US & EU operations? Take Hetzner as an example. They have a separate US company to deal with their US data center. Would their EU servers be vulnerable to the CLOUD Act?

Well, for sure they can pressure them but I highly doubt Hetzner would break the law in Europe to satisfy the US government, they are a lot more to lose here than there. I realize that that is not proof.

I dont share your optimism: The US can just say: let us access this one customer or we will ruin your vpcs in the US.

What can you do about it? FDE? Can you keep the keys away from Hetzner? How much hacking would they need to do to get them? Can US government break SecureBoot?

Im just happy my business is not important enough

Re: Fastmail offers EU data region

#215
post #213

Earlier quoted context omitted.

Well, for sure they can pressure them but I highly doubt Hetzner would break the law in Europe to satisfy the US government, they are a lot more to lose here than there. I realize that that is not proof.

I dont share your optimism: The US can just say: let us access this one customer or we will ruin your vpcs in the US. What can you do about it? FDE? Can you keep the keys away from Hetzner? How much hacking would they need to do to get them? Can US government break SecureBoot? Im just happy my business is not important enough

the alternative being hetzner giving away EU based information to the US? which would absolutely destroy their reputation in the EU. (which is a far larger market for them).

The only way to spin this as hetzner is to go public with this and make it a political point for geopolitics between the EU and the US, and take the loss /call the bluff on the US threat.

Re: Fastmail offers EU data region

#216
post #207
post #134

Earlier quoted context omitted.

Tuta is always encrypted I don't know where you got the impression that it was optional or that they could somehow magically make it work over IMAP without a bridge like proton.

> Tuta does not support the use of third-party email clients or the protocols IMAP/POP3/SMTP as we cannot guarantee end-to-end encryption of your data. So it "breaks end to end encryption" even with smtps and imaps apparently. The few emails I received weren't from tutamail users so presumably came over SMTP. It's confusing to know what they mean because they confuse terms. They say emails are "stored end to end encr…

They offer similar product to a more well known Proton.

Re: Fastmail offers EU data region

#217
post #211

Maybe it’s a silly question, but how much of those “EU Region” makeups that were seeing are enforceable in reality? In extreme cases the US DoJ can reach, let’s say the CEO/CTO arrest them or pick up family members in case of some sort of non-compliance in some criminal investigation. I can imagine something like > US DoJ has some PoI with some account in Fastmail “EU region” > Fastmail says “sorry we’re GDPR” > US D…

then it becomes a political issue between the EU and the US?

mind you, prior to this administration the EU was more then happy to help the US DOJ in such cases.

considering the stuff that happened in the past year or so, i doubt that would happen again. Actually calling bluff on the US is the only way to play this properly, because it gives the EU a mandate to strike back geopolitically if the US wants to retaliate for non-compliance by fastmail.

Re: Fastmail offers EU data region

#218

Earlier quoted context omitted.

That’s not going to help anyone. The Five Eyes is an Anglosphere intelligence alliance comprising Australia, Canada, New Zealand, the United Kingdom, and the United States. These countries are party to the multilateral UKUSA Agreement, a treaty for joint cooperation in signals intelligence. https://en.wikipedia.org/wiki/Five_Eyes

Even being stored in EU doesn't preclude your data from being targeted by signals intelligence. Which is different than requiring US based companies to provide non-US data to American government. Does fastmail have a US presence? If no - then they're not bound at all by US jurisdiction.

As an Australian, all I can say is stop being naive.

Re: Fastmail offers EU data region

#219

Five Eyes country are subject to local data disclosure orders and gag clauses, forcing them to hand over user data that may then enter the shared intelligence pool

Not sure Five Eyes will outlast Trump, the UK has reportedly stopped sharing some intelligence with the US: https://www.courthousenews.com/uk-faces-questions-on-complic...

same goes for dutch intelligence agencies and i highly doubt others inside the EU sharing data willy nilly.

https://nos.nl/artikel/2586859-aivd-en-mivd-delen-minder-inf...

Re: Fastmail offers EU data region

#220
post #180

Earlier quoted context omitted.

> just stops shy of asking Australian tech companies, like Fastmail, to build backdoors into their products so that the government can "legally access" data from them It stops just short of saying that you must do this preemptively , but is pretty clear that you must do it if they ask you to.

Why do I never hear about this ‘feature’ from American products like gmail which 99% of the HN audience is using? Isn’t USA a member of Five Eyes? I admit it is a concern, as a Fastmail user, but this discussion only seems to happen on the Fastmail threads, yet no one bats an eye if one is suggested to open a gmail account like everybody else.

> Why do I never hear about this ‘feature’ from American products like gmail which 99% of the HN audience is using? Isn’t USA a member of Five Eyes?

There is lot of hate toward Google (and other top US companies). Especially due to autobanning of accounts, 2FA etc. at the moment people have fastmail as their darling - because they are the underdog, no AI forcing in products (at the moment) etc. It is like stripe from 5 years ago.

Most have given up in snooping. Or you need to go to proton mail but it has other issues. Every company is subject to some regulations.

at the end, if the receiver of email has to also keep it safe. Do they?

Post reply on HN