Live data from Hacker News

The FastMail Security Mindset

blog.fastmail.com

261–270 of 301 posts

Re: The FastMail Security Mindset

#261

The simple reason I haven't switched email providers: all my online accounts, as well as many offline ones, are tied to my gmail account. Yes, I can set up forwarding, but that defeats the purpose of switching providers IMO (for me, the purpose would be to move away from Google completely ). I don't want Google to read any of my emails period, so forwarding is not a sufficient solution.

Try IMAPsync? http://imapsync.lamiral.info

Re: The FastMail Security Mindset

#262
post #120

Earlier quoted context omitted.

I've thought about switching many times, and would see myself using the web client, however I wonder if they support the "undo send" feature as GMail does. I cannot see it listed in their features page [1] at least. Can someone shed some light, please? TIA. [1] https://www.fastmail.com/help/ourservice/features.html

> JMAP will enable various long-desired features (e.g. snooze, delayed/undo send). says chrismorgan at https://news.ycombinator.com/item?id=15856942

Thanks for the info, that's great to hear :)

Re: The FastMail Security Mindset

#263

Earlier quoted context omitted.

> But FastMail supports other clients, right? I don't want to be forced to use their web interface or their app; I'm happy with the Apple-written Mail apps. It does, but at least for me the problem is using my separate forwarding-only e-mail address instead of fastmail.com as the sender. As far as I see, I need the native app for this.

FastMail.com can send via a forwarding email address. You'll need to set up authentication at FastMail so it can authenticate to the forwarding service of course.

I don't use the forwarding service to send. I use it to forward incoming mail to FastMail, and in FastMail I just fake the sender address when sending e-mail.

Re: The FastMail Security Mindset

#264
post #201

Earlier quoted context omitted.

Unless you have a set of objectives that are very different from what I consider "as secure as e-mail gets", please consider GSuite and not Protonmail. (I don't speak for 'tptacek, but I'm pretty sure he'd agree.) As a corollary: if you really care, use Signal for stuff you can't say over e-mail. Whatsapp's fine too. But they solve a very different security problem than the one you need e-mail to solve, which is most…

Just gonna drive by mention https://landing.google.com/advancedprotection/ , which is a physical-2fa-security-key-only version of gmail. To my knowledge it also disallows mail forwarding, and the account recovery procedure in the event of losing both second factors is intended to be a long process that involves proof of identity and multiple attempts to notify the account owner. (I work on gmail, but I'm not intimate…

That looks amazing. Does any other company provide anything like this?

Re: The FastMail Security Mindset

#265

Earlier quoted context omitted.

> the Web client is a joy to use Their web client is the only one I've ever been able to use without wanting to quit email.

When I was moving away from Fastmail, I noticed that Rainloop[1] is a pretty slick, Gmail-inspired webclient, and it's FOSS, but I couldn't find any provider who was actually using it. Can anyone comment? 1. https://www.rainloop.net/

I'm using Rainloop for my personal domains and so far love it. There's very good integration of GPG and (e.g.) Google Drive. Didn't take me long to move away from SquirrelMail or Roundcube after that. Highly recommended.

Re: The FastMail Security Mindset

#266
post #231

Earlier quoted context omitted.

Please consider adding a option to never ever allow recovering of the account without password, similar to how gandi does it. My email account / domain is my central hub for all my accounts. All of them can be taken over through fastmail (with the exception of my domain and other extremely crucial services) if an attacker happens to obtain access to it. I want to have the security that this attack can not happen to m…

I'm assuming you have 2FA turned on already. It sounds from what you're saying like you (and at least a few other hacker news posters) want is an even stricter "no seriously, I promise I won't ever screw up" mode. We try not to have those kinds of modes, because (for example): https://ianix.com/pub/dnssec-outages.html It turns out, black and white security models lead to massive losses of availability when people scr…

As a paying fastmail customer, I would appreciate such an option.

However, you do have to make sure that if I lose access to that account, I should be able to create a new FastMail account and have new traffic to my domain be directed to the new account. i.e. you do need some way to migrate a custom domain to a new account, if the new user can prove ownership and/or control of the domain name.

Re: The FastMail Security Mindset

#267
post #231

Earlier quoted context omitted.

Please consider adding a option to never ever allow recovering of the account without password, similar to how gandi does it. My email account / domain is my central hub for all my accounts. All of them can be taken over through fastmail (with the exception of my domain and other extremely crucial services) if an attacker happens to obtain access to it. I want to have the security that this attack can not happen to m…

I'm assuming you have 2FA turned on already. It sounds from what you're saying like you (and at least a few other hacker news posters) want is an even stricter "no seriously, I promise I won't ever screw up" mode. We try not to have those kinds of modes, because (for example): https://ianix.com/pub/dnssec-outages.html It turns out, black and white security models lead to massive losses of availability when people scr…

There is no demand for password only protection without recovery because it is not available on the mass market. Just like there was zero demand for cryptokitties a few months ago and now there is significant demand. You can only see a demand if there is and option for something and people use/don't use it or after conducting a poll.

Re: The FastMail Security Mindset

#268
post #201

Earlier quoted context omitted.

Unless you have a set of objectives that are very different from what I consider "as secure as e-mail gets", please consider GSuite and not Protonmail. (I don't speak for 'tptacek, but I'm pretty sure he'd agree.) As a corollary: if you really care, use Signal for stuff you can't say over e-mail. Whatsapp's fine too. But they solve a very different security problem than the one you need e-mail to solve, which is most…

Just gonna drive by mention https://landing.google.com/advancedprotection/ , which is a physical-2fa-security-key-only version of gmail. To my knowledge it also disallows mail forwarding, and the account recovery procedure in the event of losing both second factors is intended to be a long process that involves proof of identity and multiple attempts to notify the account owner. (I work on gmail, but I'm not intimate…

I know that GSuite would like to differentiate its enterprise products by features, but allowing basic/business plans to force U2F would be great. Since it's also available in GCP's Cloud Identity product (which is free), I hope this is coming down the road.

Re: The FastMail Security Mindset

#269
post #266

Earlier quoted context omitted.

I'm assuming you have 2FA turned on already. It sounds from what you're saying like you (and at least a few other hacker news posters) want is an even stricter "no seriously, I promise I won't ever screw up" mode. We try not to have those kinds of modes, because (for example): https://ianix.com/pub/dnssec-outages.html It turns out, black and white security models lead to massive losses of availability when people scr…

As a paying fastmail customer, I would appreciate such an option. However, you do have to make sure that if I lose access to that account, I should be able to create a new FastMail account and have new traffic to my domain be directed to the new account. i.e. you do need some way to migrate a custom domain to a new account, if the new user can prove ownership and/or control of the domain name.

Yes, that has to be an option anyway, if somebody sells a domain and doesn't release it from FastMail. I have a blog post for this advent series (already written and everything) about why we don't allow split billing on a single domain.

Re: The FastMail Security Mindset

#270
post #267

Earlier quoted context omitted.

I'm assuming you have 2FA turned on already. It sounds from what you're saying like you (and at least a few other hacker news posters) want is an even stricter "no seriously, I promise I won't ever screw up" mode. We try not to have those kinds of modes, because (for example): https://ianix.com/pub/dnssec-outages.html It turns out, black and white security models lead to massive losses of availability when people scr…

There is no demand for password only protection without recovery because it is not available on the mass market. Just like there was zero demand for cryptokitties a few months ago and now there is significant demand. You can only see a demand if there is and option for something and people use/don't use it or after conducting a poll.

I get your point...

though I'm not sure that cryptokitties are a great way to sell your idea here. They're the kind of tulip/fidget spinner craze that we'd invest a ton of effort into, sell a few for a while, have to support for the next 10 years and still face a noisy backlash from a few annoyed users when we finally retired it. Overall, net loss.

In the case of "no recovery allowed" accounts, the development effort is minimal, but the number of people who would turn it on "it says higher security and someone on hacker news told me to, it must be good" and then proceed to lose their account... I bet they'd be noisy when the realised they'd not only lost all their email, they'd lost their payment to us, because they'd have no authority to request a refund.

Oh wait, they would - chargebacks. Notoriously hard to fight with an online service, particularly when you're not providing said service any more. And it's always the full amount charged back too, not just the unused portion of the service.

I'll float the idea of allowing people to push right hard up to the "do not resuscitate" tattoo on their account, but I'm not going to pretend it doesn't come with some risks to us.

Post reply on HN