Live data from Hacker News

Fastmail: Staff access to your data

fastmail.com

1–10 of 25 posts

Re: Fastmail: Staff access to your data

#2
Support asked me to authorize their access by replying "OK" to an email of them. I asked to know more about this and they said that only trained engineer will access my data, and that they would wait for me to reply OK to their email before to do so...

Re: Fastmail: Staff access to your data

#3
post #2

Support asked me to authorize their access by replying "OK" to an email of them. I asked to know more about this and they said that only trained engineer will access my data, and that they would wait for me to reply OK to their email before to do so...

So, the team is being pretty transparent and explicitly wait for your approval. So, I guess it’s a good point, right?

Re: Fastmail: Staff access to your data

#4
post #3
post #2

Support asked me to authorize their access by replying "OK" to an email of them. I asked to know more about this and they said that only trained engineer will access my data, and that they would wait for me to reply OK to their email before to do so...

So, the team is being pretty transparent and explicitly wait for your approval. So, I guess it’s a good point, right?

I think the point is that the permission management is manual, not systematical.

Re: Fastmail: Staff access to your data

#6
Fastmail has a fair Australian presence; my limited understanding is that Australian law forbids secure-by-design encryption pipelines - so someone in Fastmail can read your email.

Whether or not that person works in support is an interesting but somewhat minor detail. It would be advisable not to use an Australian provider for your data if that is important to you.

Re: Fastmail: Staff access to your data

#7
It's obvious that someone who has to process your stuff in plain, unencrypted form (e.g. for spam filtering) can also access it when debugging etc.

Apparently they have strict policies in place to first ask users for consent first whenever they need to, seems good to me (happy customer of pobox since 1997 / fastmail since 2013).

Re: Fastmail: Staff access to your data

#8
post #2

Support asked me to authorize their access by replying "OK" to an email of them. I asked to know more about this and they said that only trained engineer will access my data, and that they would wait for me to reply OK to their email before to do so...

I don't remember that happening to me back when I had an issue where the dates of all my emails got screwed up (that was kind of my fault, btw). Due to the nature of the problem (and probably most problems that require support), it was obvious they'd need access to help me, though.

Re: Fastmail: Staff access to your data

#9
post #6

Fastmail has a fair Australian presence; my limited understanding is that Australian law forbids secure-by-design encryption pipelines - so someone in Fastmail can read your email. Whether or not that person works in support is an interesting but somewhat minor detail. It would be advisable not to use an Australian provider for your data if that is important to you.

[deleted]

Re: Fastmail: Staff access to your data

#10
post #6

Fastmail has a fair Australian presence; my limited understanding is that Australian law forbids secure-by-design encryption pipelines - so someone in Fastmail can read your email. Whether or not that person works in support is an interesting but somewhat minor detail. It would be advisable not to use an Australian provider for your data if that is important to you.

> my limited understanding is that Australian law forbids secure-by-design encryption pipelines

This understanding is wrong. Secure encryption is perfectly legal, tech media simply likes to overreact to laws without actually reading them.

The underlying law that lead to this widespread misconception requires Australian companies to assist law enforcement in acquiring communications but only when it can be done in such a way that nobody else is affected [0].

The example I usually use to illustrate what this means is:

- The law could potentially compel WhatsApp to add code to their application that checks for a particular hard-coded user ID (i.e. new IDs have to be pushed through the app signing and update process) and when the user with that ID sends or receives a message, a plaintext copy is sent to law enforcement.

- The law could _not_ compel WhatsApp to add a law enforcement key to every message or to otherwise weaken their encryption or security in anyway.

[0]: http://classic.austlii.edu.au/au/legis/cth/consol_act/ta1997...

Post reply on HN