3 ms·
Would one of the apparently many happy FM subscribers share details of what kind of security they provide? (It bears repeating: No email can be very secure.)
by hackuser 10y ago
Would one of the apparently many happy FM subscribers share details of what kind of security they provide?
(It bears repeating: No email can be very secure.)
- fredcy 10y agohttps://www.fastmail.com/help/ourservice/security.html https://www.fastmail.com/help/ourservice/security.html - happy FM subscriber for 3 years
- Veratyr 10y agoAlso I didn't see it directly mentioned on that page, they're not subject to US law enforcement requests (unless they go through a Mutual Assistance treaty request) and there's nothing like an NSL in Australia: https://blog.fastmail.com/2013/10/07/fastmails-servers-are-in-the-us-what-this-means-for-you/ https://blog.fastmail.com/2013/10/07/fastmails-servers-are-i...
- nsajko 10y agoBut see: https://en.wikipedia.org/wiki/Five_Eyes https://en.wikipedia.org/wiki/Five_Eyes
- jsingleton 10y agoTrue, but probably still better than the US or UK: https://protonmail.com/blog/investigatory-powers-bill-email-privacy/ https://protonmail.com/blog/investigatory-powers-bill-email-... Their EU servers are in the Netherlands. Although I guess it's hard to know if any EU traffic goes to the US servers. Australia does have similar laws but it seems they don't apply in this case: https://blog.fastmail.com/2015/04/09/fastmail-is-not-required-to-implement-the-australian-metadata-retention-laws/ https://blog.fastmail.com/2015/04/09/fastmail-is-not-require...
- DashRattlesnake 10y agoThey support multiple kinds of 2FA tokens (Yubikey, U2F, Google Authenticator, and others). I was even able to disable the phone-based 2FA, which means my account can't be hijacked by someone who's stolen my mobile number [1]. That also means I could get locked out if I lose all my tokens, but I'm willing to take the risk since I have my own domain, which could be easily ported to a new account. [1] https://www.forbes.com/sites/laurashin/2016/12/20/hackers-have-stolen-millions-of-dollars-in-bitcoin-using-only-phone-numbers/#39f31f438bad https://www.forbes.com/sites/laurashin/2016/12/20/hackers-ha...
- aiy4noh2eX 10y agoThis (although good to hear - I would also be interested in a purely U2F 2FA setup for email) seems to only be concerned with security for the user's perspective. What about the security of the service itself from a more "backed" / overall perspective (those factors beyond the user's control)? As much as I dislike Gmail as a big brother it's hard to beat Google's security team.
- feld 10y agoFull disk encryption on their servers and they ignore non-Australian court orders