23 ms·
The FastMail Security Mindset
- gst 9y ago> Just as important as what we do do is what we don’t. For example, we don’t do full message encryption (e.g. PGP) in the browser. In theory it means you “don’t have to trust us”. However in reality, every time you open your email you would be trusting the code delivered to your browser. If the server were compromised, it could easily be made to return code that intercepted and sent back your password next time you logged in; it could even just do this for specific users. It is very unlikely that a user would notice. I don't agree. I don't want full message encryption because I'm afraid that my email provider is reading my messages, but because I'm storing years worth of emails in my mailbox. With a provider such as ProtonMail that encrypts incoming messages with my personal key I know that if someone manages to get unauthorized access to my mailbox that person would only be able to read new emails, but none of my already archived mails. Of course it's possible that the intruder also manages to change the JS code returned to the client, but that's not the case for all of the possible scenarios where someone gets access to my mailbox. Full message encryption does not provide perfect security, but is able to significantly raise the provided level of security.
- BCM43 9y agoFor most providers, like Protonmail, the decryption password is the same as your login password. I'm curious what scenario you see allowing someone other than the provider to get access to your mailbox but not also your decryption key.
- dboreham 9y agoThat could happen via a breach of the provider's servers, or through dumpster diving for a discarded drive that the provider didn't properly wipe (in the case the data wasn't also encrypted at rest).
- brongondwana 9y agoEmail at FastMail is encrypted at rest in this sense (full drive encryption). It's not encrypted with a separate password per-user. We don't see any security benefits there, given that every user logs in almost every day, and if they have linked a device (many of our users use IMAP from mobile clients) they will connect and sync every time there's an update. Which changes the vector to "hack server, passively monitor for a couple of hours, gain access". The logical backflips and single-minded security outlook required to consider that significantly different from "hack server, gain access" are the kind of security theater we studiously avoid. Full disk encryption is a clear win with no significant downsides (slightly higher CPU consumption). Per-user encryption while still providing a full email service is not a clear win, and it has significantly higher downsides.
- whyagaindavid 9y agoFor proton mail you could set different passwords for decryption and login
- gst 9y agoProtonMail doesn't have access to the decryption password as it is not transferred to the server. Instead the client sends a password that's derived from it: https://protonmail.com/blog/encrypted_email_authentication/ https://protonmail.com/blog/encrypted_email_authentication/
- carussell 9y agoThe "client" is a webpage that exists as one of many assets delivered to your browser by the ProtonMail webmail server. The server has access to the password at any time if it wants it.
- arghwhat 9y agoThe decryption password is not the same as the login password for ProtonMail. Logging in at minimum requires entering your username, your login password, and your mailbox password. The result is security at rest, which fastmail does not have. ProtonMail's web app is open-source, and can be deployed locally if you wish to remove the chance of an evil app deployment. If you use the official deployment, an evil update can obtain your mailbox password, in which case the the adversary (that is, the one capable of pushing the update) observe a security level equivalent to if security at rest was not implemented. However, even in this case, the data on the mail-servers is still protected from everyone else, so while a single adversary has observed a security level identical to that of fastmail (i.e. no security at rest), everyone else still observes a secured mailbox. Not having security at rest is, in my opinion, dangerous.
- terraforming 9y agoThat's wrong. You no longer need a third password in protonmail. All you need to have, in order to login, is the username and a password. If you've 2FA enabled, you need the 2FA code of-course.
- arghwhat 9y agoI think you mean second password rather than third, but as a user of ProtonMail, I need one username, two passwords and one 2FA token to get in, with only login username/password being kept in a password manager (and all password managers get confused by multiple passwords, so I couldn't keep them all even if I changed my mind and wanted to). ProtonMail may have the option (I am not aware of this) to have login password and mailbox password set the same (and not prompt you twice if this is the case), but they are still separate passwords. You, as user, control whether you want them to be the same or not. If you chose this, the application then has an option for convenience to use the same input for both tasks. This is opposed to a service where they are always the same, so that the password send to the backend is the same used to decrypt your data.
- brightball 9y agoThat's definitely not the default with Protonmail. They'll allow you to change it to that if you really want to though. On mine at least, proton prompts me for username and password, then 2 factor auth, then the decryption code.
- arosier 9y agoOne password is now the default for new ProtonMail accounts. For accounts that were created before this authentication was released, you will remain on 2 password until you update it in your settings.
- danenania 9y agoIt would be fine if apps with in-browser crypto only made this sort of claim, but many/most of them are either stating or implying that users don't need to trust the service. This is a dangerous mismanagement of expectations, and it can be argued that the risk of creating a false sense of security far outweighs any of the benefits you mention.
- arghwhat 9y agoProtonMail's web client is open source, and can be deployed locally if you wish to avoid scenarios where an evil application is deployed. Their native apps are unfortunately not open source, though.
- tptacek 9y agoDeploying a browser Javascript application locally does not automatically protect you from serverside malicious Javascript; you have to know a lot more about how the application is structured to know whether it's even helpful.
- arghwhat 9y agoDeploying any application locally puts you entirely at mercy of whoever wrote it, and those that know how to abuse it. That holds true for any type of application. However, in this context, deploying this particular self-contained application locally protects against the hypothetical attack where a genuine application is later modified to turn malicious. It is relatively easy to look for and identify any execution of server-side content. To prove that an application is not intentionally malicious, you would have to inspect the source. To prove that an application cannot be malicious, directly or indirectly, intentionally a not, you will need full formal verification of the application. And that verification only holds if you have formal verification of what it runs on.
- tptacek 9y agoNo, it does not. You've missed my point. Deploying a browser JS application locally would help you if you could be sure that the application never loaded any additional Javascript from the server during execution. But browser JS applications can in fact do that, and so local deployment does not help as much as you think it does.
- _Codemonkeyism 9y agoYes you would probably need to play with headers.
- bluGill 9y agoYou can use PGP then. However using PGP well turns out to be hard. You can to have the client local (and built by a trusted source), not a web client. You have to ensure you didn't forget your private key. You have to understand how it works and what the limits are to ensure that you don't accidentally break something. For what fastmail is doing providing PGP is the wrong answer: there is no way they can provide it safely. In particular a government can force them to replace their web PGP with a hacked version. (and some hacks can be very subtle such that you are unlikely to notice in a code review - remember we have a government's resources created it) That isn't to say PGP is bad. PGP is better than what they offer when you use it correctly. However there are many ways to use PGP wrong which make it seem like your messages are secure, but they are in fact not. This is probably worse than not using PGP at all, at least if you know your messages are not secure you won't do anything that requires security.
- mike-cardwell 9y agoAll of my email is encrypted using PGP on the way in. I can read it on my laptop, desktop and phone because I use Evolution, Mutt and K-9 Mail, all three of which support PGP and all three of which I can use with my Yubikey. If you compromise my mailbox, you can't read any old or new email, and you can trigger as many password reset emails as you want, you wont be able to read them.
- news_to_me 9y agoWow what a coincidence — I switched from Gmail to Fastmail exactly 1 year ago today. I couldn't be happier. I mostly use native clients, but the Web client is a joy to use, and everything I've observed about Fastmail gives me confidence in their service. I never used the Gmail-exclusive features like labels, so switching was pretty easy. I highly recommend it to anyone considering it. Keep up the good work, guys.
- mycoborea 9y agoBeen using them for a few years now and they're great. Some things I like: - plays nice with mbsync - sane system: real folders, not labels - customer service with an IRL person - identities feature
- notheguyouthink 9y agoOut of curiosity, why do you consider folders to be sane, and labels not? To me I always found labels to be the exact same as a folder, but not bound to a single instance. Ie, it is everything a folder has, and more. What am I missing?
- danieldk 9y agoLabels are one of the very few things I miss when I switched from Google Apps to Fastmail, but labels sometimes do not work well with IMAP. Google Mail exposes labels as IMAP folders, but in an IMAP client, you will have identical messages in different folders. And since traditional IMAP clients are not really equipped to deal with them, label management gets annoying.
- mycoborea 9y agoI should have been more clear. Folders play way more nicely with IMAP clients as opposed to gmail labels, in my experience.
- 333c 9y agoI'm considering switching (in fact I just registered for the FastMail trial). I'm especially interested in the ability to use catchall addresses with a custom domain, which would allow me to give out an address like <hackernews@mydomain.tld>, and thus determine who shared my email address if I start receiving spam at that address. This is partly possible with Gmail, as you can use addresses like <myname+servicename@gmail.com>, but not all sites support emails with a + in them. What differences have you noticed in your year since switching? I'm especially interested in any downsides. My biggest worry about Gmail is the lack of privacy from Google.
- ta98789878 9y agoAny lawyers care to comment on this claim of theirs? It has been pointed out to us that since we have our servers in the US, we are under US jurisdiction. We do not believe this to be the case. https://blog.fastmail.com/2013/10/07/fastmails-servers-are-in-the-us-what-this-means-for-you/ https://blog.fastmail.com/2013/10/07/fastmails-servers-are-i... As a non-lawyer I would expect the US to be able to serve their host with a warrant to get whatever data the judge said they could have.
- brightball 9y agoI don't know if it will answer their specific claim, but you can read Protonmail's explanation for being based in Switzerland here if you're curious: https://protonmail.com/blog/switzerland/ https://protonmail.com/blog/switzerland/
- joering2 9y agoYou are correct but from lawyer perspective (IANAL btw) it is important they use the word "believe". As I was explained by a friend who is attorney, if you never had experience with certain law, like in this case perhaps never been subpoena for records by US, then you have a right to say you "believe" something is not the case. This is still not deceiving statement. But the moment you have been proven wrong by US Gov for example, your claim would have to be removed. on FastMail alone I did not like how slow it is. I was testing them and Protonmail at the same time and was very impress how simple it is to setup my multiple domains/users on Proton and how fast encryption/decryption works. And Protonmail "[...] is outside of US and EU jurisdiction, only a court order from the Cantonal Court of Geneva or the Swiss Federal Supreme Court can compel us to release the extremely limited user information we have.[...] [1] https://protonmail.com/security-details https://protonmail.com/security-details Full disclosure: I don't work for Proton; I'm just their happy mailer :) EDIT: Slow I mean their GUI comparing to Proton. It might be more the number of extensions I have to block or limit different shenanigans such as AdBlock etc.. but needless to say, Proton does not have that problem.
- eridius 9y agoWhat do you mean, how slow it is? I've been using FastMail for a few years now and it's always struck me as being very fast.
- darrmit 9y agoLove Fastmail - been a happy customer for several years now. Also look forward to the Advent blog posts every year.
- polpo 9y agoThis is an entry in FastMail's series of Advent Calendar blog posts that they do every year. I'm glad to see them continue the tradition this year, and it's valuable to get this level of insight into a company that I trust with my mail. If you're interested in seeing more, check this year's first Advent Calendar post which has links to their calendars from 2014, 2015, and 2016, which are all worth reading if you're a FastMail customer or just interested in how running a mail hosting company works: https://blog.fastmail.com/2017/12/01/fastmail-advent-2017/ https://blog.fastmail.com/2017/12/01/fastmail-advent-2017/
- mfgmfg 9y agoI use FastMail and love it, but I've noticed that if I use SMTP, it leaks my IP address in the email headers, whereas using the web client does not.
- amdavidson 9y agoThat's how RFC2822 defines the email headers. That's not a leak, that's just how email works. When you send from the web app it uses that client as the originator.
- justcreated 9y agoThis would be one of the cases the same text talks about "when users misunderstand the security characteristics". The journalist example can be used, but instead of checking an image sending a reply to the e-mail. I'm unsure how many journalists know that their replies using an e-mail client will send their ip address, neither if they can understand why there is a difference between the mail client and their web interface. I only know one organisation using fastmail services today, and I asked if they knew about this today, which of course they didn't. There surely are reasons to not break the RFC as gmail and others did, but the expectations from users need to be addressed somehow
- linuxready 9y agoI see the usual comment about Fastmail (comparison to Gmail, ProtonMail, web interface, spam filtering performance, servers in the US, ...) but still nothing about the TOS, which seems more important to me So here it is again: - Fastmail can immediately cancel your account for any reason: "The Service Provider may terminate your access to any part or all of the Service and any related service(s) at any time, with or without cause, with or without notice, effective immediately, for any reason whatsoever, with or without providing any refund of any payments." - Fastmail can disclose your info/data if it thinks it's in the interest of the company: "The Service Provider will not monitor, edit, or disclose any personal information about you [...] unless required or allowed by law, or where the Service Provider has a good faith belief that such action is necessary to: [...] (2) protect and defend the rights or property of the Service Provider; [...] (4) act to protect the interests of its members or others [...] By comparison, mailbox.org TOS are much better. Also mailbox.org offers GPG encryption, which Fastmail doesn't (AFAIK).
- JoshTriplett 9y ago> - Fastmail can immediately cancel your account for any reason: "The Service Provider may terminate your access to any part or all of the Service and any related service(s) at any time, with or without cause, with or without notice, effective immediately, for any reason whatsoever, with or without providing any refund of any payments." Other than the last clause about "without providing any refund", I would expect this from any service provider, and I'd certainly never want to run a service that didn't have this in its terms. I do agree that the disclosure terms are more permissive than they should be.
- gruez 9y ago>Other than the last clause about "without providing any refund", I would expect this from any service provider that's certainly not the case for office365, for example. https://www.microsoft.com/online/mosa/MOSA2014Agr(NA)(ENG)(Nov2014)(HTML).htm https://www.microsoft.com/online/mosa/MOSA2014Agr(NA)(ENG)(N... . same with gsuite. https://gsuite.google.com/intl/en_in/terms/2013/1/premier_terms.html https://gsuite.google.com/intl/en_in/terms/2013/1/premier_te... >and I'd certainly never want to run a service that didn't have this in its terms. that may make sense if it was for a free trial, or it was for a cat sharing app, but I certainly would not want my business to be dependent on a service that can be yanked away from me at any time.
- sanjeetsuhag 9y agoI only see FastMail and ProtonMail mentioned on Hacker News, never in real life. To those who made the switch away from free,conventional mail services like Gmail and Outlook, what was the appeal ? What's your case for making the switch ?
- samat 9y agoI did switch after just another chilling story about person losing his gmail account because of some machine learning security system false positive. There is essentially 0 user support from google in such cases. And paid custom domain in google suite costs exactly the same as fastmail. Plus email is fastmails primary business and I am their real customer. I loved their product and their support.
- SOLAR_FIELDS 9y agoI use ProtonMail for the simple reason that there is less of a chance they are selling my data and building up a user profile of me for advertisers to target.
- GlenTheMachine 9y agoI use FastMail for exactly that reason. And, secondarily, because I set up a GMail account for both of my kids when they were born, and I would occasionally email things to those accounts that I wanted them to have a record of. Nothing earth-shattering, just stuff I thought they might like to read when they were older. Then, one day without warning, Google shut my daughter's account down, for being under-age. I had no ability to retrieve all of those emails, and there was literally no one I could contact. Google has NO customer support, because you aren't the customer. So I decided I would be willing to pay $30 a year just to know that I could get an actual person on the phone.
- iUsedToCode 9y agoI had to send more than 500 emails / day. So i switched over to FastMail. It works well, and i like having unlimited aliases that i can kill at any moment. But there's no way of disabling deleting messages. I wanted to be extra sure i wouldn't loose any messages and what support said was basically "just don't delete them and you are all set". What is worse, they accept the default deleting of messages of some email clients. Gmail won't allow deleting from a POP email client, which is much saner in my view.
- ghouse 9y agoI was a very happy FastMail customer until a hacker asked them to reset my password. After _incorrectly_ answering a handful of questions asked by the FastMail support, the recovery email address was changed and a password reset link sent. From there, the hacker attempted password resets on other services. Initially, FastMail was dismissive that this was a simple "mix-up" and didn't disable access to the hacker for 7.5 hours after my report. To their credit, FastMail gave me a list of the email accessed and the message headers of the messages the hacker sent from my account (and then deleted -- unrecoverable). Until and unless FastMail addresses the human factor of security, their technical security mindset is of secondary importance.
- samat 9y agoDear Fastmal, I am a happy customer, but very concerned by this report. Would you mind to comment?
- deleted 9y ago[deleted]
- samat 9y agoI just forwarded this comment to their customer support. Let’s see what would be their comment.
- terraforming 9y agoPlease tag me when they answer. (does HN have tags/notifications?)
- Stratoscope 9y ago> does HN have tags/notifications? No, but if you visit your Threads page (link at the top of every page) you can see any replies to any of your comments. There's nothing special that marks a new reply, though. I have a habit of upvoting nearly every reply anyone makes to any comment of mine, as a way of thanking them for the comment. This also happens to help when I skim my Threads page, since it's easy to spot comments that still have the voting button(s).
- jwn 9y agoI don't know if any Fastmail employees read over this, but thanks for finally adding TOTP to the list of 2FA methods! I had been (uneasily) using SMS and wishing you guys would up your game, and I'm glad to see that you did.
- nikon 9y agoI've had to dump Fastmail. I was getting 10-15 very (sexually) explicit spam emails daily slipping through the filter daily even after 100's of training emails being identified. Queue weird looks at work if I left my mail client visible. Moving back to G Suite was painful. I had to manually do it after the G Suite 'Migration' tool missed 1000's of messages. But so happy to have decent search back!
- noncoml 9y agoIMHO, for the best strategy is to roll your own mail. It is pretty trivial.
- enraged_camel 9y agoThe simple reason I haven't switched email providers: all my online accounts, as well as many offline ones, are tied to my gmail account. Yes, I can set up forwarding, but that defeats the purpose of switching providers IMO (for me, the purpose would be to move away from Google completely). I don't want Google to read any of my emails period, so forwarding is not a sufficient solution.
- nvarsj 9y agoIsn't vendor lock in great? :) This is why I started using my own domain for emails a long time ago. Still have some stuff on my gmail, but I've mostly broken free.
- distances 9y agoI think the only way is to start switching gradually. If you don't want Google to read your email, keeping it as the main accounts isn't really going to help. If you do change, get a forwarding service or your own domain so that the same mistake doesn't happen again.
- werid 9y agoI did the switch a few years ago. I setup forwarding after importing all my emails from gmail, then i spent months changing email on services whenever i used them. eventually you finish and can stop the forwarding or close the gmail account completely.
- kelvinquee 9y agoTry IMAPsync? http://imapsync.lamiral.info http://imapsync.lamiral.info
- mike-cardwell 9y agoThey should do PGP on the way in, for people who want it. It's trivial to set up. All they need to do is let people paste in a public PGP key and encrypt all incoming email with that key. Here's how I've been doing it for the last 7 years: https://www.grepular.com/Automatically_Encrypting_all_Incoming_Email https://www.grepular.com/Automatically_Encrypting_all_Incomi...
- dewey 9y agoIf it would be "trivial to set up" don't you think they would've already done it and offer it as an option?
- mike-cardwell 9y agoWell, it is "trivial to set up" as per my link, and they don't offer it as an option, so apparently not. Perhaps they don't think enough people use PGP to make this a worthwhile option to add. But given the service they are offering, it seems like an obvious feature and quick win to me.
- dewey 9y ago"trivial to set up" on your own mail server with you as the only user is slightly easier than rolling it out to thousands of customers, testing it, make sure backups are all working, write documentation for users, collect public keys of users, ... You can't just add a single line with your perl script to production and hope it works for everyone...
- mike-cardwell 9y agoIf you are already providing complicated features to N customers, then adding one simple feature for those N customers is trivial. If that isn't true, then all features are non-trivial to add and you've built your systems and processes badly.
- ryandrake 9y agoFastMail is tempting. I'm currently moving over to hosting my own E-mail, since Gmail is failing to deliver a significant number of important inbound E-mails to my account, rejecting them as spam (and fails to deliver almost all of my wife's E-mail). I could be convinced to pay for E-mail, but I'm concerned with customer support and the "black box" nature of online services. For something as important as E-mail, I grudgingly feel I finally need to bite the bullet and do it myself.
- rasengan0 9y agoAnother data point: I have had a FastMail account before Gmail before Opera and Kaggle. Why pay for email? when everything was free ...Yahoo, hotmail, etc. Word of mouth. Reputation. Though times were less sophisticated back then along with security; Fastmail kept up. I used my YubiKey with them way before gmail u2f fido support and they fostered my trust over the years keeping it clean and simple. Nothing is foolproof but at least I know their track record and commitments to their users despite dropping the ball in some cases. That said, I'm glad to read about the horror stories, provider alternatives and fastmail responses; hopefully we are all the better for it.