8 ms·
One thing to keep in mind about Fastmail is that all their servers are hosted in the US and they have no plan about changing this (I asked). Post-Snowden this m
by simfoo 8y ago
One thing to keep in mind about Fastmail is that all their servers are hosted in the US and they have no plan about changing this (I asked). Post-Snowden this means you can be quite sure that all mails will end up being analysed by the US authorities
- SSLy 8y agoYeah, but on the other hand it's also a feature of Gmail. So it's not strictly worse.
- simfoo 8y agoCorrect, but since the reason this question popped up is due to privacy concerns regarding Chromium, I think it's even more important for people to know about these things to make an informed choice. By the way, I really like Fastmail - they are very competent. But mail/calender is such an important part of online identity and life, I think people should be careful about who to trust
- mda 8y agoExcept that gmail is hosted on a much better and secure infrastructure with very good SREs.
- brongondwana 8y agoOur SREs are pretty good too!
- jsmeaton 8y agoI dont think this is true. I don’t believe there is any evidence that the US government is analysing all emails hosted by all US companies. Rather, if the US government asks for a particular individuals emails the provider must grant the request provided there is a valid (possibly secret) warrant.
- doubt_me 8y agoMeta data is more than enough. They don't even care about the contents.
- jsmeaton 8y agoThat wasn’t the claim made.
- danesparza 8y agoThere is evidence that they certainly have the capability of analyzing much (if not all) communications in the world: https://www.infoworld.com/article/2608141/internet-privacy/snowden--the-nsa-planted-backdoors-in-cisco-products.html https://www.infoworld.com/article/2608141/internet-privacy/s...
- fps_doug 8y agoPost Snowden I wouldn't safely assume that the govt/three letter agencies don't do something just because there is no evidence. Snowden was years ago, the NSA surely didn't sit on their hands in the meantime, especially now with SSL being deployed everywhere. "Oh right what we did was evil and wrong, let's stop everyone"
- jsmeaton 8y agoThe claim made was that they do. You don’t get to say that without providing evidence. You can say they might be, but that’s a different claim. Also, capabilities matter. I have no doubt if they could they would. The Snowden revelations mainly revealed partnerships between service providers and gov agencies. Simply existing in the US does not mean your data is automatically available to 3 letter agencies. It could, but there is no evidence to suggest that it is.
- daxorid 8y ago> You don’t get to say that without providing evidence Put a parakeet in a windowless room and close the door. I can reasonably make the statement that the parakeet is perching, looking around, and/or preening its feathers, because that's what parakeets do. I wouldn't need direct observational evidence to make this statement. Panopticon-level spying is what intelligence agencies do. It's what they've striven to do, as much as possible, without getting caught. The Binney and Snowden leaks corroborate this, and there's no reason to believe they've suddenly stopped trying to. OP doesn't need evidence to make the reasonable claim that intelligence agencies spy on us, and likely do it by hoovering up our data for analysis.
- catwell 8y ago> all their servers are hosted in the US Not true, they have a lot of servers in Europe (Amsterdam). That doesn't make the issue less valid though, since I think they have a full copy of all the data on both sides of the ocean.
- simfoo 8y agoTheir primary servers are exclusively US-based (see https://twitter.com/FastMail/status/981284247284559872 https://twitter.com/FastMail/status/981284247284559872)
- brongondwana 8y agoWe are moving away from Amsterdam - so it will be full copies on both sides of the USA, and nothing in Amsterdam any more.
- dijit 8y agoThis makes me sad, but I'm sure there are reasons for this. Would it be possible to explain them (or link me to a document explaining them)?
- brongondwana 8y agoBasically the problem was datacentre network reliability, power reliability, and the pointlessness of having one EU datacentre which isn't reliable enough to run production out of. We'd still need to replicate to a second datacentre for multi-site safety. At that point, why bother? We'd have to run two EU datacentres to have data only in EU, and we'd still be under the same actual legal jurisdiction (Australia) either way, so it would be security theater rather than an actual change in risk. We haven't ever given data to US authorities directly, we point every single request from anyone to the Mutual Assistance Treaty with Australia, and that would be the same regardless of where servers are. In summary, having servers in the EU is 99% security theater, and the other 1% is pointless unless we had two datacenters who were as reliable as NYI have been for us. We haven't found such partners.
- raffael-vogler 8y ago> mails will end up being analysed by the US authorities I read somewhere that servers located in the US are actually safer from drag net eavesdropping b/c a judicial order is required.
- mikejb 8y agoIIUC, no judicial order is required for collecting. Only for looking at collected data; but agencies get creative around these processes, so I wouldn't count on legal protection from snooping.
- lallysingh 8y agoBut there's nothing to circumvent if the host isn't in the USA.
- rovr138 8y agoThat’s assuming the wires aren’t tapped, it’s all encrypted and doesn’t pass through the US, they’re not cooperating regardless with the US. If the US puts enough pressure, they could still cave and comply.
- lallysingh 8y agoMy point was that in some cases, it's easier for the NSA to snoop when the target is outside of the USA.
- naravara 8y agoUnless you're sticking to countries that hang their hat on digital privacy, hosts outside the USA are also likely to be snooping with varying levels of competency. "Not USA" isn't a good enough filtering criterion.
- bonestamp2 8y agoMany countries have reciprocal agreements for sharing intelligence. Unless you go to a country that is known for its privacy values at the highest level then you're likely not going to maintain you privacy from the government of your country or most other powerful governments.
- JoeyTawadrous 8y agoI build a privacy-first minimalist Google Inbox, located at https://inboxzeroemail.com https://inboxzeroemail.com Sign in with your Gmail account & get the same functionality as Google Inbox. It's hosted on Linode and our servers are load balanced across the world. Please let me know if you have any questions :)
- bad_user 8y agoI'm an European, but I don't mind. First of all when making such a choice, you have to identify who the enemy is. If you're talking about global enemies, like the NSA, then IMO without end-to-end encryption you're screwed. And if you're targeted directly, you're screwed regardless, given they have the capability to use whatever vulnerabilities they can find in your router, your phone, your OS, your browser, etc. If it's connected to the Internet, especially if you're being targeted, you're screwed. Also many European countries have signed on joint cooperation agreements with US intelligence agencies. If for example you're using servers in the UK, it's in no way safer, see: https://en.wikipedia.org/wiki/Five_Eyes https://en.wikipedia.org/wiki/Five_Eyes So back to who is the enemy? For me it's not the NSA or our local intelligence agencies. If I'm being wronged, I've got legal ways to fight back and I don't really care about the NSA. What I care about is being _profiled_ by unscrupulous companies that may end up selling that data to other actors that may harm my well being. For example insurance companies could deny insurance if they discovered you smoked cigarettes 10 years ago. Or banks changing your credit score based on who your friends are. Or supermarket chains discovering that your daughter is pregnant before everybody else does. This shit is already happening! I think the general discourse doesn't go in the direction that it should go. Organizations like EFF have been historically anti-government, but very pro corporate and private companies. Which is why I don't trust them fully. Identify that enemy. If you're an European for example, that enemy is probably not the NSA. I do prefer non-US alternatives btw, whenever I get that choice. I do so out of a desire to encourage competition and to reward EU companies that do well, as a "voting with your wallet" thing. But choosing to reject non-US companies for the reason that some of their servers are located in the US, that's frankly childish. Servers located in the US are cost effective. Either provide better alternatives, or otherwise these services will not be able to compete on the global market from a price or latency perspective.
- ataturk 8y agoThe enemy? That is an easy answer: The enemy is the public/private parternship! It's not just the NSA, not just corporations. No, it is the seamless melding of the two which are wreaking havoc on our civilization. Freedom of speech is on the chopping block right now today. Even HN has shadow-banned and otherwise taken part in censoring me and only because I express unpopular opinions about government and business. I get 1 post a day on this account. Why? What are they so afraid of?
- ahje 8y agoWhile you're absolutely right, details that are sensitive in nature should be encrypted using end-to-end encryption. Otherwise you won't be safe regardless of email provider, as the other correspondents will often be using a US email provider anyway. If your threat model includes an actual threat from organizations like the NSA, then I'd say you have bigger problems than the choice of email provider. EDIT: I self host.
- brongondwana 8y agoInterestingly, as a self-hoster your email is much more prone to metadata analysis than anybody who is hosted at one of the big providers and has most of their email transferred to other big providers down TLS-protected port 25 streams.
- lsh 8y agoThis would be a privacy Vs anonymity tradeoff, right?
- bunderbunder 8y agoThey're not cleanly separable. You can tell a lot about a person by simply looking at what's written on the outsides of the envelopes in their mail. No need to actually open them up and read the insides.
- bonestamp2 8y agoAgreed. Anonymity and privacy come from lots of little actions, none of which provide much value on their own. For example, our return mail address labels don't have our names on them... and I use them on the back of the envelope to seal the envelope. Our trash and recycling is emptied into our bins loose, so all our trash is not isolated to its own bags, it mingles with the rest of the trash. Neither of these provide a lot of value on their own, but they're easy to do and provide a little value.
- ahje 8y ago
- deleted 8y ago[deleted]
- eslaught 8y agoHow is their security? Maybe people like to forget, but security breaches are a thing, and when they occur you get the privilege of opening up your data to the entire world, not just to the NSA. Google, for whatever else you want to say about them, have first-class security.