7 ms·
> all their servers are hosted in the US Not true, they have a lot of servers in Europe (Amsterdam). That doesn't make the issue less valid though, since I th
by catwell 8y ago
> all their servers are hosted in the US
Not true, they have a lot of servers in Europe (Amsterdam).
That doesn't make the issue less valid though, since I think they have a full copy of all the data on both sides of the ocean.
- simfoo 8y agoTheir primary servers are exclusively US-based (see https://twitter.com/FastMail/status/981284247284559872 https://twitter.com/FastMail/status/981284247284559872)
- brongondwana 8y agoWe are moving away from Amsterdam - so it will be full copies on both sides of the USA, and nothing in Amsterdam any more.
- dijit 8y agoThis makes me sad, but I'm sure there are reasons for this. Would it be possible to explain them (or link me to a document explaining them)?
- brongondwana 8y agoBasically the problem was datacentre network reliability, power reliability, and the pointlessness of having one EU datacentre which isn't reliable enough to run production out of. We'd still need to replicate to a second datacentre for multi-site safety. At that point, why bother? We'd have to run two EU datacentres to have data only in EU, and we'd still be under the same actual legal jurisdiction (Australia) either way, so it would be security theater rather than an actual change in risk. We haven't ever given data to US authorities directly, we point every single request from anyone to the Mutual Assistance Treaty with Australia, and that would be the same regardless of where servers are. In summary, having servers in the EU is 99% security theater, and the other 1% is pointless unless we had two datacenters who were as reliable as NYI have been for us. We haven't found such partners.
- danieldk 8y agoWe haven't ever given data to US authorities directly, we point every single request from anyone to the Mutual Assistance Treaty with Australia, and that would be the same regardless of where servers are. The EU is outside the jurisdiction of FISA courts, whereas New York is not. I am definitely not an expert or lawyer, but I would think this is not just security theater. I was always hoping that Fastmail offer hosting that is fully in the EU. To me being affected by the Australian, EU, and US jurisdictions is worse than just the Australian and EU jurisdictions. Of course, I would prefer EU-only. I am extremely happy with Fastmail. But if there was an EU e-mail provider with feature parity, I would probably switch. Not that I expect that that'll happen anytime soon (subdomain addressing and iPhone push notifications are killer features).
- brongondwana 8y agoFor sure if we had two separate EU datacentres and no US datacentre contained a copy of the emails that would be not security theater. While there's copies in both jurisdictions, having a copy be outside the US really is security theater though. The financials of running up two full EU-only datacentres don't make sense for us at the moment given the demographic distribution of our customers. And we haven't had any run-ins with the FISA courts in the nearly 20 years we've been operating. Of course the past isn't a 100% predictor of the future, but US authorities have always been happy (or at least willing) to accept that our data is under Australian jurisdiction.
- bluGill 8y agoBut fastmail and the admins are under Australia law. This makes all attempts to do anything an international incident. FISA cannot do anything directly, they need to contact Australia for help. FISA can order NYI to put in a wiretap - but why bother when we already know there are wiretaps in all the major peering points on the internet.
- ersiees 8y agoWhy isn’t it actually possible to just encrypt saved emails on server? So that government does not have access. Couldn’t one use a hash of the password as key for the data for the data and not save that hash to check password but another one. This way (practically), at least if the password is not eavesdropped and saved by the mail provider, it would be much harder to give away emails.
- ashelmire 8y agoWithout saving a hashed password, you can’t authenticate users. End to end encryption like what you really want requires the data to be decrypted by the recipient (using a key or password).
- geofft 8y agoBecause the service provider receives the unencrypted email and can choose to save a copy, encrypt it to a different key, etc. This was the scam Lavabit pulled, and the government called them on their bluff and asked for a copy of the key and Lavabit had no legal ability to refuse. If the threat model does not include a government with the ability to use legal process, it needs to be defined more precisely. In general the US government can use legal process in the US and just straight-up hack into things elsewhere (who's going to raise a diplomatic incident over it? Russia is literally poisoning people, nobody cares, and their military is less powerful than the US's). If your threat model is other governments or just unrelated attackers like advertisers, there are more straightforward approaches.
- SturgeonsLaw 8y agoCalling Lavabit a scam is a bit of a stretch. They, by all appearances, genuinely tried to offer email as secure as it could be, given the limitations of the protocol, and when pressured to give up the keys chose instead to inform their users and fold the business.
- geofft 8y agoThey made promises that they should have known were impossible to keep. In my books, that's a scam. Sure, they tried very hard to keep them, but that doesn't change the fact that they could not deliver on their promises and anyone could have told them that. Also, no, they did not inform their users. They handed over the key and waited for users to notice court documents. See my previous comment: https://news.ycombinator.com/item?id=13447340#13448609 https://news.ycombinator.com/item?id=13447340#13448609
- deleted 8y ago[deleted]
- etix 8y agoWhat a sad news. I was expecting more servers in EU in a near future and maybe an option to select the location of our primary DC (US or EU). I've been a happy customer since 2013 and for the first time since I joined I'll be considering other options.
- bookofjoe 8y agoAll their servers are belong to us. I know humor here is frowned upon, but I couldn't resist. Sorry.