8 ms·
Advocating for privacy in Australia
- mikejulietbravo 8y agoThis completely erodes the point of end-to-end encryption.
- askvictor 8y agoWhat does? Fastmail never offered end to end encryption
- Valmar 8y agoIf you really want your encryption, use GPG, and have the people you send to use it as well. It's one of the few ways to ensure privacy between two people who trust each other.
- stephenr 8y agoYou've got that backwards. End to End encryption defeats the purpose of the "server-side" component of any government request/demand to decrypt messages/data. Any server-side email platform that 'integrates' email encryption (that is, envelope encryption, not encrypted transports) is effectively not "end to end" because your computer is not the server, and thus it's decrypted before "the end".
- jammygit 8y agoFastmail should relocate to Canada. Just throwing suggestions out there.
- stephen_g 8y agoI didn't think Canada was doing much better than us (Australia) with these kind of crazy, over-reaching laws. You'd probably have to find somewhere in Europe.
- schappim 8y agoSwitzerland might be better as not part of five eyes.
- qwerty456127 8y agoSwitzerland probably is too expensive.
- pgeorgi 8y agoNot part of any "X eyes" arrangement, but at least some parties within Switzerland are strongly engaged in partnering with foreign secret services, apparently without any consequences by the Swiss state: https://en.wikipedia.org/wiki/Crypto_AG#Compromised_machines https://en.wikipedia.org/wiki/Crypto_AG#Compromised_machines
- brongondwana 8y agoDamn, I just lost $100. Thanks. We had a bet on how long it would take for somebody to say "just relocate your entire company and all your staff's lives to another jurisdiction".
- jen729w 8y ago...and obviously someone who doesn't live in Melbourne. -- John Noble Happy Fastmail customer of, I dunno, 5+ years? Melbourne, Australia :-)
- brongondwana 8y agoI dunno, I stepped out of the office at 5:45pm to head home and got drenched. 4 seasons in 1 day and all that.
- FuckOffNeemo 8y agoWe had three seasons today. And the rainfall of an entire season this afternoon. Neemo of Brisbane.
- rswail 8y agoAh Melbourne in the "between spring and summer"... the storms recently have been impressive. But next week we enter the Xmas slumber and hot weather...
- kortilla 8y agoMaybe jammygit is on the other side of that bet... :)
- brongondwana 8y agoHey, good point. That would be a neat scam... (Not the only one who suggested the same thing though)
- hnauz 8y agoIt's the best solution. Given how mindbogglingly expensive your product is, you could try your best at least.
- Jedi72 8y agoGood writeup. Since I can already see not everyone here actually read the article, here are some highlights. > Law enforcement has always been able to request information from us through the Telecommunications Act with a lawful warrant. Because we have the ability to decrypt all data, there is no need to make changes that circumvent encryption. ... While FastMail is not directly affected, we don’t support this legislation because it carries serious implications for the Australian tech industry. > Of course, should our users choose to end-to-end encrypt their mail via PGP, we have no way to access that content, even under the AABill. Our blog explains why we have never offered PGP ourselves, and describes third-party PGP tools you can use with FastMail if you wish to manage your own encryption. The second one in particular highlights to me the fact that whilst there are many downsides to the legislation, any serious culprits i.e. state actors or organised crime have many counter moves, severely limiting the upside - something all tech people knew anyway.
- brongondwana 8y agoThanks - that's pretty much exactly it. If someone needs end-to-end encryption, it's only safe from intermediate third parties if they aren't trusting software which is updated by those third parties. So we use effective methods to protect the privacy of our users while performing our civic duty of assisting law enforcement when bad actors use or abuse our platform, and we never pretend to use the bulk of our customers as human shields to protect bad actors trying to hide among them.
- dannyw 8y agoIt's weird that you take this stance. It almost feels like you're implying that ProtonMail is a bad actor, and end to end encryption is bad because 'civic duty'. That's like "but terrorism". I understand that you're not a privacy-first company, but still, your communications haven't been reassuring me. There is extensive documentation (e.g. Yahoo FISA) that ALL content not end-to-end-encrypted is ingested for bulk surveillance and decades-long (if not infinite) retention. The only solution is 100% end to end encryption, with NO mechanism for unauthorised access (including law enforcement). Like iMessage and Signal. Anything partial of that, while saying you are pro-privacy, is IMHO harmful to privacy.
- kijin 8y agoThe ability to use standard protocols (IMAP and SMTP) is much more important to me than end-to-end encryption. I won't even touch an email service that doesn't support IMAP with a 10-foot pole no matter how secure they claim it is. I know some people are developing self-hosted gateways that can speak IMAP on the local side and a more secure protocol on the public side, and I think it shows promise. But the whole setup still feels way too fragile compared to good old email. I've been using FastMail for 11 years now, and I've recommended it to several other people. I will continue to do so for the foreseeable future.
- stilley2 8y agoMy work email has disabled imap in the name of security. My understanding is it's easier to lock down email entirely than to get doctors not to email patient data around, so I kind of understand, but it's annoying to have to read my email either using the terrible outlook web all or by giving my employer a lot of permissions on my personal phone. For context I'm in the US, where HIPAA fines can be quite high (not that that's a bad thing).
- mtgx 8y agoSo the article's tl;dr is basically: "We're advocating for privacy, but we aren't going to try to offer you any. We never did, and we certainly won't now that this law passed. You're on your own." Is this supposed to be a PR-positive announcement from FastMail, because I can't quite tell?!
- intothemild 8y agoI got the exact same feeling from reading this. It almost feels like it’s written for the Aussie Police and not really for the users.
- brongondwana 8y agoWe never offered, and never claimed to offer, a safe haven for people who have broken the law in both Australia and their own country to hide from the police. We don't place ourselves above law enforcement. We don't have data trading agreements with anybody, and we don't sell or provide backdoor channels - we only provide data in response to lawful warrants. That's the right amount of privacy and the right tradeoff with usability for just about everyone. Certainly storing your emails super encrypted in a concrete bunker on an island somewhere is theoretically safer along one axis - I wrote a whole series about Confidentiality, Availability and Integrity just over 4 years ago on this very topic: https://fastmail.blog/2014/12/02/security-confidentiality-integrity-and-availability/ https://fastmail.blog/2014/12/02/security-confidentiality-in... And the specific one on confidentiality here: https://fastmail.blog/2014/12/15/security-confidentiality/ https://fastmail.blog/2014/12/15/security-confidentiality/ (excuse the line wrapping, we moved to a new blog platform a while back and some of the older posts didn't import perfectly, but I don't want to look suspicious by editing it today!)
- kortilla 8y ago>That's the right amount of privacy and the right tradeoff with usability for just about everyone. Just about everyone who agrees with Australian laws you mean?
- xyzzy123 8y agoFunny how wanting to keep your personal correspondence private is now being conflated with “above the law”. The concrete bunker thing is a ridiculous diversion. Why are you even bringing that up? I understand that privacy is a difficult problem especially when subject to legislation but bunkers have nothing to do with it. You will obviously provide user information to government on request, you and your staff maintain the ability to access user information at all times, and you have some procedures in place to try and make sure none of this is misused. That’s ok.
- randaouser 8y agoIm hoping to resolve this using a "searchable encryption" scheme leveraging homomorphic encryption and elliptic curve based el-gamal. This would allow law enforcement to search for key words on encrypted data sets. This prevents leakage for both parties. THe use case for emails is a tad clunky as the bag of words would require precomputing, however, it is privacy preserving for both parties. If you feel this is something interesting that you would like to contribute to please msg me. I have working code in javascript (so it may soon be a plugin) and the architecture is decentralized but requires a a single message interaction between the actor querying and the data source.
- mLuby 8y ago1. Once a user identifies messages containing the search term, what are they supposed to do then? The message should still be un-decryptable to them. 2. Can't a user search all common words against a message and then rearrange those found to roughly match the message length. There are only so many ways the words "noon begins the tomorrow revolution at" can be arranged and make sense.
- randaouser 8y ago1) Can you clarify which users? The government issuing the search query is unable to decrypt the messages. If they flag it, they can order a warrant against the individual to decrypt the message. 2) A random salt is used so only exact keywords will match (I have a fuzzy matching implementation using jaccard similarity and minhashing but that is an extension). To answer your question technically yes, but what you describe would require many interactions with the data source as the content producer must apply the encrypted queries against their encrypted data. Again, I am trying to provide a solution that is beyond just giving someone the ability to read your private messages without your consent. No doubt it will require work from sidechannel attacks so appreciate any feedback
- Jerry2 8y agoTheir "Actions we are taking" section is almost entirely composed of a political lobbying strategy. Given the outcome of the vote, 44 votes for and only 12 against, their plan doesn't exude much confidence. I would have expected plans to move data and key technologists out of Australia at the very least. The company I work for uses Fastmail but our CEO has already decided to switch mail providers sometime in 2019. I don't know what other service they'll choose.
- brongondwana 8y agoThe data hasn't ever been stored in Australia. All our data is currently stored in the USA and Netherlands. Of course the "people are planning to leave us because of the hamhanded way you introduced this legislation" is a major part of all our feedback to legislators. The AABill happened the way it did in Australia because our politics is particularly broken right now (seriously, we have a minority government which has change leaders twice and lost multiple members to scandals). We call it "wedge politics" and Labor were forced into supporting it because otherwise they'd look soft on terrorism going into the holiday period, and anything at all which happened would be blamed on them not supporting the bill.
- neotek 8y ago>anything at all which happened would be blamed on them not supporting the bill. Which is idiotic, since the LNP would blame Labor either way, as they do for every single other failure they (the LNP) are responsible for. I wish Labor had some fucking guts once in a while.
- throwaway12iii 8y agoLabor are happy to take this power, and blame the power grab on the others.
- neotek 8y agoLabor had a series of sensible amendments that would have diminished the opportunity for any government to abuse this silly legislation. I think trying to equate both parties is disingenuous and wilfully ignores a mountain of context.
- Gatsky 8y agoThe comments here are disappointing. The gulf between cryptopurists and software that people actually use remains wide.
- bad_user 8y agoEDIT: note that I'm probably wrong, see reply below by @brongondwana! --- One problem not being addressed is that via #AABill data access requests can now be submitting without warrants issued by a judge, so it removes the judicial oversight. Also this law says that all such requests need to be "reasonable", but it doesn't define what that means. For example is blanket surveillance reasonable? AFAIK this law doesn't say. And companies like FastMail cannot report abuse publicly, or the people responsible risk 10 years in jail. Couple this with the fact that Australia is part of the "Five Eyes", being the only country without a "Bill of Rights", it means that agencies like the NSA could use Australia for their dirty work. Please correct me if I'm wrong, I haven't read the actual bill, just random commentary on the net. I'm a FastMail customer, but reading this blog article is leaving me worried, because FastMail keeps mentioning "lawful warrants", but from what I've read warrants aren't needed anymore. It's pretty sad. I've seen many Australian software companies doing a good job, like FastMail here and their reputation is now tarnished due to incompetent politicians. The wave of populism and stupidity has been spreading.
- brongondwana 8y agoWe've never done blanket surveillance, and specifically mention "individual users" in the blog post. There's been a lot of FUD about warrants not being needed - I think the ZDNet article we linked covers that very well: "[a judge doesn't have to sign off on the specific method by which data is requested] However there must be an underlying warrant to access communications under the Telecommunications (Interception and Access) Act or the Surveillance Devices Act or state-level equivalents." So the request still requires a warrant that specifies which communications are to be intercepted, but not a warrant that specifies how the interception is to be performed. Sadly, random commentary on the net does tarnish reputations every bit as well as facts :(
- bad_user 8y agoThanks for the clarifications. You might want to update the article, to make it clear that warrants are still needed. Also keep up the good work and I hope #AABill doesn't hurt your business.
- 8y ago
- dbg31415 8y ago> FastMail won’t be making changes to our technology or policies in response to this bill. Law enforcement has always been able to request information from us through the Telecommunications Act with a lawful warrant. Because we have the ability to decrypt all data, there is no need to make changes that circumvent encryption. Isn't this, "No need to force us to install a backdoor, we've already got one!" Kind of disappointing. Nothing in this article seems to be promoting privacy, just ways they comply with the laws -- and have been for as long as they've been around. If you care about privacy, shouldn't you move your HQ out of Australia? You aren't allowed to even tell people you've been served warrants now, correct? Gag orders mean we have to trust the Australian Government... we can't trust service providers. Eww. * Honest Government Ad | Anti Encryption Law - YouTube || https://www.youtube.com/watch?v=eW-OMR-iWOE https://www.youtube.com/watch?v=eW-OMR-iWOE
- rndgermandude 8y agoIt's not a backdoor. It's a front door, and clearly marked and prominently documented as such.
- cyphar 8y ago> Isn't this, "No need to force us to install a backdoor, we've already got one!" Fundamentally there is no need for a backdoor for emails. The entire protocol results in plaintext being received on the server, and so there is no need to add a backdoor. Email isn't end-to-end encrypted -- you've always had to use PGP if you wanted that. Lavabit had the same problem when the US sent and NSL that asked for the TLS keys of his server to decrypt the email traffic that Snowden had sent.
- charliebrownau 8y agoAustralia is lost We went from the Lucky country pre 1998 Now to the MOST EXPENSIVE country in the west We are now an socialist Democracy heading to an socialist dictatorship by 2020-2025 If AU+UK+NZ doesn't even up in an civil war before 2025 id be very surprised AU Parties:- * Greens * Labor * Liberals are all Global LEFT socialists As is NZ and UK government
- jaimex2 8y agoSo are you guys going to change or put an asterix on the front pages "Get private, secure, ad-free email hosting for you or your business" claim? :)
- rswail 8y ago[disclaimer: happy fastmail user, 30+ year Aussie programmer] What I really really like about this blog entry and the Fastmail service in general is that it is practical and clear. Fastmail does not and has not ever offered data privacy from properly constituted legal requests. Within the service they offer of email (and calendaring and contacts), they protect their user data by having it encrypted at rest and in transit. Email protocols are not suited to E2E encryption because of the historical evolution of those protocols. So if you want E2E, there are appropriate solutions. In terms of people who want access to your data, there are two types, bad/illegal actors and those operating under the judicial system. Under the judicial system in place in Australia, as has been explained, warrants (and the equivalent for non-law enforcement security services) are still required for access to an identified person's information. Fastmail has always been clear that they would respond to a properly constitued legal request. In terms of lobbying, it is up to all Australian tech people to respond to this legislation and its ill-considered requirements. I've already written to Mark Dreyfus as Shadow Attorney General and also the senior ALP person on the PJCIS which is responsible for this legislation. I intend to engage further in the new year with all those relevant MPs, ministers and shadow ministers, with the primary goal of clarifying that the tradeoff between security and privacy is not a zero-sum game, that invading privacy in such a ham-fisted manner as defined in the legislation is more damaging to both our industry and our community than the stated objectives of our security services to avoid bad actors "going dark".