11 ms·
It's true that every service has to deal with the same policy and lockout problems, but that doesn't lead to the conclusion that the risk is the same. I pay for
by guptaneil 4y ago
It's true that every service has to deal with the same policy and lockout problems, but that doesn't lead to the conclusion that the risk is the same. I pay for FastMail because
1. if something goes wrong, I can reach a human without needing to write a viral blog post first. Other services pay for a customer service department.
2. I trust FastMail more to not shut down their product because they got bored. Sure Gmail will probably not go away, but I'm honestly not as confident about Google Workspaces or whatever it's called now for individuals.
3. I'm tired of acting like using products from an ad company is a good idea. People happily use an email service, browser, OS, and more from the modern DoubleClick without a second thought.
- jeffbee 4y ago"I can reach a human" is a huge security vuln. I don't want people social engineering my identity provider.
- theptip 4y agoAn extremely underrated (and insightful) point to consider. More generally, how do you actually get a measure of risk between two providers, when the absolute frequencies of measurable events are very low? It seems plausible to me that FastMail could have 10x or 100x the level of security incidents as GMail, and it would still net out to an undetectable difference in the number of public complaints. If we had internal data… but of course we don’t.
- jeffbee 4y agoWhen I worked in the anti-abuse business, account security was tracked by lurking in organized crime fora and determining the market price for stolen accounts. I don't know what it looks like for FastMail, but I do recall that the range between good and bad platforms was huge. A stolen Google account was like $10, but stolen Yahoo! Mail accounts were more like a nickel per thousand.
- drivebycomment 4y agoYou can search for "bulk account purchase" and there are various "sellers" where you can compare the price quickly.
- Juliate 4y agoYou do want that. But with proper (actual) procedures in place. The opposite of that is, you do not have a way of recourse, ever. Even states have some.
- jeffbee 4y agoIt is a fantasy that you can have humans adhere to procedures. That's the whole underlying problem of social engineering. Just take the human out of the loop.
- mindcrime 4y ago> Just take the human out of the loop. "I don't know if you wanna entrust the safety of our email to some silicon diode." All joking aside: I mean... we already know that taking the humans out of the loop leads to undesirable consequences (like losing your Google account with no recourse). So the only question is whether or not the consequences of one scenario or the other is particularly worse.
- nix23 4y ago> Just take the human out of the loop. This i going to be funny if you get locked out of your bank-account or you have to lock-down your credit-card...computer says no.
- ClumsyPilot 4y ago> Just take the human out of the loop. Should we do the same for accusations of crime, get rid of judge and jury, consult a decision tree on whether you get the electric chair
- Juliate 4y agoSee, that's the fundamental hubris/weakness of the "Silicon Valley current ethos" (well, most tech ethos today) taken to the extreme: taking the human out of the loop. Then who/what does it actually serve? (or maybe, they perfectly know it, but don't saying out too loud)
- nirvdrum 4y agoI'll take the limited risk. I've had to contact Fastmail support and it was a breath of fresh air. It's a bit absurd that something so fundamental as email has essentially no support from a company as large as Google; it's not a bug-free product. I suppose eliminating humans is a security win, but HN is full of stories of AI systems failing and banning accounts for essentially nothing. Not having a human to appeal to is far riskier to me. It's not like these AI systems can't be gamed to knock people offline. I'll take the risk of having humans involved -- it's far less stressful.
- celdon25 4y agoMy main email account was through Hotmail in 2000, and it got shut down that year due to a social engineering attack. The guy who did it even told me he was going to do it first. I didn’t get to have it covered in any mainstream news headlines either :P
- remus 4y ago> It's a bit absurd that something so fundamental as email has essentially no support from a company as large as Google; it's not a bug-free product. I'd be willing to bet that gmail has a couple of orders of magnitude more users than fastmail while also providing a substantially bigger inbox (than the cheapest fastmail option), and providing the whole thing for free. I dont think it's surprising that they make trade-offs to support that model. Just think of how many support staff you'd need to support 1.5 billion users! > HN is full of stories of AI systems failing and banning accounts for essentially nothing. Not having a human to appeal to is far riskier to me. It's not like these AI systems can't be gamed to knock people offline. I'll take the risk of having humans involved -- it's far less stressful. I don't think the trade off is that simple. There are plenty of stories of support staff getting scammed in to incorrectly providing access to accounts. Is one better than the other? It's not a clear choice imo.
- 988747 4y ago>> I dont think it's surprising that they make trade-offs to support that model. Just think of how many support staff you'd need to support 1.5 billion users! Google has a shitload of money, they can afford hiring enough staff. Cost is a lame excuse here.
- ocdtrekkie 4y agoOn the contrary, I would argue this is the exact mindset that makes Google so bad at securing their systems. Every single large Google platform is also the leading distributor of its kind of malware, ultimately because computers are stupid and once you understand what they are programmed to handle you can work around them. Humans can become suspicious and can be held accountable, computers do what they're told and nobody is taken to task when something goes wrong. I would contend that if you cannot reach a person, you cannot trust a system. And that has generally held in the entire history I've been on the Internet. I chose my web hosting by who had phone support, I've had the CEO of Fastmail respond to my support tickets before. I have yet to be betrayed or compromised by a single platform where humans were involved, but automated systems have failed me regularly. This is true of offline systems as well. If you want a security system to protect your business, you may have keypads and sensors and things, but you also have a monitoring center staffed by people who can see events in real time. I think our industry has had a fantasy that complex enough math problems can provide real security, but I would hope by now the cryptocurrency market would've put that silliness to bed by now.
- GeekyBear 4y ago> I can reach a human" is a huge security vuln Google's algorithms make entirely too many errors. "I can't get my account back unless a viral account of my problem makes the front page of HN" is an unacceptable risk.
- remus 4y agoI'm not sure how you can make that judgement without extra context (that is almost certainly tightly held within google). For example, what actually is the error rate? How does that compare to improper access that is successfully prevented? Obviously any real person losing access to their account is a rubbish experience for that person, but an error rate of 0% is not possible with any system (including those with plenty of humans involved) when there are billions of users involved. I think a much more interesting question is "what's the acceptable error rate?"
- cycomanic 4y agoI highly doubt that Google even tracks the error rate. I mean that you somehow need to make a viral post on HN to get your account back is evidence of that, they don't even know they made a mistake. Also based on the number of posts that we see here it's a nonneglible error rate. How many users does HN have a couple of 10thousand. So 32 posts makes it maybe 1 in a 1000, even if it is a 1 in 10000 or even 1 in 100000 error rate that's a pretty high probability to loose your online identity.
- jeffbee 4y ago> I highly doubt that Google even tracks the error rate. Please. Google has an entire team devoted to account abuse quality research. https://storage.googleapis.com/pub-tools-public-publication-data/pdf/ab2bedf04f6d4ff60c59b502809c2f151373de54.pdf https://storage.googleapis.com/pub-tools-public-publication-...
- cycomanic 4y agoSo if there is no way of contacting a human if you have been locked out of your account, how do they determine a false lock out? I am serious, every thread here on HN about being locked out said that the affected person tried all other avenues and did not get anywhere near a real human. So that would make all research flawed wouldn't it? Because it simply checks that the algorithm is consistent. Let's not assume malice. However, that doesn't make it much better because it means the account abuse quality research team is borderline incompetent.
- godshatter 4y agoI'm not sure that "better scream loudly on social media" is any better of a solution.
- NovemberWhiskey 4y ago>I don't want people social engineering my identity provider. How do you balance that risk vs the risk of losing control of your identity altogether due to a technology control malfunction etc. though?
- jefftk 4y agoThis isn't just a hypothetical: a few years ago Fastmail support was socially engineered into giving access to a HN user's account: https://news.ycombinator.com/item?id=15855081 https://news.ycombinator.com/item?id=15855081
- nmjenkins 4y ago(Architect of Fastmail's login/account recovery protocols here.) Firstly, I will say this incident was unacceptable, and we were deeply sorry about it. However, it is also the only time it has happened in our over 20 year history (to the best of our knowledge of course). We already had several projects underway to improve the security of account recovery at the time, which unfortunately hadn't quite landed yet. Since then we have introduced an automated recovery tool with a very carefully designed flow (more info: https://www.fastmail.com/blog/security-account-recovery/ https://www.fastmail.com/blog/security-account-recovery/) that securely handles most common cases (e.g., forgotten password, or user's account stolen due to password reuse/phishing). Human support is still available, but any account recovery request can only be handled by senior support agents who have undergone rigorous training, and in the case of any doubt are escalated all the way up to our senior security engineers. Elsewhere it's been mentioned that different people may have different priorities in balancing ensuring they don't lock themselves out, versus ensuring an attacker can never access their account. We provide some flexibility here. If a user has 2FA enabled, we must verify two separate means of verification to grant access, whether via our automated tool or support-assisted recovery. Users can also submit a support ticket to request we add a note to their account to never do human-assisted recovery. I realise it's very hard to assess the security competence of an organisation from the outside, and for what it's worth, we think the Google security team also do an excellent job. But overall I think we do a very good job of keeping users secure while not locking them out of their own account.
- jjav 4y ago> Elsewhere it's been mentioned that different people may have different priorities in balancing ensuring they don't lock themselves out, versus ensuring an attacker can never access their account Thank you, this is the most important observation. Service providers should be providing flexible mechanisms to meet different needs, they should absolutely not be imposing a one-size-fits-all policy. That's the fundamental wrongness with google/facebook and their ilk. Only I know what the security levels I need for any given account I own. I must be able to configure the policy. Sometimes, I value my access above all else. With some other account I may value preventing access to others even at the risk of losing access myself. Other variants are possible. Only I know what the correct policy is in any given case.
- LeifCarrotson 4y agoA critical question is what threat models you're worried about: Are you worried about an individual interested specifically in you, Jeff B, to get something worth many thousands of dollars that they know you have? Don't put a human in the loop, they're going to track you across Facebook/LinkedIn/local government resources, they're going to know more about your car registrations and when you bought your home than you know about yourself, and they're going to be able to very convincingly social engineer a human in the loop if one exists. Or are you worried about a group of hackers continuously crawling the web for a database dump from some service you and ten thousand other people signed up for, or some flaw in the authentication sequence to automatically sign everyone in the database and all their contacts a spam network for pennies per person? Their scheme falls apart if they have to call a human, because it's just not worth the time to look up your public records and talk to a human about you. Second, what happens after you get hacked? Are you more concerned whether you no longer have access to something very important to you? For example, if you've distributed business cards or have contacts stretching back decades with jeffb@gmail.com, losing that account might mean an old friend or business contact fails to find you again. Having a human in the loop for the last-resort password reset can prevent completely losing access. Or are you more worried about someone getting access to the data behind your login? You've presumably got backups, so you'd rather no one ever had access again than some malicious third party got the password to your crypto wallet, SSH keys to your website, or other private data. Those have very different ideal responses. Unfortunately, most people tie both categories together in their single Google account, or in an Amazon account tied to both shopping and AWS resources.
- xdennis 4y ago"For Security!" has become a universal cudgel: * For your own security (from theft) we'll hardware lock your phone. Best to throw it in the dumpster if you forget the password. * Can't allow people to repair their own hardware. What if kids try to do it and end up burning the whole apartment block. Best to forbid it for security. * You can't film public institution: it's a security issue. * And now: can't allow humans to operate business decisions. What if they're socially engineered? Best leave everything to automation and fuck you if you slip through the cracks. It's funny because in the airplane industry, even though planes basically fly themselves, companies still want pilots, because that's what people are best at: solving unique problems as opposed to repetitive issues.
- dylan604 4y ago2) Why in the world would Gmail get shut down? The veins of treasure to be mined from within the user's emails are vast and endless. It is quite simply a mother lode. The only bigger source within their direct control is the search input screen.
- mattnewton 4y agoI think they are talking about some change to workspace effectively breaking the service for them. This has some precedent (with the old “dasher” personal accounts having growing pains for some people migrating IIRC) but also seems like a very low risk.
- jxf 4y agoWhat are the "dasher personal accounts"? I haven't heard of that before and search results seem to think I'm asking about DoorDash.
- mattnewton 4y agoThat was the internal name for personal paid gmail - I honestly cannot remember the nondescript word combination they called it publicly, but it was rolled into Gsuite which is now google workspace and google decided they wanted to focus on business users instead. I think this is a relevant article: https://arstechnica.com/gadgets/2022/01/google-relents-legacy-g-suite-users-will-be-able-to-migrate-to-free-accounts/amp/ https://arstechnica.com/gadgets/2022/01/google-relents-legac... Anyways, basically agree that gmail isn’t going anywhere, just a gmail-related story of people depending on a new flavor of gmail/ google identity that was being migrated messily.
- buggeryorkshire 4y agoGAFYD (Google Apps For Your Domain) I used this for 10 years or so before realising they'd moved the backends as they were planning the workspace thing and they were separate - you couldn't share between the two, loads of features missing etc . Typical Google - all the ideas, no execution.
- gary_0 4y agoAny company with a business model that takes your money and gives you service is inherently more secure than one that sells your eyeballs to advertisers in exchange for giving you free stuff. The former companies have a direct incentive to keep giving you service as part of their core business. The latter are really only paying attention to the money they get from advertisers.
- 411111111111111 4y agoThis comment is so ironic considering that Apple has just lost their lawsuit in the EU for doing exactly the same. Wherever you paid for the product seems to have little impact, the reality is that all tech giants carelessly invade your privacy with no recourse for the user.
- the_snooze 4y ago>Any company with a business model that takes your money and gives you service is inherently more secure than one that sells your eyeballs to advertisers in exchange for giving you free stuff. If anything, companies try to double-dip and serve multiple masters. See: the security and privacy mess in smart TVs. Last I checked, LG wasn't giving their TVs away.
- efsavage 4y ago> If anything, companies try to double-dip and serve multiple masters. See: the security and privacy mess in smart TVs. Last I checked, LG wasn't giving their TVs away. This is true, and you transition from customer to eyeballs once you take delivery of the product, but it is also tempered by the fact that they would like to sell you your next TV as well.
- c22 4y agoGoogle has the same incentive to consider users. If your eyeballs go away they have no recourse for tomorrow. This is no doubt why they give their services away. If they thought they could achieve similar market share while also charging you they certainly would. (And they do whenever they see the chance.)
- waynesonfire 4y agoThe only time I've been locked out of e-mail is when my credit card company incorrectly labeled the payment to the provided as fraud and the so called company that you can call and reach a human to discuss issues with, was not very sympathetic to my case and I didn't have e-mail access for 4-5 days until the issue was resolved. Just an interesting data point. It wasn't my intention to label the payment that way. It is what it is, but, just as OP seems to be believe, I would expected the issue to be resolved faster. Though, perhaps if I were to receive a "fraud" label on a non-paid account maybe I would be blocked to this day.
- balboah 4y agoUsed fastmail (and proton) for a year or two. Had to go back to google because there’s just too much spam otherwise
- lolinder 4y agoI've been on Fastmail for several years and I've had no spam in my inbox at all. Not a single email. That's a better track record than Gmail for me.
- chrisweekly 4y agoSame experience here. Fastmail is amazing.
- slantyyz 4y agoI've been on Fastmail for almost a year, and I get spam/obvious phishing attempts in my inbox. Compared to my experience with GMail before switching to Fastmail, I found Gmail to be noticeably better at spotting and filtering both spam and phishing emails. Having said that, I'm still not going back to Gmail.
- jp191919 4y agoI haven't have any problems with spam on PM, but I also don't give out my email addresses willy-nilly. I have junk emails for that.
- fragmede 4y agoWhat I'm hearing is that PM's spam detection is so poor that you don't feel like you can freely share your PM email address, out of fear that you'll get spammed. That's not a very convincing pitch for their product.
- coffeeblack 4y agoI am using Protonmail for some years now. I have maybe one spam mail per week in my inbox, everything else is filtered correctly.
- howmayiannoyyou 4y agoLeft Gmail b/c for months it locked me out periodically for too many hits. Neither they nor I could ever identify the source of this. Moved to Fastmail. No issues since.
- samstave 4y agoI used to use gmail as primary and yahoo as spam. Now I use proton as primary and gmail as spam. gmail's quality right now is absolute garbage.
- mindslight 4y agoHumans executing security policy (inherently imperfectly) versus ML algorithms executing security policy (deliberately imperfectly) is not the main issue. The real problem is that the industry hasn't purposefully sat down and hammered out the full contours of user verification. Each company just starts off with simple passwords, bolts on a few other arbitrary mechanisms, and then forces that on their customers - residual probabilities and collateral damage be damned. Strong passwords, hardware security keys, shared secrets meant for offline storage, SMS challenge, other accounts, snail mail address verification, notarization (governmental identity), voiceprints, time delays, etc. Each one represents its own tradeoff of convenience versus reliability versus forgeability versus privacy. Users should be able to pick their own policies. For an email account where I've already provided my real world governmental identity, I'd most likely prefer snail mail address verification plus notarization (combined with notifications to the account and a waiting period). Whereas for another where I've deliberately avoided spilling my governmental identity, I should be able to express that a password plus hardware security key is the highest level of verification there will ever be. Furthermore, companies need to make their own rules for falling between everyday access to account recovery explicit, and allow users to express preferences there too. There should be no cases of the wind blowing from the east so we require account recovery today, forcing users to be policed on what IP addresses they're coming from, etc.
- malepoon2 4y ago4. I like separate services/accounts. So many stories of people being locked out of their account because of YouTube or something. I feel much better now that my Google account is only used for Android and YouTube.
- EVa5I7bHFq9mnYK 4y agoGood it's a paid product. I had an account with a free email provider openmailbox.org, which closed down. I lost my mail box and, together with it, a valuable domain I bought in 1995.
- amf12 4y ago> I pay for FastMail because - if something goes wrong, I can reach a human You can do that with GMail too, upgrade to the workspace account. I had some issues with it last week, and I was able to reach a human and get it resolved soon. This is regardless of Google. Reaching humans is impossible with "Outlook" free email accounts, but amazing with Microsoft 365.
- PascLeRasc 4y agoI can't find any information on what happens if you stop paying for a Fastmail account. 1Password for example freezes your account in read-only mode. It's documented that Fastmail will re-use addresses for free trials and when a user requests to cancel [1]. It isn't clear what would happen if for some reason your card expired, they stopped accepting it [2], or your bank messed up and blocked the transaction [3]. To me, this introduces a new way to lose your account that isn't there with a free email service like Gmail. [1] https://www.emaildiscussions.com/showthread.php?p=622760 https://www.emaildiscussions.com/showthread.php?p=622760 [2] https://news.ycombinator.com/item?id=29988359 https://news.ycombinator.com/item?id=29988359 [3] https://www.reddit.com/r/personalfinance/comments/d1okxu/chase_banks_bill_pay_stopped_paying_amount_due/ https://www.reddit.com/r/personalfinance/comments/d1okxu/cha...
- garciansmith 4y agoI had an issue with the credit card used to renew a Fastmail account. Fastmail sent me emails about the issue, but it took a couple days to fix everything on my end. Even after the renew date passed my email functioned as normal, so there seems to be, at least, a grace period. Not sure what would have happened if it went on for longer though.
- xeeeeeeeeeeenu 4y ago>Not sure what would have happened if it went on for longer though. When I missed the payment they sent me this: "You can still use your account for now. If the subscription is not renewed soon, sending and receiving email will be disabled. If the subscription is still not renewed after a few weeks, access will be disabled. Eventually, the entire account will be deleted, including all stored messages."
- ziml77 4y agoSpecific timelines would be nice to know, but otherwise this sounds reasonable. If you stop paying, you have a grace period to download all of the messages before they stop you from using their service as a read-only archive. Then you have another grace period to pay before they clear out your data so they're not wasting space holding onto your junk and to avoid maintaining any liabilities that come with having your data stored on their servers.
- deleted 4y ago[deleted]
- csomar 4y agoAnother one: I can link my domain. I backup my emails regularly. Getting locked out of fastmail is a temporary disruption for me.