5 ms·
Tell HN: Fastmail is leaking internal routing email address/username with teams
Using throwaway...
Fastmail is leaking the distribution mail address/username via the X-Resolved-to header.
Now, normally this wouldn't be such a big problem, but when someone (needs to) forward(s) the original email as attachment, the internal email addresses are revealed, which is many cases is your Fastmail username. In my opinion this is a security / data leak. Fastmail's "fix" is to manually remove the X-Resolved-to form the email source. Of course this is ludicrous because:
1) People in your team would never do that, and non-technical people wouldn't even know how to.
2) It's easy to forget.
3) It changes the email, so any signature will not be valid anymore, marking it as corrupted.
I asked to escalate the issue when support couldn't reproduce (not sure why not, as my screenshots were clear, and their KB article explains that these headers exist). Even though it has been "escalated" to the "Support Lead - customer/technical" the "solution" still is to remove the header manually.
The header is of no use for Fastmail's customers, and is probably only used to Fastmail's internal routing for the team-mailbox-feature. It actually makes me second guess if JMAP is even properly designed. I'm very disappointed by the way this has been handled, as I clearly described why this is an issue.
Over the course of two weeks:
Reply 1:
> The X-Resolved-To header is only added to incoming emails to Fastmail, hence only you will be able to see this header. It is not applied to outgoing emails, that is the X-Resolved-To header is not passed along when forwarding an email or replying to an email.
> However, I have shared your suggestion with our development team as a feature request. Please note that we're unable to offer any timeline as to if or when this feature could be implemented.
Reply 2:
> I'm afraid I was unable to reproduce the issue you are seeing. When forwarding an email as an attachment and later checking the headers of the attached email, I could not find the X-resolved-to header nor was my Fastmail username mentioned in the headers.
> Therefore, could you please share a screenshot of the issue?
> On the other hand, I understand that your Fastmail username will be exposed when sharing a screenshot of the email headers. Therefore, I recommend refraining from doing so. If needed, you could copy-paste the headers to a Word doc, remove the X-resolved-to header and then share the screenshot.
Reply 3:
> I’ve escalated your ticket to a Tier 2 agent, as they are best suited to assist with this issue. Please note that if you have a complex issue, or if they’re handling a large number of tickets, response time may be longer.
Reply 4:
> I’ve escalated your ticket to a Tier 3 agent, as they are best suited to assist with this issue. Please note that if you have a complex issue, or if they’re handling a large number of tickets, response time may be longer.
Reply 5:
> Unfortunately there is currently no way to remove the X-Resolved-to header if you forwarding the raw form of the email. You will need to manually remove the header, by downloading the email, opening it in a text editor and then attaching the email again. Note that, the email authentication is checked against the email and not the attached ones, so that shouldn't fail the sending email authentication. However, if you are doing any checksum against the original email content, then yes that would fail because of change in headers. I am sorry, but there is currently no work around to this
- nickphx 3y agoIf I understand this correctly.. someone that you communicate with via e-mail may potentially see your username for the email provider you're sending mail from? Why is that an issue?
- aendruk 3y agoI may send mail as a pseudonym but log in to Fastmail using my full name.
- dewey 3y agoThat sounds like a process where it's very easy to slip up and if that's something to be concerned about in your threat model maybe you should not be doing that in the first place.
- layer8 3y agoThey can now phish you using your Fastmail username.
- throwawayfm 3y agoIf "support@yourdomain.com" internally is sent to timcook@apple.com, people will know. If it's sent to nickphx+support@fastmail.com, your personal email address, name, and login are leaked.
- slau 3y agoYour username is not a secure part of the authentication process. In most companies, people’s username is easily guessable, or even public information. I feel you’re making a very massive issue out of something that is… not? Yes, sharing the full headers of your emails will reveal some information, potentially even personally identifiable information.
- k_roy 3y agoI think you are missing the point by a mile. Their whole spiel is about "privacy first". https://www.fastmail.com/privacy-first-company https://www.fastmail.com/privacy-first-company I don't even use my @fastmail.com address. I have like 6 domains that I use for various things, and a single domain for one-time/throwaway/order emails via 1Password integration. I just verified every time I send an email, my main @fastmail account is attached in every email. I don't care about people knowing my email, but security isn't the point or even the concern. If I'm using an alias, I don't want account A associated to account B, especially for a service I'm paying for to keep my email out of the hands of Google.