13 ms·
FastMail’s servers are in the US – what this means for you
- CurtMonash 13y agoThe persuasive part of this is disclosure. It's a promise to be open about any breaches, plus an observation that the US lacks the legal clout to stop the promise from being kept.
- rdl 13y agoThe personal location of the operators is probably the #1 most important security risk; location of customers, location of servers, and country of incorporation are also important. It's much easier to compel operators to do something (through legal threats or potentially physical threats) than it is to do any active modifications to a complex system, undetectably. Passive ubiquitous monitoring is a concern because it's passive and thus hard to detect -- it's highly unlikely TAO can go after a large number of well-defended systems without getting caught. Obviously they'd be likely to hide their actions behind HACKED BY CHINESEEEE or something, but even then, it's relatively rare to have a complete penetration of a large site in a way which isn't end-user affecting, and rarer still for the site not to publicize it. That said, if I wanted to compromise Fastmail, I'd either compromise a staffer or some of their administrative systems to impersonate staff.
- tweeeyjg 13y agoThis is a joke right? How much were they paid by the NSA to write this post?
- sschueller 13y agoThe US government will just take their server. They don't care if you go out of business. Look at what they did to megaupload.com.
- Confusion 13y agoThere's a difference between going after a company that is obviously facilitating copyright infringement and is mainly used for that purpose vs. going after a respectable service provider. The latter would raise hell in the international relations between countries.
- alextingle 13y agoThat's just a matter of perspective. Was Megaupload "obviously" facilitating copyright infringement any more than Google does?
- jmtulloss 13y agoThe point that they're trying to make, and which is true in the Megaupload case, is that they would know that this had happened and they would disclose the fact that it happened.
- brongondwana 13y agoThis is the same megaupload where FBI agents took part in a raid on a house in a non-US country? http://www.listener.co.nz/commentary/the-internaut/kim-dotcom-megaupload-new-zealand-timeline/ http://www.listener.co.nz/commentary/the-internaut/kim-dotco... As I said in a response on our forum, if the stakes are high enough, no datacentre in the world is safe. Bruce Schneier recommends protecting against terrorist attacks by improving emergency response capabilities - with the side benefit that your measures also help against natural disasters: https://www.schneier.com/essay-292.html https://www.schneier.com/essay-292.html (edit: that's not a great version of his point actually, https://www.schneier.com/blog/archives/2005/09/katrina_and_sec.html https://www.schneier.com/blog/archives/2005/09/katrina_and_s... is more on point) Similarly, our main focus for security is protecting against all forms of attackers, including common theft or misplacement of our servers. We consider that to be more valuable for the overall security of our users (including security against denial of service) than fighting an impossible fight. FACT: if the three letter agencies in the USA want your data desperately enough, they will get it. With FastMail, they have a legal way to obtain it which is quite a lot of effort, but (hopefully) less expensive to them than taking our servers offline. What they can't do, by Australian law, is require our cooperation in blanket surveillance on all our users.
- andrewfong 13y agoNote the obvious caveat though: "There are of course other avenues available to obtain your data. Our colocation providers could be compelled to give physical access to our servers. Network capturing devices could be installed. And in the worst case an attacker could simply force their way into the datacentre and physically remove our servers." As the colocation providers are based in the U.S., they would be subject to the National Security Letters. FastMail claims this is no different from any other hacking attempt. But in a normal hacking attempt, colocation providers would be free to explain to FastMail the extent of any hacking on their end. Moreover, hackers typically do not have physical access to any data. Even with encryption, physical access opens up a lot of attack vectors that most sysadmins don't anticipate.
- MichaelGG 13y agoIf they mount webcams and other sensors inside the cabinet, they could detect unexplained access to their servers. Not sure what it'd really accomplish. The colo provider would either say "tech mistakenly opened that cabinet" or "no comment". The only real defense is to assume any such access is a breach and have servers immediately overwrite FDE keys in RAM and power off - and if they were that committed, they wouldn't host in the US in the first place.
- jamesaguilar 13y agoFull disk encryption would be another option, with the key being obtained over a secure channel from servers hosted remotely before booting to the real system. Then, as long as they can detect whether the server asking for the key has been compromised, I think it should be pretty safe. (Not a security researcher though, I wouldn't bet money on it.)
- toast0 13y agoRemotely detecting if the server is not compromised when you don't trust the physical surroundings is probably unsolvable. If your attackers are very motivated and have lots of resources, what's to prevent them from installing a ram bus signal analyzer during a scheduled/unscheduled downtime. This would be pretty hard to detect (absent an elaborate video monitoring setup), as a good analyzer should not impact the system being monitored.
- MichaelGG 13y agoThe only real benefit I see here is that your IP won't be easily revealed. That is, given a fastmail account, the e.g. FBI cannot quickly get your login IP, like they can with e.g. Outlook or Gmail. So, for just low-level anti-surveillance, SSL to fastmail might suffice instead of using Tor with Gmail. Unless you're using PGP or S/MIME, SMTP is still most often unencrypted.
- rdl 13y agoI think the assumption is that FBI has to obey the law to produce evidence for prosecutions. NSA doesn't, particularly vs. "foreign".
- nullc 13y ago> There are of course other avenues available to obtain your data. Our colocation providers could be compelled to give physical access to our servers. Network capturing devices could be installed. And in the worst case an attacker could simply force their way into the datacentre and physically remove our servers. > These are not things we can protect against directly but again, we can make it extremely difficult for these things to occur by using strong encryption and careful systems monitoring. Were anything like this ever to happen we would be talking about it very publically. Such an action would not remain secret for long. > Ultimately though, our opinion is that these kinds of attacks are no different to any other hacking attempt. We can and will do everything in our power to make getting unauthorised access to your data as difficult and expensive as possible, but no online service provider can guarantee that it will never happen. This kind of frank disclosure should be highly rewarded. I provided similar frank disclosure text (elsewhere) only to have it whitewashed. When everyone is underplaying the real limitations it's impossible for people to choose alternative tradeoffs— "Why should I use this slightly harder to use crypto thing when foo is already secure?"— because the risks have been misrepresented. Underplaying the limitations also removes the incentives to invent better protection— "Doesn't foo already have perfect security?".
- danenania 13y ago"This kind of frank disclosure should be highly rewarded." Yep, definitely. I think even more important than the information itself is the spirit of honesty and integrity that it demonstrates. This stands in stark contrast to the ambiguous slimeball statements issued by the likes of Google, Facebook, Apple, Microsoft, etc. When Big Brother comes knocking, which companies are going to take a risk to stand up for you? It's as much a question of character as policy.
- annnnd 13y agoNote that G, FB, A and MS are not in a position where they can write such disclosure. I am not arguing with your main point, I applaud FastMail for taking a stand - it's just that USA companies must use "ambiguous slimeball statements" to at least appear clean (because they are not). I would argue that if FastMail were an USA company their statements (if any) would be just as ambiguous as those of G, FB, A and MS.
- traeblain 13y agoSo they are saying that they can never get a NSL to turn over information, but where are these servers? Who has the keys to the door of the server room? So maybe they don't get the NSL, but the people/group/company that is handling the servers might. This seems disingenuous. I could be wrong, but it feels like they are making claims that will dupe people into their service because they feel safe.
- frenger 13y ago> So maybe they don't get the NSL, but the people/group/company that is handling the servers might. This seems disingenuous. well they do say explicitly that, near the bottom. Hardly disingenuous.
- gelatocar 13y agoThey do in fact mention that in the article: > There are of course other avenues available to obtain your data. Our colocation providers could be compelled to give physical access to our servers. Network capturing devices could be installed. And in the worst case an attacker could simply force their way into the datacentre and physically remove our servers.
- phy6 13y agoIf I was going to set up a honeypot for evil-doers/dissidents, this is the message I would spread.
- robn_fastmail 13y agoIf I was an evil-doer/dissident I wouldn't be trusting my life to the collective wisdom of the internet ;)
- frank_boyd 13y ago> our primary servers are located in the US Why would you do that, especially when you're not even a US company?
- robn_fastmail 13y agoBecause most of our customers are in the US. If your goal is to provide the fastest service around, it helps to put your servers near your users.
- skrause 13y agoBut maybe most of your users are from the US because the servers are there? I'm from Europe and was a FastMail customer once, but I switched away because I didn't trust the US-based servers (and that was even before the NSA scandal).
- brongondwana 13y agoAlso because Australian bandwidth is hella-expensive, power isn't great either. Why New York rather than West Coast - that's a trickier one. I'd certainly appreciate the slightly faster pingtimes, but it would be slower for Europe. I think a major consideration is that we found a really good datacentre with NYI, and we're sticking with them because they're incredibly reliable. Reliability matters in this business.
- frank_boyd 13y agoYou're implying that you would make less money by trading in your US location for more security. That means that you believe not enough users care enough about their privacy to accept that (really light) trade-off.
- brongondwana 13y agoIt might also mean that many of our users believe in the same tradeoff that we do - that we're not overreacting to one low probability/high visibility risk by throwing out the incredibly good reliability we've had for years to shut everything down, ship it to a location with unknown reliability and spin it all back up again - complete with new IP addresses and all the headache that would cause tons of customers who have hard coded things on their own domains (annoying but true - recycling IPs is hard) There are tons of downsides to shutting down everything that's working well in a knee-jerk reaction to one possible risk - never mind that the government of whatever country we choose could very well cooperate with the same agencies we're running from - or they could just corrupt an employee of the datacentre we're in - or... So maybe if you're going to put words into our mouth you could put ones about how much we care about our users and our reliability that we don't jump on unproven setups just because of a single (unchanged, just more public) risk.
- brongondwana 13y agoHello inflammatory headline. That's a very small part of a lot of what we have to say, most of which is: * we can't be compelled (under current laws) to install blanket monitoring on our users * we can't be compelled to keep quiet about penetration that we notice * there are always risks, including the risk that any random group knows unpublished security flaws in the systems that we use We have written some things about techniques we use to reduce those risks (physically separate internal network rather than VLANS on a single router for example) - these help protect against both government AND non-government threats. But we can't make those risks go away entirely. What we're saying is - the physical presence in the USA only changes one low-probability/high-visibility threat, which is direct tampering with our servers. Regardless of the physical location of servers, we would still comply with legally valid requests made through the Australian Government. It is our belief and hope that this process is difficult enough to mean that US agencies only ask for data when they have good cause rather than "fishing" - but still easier than taking our servers and shutting us down, with all the fallout that would cause.
- robn_fastmail 13y agoHi, FastMail employee and author of (most of) that blog post here. Just so we're clear, the point of this post was not that we don't think the rules don't apply to us. Instead we're trying to make it clear where position on these things are. The topic of this thread is a sensationalist sound-bite, nothing more. I'm not going to go over the points again here because I'm pretty sure we said it all in the post (but ask questions if you like, I'll be here all week!). The most important point to take away from this post is that your privacy is your responsibility. We're trying to provide you with as much information as we can to help you determine your own exposure, and to let you know what we will work to protect and where we can't help. Its up to you to determine if our service is right for you. No tricks, and no hard feelings if you'd rather take your business somewhere else!
- lessnonymous 13y agoHi Rob, Has the headline on HN been updated? Because both you and brongondwana talk about it being sensationalist, where I see it as just being a summary of the most salient part of what you have to say. Do you have Australian legal advice to back up your conclusions? (I agree with them, but would like to make sure we're talking more than the "gist" of the law)
- robn_fastmail 13y ago> Has the headline on HN been updated? Because both you and brongondwana talk about it being sensationalist, where I see it as just being a summary of the most salient part of what you have to say. To my mind it was one of the least interesting parts of what we had to say. "Non-US company not bound by US law" - its hardly earth-shattering news. Would "Non-Senegalese company not bound by Senegal law" be as interesting? EDIT: Sorry, it just occurred to me that it was changed already and you might have posted this afterwards. The original post headline was "FastMail claims they do not have to comply with National Security Letters". That's what we were referring to when we said it was "sensationalist". > Do you have Australian legal advice to back up your conclusions? (I agree with them, but would like to make sure we're talking more than the "gist" of the law) We've made our position public, and we're satisfied that its an accurate reflection of our position and our understanding of Australian law. You must not rely on it as a legal basis for anything though - get your own legal advice that applies specifically to your own circumstances!
- deleted 13y ago[deleted]
- westicle 13y ago> Australia does not have any equivalent to the US National Security Letter, so we cannot be forced to do something without being allowed to disclose it. This is not true. The Australian Crime Commission has some of the most extensive secret coercive powers in the Western world. http://www.austlii.edu.au/au/legis/cth/consol_act/acca2002289/s29b.html http://www.austlii.edu.au/au/legis/cth/consol_act/acca200228... I would suggest that either: a) Fastmail is aware of this and is covertly spreading the word that it might be compromised; or b) Fastmail needs better lawyers.
- robn_fastmail 13y agoI would argue that section 29 is very narrow in its scope, and allows for disclosure once an investigation is completed, and allows for disclosure to an attorney, whereas my understanding of an NSL is that it can order pretty much anything it wants without limitation. That seems quite different to me. But then, I'm not lawyer. You're probably not either. Which is why I keep telling people to get their own legal advice if they're concerned about it.
- westicle 13y agoActually I am a lawyer. In the past I have even advised clients who received ACC notices (they are more common than most people would think). Needless to say I was staggered at the scope of the powers granted. Forget about transparency, justice and the rule of law. If you receive one of these you can be compelled to give evidence or documents in secret, without judicial oversight or public scrutiny.
- Wingman4l7 13y agoWhen you say "compelled", do you mean "divulge at the threat of guaranteed jail time" as in the UK's RIPA-based mandatory key disclosure law? Wikipedia seems to indicate it'll cost you 6 months in jail: https://en.wikipedia.org/wiki/Key_disclosure_law#Australia https://en.wikipedia.org/wiki/Key_disclosure_law#Australia
- 13y ago
- 616c 13y agoThank you, Fastmail. This is why I pay for you.
- TwoBit 13y agoDespite that they just stated that your data will be owned by the US government in a raid on the US-based fastmail servers? And with no apparent way for US-based users to avoid that?
- andyhmltn 13y agoIn all fairness, how are they supposed to combat that without moving their server location?
- bad_user 13y agoI found this article brutally honest. What they are saying is that (1) NSA snooping is more expensive for the NSA as they can't engage in blanket surveillance on all of their users, while keeping them silent, but on the other hand (2) you can't expect and shouldn't assume privacy, because if the NSA wants to listen on your traffic, they will. This in combination with FastMail being acquired by its former employees, coupled with their investment in CardDAV and CalDAV, makes me really excited about them. I was actually looking for a good replacement to Google Apps and FastMail might be it. It's still a little expensive though, compared to Google Apps, I hope they'll bring those prices down just a little.
- TwoBit 13y agoI think there's reason to believe that a targeting a person like Snowden would cause the U.S. to use the most extreme measures discussed in the post, such as seizing the servers.
- brongondwana 13y agoThe point is, they wouldn't need to, because the Australian Government would order us to turn over the data, and we would. Everybody wins (except theoretical-Snowden) Mind you, theoretical-Snowden is already screwed at this point, regardless of where his mail is. No reason to believe any European country would be susceptible to pressure: http://www.bbc.co.uk/news/world-latin-america-23174874 http://www.bbc.co.uk/news/world-latin-america-23174874 Or maybe there is. Which comes back to the point I've been trying to make all along here. In the most serious extreme, nowhere in the world is "safe". In a less serious case, nobody's going to invade NYI with jackboots on. The window between those two cases is where being not-in-USA could theoretically save us from having our servers snatched (assuming said jackboots weren't willing to just wait for the Australian Government to order us to hand the data over)
- pppp 13y agoI am more than willing to give FastMail twenty USD per year, so it is not expensive in that regard, but it is expense for what you get. 1GB of space? Give me a break. All of the tiers need to shift down a notch while keeping the price the same. $20 for 10 GB would be reasonable.
- iSnow 13y agoSince the Silk Road bust we know the US LE is able to convince or force colocation providers to provide them with an image of a server. After that, pretty much any communication can be considered open to the NSA. I am not surprised that he does not clearly mentions this. So FM should move their servers out of the US even if that's inconvenient.
- robn_fastmail 13y agoActually we did clearly mention it: "Our colocation providers could be compelled to give physical access to our servers." But in the very next paragraph: "These are not things we can protect against directly but again, we can make it extremely difficult for these things to occur by using strong encryption and careful systems monitoring. Were anything like this ever to happen we would be talking about it very publically. Such an action would not remain secret for long." Its not hard for a skilled sysadmin to take an image of a running server. Its extremely difficult to do it without administrative access to the machine AND to do it without anyone noticing.
- sandstrom 13y agoYou could move the servers to a country with more respect for rule of law. That would be awesome!
- kryptiskt 13y agoSilk Road wasn't hosted in the US, in the documents it says they got the server image from another country.
- rplnt 13y agoWhat we also know from that is that it doesn't really matter where your servers are physically located.
- Quai 13y agoI know that my word doesn't mean much, but I have had the chance to talk to several of the guys working at Fastmail during their years at Opera Software. They are -serious- about mail and they are -serious- about privacy. Next time I'm out shopping for email services, I will give my moeny to them! (And, to give something back for all the Tim Tams brongondwana brought with him to Norway ever time he was on a visit ;) )
- robn_fastmail 13y agoIf you want to just send timtams, that would be fine too. We seem to have run out of them in the office...
- brongondwana 13y agoI'll get you timtams if you run the fire escape with us...
- robn_fastmail 13y agoI'm afraid that if get fit and stuff I won't want them anymore! :'(
- brongondwana 13y agoHasn't stopped me.
- robmueller 13y agoStick to IRC for the internal chats guys. Wait, I meant email... ;)
- topbanana 13y agoThey don't need to seize the server. SMTP is plaintext and on a well known port number. I'm sure the NSA have a record of every email sent through the US in the last few years.
- kijin 13y agoIt is possible to encrypt SMTP connections with standard SSL/TLS technology. FastMail has been using opportunistic encryption on their incoming and outgoing SMTP servers for years. If you send an email to another service that does opportunistic encryption, and if both the sender and recipient uses SSL to access their mailboxes (as FastMail requires), the email will never be transmitted in plain text over the Internet.
- janvidar 13y agoThe problem with such opportunistic encryption, is that you could insert a man in the middle which basically intercepts the traffic and modifies the handshake to exclude the STARTTLS extension. With opportunistic SMTP encryption this will cause things to proceed in plain text. The sinister thing about this is that e-mails still flow, so it still works.
- robn_fastmail 13y agoThere's a solution for this. Its called DANE. See http://tools.ietf.org/html/draft-ietf-dane-smtp http://tools.ietf.org/html/draft-ietf-dane-smtp We're currently investigating it.
- kijin 13y agoInteresting. Meanwhile, does SMTP have something like HTTP Strict Transport Security? It would be nice for an impartial party to compile a list of mail servers that pledge to accept encrypted connections, and for sending MTAs to treat it as a connection failure if the destination is on that list but doesn't appear to support encryption.
- 13y ago
- bckrasnow 13y agoTransparency takes precedence over everything else in this post, aka the thing you haven't seen US companies doing at all. Hmmmmmmmmmmmmmmmmmm.
- smegel 13y agoNow swear in blood you weren't under any kind of nondisclosure order when you wrote that.
- dutchbrit 13y agoOr the US could just go to the Datacenter and force them to give access.
- Maximal 13y agoAs Australia is a member of the five eyes group, I do not see any added protection from FM being incorporated there rather than in the USA. This is why I use a email service in Norway (runbox.com), which, as far as I know, is not sharing information by default.
- brongondwana 13y agoThe legal situation in Norway is... in flux at the moment. The Snowden revelations might stop information sharing from coming in, but Norway is looking like leapfrogging Australia pretty much with data retention (along with much of Europe): http://theforeigner.no/pages/news/updated-parliament-passes-data-retention-directive/ http://theforeigner.no/pages/news/updated-parliament-passes-... Norway isn't some magical safe haven from legal data requests. We receive law enforcement requests through the Norwegian system for mail.opera.com users (which, despite running on the same infrastructure, is operated under Norwegian law, not Australian - isn't life complex) http://en.wikipedia.org/wiki/Telecommunications_data_retention http://en.wikipedia.org/wiki/Telecommunications_data_retenti... tells a few interesting stories. Australian law may indeed change, and we'll be compelled to update our policies to match. So far, we've avoided it. http://www.smh.com.au/technology/technology-news/government-shelves-controversial-data-retention-scheme-20130624-2oskq.html http://www.smh.com.au/technology/technology-news/government-...
- workhere-io 13y agoThere's one question they haven't answered: Why do they even need to have their servers in the US? Their blog post admits that there's a big chance that the US is spying on their customers. Given the fact that FastMail is a Norwegian/Australian company, why don't they just move their servers to e.g. Norway? I realize that even if the servers were in Norway, an email from a FastMail user to a gmail.com account would still be read by the NSA (because it would pass through American servers), but email sent from FastMail to other email hosts in relatively safe countries would not be read by the NSA.
- alfiejohn_ 13y agoWe're no longer Norwegian :) http://blog.fastmail.fm/2013/09/25/exciting-news-fastmail-staff-purchase-the-business-from-opera/ http://blog.fastmail.fm/2013/09/25/exciting-news-fastmail-st...
- workhere-io 13y agoAlright, but the point still remains: You could theoretically place your servers anywhere in the world, so why choose the US?
- alfiejohn_ 13y agoLike what Bron mentioned above: 'Which comes back to the point I've been trying to make all along here. In the most serious extreme, nowhere in the world is "safe"' Do you have any suggestions for countries that have excellent data connectivity, would successfully resist pressure from US/UK/X authorities to hand over our servers, and at the same time would not themselves want access to?
- workhere-io 13y agoNorway, Iceland and Switzerland come to mind. As for whether or not they want access to data: There's nothing wrong with governments accessing data if there's a court order in place and their request is part of an investigation. It's the automatic surveillance of everyone that NSA does that's a problem, and it's certainly not all countries that do that. In the most serious extreme, nowhere in the world is "safe" Sure, but there are levels of safety, and the US has turned out to have a low degree of safety for a Western country. The fact that you probably can't find a perfect country shouldn't be an excuse to pick a notoriously unsafe one.
- deleted 13y ago[deleted]
- rdl 13y agoAs far as I know, Australian law is common law and would allow a judge to seal a warrant. So, fastmail's asertion that there is nothing like an NSL where they couldn't disclose a search is incorrect. I'm sure it is just lack of awareness, rather than intentional deception. (Ianal, ianaa, but I am pretty sure I am correct on this point.)
- a3n 13y agoFastMail's servers on on the internet, and so you're fucked. Just sayin'.
- jessaustin 13y agoWhile some describe this as "frank", I think to have that quality TFA would need to specify where the decryption keys are stored. Are they in the USA colo's too? (I realize I could probably figure this out myself if I could be arsed to do so, but why not just tell us?)
- duncan_bayne 13y agoThis makes me very happy to continue being a Fastmail customer.
- aamargulies 13y agoI've been having a discussion with a fastmail staff member about surveillance and fastmail. You can see the discussion here: https://www.fastmail.fm/html/?MSignal=TZ-**378397*97ae93f3 https://www.fastmail.fm/html/?MSignal=TZ-**378397*97ae93f3