Is this supposed to be a PR-positive announcement from FastMail, because I can't quite tell?!
Is this supposed to be a PR-positive announcement from FastMail, because I can't quite tell?!
We don't have data trading agreements with anybody, and we don't sell or provide backdoor channels - we only provide data in response to lawful warrants.
That's the right amount of privacy and the right tradeoff with usability for just about everyone. Certainly storing your emails super encrypted in a concrete bunker on an island somewhere is theoretically safer along one axis - I wrote a whole series about Confidentiality, Availability and Integrity just over 4 years ago on this very topic: https://fastmail.blog/2014/12/02/security-confidentiality-in...
And the specific one on confidentiality here: https://fastmail.blog/2014/12/15/security-confidentiality/ (excuse the line wrapping, we moved to a new blog platform a while back and some of the older posts didn't import perfectly, but I don't want to look suspicious by editing it today!)
Just about everyone who agrees with Australian laws you mean?
The concrete bunker thing is a ridiculous diversion. Why are you even bringing that up?
I understand that privacy is a difficult problem especially when subject to legislation but bunkers have nothing to do with it. You will obviously provide user information to government on request, you and your staff maintain the ability to access user information at all times, and you have some procedures in place to try and make sure none of this is misused.
That’s ok.
Unless you're starting from a premise that bad actors don't exist, and the police never do anything of value, there needs to be a facility by which police perform the role we expect of them in a civilised society, which includes following chains of evidence and requesting assistance of third parties they find along the way. The warrant system is a check against abuse of that process, not a repudiation of the idea that police also have a job to do.
I guess if a judge wants they should be able to watch you poo, pity we don’t have mandatory poo cams yet.
The judge should according to the laws be able to hear what you say to your wife at night.
Just that technology hasn’t caught up with what the law dictates yet.
After all, who are we to say what’s right? That’s for the professionals like the people who passed the AAA bill.
Who would you suggest should decide, when shown evidence that a spear phishing that stole thousands of dollars came from an email account, whether the provider should be requested to hand over data.
Policing isn't all poo cams.
I'd prefer that a judge tell me whether the police have sufficient evidence for a data request than have to make that call myself.
Thats the problem here. Computers (smartphone/laptop/server/toaster/etc) are/will continue to hold most intimate and private data about a individual. Do you want all that disclosed on one person's word ? I dont. I dont think there can be any check-and-balance that absolutely prevent any person from giving a malicious order. One bad disclose order can be enough to ruin a life. Is that jurisdiction willing to be liable for the compensation (if compensation is even possible) ?
I believe Internet is a country of its own. Its a virtual world, it has no physical manifestation. There is no need to invade Internet to secure physical world.
There's also no check and balance the absolutely prevents somebody punching me in the face and ruining my life, but I still walk down busy streets.
If you have a problem with the concept of judges as the arbiter of limits on the powers of law enforcement, I am keen to hear your workable alternative that doesn't have worse downsides.
As I said there are already enough physical measures (defence, surveillance etc) that can ensure public safety. However If I were to compromise: We can have multiple judges. An order should be vouched by more than one judge. It would be even better if the user can whitelist/blacklist judges to submit. Less bureaucratic liability for the state if data gets leaked/misused.
https://www.smh.com.au/national/teenager-daniel-christie-die...
I guess it's the punch then.
I can avoid sucker punchers. No need to give up privacy. I can avoid going outside a walled garden. No need to give up privacy.
You seem to be saying that its fair trade. I disagree.
My point, I suppose is that there are ways to architect systems such that concrete bunkers are un-necesary and irrelevant.
The simplest such systems do involve trust in you. I suppose to a first order you are trustworthy since you have explained you will hand over user data upon request according to the laws you are subject to. This is a sane business decision.
Finally, a solid stance against at least business surveillance is a great start.
So are you saying that just by offering end-to-end encryption yourselves would be "helping people who have broken the law"?
Well, at least it's good to know where you stand and to have this in the public record, in case someone mistakenly thinks that Fastmail is a good alternative to other end-to-end encrypted email service providers.
https://fastmail.blog/2018/02/14/email-is-your-electronic-me...
End-to-end encryption is great for "this message will self destruct in 5 seconds" type instant messaging, but I have a friend who recently forgot her password on an "end-to-end encrypted" email service and lost all her emails. Not a great choice, though luckily she hadn't been using it long, so she didn't lose many memories.
An extreme black-and-white view on confidentiality vs the other parts of security is poor threat modeling, and we especially don't like the idea of selling snakeoil where we claim a level of confidentiality from ourselves which is not supportable by facts.
Of course this is reasonable, but I'm curious what you think of companies who do put themselves above law enforcement when it's the right thing to do.
i.e. lawmakers do not always make laws that are right and law enforcement does not always do the right thing when interpreting and enforcing laws. A case to cite might be Apple vs. FBI in 2016. The company placed itself above law enforcement. They disagreed with law enforcement and would not cooperate when I am certain many companies would have cooperated. It was a gamble. As a user, I am glad they stood their ground and I was/am glad to give Apple my money. I've also set my businesses up on FastMail at least twice, which is why I ask.
Maybe only a company with Apple's resources can take a risk like this? Thoughts?
This puts me in direct conflict with the way the law is going right now, where it is supposed to be acceptable for government and/or searches to be an invisible third party to all conversations.
Not sure where this goes but I feel like there is an MLK or electronic Jesus moment here somewhere.
Apple did no such thing. They asserted their legal rights. They used the exact mechanism -- the law -- that you are saying they ignored or held themselves above.
When law enforcement takes a wrong turn (as the FBI did) it is, I believe, reasonable for a citizen to consider themselves above (read: "better than") law enforcement. Mechanisms to deal with this include constitutional principles (which may also be considered above the law) and, generally, the courts.
During those proceedings, they also explained how complying with the FBI's request would lead to a highly damaging corruption of the privacy of their users data.
They asked the judge to make a judgement which was that Apple were right in saying that the FBI had over-reached in their warrant.
The case was headed to appeals when the FBI withdrew after finding another way to get the information they needed. Notably they did so without Apple having to compromise security or user data privacy.
Exactly. I didn't say they did. The comment was about being above law enforcement. See my other peer response here.
You seem to be conflating the concept of "I don't want my emails read" with "I am a criminal".
Why?
If you want to use PGP for encrypted email, and they supported it e.g. in their webmail - that would open them up to being a valid 'target' for the new bill, to provide access to your encrypted messages.
If they're just a conduit for your PGP (or even S/MIME) encrypted messages, the government can compel them all they like - there's literally nothing they can do to decrypt those messages.
Note: I am not a customer, or involved in FastMail at all (I am Australian though). This is just one of the facets of encrypted email IMO - if it's decrypt able somewhere between your laptop/phone/etc and the other persons laptop/phone/etc, it's not end-to-end encrypted, is it?
Either you give the factual power to access your emails to some party, then whoever you give that power to can as a matter of fact access your emails, and in particular that means that they can be coerced into accessing your emails, or you don't give them the power, then they can't.
You are demanding that they offer a product where they have the power to access your emails (as an unavoidable technical necessity for what you expect from the product) while they at the same time can truthfully state that they can not access your emails. That is simply a logial contradiction that cannot exist, and any PR that pretends that it did would be simply marketing bullshit.
It’s a similar deal on mobile apps; the situation is probably a little better if it’s truly a native app (by which I mean: all executable code comes from the app store, rather than executing arbitrary code fetched at runtime, as with websites) in that they probably can’t serve you specifically a different version to everyone else (I expect that’d need cooperation from the app store provider—not implausible, I caution) and so any vulnerabilities are more likely to be noticed in any auditing that others may do; but it’s also much worse because there you can’t lock it down with a browser extension that intercepts and verifies all the code.
Running the encryption no the user’s computer instead of your own servers is not a panacea, because you still control the code.
Your tl;dr is not quite accurate.
All companies, including FastMail, have to cooperate with local law enforcement. But there are different levels of cooperation. FastMail's level of cooperation, according to TFA, is, "Show us a valid warrant, and we'll show you exactly what you asked for, nothing more".
Certain other companies might be more cooperative, handing over user information in response to informal (warrantless) police queries, or handing over information to copyright-enforcement lawyers who write threatening (but not legally enforceable) letters, or handing over more information than is specified in a warrant. (I can't remember specific examples, but they get mentioned on HN now and then).
So FastMail is stating it will try to limit privacy violations as much as it can, without violating Australian law. This is not total privacy, but neither is it the same as "we aren't going to try to offer you any".
(Not affiliated in any way with FastMail, not even as a user)
It almost feels like it’s written for the Aussie Police and not really for the users.