A new look, logo, and website for Fastmail
fastmail.blog
fastmail.blog
Are Australian legislators really that clueless? There seems to be a very strong incentive against making business with Australian companies.
The Australian law is broader and contains fewer checks than anything comparable in the developed world. It lets law enforcement compel, with no oversight and in secret, any Australian "to re-engineer software and hardware under their control, so that it can be used to spy on their users" [1]. (Australia has no bill of rights [2].)
The American analog is an intelligence agency getting a national security letter [3] stamped by a FISA court [4]. The order can compel disclosure of information on hand, but cannot compel a product to be re-engineered [5].
[1] https://www.eff.org/deeplinks/2018/12/new-fight-online-priva...
[2] https://www.nytimes.com/2018/09/04/opinion/australia-encrypt...
[3] https://en.wikipedia.org/wiki/National_security_letter
[4] https://en.wikipedia.org/wiki/United_States_Foreign_Intellig...
[5] https://en.wikipedia.org/wiki/FBI–Apple_encryption_dispute
OTOH this could be unnecessary at large American companies because the needs of national security services may have been engineered in. Thinking of Room 641A [1], etc.
That's voluntary co-operation. The situation is far from perfect in the United States, but Australia is an extreme case.
Not if you’re Ladar Levison running Lavabit in 2013. He opted to shut down the service instead of complying: https://en.wikipedia.org/wiki/Lavabit#Suspension_and_gag_ord...
I moved my addresses over to my own domain (lyndsysimon.com) many years ago, way back when I was still using gmail as my provider. I've since switched a couple of times, and have never had to change my address.
These days I use Protonmail. I like it for what it is, and it checks all of my "privacy" boxes, but the search functionality leaves much to be desired. I understand the technical limitations that constrain that, but I still wish there were more options.
I do not really care about my personal case, here. But I try to maintain a (some say exaggerated) consistency in "paying with my wallet" according to my principles. Since the Australian government provisions seem an unacceptable betrayal to its citizens, the only way that I can make some pressure in favor of them is by visibly boycotting Australian tech companies. If I were an Australian citizen concerned with the AABill I would certainly appreciate this gesture. My fastmail account is just a 80 EUR/year epsilon amount which will not affect the economy in the least. But it is symbolic gesture in the right direction.
I am still undecided on dropping my fastmail account. But if I do I'll try to make as much noise as possible regarding the reasons.
First, compare practical law impacts if you look elsewhere. For example, in the US the gov can get email from providers that's more than 180 days old without a warrant.
Second, Fastmail like Google, Microsoft, and most others has access to your email. They comply with court orders for email like other providers. Fastmail has noted the gov doesn't need a backdoor to get to email. Same with other companies in other countries.
Email shouldn't be used for things that are particularly private to begin with.
To begin with, governments should not be able to access your non-particularly private stuff without an explicit court order.
With a warrant signed by a judge. Also, if the keys are on your device the service has nothing to turn over. The court can't force the provider to engineer in a backdoor.
None of those checks or limitations apply in Australia.
https://en.wikipedia.org/wiki/Protect_America_Act_of_2007#3....
Most people don't include national security investigations in their threat model. The more general risk is a court allowing the executive to cast a broad net to collect information rather than accounts known to belong to targeted, named individuals or groups.
That was the point of this thread.
The words "highly unlikely", however, do not really mean anything and the argument falls down.
Besides that part, most of their text seems quite honest, clear and compelling. Βut I would appreciate that they delve precisely into these "highly unlikely" cases.
They could always decrypt your data. They don't need to add a backdoor, because they've always had full access. Nothing changes at all.
The crucial point of the post concerns the possibility that fastmail developers are forced to introduce secretly a government backdoor. This possibility is briefly dismissed as follows:
> There are also concerns that individual employees may be forced to build a backdoor, without being able to alert their employer. While frightening for anyone working in technology, we believe this fear is largely unfounded [1]. Most organisations have practices (pair programming, code reviews, risk evaluations) that would reveal such behaviour quickly.
The only reason given for the word "unfounded" is an article on zdnet [1], that explains the reasons why these backdoors are unlikely (but does not rule out the fact that they are possible). The word "unlikely" comes from the title of this article.
[1] https://www.zdnet.com/article/australias-encryption-laws-are...
You forgot to mention about new backdoors.
[0] https://reclaimthenet.org/fastmail-australian-encryption-law...
More info in this blog post, specifically under "The AABill doesn’t change your privacy or data security with FastMail": https://fastmail.blog/2018/12/21/advocating-for-privacy-aabi...
That doesn’t sound like a small thing. “Nobody can read your private data, not even us” is a big selling point these days. Sounds like Australian companies can no longer do that, putting them at a disadvantage.
And let’s not forget there’s no such thing as “a backdoor for law enforcement”. A backdoor is a backdoor, and it will be exploited by malicious actors. And they’re mandatory? Black hats everywhere must be getting dehydrated from salivating so much.
It is a big selling point. So is being accessible via any standards-compliant MUA, as opposed to e.g. Proton Mail and Tutanota. I'd love for there to be a secure email service with my privacy protected both by law and cryptography which also has me in full control of my data; until then it's a hard choice but I'd prefer to stay out of the walled garden. FWIW I'm not worried about Fastmail acting against my best interest.
> And let’s not forget there’s no such thing as “a backdoor for law enforcement”. A backdoor is a backdoor, and it will be exploited by malicious actors. And they’re mandatory? Black hats everywhere must be getting dehydrated from salivating so much.
I'm aware there's no such thing as a secure backdoor. Also to my knowledge the law doesn't mandate them, only access to the requested data. Said access could require manual action.
I don't agree with the law, but again the law does not change anything wrt Fastmail's obligations; anything the government might ask of them now, the government could have asked of them before.
It's a shit world requiring shit tradeoffs and Fastmail is one of few companies that are working towards keeping the internet open and (somewhat) decentralized. Their reward? The implication that they are somehow worse than any other non-e2e email service in any other country.
This is a little scary because credit cards are not that common here in Europe and having such sudden changes it not confidence-building.
Luckily, I use my own domain and if Fastmail turns too unreliable, I can just switch to an other provider and point my DNS entries over to them.
I would say however (from personal experience which may be biaised) that cards in Germany are less welcome than in other EU countries (for historical privacy reasons)
Not as high as I expected it to be honest but the article is pretty interesting. Apparently people have them but don't use them because they are not widely accepted in stores and they are very debt averse.
Source: https://www.dutchnews.nl/features/2018/01/credit-cards-not-y...
source: I work at Fastmail.
Please.
Implying that this interpretation may/should be true for others comes across to me as self-serving, though. You can attach whatever meaning you wish to a circle, but unless you make an actual effort to convey that meaning, then a circle remains... a circle. And they haven’t made any effort to do so here.
IMO, They’re just serving up a big cup of hyperbole for anyone willing to take a sip. Par for the usual corporate course, I guess.
And how about this gob of drivel in the announcement:
> ... makes it easier to talk about why it's important to feel good about email.
Meanwhile, documentation of essential features has gone stale:
>Keep in mind that U2F is not enabled in Firefox by default. >Good if you want the best security and you're only using Chrome. https://www.fastmail.com/help/account/2fa.html?u=04c140b1
U2F 'security.webauth.u2f' is enabled by default, at least for the 67.0.4 Linux build, current on Ubuntu 16.04.
It is striking how both Soverin and now Fastmail have a breezy abstract style with colorful illustrations. While the other providers feel like VPS hosting landing pages or enterprise sales pages.
I wonder if the consumer focused brand of Fastmail and Soverin is aspirational or where their customer base actually is.
Not if I get into a dragnet by Australian security services.
Wanted to get away from Gmail. Evaluated Fastmail, Protonmail, Mailbox.org and Posteo. Posteo went out because it doesn't do custom domains on principle, Protonmail went out because search is an issue with encrypted mails at rest. I'm not using Email for something that is illegal (journalism, opposition, ...) in my country, so encryption at rest has only minor impact on my decision. Fastmail looked nice with features but keeping my mail in the EU weighted more. Now that I no longer run a large website, I like the GDPR ;-)
In the end migrated to Mailbox.org on my own domain, went smoothly and I'm quite happy now.
Minor gripe: I wish Mailbox.org would understand IMAP is an API like every other API and provide unique API keys for applications (like GMail does).
Pricing can be a legitimate discussion but your original comment was rightfully downvoted for sounding like whining and not providing much substance.
That last part costs but it makes a huge difference. I've used GMail, Outlook (including web), Yahoo, Fastmail, desktop clients, and more. I found myself using Fastmail more efficiently than the others. I was faster at email.
That UX/UI isn't a commodity. I wish it was.
Migadu doesn't charge for storage space, but its pricing is based on the number of outgoing mails. Mxroute has tiers based on storage space.
Migadu has a free tier that you can use forever if you have minimal outgoing email requirements. It's also a good way to check its admin interface. Mxroute has no free tiers or free trials. There's no way to know how it is without paying and signing up.
Migadu is based out of Switzerland, with its servers in France (a Nine Eyes country). Mxroute is based out of the U.S. (a Five Eyes country).
Neither of these two providers come close to Posteo, Mailbox.org or Mailfence on their privacy statements or stance.
Does "new website" mean marketing website or a redesigned web based mail app? I'm assuming this is just marketing/branding changes given it's written by a marketing person.
I can't check it myself because I closed my account with them a couple of weeks ago, so maybe a current user can confirm.