Switching from Gmail to FastMail
maxmasnick.com
maxmasnick.com
Update: hmm, so Opera aren't american? interesting. All the servers are definitely in the US though:
> "we have standard servers and a high speed connection in the US." - https://www.fastmail.fm/help/overview_about.html
> American company…
Then, noticing the critical error, the GP said:
> Fastmail is owned by Opera a Norwegian company.
Replying to the American company part.
> You said: Their servers are located in the US according to the article.
So, the servers location have nothing to do with whether the company is American or not. And while that might have a bearing on certain facets of the topic as a whole, it's meaningless in this context. Basically, what you said does not change anything.
As in, the actual point, which is that your e-mails are liable to be searched by the NSA.
Correct me if I'm wrong, but if Fastmail moved servers outside the US, then it would be in a better position as a non-US company than if it was a US company with servers outside the US?
Despite what some might believe, where a company operates from is actually important, regardless of where the servers are hosted.
Believing that it being an American company or not is not important is silly.
http://www.huffingtonpost.com/2012/05/29/facebook-opera_n_15...
People are operating on the equation of "hosted in America = possibly accessible via PRISM = compromised by the NSA," which is understandable given all the recent news. Perhaps you don't trust the assurances that the NSA's computers are only scanning metadata by default, only flagging suspicious keywords that then have to be processed by a human agent before they go ahead and actually start scanning your real email which of course they will usually only do with a warrant obtained in secret from a secret court that pretty much never turns down any warrant request!
Okay, but those very reassuring reassurances actually only apply to American servers. Communication going between servers in America and international servers is just as likely to be targeted and quite possibly more likely to be subject to deep scanning. We have to throw in "likely" and "possibly" because, as with all things NSA, we really don't know. But if you're concerned about data interception, it's very likely not relevant whether FastMail's servers are located in New York, Norway, Australia, or the Fortress of Solitude.
India -> US -> Japan -> US -> Japan -> Singapore
I'm not saying that the NSA has forced other countries to route their data through them. It could be due to several other reasons. But the main point is that it is hard to escape the NSA. Even if you do your best to keep your data away from the US, there are certain factors out of an individual's control (such as routing).It's still not ideal (they can still see who you're talking to), but you'll never have 100% privacy. Just make as much of the data useless as possible.
You do unless you're using PGP for all your emails, because SMTP can be easily intercepted in plan-text.
Of course, if you're using full end-to-end encryption (like PGP) for all your emails, you don't care so much about using HTTPS to fetch them, because you're using end-to-end encryption.
My Azure IP shows up in Seattle, yet the connection goes to Amsterdam. What you're seeing is where the owner of the IP is located; that is not necessarily the same as the server.
Privacy laws vary a lot within Europe - even within EU - and while I'm sure every country in the world is "happy to spy", as you put it, I can't think of any European country save for the UK whose spying is as intensive as NSA's.
http://www.lemonde.fr/societe/article/2013/07/04/revelations...
The very nature of e-mail leads me to conclude that it really doesn't matter where an e-mail provider is located, because it will always be intercepted at some point. One can use another e-mail service, but if the people you talk to still use gmail, then does it really matter?
Perhaps it's time to talk about new messaging systems, with encryption by default, and a new address and routing system coupled with Tor.
Bitmessage is up and coming, but needs a lot more development.
You could use OTR with servers for offline support and contact management (jabber, etc), but this isn't as convenient as email.
OTR (instead of PGP) over email is a theoretically possible, but the problem is still the same: No money in open source encryption == No easy to use interface.
It would be interesting to setup a mail service with numerous SMTP relays around the world and attempt to connect the "closest" (least likely to be eavesdropped) relay to 3rd party SMTP servers. Communication between the relays and the main service (which stores your email in a friendly jurisdiction) would be strongly encrypted.
http://www.maxmasnick.com/2013/07/19/fastmail/#fn:1 "This may be a deal breaker if you’re concerned about government spying. "
I believe that Fastmail is a valid option if your main problem is with Ads and the fact that Google might be reading all your mails and companies are buying this big data to sell you better services / more targeted Ads around the web.
I'm currently switching to Fastmail because I don't believe in free lunch and I won't stand for it anymore.
If I want to make sure no one is reading my mails, then I have a problem. Most governments are doing this and we can't do much about. If I need privacy, then I use GPG.
No functional difference for me, and I save some bills. I don't consider it a free lunch, either, since I basically pre-paid when I bought my iPhone.
If you want sender/receiver privacy too, you can try using Tor hidden services direct to the individual. I can't think of any other way off the top of my head to send SMTP mail and completely conceal the recipient(s).
What is secure? If government sezies your key, in some jurisdictions they can compel you to release your passphrase (if one is required), then they can go back and decrypt absolutely everything you ever sent. (OTR gets around this but this is largely by leaving the network layer location privacy / initial authentication / key exchange problems out of scope.)
Finally, traffic analysis is pretty powerful. Even if Eve can't read your messages, she can see who they went to and when (and maybe who they in turn communicated with afterwards) and thus easily determine probable relationships - Tor based endpoint, or not. (Hrrm ... but two Tor based endpoints, on the other hand...)
"Secure" in this context means "not readable by anyone but the recipient". Of course, if you have the recipient in custody, this is the easiest method to decrypt the messages: http://xkcd.com/538/
(OTR-style cryptography is nice, but sucks for store-and-forward communication; for a comporably difficult message to decrypt more than once, use one-time pads - but don't complain to be about distributing the pad dictionary, that's totally out of scope here ;)
https://github.com/crised/SafeGmail
No good (edit: stable and drop-in) Firefox tool yet.
Here's more of the text from
https://www.fastmail.fm/help/overview_company_info.html
FastMail.FM's was started by Rob Mueller and Jeremy Howard in 1999. We are located in Melbourne Australia, we use IBM servers hosted by NYI in NYC US. FastMail.FM is now run by Opera Software Australia Pty Ltd, a whole owned subsidiary of Opera Software ASA of Norway.
https://news.ycombinator.com/item?id=6037235
From the article:
"The contract was prompted by Telstra's undersea telecommunications joint venture called Reach. When it sought a cable licence from the US Federal Communications Commission, the DoJ and the FBI insisted on a binding security agreement.
"The contract does not authorise Telstra or law enforcement agencies to undertake surveillance. But under the deed, Telstra must preserve and 'have the ability to provide' wire and electronic communications involving any customers who make any form of communication with a point of contact in the US, as well as 'transactional data' and 'call associated data' relating to such communications."
. . . .
"The document was signed by Douglas Gration, a barrister who was then Telstra's company secretary and official liaison for law enforcement and national security agencies. "He told the Herald he could not remember much about the agreement. 'Every country has a regime for that lawful interception,' he said. 'And Australia has got it as well.'"
This looks like a pattern of mutual agreements among governments that cooperate in routing and connecting cables for international telecommunications. The statement is NOT that every telephone call from Australia to another country is listened to, but that a data archive is maintained that might be accessible with court orders. Particularly significant is the statement that other countries ask for the same arrangement if a cable connects to or through that country.
Switching email providers has little to do with what governments have access to your data by mutual agreements among the governments.
"> I feel safe in speculating that if you will not pony up the emails to a US judge, the people who maintain the server farm here in the US will.
They can't - they have no access to the emails, because they can't login to the machines and they can't access the encryption keys for the data. All maintenance of the OS/software is done from Australia.
We've had a number of US-based law enforcement bodies over the year try to get hold of our data without going via the appropriate Australian bodies, and it doesn't work out for them. In the end, they have always ended up submitting a request for cooperation via the Australian Federal Police, as they are required to do, and we respond to that request in line with Australian law."
2009 Slashdot.org Interview with Howard Jeremy, Founder of Fastmail
http://tech.slashdot.org/comments.pl?sid=1391605&cid=2963395...
https://www.digitalocean.com/community/articles/how-to-insta...
Works wonderfully.
For us as a European business, that's a dealbreaker. It's not that we are completely paranoid and migrating off of American systems in a big hurry, but moving forward, not in the US and not owned by an American company is a requirement for any new service we use.
Even if we didn't care, we have to take into account our clients, and "no data under US control" has become not just a selling point, but a strict condition for many projects.
This was already very much the case before the PRISM scandal, and it's only going to get worse now.
Yet, FastMail looks quite nice.
The other thing I forgot to mention in the post is contact syncing. I'm honestly not sure if I like the contact pollution gmail does more or less than not having sync between FastMail and my phone.
You can set many alternative login passwords in fastmail and the google auth is one of those.
So with the google auth you use your google auth fastmail password and append your google auth login so if your password is Password1, when you login you would be typing something like Password1123456 to login.
You can also set other login passwords for applications or imap with or without delete capabilities but a lot of the time they need full permissions to work with email clients, it could be nicer.
Do you know if there's any plan for them to release an android app that would let my phone sync?
And I do realize the irony in trying to cut out google while using an android phone.
I use K-9 Mail on Android with Fastmail. They both support IMAP IDLE, so you get immediate push notifications of new messages.
I actually don't care that Google is machine-reading email to serve ads (see http://www.maxmasnick.com/2012/02/12/gmail_paranoia/), but I do care about polluting the interface with ads that look like email for the same reason I don't like the new compose interface. Both make the interface worse, and email is bad enough as it is without bad UI.
Fastmail isn't even under the control of your local firewall.
Then turn that function off [1]. There's no more security threat from well-known browser plugins from Mozilla's site than well-known packages from your OS's apt repo. And both are open source.
I bet not.
Google could easily decide to serve ads to paying customers, and it seems likely that they've left this option open to exercise later.
The fact that they apparently "do not rely on ads" is irrelevant.
There are plenty of existent services that have revenue from customers, but still serve ads (visible examples include: pay-TV, public transport)
Why would I be 'uncomfortable' with ads? Sometimes I feel like the issue with ads in Google/other services falls victim to the 'Nickelback Effect', where a few other very vocal people hate the subject at hand and it spreads virally to the point where people can't describe why they hated the subject in the first place.
To those who are arguing about advertisements not showing up in the Fastmail's paid tiers should also realize that there is the Google Apps for Business accounts, where you don't see ads. It also beats the popular 'if you are paying you are the product meme'.
As I mention in my post, Google Apps is a lot of overhead for just email. There are additional complexities with switching from gmail to google apps because of the integration with all other google services.
If someone was interested in switching from gmail to a paid service, I would argue that FastMail may be a better choice than Google Apps.
How times change. This is how message threading has always worked before we got gmail and Mail.app which I have resisted switching to for years because the just didn't do threading "right".
And now get off my lawn :-)
I've been using email since like 1996 but had never seen that kind of thread hierarchy display until I used MailMate. I can't believe all these email clients have been holding out on me!
I remember being concerned about the buyout, but it seems it's been nothing but good for them. Opera are a great company.
Rackspace also allows you to run exchange mailboxes alongside IMAP if you have a few users who are still tied to outlook.
Additionally it seemed like they were chasing the smaller accounts. Whenever I consulted the help/documentation it focused on the converting the 1-5 user shops into paid accounts. There wasn't many resources for someone who walked in expecting to pay $2k/month. I had to dig for details. Eventually I created a paid account just to test all the details.
Contrast that with rackspace where everything worked smoothly out of the box. Any limitations were spelled out clearly. In general it felt like all my needs were anticipated. In two years with them I've opened maybe three tickets all solved exceedingly fast.
I think it's more important to diversify services than to insist on airtight alternatives. My mail is not terribly exciting, but when combined with the rest of my searches, visited webpages [1], chats, news reading habits, social network connections, and phone location, all housed under Google's roof, it seems like I'm making it easier to piece together my life [2]. At least make it a little difficult by having to go to separate companies with court orders.
[1] And web developers contribute to the surveillance by installing analytics code.
[2] That of course is the Google AI wet dream, moar data.
Any proof to this? And, no, twitter is not a source of record.
For instance, most of my mail is sorted into labels, skipping the inbox. When using a mail client with IMAP, these labels shows as folders. Deleting the mail from my client, doesn't delete it from Gmail, only removes the label. Useless.
However, along these lines the removal of Jabber support from Gmail is a little bit scary (first they removed federation support, then they killed it altogether). Limiting or removing IMAP is not outside the realm of possibilities.
> However, along these lines the removal of Jabber support
> from Gmail is a little bit scary (first they removed
> federation support, then they killed it altogether)
Federation support was temporarily disabled, then re-enabled once they got spam filtering in place. Currently, XMPP works perfectly with a Gmail account.My understanding is that upgrading to Hangouts still disables the old XMPP support.
> My understanding is that upgrading to Hangouts still
> disables the old XMPP support.
Sort of; the web interface will connect to either Hangouts or XMPP, but not both at once. XMPP continues to work fine for non-web clients, such as Pidgin.And just for added measure, deleting the label seems to me to be the right thing to do.
However, most IMAP clients expose mailboxes as "folders" and barely support flags at all (no indexing, not even slow search, no UI at all most of the time, and if it even bothers to parse them, often has some silly limit like "five flags that must be configured ahead-of-time in Settings"), so users would have had a totally useless experience.
In essence, Gmail's IMAP is implemented the way it is not because it is the best way to map Gmail's semantics on to IMAP, but because it provides a reasonable fit to the way Outlook, Thunderbird, and Apple Mail (the only e-mail clients that have any marketshare) represent IMAP. Those clients represent trees of mailboxes as a folder hierarchy.
While commonly believed, people really need to stop blaming IMAP for Gmail: it's about as silly as claiming using HTTP headers as part of an API specification is impossible because none of IE, Firefox, Chrome, or Safari, allow users to modify the headers in their document-oriented web browsers.
I don't mind paying a little extra to cover the licensing. But I don't want to be stuck with IMAP again -- the biggest draw for service for me is the "Contacts + Calendar + Tasks + Mail" instant syncing of something like ActiveSync.
Rackspace E-mail comes closest from what I've tried. But being stuck on Outlook Web Access isn't awesome.
From the first time I tried Fastmail I noticed that the site was compatible with my mobile devices, which, at the time (2006), was the exception rather than the rule.
When ASA/Opera took the site over, the site quality went down, IMHO, but I still use Fastmail today because it just works.
Then this can be combined with an email service that encrypts all incoming emails as they arrive such as Countermail or Lavabit.
Honestly, if they were interspersing ad messages with my regular mail it would be a big issue. But just like with search, where ads are separated off to the side, the ads here are clearly marked and separated. So I don't see a problem.
Two feature requests though:
1) Push support for iPhone
2) Have my email encrypted on disk (in the unlikely event there's a security hole or a rogue sysadmin or something, I don't want my email copied wholesale by one attacker) -- I'd pay extra for this
In any case, an account with 8 GB of email storage and 6 GB of file storage (Family account), or 10+2GB (personal account) is still cheaper than Googles 'one plan' service.
Google just aren't interested in marketing GApps to enthusiasts and families.
I've had my email address since 1995. I have 5Mb / 6 emails in my Maildir and that's only because I've got lazy recently. I've recieved probably 500,000 emails over the years.
Hoarding email is like recording all your phone conversations and keeping the tapes in your living space. If it's worth keeping, save it elsewhere. If it's not, delete it.
One problem I've had is with their spam filtering. I've marked everything spammy as Spam (some 800 messages so far), but I can't figure out how to get things marked as non-spam (so that the personal database gets enabled). I've setup auto-non-spam folders and a lot of messages get routed into those, but they're not being counted as non-spam. I've also moved a few messages manually, and they also don't get counted.
Also, if you haven't talked to support about this, I'd definitely recommend it. They've always been super helpful with me.
I am skeptical of performance claims especially by people (not referring to you, but to the author of the post) who think mail.app is fast. Mail.app needs several seconds to do things that gmail does in 50 milliseconds, like load a thread with 100 posts, or free text search.
That's a lot of email...how much does it cost to store on gmail?
Anyone have some good solutions?
Based on this excellent post (https://kkinder.com/2013/05/21/leaving-googles-silo-alternat...) it seems like there isn't a great drop-in replacement for Google Calendar (except for iCloud).
The noise on HN regarding this is extreme because this is a community of people who are really passionate about these topics, most people are not though.
But if you dont feel strongly about issues such as privacy, of course you dont see the point.
http://web.archive.org/web/20130609020621/www.news.com.au/te...
If it was, I'd try http://mailroute.net. Apparently it's supposed to be pretty good at handling spam.
They looked like a great option but when I set up an account recently they emailed me my username and password in plain text. I cancelled immediately but if they get the security basics right I may look at it again.
>Don't use hushmail. Never use hushmail or suggest it to others - they snitch out their users. Fuck them.
So sadly, I think gmail still has what's basically a killer app for me.
The family plan seems overpriced as well, as I'm the only one who needs large disk space, the other 3 accounts don't need so much.
It's wall to wall spam every time I open it up, stuff I don't ever see in Gmail.
There are tradeoffs....
This is not how you test things. For those prices vs storage I'd rather roll my own if I had to move off Gmail
How is it different from the threaded view that has been present since at least Netscape days?
As to these ads you're so troubled by:
Twitter ads look like tweets, Facebook ads look like Facebook posts, and of course search ads look like search results, at least in Gmail they have their own designated area. They replace the webclip ads when the "promotions" tab is enabled http://googlesystem.blogspot.com/2013/06/ads-in-gmails-promo...
https://news.ycombinator.com/item?id=6069372
Also quoting some random Marco Arment anti-Google troll as though it has some weight or authority doesn't help your point.
Yeah, those are good arguments to avoid using Twitter and Facebook as well.