Update: hmm, so Opera aren't american? interesting. All the servers are definitely in the US though:
> "we have standard servers and a high speed connection in the US." - https://www.fastmail.fm/help/overview_about.html
Update: hmm, so Opera aren't american? interesting. All the servers are definitely in the US though:
> "we have standard servers and a high speed connection in the US." - https://www.fastmail.fm/help/overview_about.html
Here's more of the text from
https://www.fastmail.fm/help/overview_company_info.html
FastMail.FM's was started by Rob Mueller and Jeremy Howard in 1999. We are located in Melbourne Australia, we use IBM servers hosted by NYI in NYC US. FastMail.FM is now run by Opera Software Australia Pty Ltd, a whole owned subsidiary of Opera Software ASA of Norway.
If you want sender/receiver privacy too, you can try using Tor hidden services direct to the individual. I can't think of any other way off the top of my head to send SMTP mail and completely conceal the recipient(s).
What is secure? If government sezies your key, in some jurisdictions they can compel you to release your passphrase (if one is required), then they can go back and decrypt absolutely everything you ever sent. (OTR gets around this but this is largely by leaving the network layer location privacy / initial authentication / key exchange problems out of scope.)
Finally, traffic analysis is pretty powerful. Even if Eve can't read your messages, she can see who they went to and when (and maybe who they in turn communicated with afterwards) and thus easily determine probable relationships - Tor based endpoint, or not. (Hrrm ... but two Tor based endpoints, on the other hand...)
"Secure" in this context means "not readable by anyone but the recipient". Of course, if you have the recipient in custody, this is the easiest method to decrypt the messages: http://xkcd.com/538/
(OTR-style cryptography is nice, but sucks for store-and-forward communication; for a comporably difficult message to decrypt more than once, use one-time pads - but don't complain to be about distributing the pad dictionary, that's totally out of scope here ;)
https://github.com/crised/SafeGmail
No good (edit: stable and drop-in) Firefox tool yet.
The very nature of e-mail leads me to conclude that it really doesn't matter where an e-mail provider is located, because it will always be intercepted at some point. One can use another e-mail service, but if the people you talk to still use gmail, then does it really matter?
Perhaps it's time to talk about new messaging systems, with encryption by default, and a new address and routing system coupled with Tor.
Bitmessage is up and coming, but needs a lot more development.
You could use OTR with servers for offline support and contact management (jabber, etc), but this isn't as convenient as email.
OTR (instead of PGP) over email is a theoretically possible, but the problem is still the same: No money in open source encryption == No easy to use interface.
It would be interesting to setup a mail service with numerous SMTP relays around the world and attempt to connect the "closest" (least likely to be eavesdropped) relay to 3rd party SMTP servers. Communication between the relays and the main service (which stores your email in a friendly jurisdiction) would be strongly encrypted.
> American company…
Then, noticing the critical error, the GP said:
> Fastmail is owned by Opera a Norwegian company.
Replying to the American company part.
> You said: Their servers are located in the US according to the article.
So, the servers location have nothing to do with whether the company is American or not. And while that might have a bearing on certain facets of the topic as a whole, it's meaningless in this context. Basically, what you said does not change anything.
As in, the actual point, which is that your e-mails are liable to be searched by the NSA.
Correct me if I'm wrong, but if Fastmail moved servers outside the US, then it would be in a better position as a non-US company than if it was a US company with servers outside the US?
Despite what some might believe, where a company operates from is actually important, regardless of where the servers are hosted.
Believing that it being an American company or not is not important is silly.
http://www.huffingtonpost.com/2012/05/29/facebook-opera_n_15...
People are operating on the equation of "hosted in America = possibly accessible via PRISM = compromised by the NSA," which is understandable given all the recent news. Perhaps you don't trust the assurances that the NSA's computers are only scanning metadata by default, only flagging suspicious keywords that then have to be processed by a human agent before they go ahead and actually start scanning your real email which of course they will usually only do with a warrant obtained in secret from a secret court that pretty much never turns down any warrant request!
Okay, but those very reassuring reassurances actually only apply to American servers. Communication going between servers in America and international servers is just as likely to be targeted and quite possibly more likely to be subject to deep scanning. We have to throw in "likely" and "possibly" because, as with all things NSA, we really don't know. But if you're concerned about data interception, it's very likely not relevant whether FastMail's servers are located in New York, Norway, Australia, or the Fortress of Solitude.
India -> US -> Japan -> US -> Japan -> Singapore
I'm not saying that the NSA has forced other countries to route their data through them. It could be due to several other reasons. But the main point is that it is hard to escape the NSA. Even if you do your best to keep your data away from the US, there are certain factors out of an individual's control (such as routing).It's still not ideal (they can still see who you're talking to), but you'll never have 100% privacy. Just make as much of the data useless as possible.
You do unless you're using PGP for all your emails, because SMTP can be easily intercepted in plan-text.
Of course, if you're using full end-to-end encryption (like PGP) for all your emails, you don't care so much about using HTTPS to fetch them, because you're using end-to-end encryption.
My Azure IP shows up in Seattle, yet the connection goes to Amsterdam. What you're seeing is where the owner of the IP is located; that is not necessarily the same as the server.
Privacy laws vary a lot within Europe - even within EU - and while I'm sure every country in the world is "happy to spy", as you put it, I can't think of any European country save for the UK whose spying is as intensive as NSA's.
http://www.lemonde.fr/societe/article/2013/07/04/revelations...
http://www.maxmasnick.com/2013/07/19/fastmail/#fn:1 "This may be a deal breaker if you’re concerned about government spying. "
I believe that Fastmail is a valid option if your main problem is with Ads and the fact that Google might be reading all your mails and companies are buying this big data to sell you better services / more targeted Ads around the web.
I'm currently switching to Fastmail because I don't believe in free lunch and I won't stand for it anymore.
If I want to make sure no one is reading my mails, then I have a problem. Most governments are doing this and we can't do much about. If I need privacy, then I use GPG.
No functional difference for me, and I save some bills. I don't consider it a free lunch, either, since I basically pre-paid when I bought my iPhone.
"> I feel safe in speculating that if you will not pony up the emails to a US judge, the people who maintain the server farm here in the US will.
They can't - they have no access to the emails, because they can't login to the machines and they can't access the encryption keys for the data. All maintenance of the OS/software is done from Australia.
We've had a number of US-based law enforcement bodies over the year try to get hold of our data without going via the appropriate Australian bodies, and it doesn't work out for them. In the end, they have always ended up submitting a request for cooperation via the Australian Federal Police, as they are required to do, and we respond to that request in line with Australian law."
2009 Slashdot.org Interview with Howard Jeremy, Founder of Fastmail
http://tech.slashdot.org/comments.pl?sid=1391605&cid=2963395...
https://news.ycombinator.com/item?id=6037235
From the article:
"The contract was prompted by Telstra's undersea telecommunications joint venture called Reach. When it sought a cable licence from the US Federal Communications Commission, the DoJ and the FBI insisted on a binding security agreement.
"The contract does not authorise Telstra or law enforcement agencies to undertake surveillance. But under the deed, Telstra must preserve and 'have the ability to provide' wire and electronic communications involving any customers who make any form of communication with a point of contact in the US, as well as 'transactional data' and 'call associated data' relating to such communications."
. . . .
"The document was signed by Douglas Gration, a barrister who was then Telstra's company secretary and official liaison for law enforcement and national security agencies. "He told the Herald he could not remember much about the agreement. 'Every country has a regime for that lawful interception,' he said. 'And Australia has got it as well.'"
This looks like a pattern of mutual agreements among governments that cooperate in routing and connecting cables for international telecommunications. The statement is NOT that every telephone call from Australia to another country is listened to, but that a data archive is maintained that might be accessible with court orders. Particularly significant is the statement that other countries ask for the same arrangement if a cable connects to or through that country.
Switching email providers has little to do with what governments have access to your data by mutual agreements among the governments.
Deleted comment
Deleted comment
However, I am pointing out something that a lot of non-US citizens on HN have been saying lots over the past few weeks; setting up an email service that is outside the US (for the purpose of trying to avoid PRISM surveillance) is nontrivial, and while it would be great if this app were the answer to that, it sadly isn't.
I'm all for the US justice system doing what it's supposed to and having the supreme court rule on the constitutionality of PRISM! Then it will no longer be valid to generalise that all US-hosted services are bad news for privacy.
On the other hand, if you have specific counterparties and you can get them to switch to the same thing you're using, just use TorMail, or run a VPS somewhere where you both have SSH keys and use it as a dead-drop, or whatever. "The solution must involve SMTP and POP/IMAP" is only relevant when you're communicating with unauthenticated peers... at which point, you'd better not say anything important anyway. ;)
If noone is standing up for the constitution anymore, then the legislature + executive have taken control.