FastMail’s servers are in the US – what this means for you
blog.fastmail.fm
blog.fastmail.fm
> These are not things we can protect against directly but again, we can make it extremely difficult for these things to occur by using strong encryption and careful systems monitoring. Were anything like this ever to happen we would be talking about it very publically. Such an action would not remain secret for long.
> Ultimately though, our opinion is that these kinds of attacks are no different to any other hacking attempt. We can and will do everything in our power to make getting unauthorised access to your data as difficult and expensive as possible, but no online service provider can guarantee that it will never happen.
This kind of frank disclosure should be highly rewarded. I provided similar frank disclosure text (elsewhere) only to have it whitewashed.
When everyone is underplaying the real limitations it's impossible for people to choose alternative tradeoffs— "Why should I use this slightly harder to use crypto thing when foo is already secure?"— because the risks have been misrepresented. Underplaying the limitations also removes the incentives to invent better protection— "Doesn't foo already have perfect security?".
Yep, definitely. I think even more important than the information itself is the spirit of honesty and integrity that it demonstrates. This stands in stark contrast to the ambiguous slimeball statements issued by the likes of Google, Facebook, Apple, Microsoft, etc.
When Big Brother comes knocking, which companies are going to take a risk to stand up for you? It's as much a question of character as policy.
I would argue that if FastMail were an USA company their statements (if any) would be just as ambiguous as those of G, FB, A and MS.
Yet could, e.g, Google Ireland Ltd do so, by some interesting twist of laws?
Remember how quickly SOPA sank after the Silicon Valley establishment turned against it? Do you think the government is going to put the CEOs of some of America's most popular and profitable companies in jail for an act of civil disobedience that the majority of the country and the world would support wholeheartedly?
SV is more powerful than it realizes, and has little to fear in the current climate. The American national security state, on the other hand, is weakened and vulnerable. Now is the time to take a stand. Not doing so is equivalent to complicity.
The NSA is a 60 year old spy agency at the heart of the national security infrastructure and government.
You are comparing two entirely dissimilar things.
Also, how exactly is the American national security state 'weakened and vulnerable'?
At the moment, there are many people shouting for them to be shut down. Will it happen? Probably not. But at the moment, that is something for the NSA to worry about and to try to do damage control over. In that sense, they are certainly in a quite worse position.
The US Government operates on an extralegal basis (ie they're willing to cross any line), and roughly 85%+ of all new debt is purchased by the Federal Reserve. What very specifically is not going to happen, is the shut down of the military industrial complex of which the NSA is such an integral part.
So long as the dollar (Federal Reserve Note I should say) remains the global reserve currency, the national debt is a trivial problem (as is paying the interest on it). The dollar is the real linchpin, to everything. All else is a sideshow of political gamesmanship.
If a credit card company refuses to raise your limit, that is not a default. A default is when you stop making payments on your debt. As long as the government has enough tax income to pay interest on its debt, there is no default. Calling it a default is a scare tactic to get their credit card limit raised.
The solution is for governments to spend only the tax revenue they receive - no more. Not only should the debt ceiling not be raised, it should be slowly lowered to zero over the next 10 years. If the government had to explain to everyone how much their taxes would need to be raised in order to invade Syria, etc., people might actually pay attention. Just my opinion.
If the US wanted to instantly achieve a balanced budget, they would have to spend 3/5ths the current amount. When a government cuts the amount it spends, it shrinks the economy, and reduces tax take.
In the UK, a limited form of this strategy seems to be working, but in Southern Europe, a strong 'austerity' strategy is creating a spiral of reducing tax take (requiring ever greater cuts).
So the sharp reduction in the deficit you mention is not possible. It would need to be gradual.
The elephant in the room is that, in the US, China, and Europe, the aging population is coming. As the proportion of contributors to consumers of public spending shifts, more debt is inevitable. It's going to suck pretty bad for everyone, but if we (all of us) can't achieve a balanced budget before that hits, then things are not going to be as gentle.
Currently government isn't able to pass a "normal budget" much less a very radically changed budget + huge and rapid changes in government agencies - if USA doesn't rise the debt ceiling, the actual effect will be not paying the interest due which is called a default.
I think it's already been established that the NSA has HUGE financial resources (from the part that we can tell) and to top it all off, fighting the NSA on it's grounds would most likely pass through the FISA court. A court which in and of itself, is shrouded in secrecy.
Also, this: http://www.nbcnews.com/id/12727867/#.UlKlY2RtVOg
It would be interesting to see what would actually happen if one of the big American internet companies just said the truth. "We have received 35 NSL's and we gave them your data."
What would actually happen? Would their stock go up or down? Would they gain or lose customers? Would anyone be prosecuted and jailed?
If you support the rule of law, you should expect and demand that if it comes to legal consequences that's exactly what will happen. You can fight the law in parallel and use the trial to challenge it, but expect the consequences anyway. Otherwise you're calling for the rich and powerful to be held to a different, weaker standard just because in this case you might like the outcome.
You can treat it as the lesser evil, acknowledging that they're already held to weaker standards and that happens to be useful here, but you'd still be helping to entrench a system which is ultimately bad for you unless you're also very rich.
Those companies, being a huge influence on the internet culture and economy, a trend-setter, one might even say the internet gatekeepers - I think they not only should disclose and vehemently oppose any attempts on user rights, but it is their moral obligation to do so.
How is it that individuals and small parties are scrutinized and put down for a single misstep or a character flaw, while enterprises are forgiven, or worse - go unnoticed, for systematic violations of our rights.
Also, keep in mind, that being a big business like Google, inevitably puts you in a close proximity to government and politics. One thing is certain, they do not lobby on our behalf. Though they could. If Google and other giants had a moral compass resembling one of Lavabit or FastMail, perhaps PRISM would fail or never happen.
Keep in mind that these companies' only obligations are to their shareholders.
Also, who is to say that moral behavior isn't in the long term interest of shareholders?
Your statement is mostly true but completely hollow. Just because your primary obligation is to your shareholders doesn't mean you go along with (arguably) illegal acts committed by your government that run counter to your users. Because if you do that long enough, your users will leave and you will have screwed your shareholders in an attempt to look out for your shareholders.
This is why your comment is hollow. Because it attempts to excuse any behavior that provides short-term gain regardless of mid-term or long-term pain.
http://www.washingtonpost.com/blogs/wonkblog/wp/2013/09/09/h...
If Snowden, an individual contractor, can dive deep into the data how do we know that others are not doing the same for other purposes?
With all due, Im sorry but, no.
Had it come before the Snowden leaks, absolutely. But it didn't.
After the event, facing a danger of customer loss or loss of confidence, it can only be seen as too late and defensive move. All these companies must have known something about these risks, yet remained in a passive conspiracy of silence. Not one stood up until Snowden did. By then, too damn late.
What you say may be applicable to the big players, but not to the smaller ones.
http://blog.fastmail.fm/2013/09/25/exciting-news-fastmail-st...
You are assuming they were cooperating with the NSA behind the scenes like Google et al, but they are saying they were not and could not be compelled to do so by Australian Law.
https://news.ycombinator.com/item?id=6506711
In short, don't expect that you can get any advantage from FastMail being Australian company -- you can even be worse off.
The problem is that for most services, it is hard to tell where the company is from and where they are hosted, unless you're technical enough to run a traceroute. At StartHQ we've been trying to make that easier to find for non techies and the fact that FastMail host in the US became quickly apparent via their app profile page when we first added it: https://starthq.com/apps/fastmail - there was a pretty lively discussion on FB about it at the time as well.
If I don't trust (say) the Russian government, it is more secure to put my hosting in Russia? Nonsense.
You can for example trust the Finnish government not to look at your data or let other governments do the same. A number of companies here in Finland are emphasizing that point in their marketing nowadays.
When they actually have a security breach and they promptly "[talk] about it very publicly", that will be something commendable. Right now we have words, not actions.
Though honestly I'd much rather have such words than not.
This is not true. The Australian Crime Commission has some of the most extensive secret coercive powers in the Western world.
http://www.austlii.edu.au/au/legis/cth/consol_act/acca200228...
I would suggest that either:
a) Fastmail is aware of this and is covertly spreading the word that it might be compromised; or
b) Fastmail needs better lawyers.
But then, I'm not lawyer. You're probably not either. Which is why I keep telling people to get their own legal advice if they're concerned about it.
Needless to say I was staggered at the scope of the powers granted. Forget about transparency, justice and the rule of law. If you receive one of these you can be compelled to give evidence or documents in secret, without judicial oversight or public scrutiny.
A year of incarcerating someone is only worth $3,400 to the government? Strange, considering that if you're going to be pedantic about money, the cost of incarceration is surely at least one order of magnitude more than that.
It seems to me that this kind of thing is for investigations where they don't want suspects to know they're being investigated, which is fair enough. It doesn't seem like they're doing it to keep secrets for "National Security".
- ACC has judicial oversight
- its unclear how this interacts with the Telecommunications (Intercept and Access) Act
With my boss throwing in:
- law is a giant mess
- until you have two extremely well-funded parties disagreeing vehemently about the interpretation, you'll never get a final answer
We're still happy with our publicly-stated position. You might disagree, and I'm not really in a position to argue with you. Its my corporate masters with their necks on the line, and they seem relaxed about it. That's good enough for me :)
But these laws have been active and in common use for over 10 years without a single public challenge. I also know that the ACC's interpretation of their own powers has been used to prevent suspects disclosing certain matters even to their own lawyers.
The fact that no high-profile judicial decisions have placed limits on what the ACC does indicates to me that the law is fairly settled in this area.
I just wanted to point out that the original statement "Australia does not have any equivalent to the US National Security Letter, so we cannot be forced to do something without being allowed to disclose it." does not seem well-founded.
But now reading this exchange I now see that your company doesn't actually know the Australian law any better than it knows the US law, and now I feel that fastmail might actually be WORSE than a US company in terms of privacy. Thanks for letting us know.
The title of this post should be changed to:
FastMail’s servers are in the US – what this means for you -> absolutely nothing.
I'm not calling you a liar, btw, I just think you're naive/oblivious, and considering you just now discovered what ACC is and had to check with your lawyer (who isn't even sure how it interacts with other laws), I wouldn't use your service to send any critical information. Ever.
We have no doubts either. The privacy policy clearly states we will give your data to the Australian authorities if supplied with the proper supporting documentation.
I didn't just find out about the ACC, though I wasn't aware of the details. But I'm not a lawyer, just a sysadmin, so I don't need to be. The "its not clear" bit is simply that there are two laws that appear to be in contradiction with each other. Its never been tested in court. And thus, its not clear. But we have confidence that what our position is legally supportable or we wouldn't be here.
[0]http://www.ag.gov.au/NationalSecurity/Counterterrorismlaw/Pa... [1]https://en.wikipedia.org/wiki/Anti-Terrorism_Act_2005
Just so we're clear, the point of this post was not that we don't think the rules don't apply to us. Instead we're trying to make it clear where position on these things are. The topic of this thread is a sensationalist sound-bite, nothing more.
I'm not going to go over the points again here because I'm pretty sure we said it all in the post (but ask questions if you like, I'll be here all week!).
The most important point to take away from this post is that your privacy is your responsibility. We're trying to provide you with as much information as we can to help you determine your own exposure, and to let you know what we will work to protect and where we can't help. Its up to you to determine if our service is right for you. No tricks, and no hard feelings if you'd rather take your business somewhere else!
Has the headline on HN been updated? Because both you and brongondwana talk about it being sensationalist, where I see it as just being a summary of the most salient part of what you have to say.
Do you have Australian legal advice to back up your conclusions? (I agree with them, but would like to make sure we're talking more than the "gist" of the law)
To my mind it was one of the least interesting parts of what we had to say. "Non-US company not bound by US law" - its hardly earth-shattering news. Would "Non-Senegalese company not bound by Senegal law" be as interesting?
EDIT: Sorry, it just occurred to me that it was changed already and you might have posted this afterwards. The original post headline was "FastMail claims they do not have to comply with National Security Letters". That's what we were referring to when we said it was "sensationalist".
> Do you have Australian legal advice to back up your conclusions? (I agree with them, but would like to make sure we're talking more than the "gist" of the law)
We've made our position public, and we're satisfied that its an accurate reflection of our position and our understanding of Australian law. You must not rely on it as a legal basis for anything though - get your own legal advice that applies specifically to your own circumstances!
I've mentioned it elsewhere but it's worth repeating here. Finding established case law dealing with foreign assets seized (possibly illegally) on US soil and the repercussions would make for an interesting exercise. I feel like there's one instance in particular that was especially noisome that happened recently, but I can't for the life of me remember what it was.
If you don't mind my asking, what contingencies do you have in place in the event of a seizure of hardware assets? It's unlikely, but the FBI has been known to take anything that vaguely looks like a server...
This would be a catastrophic event, no doubt about it, and there would be significant disruption for our users. But it wouldn't mean the end of FastMail.
Bootstrapping from that would be significantly more painful though, and a lot more "gappy".
"We've made our position public, and we're satisfied that
its an accurate reflection of our position and our
understanding of Australian law. You must not rely on it as a legal basis
for anything though"
I'm not sure if I see the value of you saying it, then. Why not get a lawyer to provide you with a position that can be relied upon?Or put another way, I don't think "Your Honour, FastMail's lawyer said it was ok" is valid defense for anyone except us.
My point is that you have given advice, with the implication that it would soothe some of our concerns. And then, in the very next sentence, you've said, in effect, it's legally worthless.
So, how exactly does your own advice to us help in any way whatsoever?
So, the point remains: what value does this advice have over against the advice from Google, etc? It's a rhetorical question, by the way.
We have been contacted by Australian authorities in the past, and have worked with them in accordance with Australian law and our privacy policy, which you can read here: https://www.fastmail.fm/help/overview_privacy.html
"There are of course other avenues available to obtain your data. Our colocation providers could be compelled to give physical access to our servers. Network capturing devices could be installed. And in the worst case an attacker could simply force their way into the datacentre and physically remove our servers."
As the colocation providers are based in the U.S., they would be subject to the National Security Letters. FastMail claims this is no different from any other hacking attempt. But in a normal hacking attempt, colocation providers would be free to explain to FastMail the extent of any hacking on their end. Moreover, hackers typically do not have physical access to any data. Even with encryption, physical access opens up a lot of attack vectors that most sysadmins don't anticipate.
A Free/Open HSM design would go a long way, along with more host-based trusted computing security (Intel SGX, etc.). But just physically controlling the surroundings is probably the only feasible option today.
Nobody really builds systems where an HVAC engineer walking into your cage to move a cooling tile will cause an outage, they just love to talk about how they would build them.
I wonder how many "sorry, the hairtrigger anti-intrustion systems took the site down" outages it would take before people begged us to turn the sensitivity down.
> We use encryption to make hard drives worthless if they are stolen or just misplaced. [1]
[1] http://www.emaildiscussions.com/showpost.php?p=561920&postco...
Anything that makes hard drives unreadable by thieves would probably also make them unreadable by any U.S. agency that seizes them. Unless of course NSA has already broken the algorithms used by the disk encryption software.
It's much easier to compel operators to do something (through legal threats or potentially physical threats) than it is to do any active modifications to a complex system, undetectably. Passive ubiquitous monitoring is a concern because it's passive and thus hard to detect -- it's highly unlikely TAO can go after a large number of well-defended systems without getting caught. Obviously they'd be likely to hide their actions behind HACKED BY CHINESEEEE or something, but even then, it's relatively rare to have a complete penetration of a large site in a way which isn't end-user affecting, and rarer still for the site not to publicize it.
That said, if I wanted to compromise Fastmail, I'd either compromise a staffer or some of their administrative systems to impersonate staff.
Look at what they did to megaupload.com.
http://www.listener.co.nz/commentary/the-internaut/kim-dotco...
As I said in a response on our forum, if the stakes are high enough, no datacentre in the world is safe.
Bruce Schneier recommends protecting against terrorist attacks by improving emergency response capabilities - with the side benefit that your measures also help against natural disasters:
https://www.schneier.com/essay-292.html
(edit: that's not a great version of his point actually, https://www.schneier.com/blog/archives/2005/09/katrina_and_s... is more on point)
Similarly, our main focus for security is protecting against all forms of attackers, including common theft or misplacement of our servers. We consider that to be more valuable for the overall security of our users (including security against denial of service) than fighting an impossible fight.
FACT: if the three letter agencies in the USA want your data desperately enough, they will get it. With FastMail, they have a legal way to obtain it which is quite a lot of effort, but (hopefully) less expensive to them than taking our servers offline.
What they can't do, by Australian law, is require our cooperation in blanket surveillance on all our users.
The stakes being relevant to US that is.
And, my initial response to seeing this headline: "Oh, _yes_ you do."
That's a very small part of a lot of what we have to say, most of which is:
* we can't be compelled (under current laws) to install blanket monitoring on our users
* we can't be compelled to keep quiet about penetration that we notice
* there are always risks, including the risk that any random group knows unpublished security flaws in the systems that we use
We have written some things about techniques we use to reduce those risks (physically separate internal network rather than VLANS on a single router for example) - these help protect against both government AND non-government threats. But we can't make those risks go away entirely.
What we're saying is - the physical presence in the USA only changes one low-probability/high-visibility threat, which is direct tampering with our servers.
Regardless of the physical location of servers, we would still comply with legally valid requests made through the Australian Government.
It is our belief and hope that this process is difficult enough to mean that US agencies only ask for data when they have good cause rather than "fishing" - but still easier than taking our servers and shutting us down, with all the fallout that would cause.
This in combination with FastMail being acquired by its former employees, coupled with their investment in CardDAV and CalDAV, makes me really excited about them. I was actually looking for a good replacement to Google Apps and FastMail might be it. It's still a little expensive though, compared to Google Apps, I hope they'll bring those prices down just a little.
Mind you, theoretical-Snowden is already screwed at this point, regardless of where his mail is. No reason to believe any European country would be susceptible to pressure:
http://www.bbc.co.uk/news/world-latin-america-23174874
Or maybe there is.
Which comes back to the point I've been trying to make all along here. In the most serious extreme, nowhere in the world is "safe". In a less serious case, nobody's going to invade NYI with jackboots on. The window between those two cases is where being not-in-USA could theoretically save us from having our servers snatched (assuming said jackboots weren't willing to just wait for the Australian Government to order us to hand the data over)
I realize that even if the servers were in Norway, an email from a FastMail user to a gmail.com account would still be read by the NSA (because it would pass through American servers), but email sent from FastMail to other email hosts in relatively safe countries would not be read by the NSA.
http://blog.fastmail.fm/2013/09/25/exciting-news-fastmail-st...
'Which comes back to the point I've been trying to make all along here. In the most serious extreme, nowhere in the world is "safe"'
Do you have any suggestions for countries that have excellent data connectivity, would successfully resist pressure from US/UK/X authorities to hand over our servers, and at the same time would not themselves want access to?
As for whether or not they want access to data: There's nothing wrong with governments accessing data if there's a court order in place and their request is part of an investigation. It's the automatic surveillance of everyone that NSA does that's a problem, and it's certainly not all countries that do that.
In the most serious extreme, nowhere in the world is "safe"
Sure, but there are levels of safety, and the US has turned out to have a low degree of safety for a Western country. The fact that you probably can't find a perfect country shouldn't be an excuse to pick a notoriously unsafe one.
"We have a complete live-spare datacentre in Iceland. Eventually it will be a fully operational centre in its own right, but for now it’s running almost 100% in replica mode."
I'm not so sure about the safe-haveness of Switzerland these days. They already caved to the US, giving them access to banking info (what they're famous for... which leaves me wondering what Switzerland got in return):
http://uk.reuters.com/article/2013/08/28/uk-switzerland-usa-tax-idUKBRE97R0CY20130828Let me know when that happens and I'll gladly sign up for your service :)
I'm not so sure about the safe-haveness of Switzerland these days. They already caved to the US, giving them access to banking info (what they're famous for... which leaves me wondering what Switzerland got in return):
I don't see how bank secrets have anything to do with Internet surveillance. There's a general tendency now both in the US and the EU to pressure tax havens such as Switzerland, Andorra, the Bahamas, etc. to give up their bank secrets so that corporations and rich individuals can't hide their income and avoid paying taxes. That seems fair enough, and I don't see a direct link between that and Internet surveillance.
Next time I'm out shopping for email services, I will give my moeny to them! (And, to give something back for all the Tim Tams brongondwana brought with him to Norway ever time he was on a visit ;) )
Wait, I meant email... ;)
So maybe they don't get the NSL, but the people/group/company that is handling the servers might. This seems disingenuous. I could be wrong, but it feels like they are making claims that will dupe people into their service because they feel safe.
> There are of course other avenues available to obtain your data. Our colocation providers could be compelled to give physical access to our servers. Network capturing devices could be installed. And in the worst case an attacker could simply force their way into the datacentre and physically remove our servers.
well they do say explicitly that, near the bottom. Hardly disingenuous.
Unless you're using PGP or S/MIME, SMTP is still most often unencrypted.
So FM should move their servers out of the US even if that's inconvenient.
"Our colocation providers could be compelled to give physical access to our servers."
But in the very next paragraph: "These are not things we can protect against directly but again, we can make it extremely difficult for these things to occur by using strong encryption and careful systems monitoring. Were anything like this ever to happen we would be talking about it very publically. Such an action would not remain secret for long."
Its not hard for a skilled sysadmin to take an image of a running server. Its extremely difficult to do it without administrative access to the machine AND to do it without anyone noticing.Why would you do that, especially when you're not even a US company?
Why New York rather than West Coast - that's a trickier one. I'd certainly appreciate the slightly faster pingtimes, but it would be slower for Europe.
I think a major consideration is that we found a really good datacentre with NYI, and we're sticking with them because they're incredibly reliable. Reliability matters in this business.
There are tons of downsides to shutting down everything that's working well in a knee-jerk reaction to one possible risk - never mind that the government of whatever country we choose could very well cooperate with the same agencies we're running from - or they could just corrupt an employee of the datacentre we're in - or...
So maybe if you're going to put words into our mouth you could put ones about how much we care about our users and our reliability that we don't jump on unproven setups just because of a single (unchanged, just more public) risk.
FYI you have about 1.5 hours to edit your post. You may want to do that, because otherwise it will probably scare off most informed potential customers who read it.
> FYI you have about 1.5 hours to edit your post. You may want to do that, because otherwise it will probably scare off most informed potential customers who read it.
(The above post was, curiously, edited very slightly before I was able to reply.)
It's possible brongondwana is taking some of the discussion here personally, but most people invested emotionally in their company are going to feel some need to defend their decisions against criticism they see as invalid or misplaced. I can't help but feel that some of your post is also somewhat emotionally-charged. I apologize if I'm misreading it.
Regardless, to play devil's advocate, both of the FastMail employees have a point (I also fail to see how they're being "mean;" maybe it's a cultural difference?). While they may not be a huge company with a great deal of leverage with the right government officials, I think such criticism levied against them is indeed kneejerk and perhaps a touch myopic. It's ignoring the greater story at large, which is the souring of US policy abroad, particularly among our allies. As an example, an enterprising Australian politician who wanted to make a name for his or her self could certainly take any such incidents against FastMail and use them as political leverage.
I can only imagine just how incendiary such headlines might become: US Seizes Australian Servers in NSA/FBI/Scary-three-letter-name US Agency Sting Operation. That'd go over real well, especially among Commonwealth nations.
I would submit to you (and others) that the best means of debating this would be to research case law and find examples where US courts upheld government actions against foreign assets held or based in the US. IANAL, but I can't help myself from thinking that such a foundation would be much better than accusing one side in particular of being "mean."
I think if that were to happen, it would be another nail in the coffin for the "US cloud".
From www2.itif.org/2013-cloud-computing-costs.pdf
"The U.S cloud computing industry stands to lose $22 to $35 billion over the next three years as a result of the recent revelations about the NDA's electronic surveillance programs"
I'm guessing people are assuming Europe as the bastion of all things good here. Certainly it's more affordable for hosting than Australia, and more reliably connected than anywhere else.
A more realistic scenario, if we had the budget for it, would be to buy a duplicate set of hardware, install it in the theoretical new location, duplicate all the data, grandfather everything running at NYI.
This would be a process that would take months or years of real time as well, plus quite a lot of admin time. Just duplicating all the email, well - I did it recently, I carried an almost full set of backups on encrypted hard disks from New York to Australia (the key was only ever in tmpfs on the host in New York, copied in over ssh inside a VPN link, and all copies nuked and the server rebooted and reinstalled before I left New York) Even filling those disks at the maximum IO rate we could sustain took over a week - and unpacking it at the other end would take as long again.
All this for theoretical security against one of very many risks we face. It is my considered opinion that we can get better return on our security investment (both time and money) in other ways than scrambling to get everything out of the USA.
And "emails being read by the US Government" is only one of very many security threats. We could make our users' emails VERY secure by putting all our servers in the shredder - it might reduce uptime and recoverability of data somewhat...
... so I'm hoping most informed potential customers understand that there are other risks in the world, and we balance our defenses amongst the various risks.
Throwing away everything that's good about our New York hosting in exchange for maybe being more secure against one particular risk is not a decision to make lightly, your assertions nonwithstanding.
As others have noted, I would consider Fastmail if servers were located in a country with greater respect for privacy, judicial oversight and rule of law.
This is why I use a email service in Norway (runbox.com), which, as far as I know, is not sharing information by default.
http://theforeigner.no/pages/news/updated-parliament-passes-...
Norway isn't some magical safe haven from legal data requests. We receive law enforcement requests through the Norwegian system for mail.opera.com users (which, despite running on the same infrastructure, is operated under Norwegian law, not Australian - isn't life complex)
http://en.wikipedia.org/wiki/Telecommunications_data_retenti... tells a few interesting stories.
Australian law may indeed change, and we'll be compelled to update our policies to match. So far, we've avoided it.
http://www.smh.com.au/technology/technology-news/government-...
FastMail has been using opportunistic encryption on their incoming and outgoing SMTP servers for years. If you send an email to another service that does opportunistic encryption, and if both the sender and recipient uses SSL to access their mailboxes (as FastMail requires), the email will never be transmitted in plain text over the Internet.
With opportunistic SMTP encryption this will cause things to proceed in plain text. The sinister thing about this is that e-mails still flow, so it still works.
We're currently investigating it.
I can see I'll be spending some time on this in the next few days!
My current side-project involves a RaspberryPi (sitting in my loungeroom on my home ADSL connection), iRedMail, full disk encryption, a handful of inexpensive VPS providers with APIs that allow automated provisioning (DigitalOcean, NineFold, and Hetzner – to spread out the jurisdictions) – with the RasPi opening a reverse SSH tunnel for ports 25 and 465. Add in a DNS provider with a useable API so the 'Pi can spin up and shut down VPSes itself and update MX records to suit, and VPS images configured to not log anything mail-related, and I think I've gone as far as I can to secure my end of all my email. Having physical control of the hardware/storage that my email relies on won't protect me against NSA level targeted-at-me snooping, or even local law enforcement with sufficient "probable cause" to get a judge to sign a search warrant, but at least I'll _know_ if someone grabs my server hardware. (Hmmm, I wonder if there's some NSL-type coercion that could be used against my partner to force her to let someone take/image my 'Pi while I'm not home, and not be allowed to tell me?)
Possible over-paranoid ideas include refusing port 25 smtp connections that wont negotiate a secured connection in response to a STARTLLS command, and possibly blacklisting mail originating from any of the 8 known PRISM collaborators. I like the _idea_ of ensuring none of my mail arrives from known-intercepted sources, but reality dictates otherwise since way too many of the people I really do want to communicate with are exclusively using gmail/yahoo for email (or worse still, have migrated largely to Facebook messaging instead of email).
Meanwhile, does SMTP have something like HTTP Strict Transport Security? It would be nice for an impartial party to compile a list of mail servers that pledge to accept encrypted connections, and for sending MTAs to treat it as a connection failure if the destination is on that list but doesn't appear to support encryption.
( http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/produc... for anyone who wants details… )
(Ianal, ianaa, but I am pretty sure I am correct on this point.)
Just sayin'.
Hmmmmmmmmmmmmmmmmmm.