HNHacker News
TopNewBestAskShowJobs

nmjenkins

1,587 karma · joined April 26, 2012

submissionscomments
nmjenkins··on Improved fraud prevention with Radar 2.0
(I work for FastMail) We charge in USD, but the payment is processed in Australia. For some reason, American banks often block all payments processed outside of the USA; it's like they haven't heard of the concept of the internet and global trade…

We don't see this problem with banks in any other country (not do I ever have the problem in reverse, buying goods and services from foreign websites with my Australian credit card).

nmjenkins··on Google is testing expiring emails in the new Gmail
(Editor of the JMAP spec here.) We at FastMail are using standard IMAP/POP/SMTP, which we offer to all our customers to access their email. In addition, we have invested a large amount of time and resources in R&D to design a next-generation client-server sync protocol based on our deep experience with email. While we could just use this ourselves, we believe an open internet built on standards is healthiest for everyone in the long run. That's why, once we felt we had a solid foundation, we took this work to the IETF where a working group was formed. The spec has evolved considerably since then based on the feedback of many other experts in email from both the open-source and commercial world of email vendors.

The spec is now nearly complete and we expect standards-track RFCs to be published later this year. Adoption will then happen slowly over time, as it did with IMAP. Smaller, more nimble companies are likely to move first and then larger companies following later. IMAP took many years to get widespread adoption; I hope we can make the move to JMAP a bit faster, but these things always take time (often measured in years!) to develop, test and release.

I love XKCD as much as the next guy, and of course it's kind-of right, but also too cynical: the only other alternative is to not make an effort at all, and accept the status quo is the best you can hope for. We'd like to do better than that. If we fail, at least we know we tried.

nmjenkins··on Stride, Atlassian’s Slack competitor, opens its API to all developers
https://topicbox.com – as Slack is to IRC, Topicbox is to mailing lists.
nmjenkins··on How to Run Your Own Mail Server (2017)
Do you really use both Dovecot and Cyrus? Which one do you use for what?
nmjenkins··on Overture JS – A powerful basis for building web applications
Well you must have updated the whois data or protection options with your domain registrar at the same time, whether intentionally or not. FastMail is just hosting the DNS. It cannot have any effect on your whois data.
nmjenkins··on Overture JS – A powerful basis for building web applications
Hello, primary author of Overture here. Wasn't expecting someone to link to this old site again!

Anyway, a few quick points. Overture is the basis for both the FastMail (https://www.fastmail.com) and Topicbox (https://www.topicbox.com) web apps and really does provide a great basis for building large, performant rich applications. However…

I do not recommend other people user Overture directly at the moment (although you might like to look at the code base for some useful ideas you can steal). We don't currently have the resources to build all the documentation, tutorials and other resources needed to build a community around it, and with that in mind we are currently not committed to non-breaking changes or semantic versioning (we can update our own apps at the same time as any breaking change). We originally open-sourced this when we were part of Opera, mainly so that if we parted ways and needed to build something new, we could still reuse all this code (it couldn't end up as proprietary Opera code!).

I'm happy to answer general questions here however if people are interested.

nmjenkins··on Ask HN: Fastmail 2fa via Google Authenticator useless?
(I designed the FastMail 2FA system)

Short answer to your question: no.

We are concerned with both keeping other people out of your account and making sure you still have access to your account.

For most users, the risk of losing their authenticator token or security device and so getting locked out of their own account is greater than the risk of someone hijacking their phone number. This is why we require you to add a recovery phone first.

It's very important to note that if you have 2FA enabled at FastMail we always require two factors to access or recover your account. Hijacking your phone is not enough: the attacker would still need to have also stolen your password. And hijacking your phone number is a very visible move, which you will quickly notice. In the highly public cases we've seen of this kind of attack over the last few years, I believe in every one the attacker has not had the password, and has only succeeded because they could gain access to the account with SMS alone.

For advanced users you can remove the recovery phone at FastMail after setting up 2FA. If you do this, I strongly recommend you write down your recovery code and store this somewhere safe and set up at least two different authentication mechanisms.

nmjenkins··on JMAP: A better way to email (2014)
Just as an update since then: a JMAP working group was chartered at the IETF a few months ago, and is working towards bringing the spec to RFC status: https://datatracker.ietf.org/wg/jmap/about/
nmjenkins··on Teller Reveals His Secrets (2012)
I remember reading this article a while back, and this phrase in particular stuck with me:

> You will be fooled by a trick if it involves more time, money and practice than you (or any other sane onlooker) would be willing to invest.

There's a strong analogy here I think with how computers are essentially magic: CPUs do very simple things just insanely fast, essentially investing way more "time" than you as a human could consider putting into a task.

nmjenkins··on Ask HN: How do you handle email servers?
FastMail doesn't charge extra for multiple domains, so for two users it's just $5 x2 = $10/month.
nmjenkins··on Adding a security key to Gmail
You can also use U2F on Firefox with FastMail.
nmjenkins··on Ask HN: Is there a powerful open-source Google Calendar replacement?
We (FastMail) have a solution to this. You can view the calendar in "floating time", in which we display every even in the event's own time zone. So you can see your Hong Kong events as they will be in Hong Kong, but your San Francisco flight will be shown at 00:50.
nmjenkins··on Paypal Horror Story 40k Frozen No Answers
No, Stripe doesn't support this unfortunately. Pin does though (an Australian Stripe competitor).
nmjenkins··on Cloudflare and FastMail: Your info is safe
Nailed it. I work on FastMail's web UI and we really care about latency mitigation; we know if we can make it fast with 300ms round trip times, it will be insanely fast for customers with shorter ping times.
nmjenkins··on Cloudflare Reverse Proxies Are Dumping Uninitialized Memory
We, FastMail, are not affected by this. We do not proxy TLS connections via any third party. We use CloudFlare for DNS distribution only, which is not part of this issue.
nmjenkins··on NIST’s new password rules – what you need to know
(FastMail developer here)

The issue was actually that we support many different protocols (not just mail) and some combinations of clients/protocols have had issues in the past (it might have been some FTP clients I think, but can't remember right now.)

Anyway, this restriction no longer applies as we now require server-generated app passwords for 3rd party apps: https://www.fastmail.com/help/clients/apppassword.html. So feel free to use as many spaces as you like in your password!

nmjenkins··on Android user locked out of Google after moving cities
We're not aware of any general issues like that. Please open a support ticket with the full details and we'll happily investigate: https://www.fastmail.com/action/support/
nmjenkins··on Ask HN: FastMail Alternative with Reseller Option?
Hi. I'm a director at FastMail. I'm very sorry to hear of your troubles, and I'd really like to follow up on the support tickets to find out what happened. I realise you may well have moved on by now and I fully understand that, but if you could post the support ticket numbers here we will definitely look further into the issue, whatever it was.
nmjenkins··on A practical security guide for web developers
The "Secure" flag has nothing to do with protecting against XSS. It protects against anyone who can proxy your requests (i.e. when you connect to dodgy wifi) being able to steal your session simply by injecting <img src="http://yoursite.com"> into any non-secure web page your request. That is a massive security hole and not theatre in the slightest.

The HTTP-only flag is less important but still useful. As I said, you're still in deep shit because of course they can make actual requests and if you think it's all you need to protect you then that's a problem. But there's still a difference between an attack that can be persisted, and one that gets interrupted as soon as the user navigates away from the page.

nmjenkins··on A practical security guide for web developers
This is not security theatre.

Secure => Attacker can't simply inject an img to a non-https version of the site and then intercept the cookie sent by the browser, therefore stealing the session.

HTTP-only => An XSS attack can't steal the session cookie. You're still in big shit, but it's much harder to persist the attack beyond the user closing the browser window.

nmjenkins··on Controlling the ‘referer’ header
Thanks, fixed (will be live in a minute or two). Should have double checked that rather than just writing it from memory!
nmjenkins··on The Secret of Immigrant Genius
Err… a quarter means 25%, not 15%.
nmjenkins··on Progress on JMAP, better standard for synchronising mail, calendars and contacts
This will be way too slow, and is not at all feasible on a device like a mobile phone where you want only the recent email cached locally, but want to be able to stream on demand the rest with minimal latency (so it appears to the user as though it's all loaded locally under ideal network conditions). The server needs to be able to sort the messages, calculate threading, unread counts etc.
nmjenkins··on Email made me miserable, so I decided to build my own email app from scratch
We have no speed problems using this in production at FastMail (we're kind of known for our speed in fact…). We use it at render time, both on desktop and mobile.
nmjenkins··on Why CardDAV took so long
You can turn this off in Settings -> Preferences -> Auto-save contacts.
nmjenkins··on A story about &lt;input&gt;
> The only way to keep non-numbers out of your number input is to cancel keydown events selectively

There's a much simpler way: monitor the "input" event, and whenever fired, do this.value = this.value.replace(/\D/g,'');

The user will never see anything they type other than numbers.

nmjenkins··on A story about &lt;input&gt;
> Why not just use text input? Because on iOS, `type="number"` is the only way to show the number keyboard

Actually, this isn't true. It will also show the number keyboard on a normal type=text input if you add a pattern="[0-9]*" property.

EDIT: Sorry, misread your comment; you wanted the decimal separator too. I believe that might be impossible to get without type=number.

nmjenkins··on Trix: A rich text editor for everyday writing
I mean things as simple as bolding a piece of text. The way to get the browser to do this for you is to using the document.execCommand method, but the results are inconsistent between browsers. Worse than that though is stuff like hitting "enter" on the keyboard – all sorts of crazy stuff happens (new <span> tags being added, nothing consistent between browsers, generally doesn't do what you want). We came to the same solution the guys at Basecamp have: you generally can't trust the browser to get you from state A -> B and have to do it yourself.

Probably the hardest thing to do is handle copying and pasting, partly because most browsers give you very little control over this, so you have to resort to terrible hacks. You also have to decide how much of the formatting in the clipboard item was "intentional" and how much should be cleaned. I see if you copy/paste just a word from within Trix, it pastes it as a whole block with the block's formatting around it. I suspect this may surprise many users who expect it just to copy the word (the inline bit, not the block around it in editor parlance). Once you start going down this rabbit hole, you end up having to do things like take one DOM tree and recursively merge the "edges" with the adjacent trees to get it to behave as the user expects. I think we do a pretty decent job with Squire, but I'm sure there are still more edge cases we haven't covered.

nmjenkins··on Trix: A rich text editor for everyday writing
Looks decent. The approach taken is the right one: we do something very similar with the Squire rich text editor (https://github.com/neilj/Squire) which I wrote for FastMail's webmail. Basically the browser can't be trusted to do any formatting itself, which is a slightly depressing state of affairs, especially as there has been zero improvements in this area for the last 5 years. I guess it's not shiny enough for browser devs to focus on.

Looking through the code, a few things jumped out that should be looked at:

* Native TreeWalker implementations are buggy in some browsers. In the end we decided it was safer to just implement the bit we needed ourselves (see comment at top of https://github.com/neilj/Squire/blob/master/source/TreeWalke...).

* The HTML sanitisation using document.implementation doesn't account for DOM clobbering so is currently bypassable with the right malicious content. I recommend using https://github.com/cure53/DOMPurify for this rather than writing your own. It's tricky to get all the edge cases right, so better to use something that's been reviewed by several people (and in DOMPurify's case also undergone a formal security review). Again, we use this at FastMail as part of our webmail.

nmjenkins··on Flexbox in 5 minutes
That's because flexbox is still prefixed in Safari 8 (see http://caniuse.com/#feat=flexbox). Just add -webkit- versions of all of the properties as well and it will probably work. e.g. "display: -webkit-flex".
← PreviousPage 3 of 5Next →