example.com/path/to/article
000 points · username · 0 hours ago
example.com518 points · 296 comments · 1 month ago · groomlake
jacquesm
altairprime
robin_reala
If what you need is a guarantee that your data remains only in the EU, we don’t have that, and we’d rather tell you directly than let you assume otherwise.
tumdum_
cube2222
Side note, I moved to Fastmail a couple years ago, and so far I’ve been very happy with it! The Gmail migrator works great, too.
hn_submit
Anyone who falls for this is a fool wanting to be fooled.
rzerowan
The more concerning issue as far as Australian based tech is The Assistance and Access Act 2018 which
"...permits government enforcement agencies to force businesses to hand over user info and data even though it’s protected by cryptography.
If firms don’t have the power to intercept encrypted data for authorities, they will be forced to create tools to allow law enforcement or government to have access to their users’ data."
As far as i know this has not been challenged or walked back and with the rise of ChatControl like laws doesnt seem it will.
tamimio
zecg
Resilient replicas of your data will live in the US (for now). As we only have one location in Europe so far, the geographically separate copy will remain on servers in one of our US locations.
Wow, it's nothing. How about writing your PR after the data is not going to the US at all?
_tk_
At this point it’s unclear what a future digitally sovereign infrastructure should look like. Even if a company or a European state somehow manages to store data that is out of reach for the US Government, an amendment to FISA or the Cloud Act is something that any Congress should be able to put together.
user00005
I use Fastmail but just consider it safe from third party advertisers. If I wanted safety from governments I would use something else, or at least encrypt my email contents.
doener
PeterStuer
lschueller
Is there an alternative that really keeps data in the EU? (And not only in the sense it serves a sales promotion)
daft_pink
igl
greenleafone7
I feel that that's the whole point. And the whole point of them making this article/advertisement.
[deleted]
plqbfbv
philipwhiuk
Emergency backups for everybody are stored in our Philadelphia location. As well as the live replicas of your data, we also keep a separate set of encrypted backups taken every few hours for every account. These are in Philadelphia for all users at the moment.
So all of this is pointless.
rb666
egorfine
In all seriousness though, what are the chances Fastmail won't require KYC at some point? I have sent them a support request with that question and got a non-answer.
PS: Am a paying customer for like a decade
8by3
sparkling
crossroadsguy
varispeed
Cider9986
trocado
kmfrk
I_am_tiberius
Marciplan
victorbjorklund
ln809
atmosx
inigyou
braza
In extreme cases the US DoJ can reach, let’s say the CEO/CTO arrest them or pick up family members in case of some sort of non-compliance in some criminal investigation.
I can imagine something like > US DoJ has some PoI with some account in Fastmail “EU region” > Fastmail says “sorry we’re GDPR” > US DoJ says “now” or… > Fastmail refuses
Then what?
ThePowerOfFuet
Aussie law might be even worse than US; I would never use Fastmail.
KingOfCoders
"Resilient replicas of your data will live in the US"
?
superq
* a physical thing that can only live in one place
* not copyable
* can be 'contained'.
The whole thing reeks of bureaucratic 'best practices' that just aren't.
Even worse than that, trying to keep email restricted to the EU (or anywhere else) means that you effectively wouldn't be able to communicate with anyone in a different region, which is kinda the whole point.
Why not just make your own internet next? and then you can disconnect from everyone else who is trying to hack you. Just pull your network plug.
Email itself is hopelessly insecure by design anyway. Not just metadata when you are E2EE everything inside the envelope, but even basic vulns like downgrade attacks are simple because it's literally a violation of the RFCs (so you're not spec-compliant) to require TLS or any other encryption.. Why? because requiring modern crypto might interfere with deliverability and backwards compatibility. The real, deeper reason is that email is from a kinder, simpler time (well, at least simpler) and the design goals were never updated to keep up with the times.
Email is what we have. Just understand its flaws and then use other tools where you can. And who cares where your email lives - it's too easy to break anyway.