Comment by jorvi
15 hours ago
As Fastmail themselves have pointed out many times, e-mail is inherently a multi-party activity with both parties holding a copy of the e-mails. Aside from the microscopic amount of people GPGing their e-mail and sending it over good servers, your e-mail is as private as the other party treats it. Which isn't very much. And you can't do anything about that.
You want private and / or anonymous communications? Don't use e-mail.
Fair point, but my desire is for "good enough" rather than perfect. I know my emails go into other systems, it's more about feeling that my inbox is hosted by a company solely based in a jurisdiction where it can't be compelled to do anything by the US government. It's also a matter of principle - I want to move as much of my infrastructure as I can away from US-based services because I don't trust things not to get worse there.
The bigger issue isn't a privacy one, it's a security one. For many people, if you can get access to their email box, you can account-reset your way into any other account they own. So if an authoritarian state compromises your account (because they control the servers), there goes your everything
A lot of people seem to ignore this point when it comes to Proton’s E2EE of emails at rest. It wasn’t even a year ago when the US government subpoenaed a Pennsylvania man’s entire Gmail inbox because he wrote a letter to a DHS attorney. This wouldn’t happen with Proton. It would definitely happen with Fastmail.
wow, hadn't heard about this until now. article: https://archive.is/J9Ant
correction that it says:
> The investigators who questioned Jon told him Homeland Security couldn’t obtain his emails, documents, photos or other content with an administrative subpoena, he said, but the breadth of what federal investigators did ask for shook him.
> Among their demands, which they wanted dating back to Sept. 1: the day, time and duration of all his online sessions; every associated IP and physical address; a list of each service he used; any alternate usernames and email addresses; the date he opened his account; his credit card, driver’s license and Social Security numbers.
However, what information the US government can or can't get from tech companies seems like a moving target.
1 reply →