Security

Return to FastMail.FM home.

Overview

Storing your information reliably is important, but once it's stored, ensuring that it's secure is also critically as important.

TLS/SSL Access

We support TLS/SSL with all of our protocols. TLS/SSL is designed to encrypt all traffic and prevents eavesdropping, tampering, and message forgery on any communication between your computer and our servers.

In most cases, enabling TLS/SSL involves only changing a few settings in your email client or how you use our website.

Servers/Software

Maintaining secure servers requires putting in place a careful security policy.

Physical

All our servers are hosted at a secure facility at New York Internet. As their website notes:

Data Center security is a top priority for NYI. We have taken extreme care to install the utmost security so that our customers know that their data is safe. Our Data Centers are located at heavily protected buildings where the security personnel are on guard 24x7. Other security features include biometric fingerprint readers on door locks, strategically placed cameras and motion detection, doors equipped with alarm system.

Limitations

Note that while communication between your computer and our servers is encrypted, any email that you send that has to go to another server has to pass over the Internet in an unencrypted form.

The only way to ensure end-to-end security with email is to use email encryption software such as PGP or S/MIME. Both of these systems require the creation of certificates, and run on your computer and are attached to your email client to encrypt/decrypte the email.

Providing secure end-to-end encryption via webmail is impossible. There are basically two options, both flawed.

Famously hushmail which allows you to use both of these options recently admitted that the government compelled them to turn over the unencrypted emails of a number of users.

Their contention on how secure they are then relates to what it requires to get a court order.

That's also backed up by the fact that all Hushmail users agree to our terms of service, which state that Hushmail is not to be used for illegal activity. However, when using Hushmail, users can be assured that no access to data, including server logs, etc., will be granted without a specific court order.

Smith also says that it only accepts court orders issued by the British Columbia Supreme Court and that non-Canadian cops have to make a formal request to the Canadian government whose Justice Department then applies, with sworn affidavits, for a court order.

The same applies to us as our terms of service state.

Again to summarise, to get secure end-to-end encrypted email, you must use an email client and a security system like PGP or S/MIME.