I always use unique email as well. Just recently I started getting spam at newrelic@domain.com. It was easy to see where spam came from and add New Relic to the list of companies I’d not do business with.
HN user
dannysu
I always use unique email. So far this problem only happened once with Zenni Optical.
@Fastmail: Another request. If I’m using my own domain, could the email generated be simpler?
Instead of “some.thing1234@”, I’d rather just have “thing1234@“.
Update: hmmm… looks like I can’t initiate an email with masked email though. I can set up my wildcard to do that in the more rare case when I need to initiate email.
Ah thanks. Currently out so didn’t check the desktop website. Hope the delete button can work on mobile too.
This is a great feature. I’m glad this will bring it to more people.
@Fastmail: Please let me delete a masked email after creating it. Thanks.
I just tried it with my own domain via the Fastmail iOS app. There doesn’t seem to be a way to delete things.
I do like that I can attach notes and have an easy block button. I might start using it instead of my existing wildcard setup, but need delete.
Using unique email per service is really great. I detected Zenni Optical either had a security breach or sold my information because of the unique email I used.
I have an add-on that I submitted an update for on June 21, 2021. It’s still “Awaiting Review”.
It’s an add-on that only I use. It’s not published broadly. I basically only needed Mozilla to sign it so I can install it.
Very frustrating. After waiting for a long while, I gave up and switched to the Developer Edition so I can use my own add-on.
I've been a fan of Khan Academy since they were just some Youtube videos.
You can find Khan Academy's past Form 990 online and I've been archiving them.
Sal Khan made:
2008: ? ($0 revenue)
2009: ?
2010: $70,833
2011: $348,879
2012: $348,529
2013: $348,292
2014: $548,116
2015: $800,000
2016: $815,000
2017: $785,000
2018: $824,000
You can see that, just like a startup, the sacrifice in the beginning as a founder is real. Before 2010 his salary from KA was probably 0 or significantly less. $70K in 2010 was less than my new grad salary. The jump in 2011 to $350K is around how much a senior makes in HCOL areas now. There has been basically no adjustment in his earning for 4 years from 2015 to 2018.
From the 990 forms, you can also get a sense of how much other people in the organization are being paid. I think all of them can command higher compensation elsewhere, but choose to work at KA because leveling the playing field for education is such a great mission.
Sal Khan's compensation as a CEO is only ~3.x times of many senior positions in the organization. Not outrageous at all.
In 2008's Form 990, Sal Khan wrote that KA is being used by 10,000 students daily. I don't know how many accounts, but growing from that to 71 million in 2018 is incredible. The impact to the world is undeniable.
This looks to be the source webpage where the PDF came from: https://www.levels.fyi/2019/
I use offlineimap (https://www.offlineimap.org/) weekly to backup my email from FastMail.
I wrote tweets2rss[1] and use it to turn my private lists into RSS feeds. For example, I have a feed in my RSS reader for interesting people (Bill Gates, Elon Musk, etc) and a list for interesting companies.
[1]: https://github.com/dannysu/tweets2rsshttp://www.idownloadblog.com/2013/02/01/path-ftc-settlement/
I think Apple didn't always have that. There was the Path scandal and outcry that caused Apple to introduce better privacy options.
Bron, I think your concerns are justified and understandable. Thanks for entertaining the idea.
I am one of those advocates and would enable such option if given. That said, I did have an instance when I had to call AWS support because of their own screw-up. I closed the AWS portion of my account but not the Amazon.com shopping portion. I later found out that I can no longer remove 2fa on the AWS portion because I no longer have it. I no longer have it because I already closed the account and thought it was safe to remove. However, because of their faulty system design, a closed account was enforcing 2fa on my Amazon.com portion preventing me from accessing it. In this case, the support agent helped me to regain access.
That support agent's ability to fix their faulty system design is both good and a potential liability. I wouldn't want a "I won't ever screw up" mode there.
In the case of email though, when certain conditions are met, it becomes a safer thing to do compared to getting screwed over by support staff.
The pre-conditions are: 1) The user is using custom domains only 2) The user has past emails backed up on his/her own devices
When these conditions are met, the user has complete control of their email destiny. In the case of losing FastMail account access, they can continue to receive email because they control the domain. They also have complete email history because they back it up.
That said, I believe your clearer response elsewhere in this thread is good enough for me personally. I was concerned before because of the vague responses. I think for FastMail, the risk perhaps outweighs the better security for me personally even if I would welcome it.
hi Bron, thank you for this response. Much clearer and I think this is what everyone wanted to see.
Can I just clarify some things for peace of mind?
1) When you say regular support staff cannot alter security-sensitive details. How is that done? Do they only perform changes through a limited set of UI?
2) When you say if 2fa is enabled it goes to senior security team, is that an automated process such that support staff don't see that ticket at all? The support ticket interface doesn't seem to have anything that helps to automatically route password reset requests.
3) Was the security incident involving ghouse through support tickets?
4) Do the senior security team have direct data access? i.e. do they also change things through a UI or do they have capability to directly change data?
Thanks
It's a consistent, fixed standard that you hope you have trained your employees to adhere. Fingers crossed. /s
The blog post was in 2014. This security bypass happened in 2016.
I think what we're witnessing here is that despite best intentions and past experience, humans are going to be humans. I actually felt good after reading that blog post in 2014 thinking that you guys are going to be better than most companies here.
Nope.
But I think a lesson can be learned here. The lesson is simply that humans are the weakest link. As much as you might try to add process and try to minimize, the best is having zero human capability at all. So when tptacek asks _who_ has ability to change things about an account, we really do want to know. Because those people are the weakest links. (don't mean naming names, but understanding who in general has those powers)
I mentioned elsewhere. I own my domain. I backup my emails. It's way more likely for a FastMail human loophole to screw me over than for me to need human assistance on login (which is never).
Oh, and also, I use my own domain on top of having a backup of my emails.
What this means is that if all recovery options are not working and I'm actually locked out, I can fix it.
I own the domain, I own my past emails, I can still get emails. Maybe I'll lose some emails for a day, but that's it. If I want to prove my identity to FastMail, I can also prove that I own the domain.
But the point is, getting locked out of something as important as email is not gonna happen due to my screw-up. It's more likely for a support loophole to screw me over.
I understand what you're saying, but I think perhaps we can agree that the current response is insufficient?
Have you taken a look at the link I supplied above where FastMail wrote about how 2fa protection could be bypassed at Gandi? They were very specific and clear about the recommendations being implemented.
Now, compare that to their current response. I think definitely the difference can be seen.
This is serious stuff.
And, I'm absolutely serious about never needing human assistance. I already have mechanism setup for my family to retrieve my digital assets should I disappear tomorrow. I worked on this together with my wife. I know most people have not thought about this and you're right in your skepticism, but I'm serious.
Also, could you please add ability to get a phone call (instead of text message) to receive recovery options?
That way I can setup my grandparents' phone number or something obscure as yet another recovery option.
And then, please let me lock down any possibility of your support staff screwing up.
What I'm hearing is that the human aspect remains and there is absolutely no prevention of this happening in the future.
The other response contains weasel words like "For instance, _some cases_ take 24 hours before the reset password goes into effect". Why "some cases"? Why isn't it all cases?
I think we as customers deserve complete transparency on this and know what prevention will be in place.
This can be enough for me to consider leaving depending on how it's fixed.
This response says absolutely nothing about how the vulnerability is prevented in the future. It's just a bunch of vague promises and mumbo jumbo. What specific procedures are in place to prevent it? At a minimum, I expect to see something specific like when you guys almost lost your domain because of Gandi [1].
And even then, can I have an option to select absolutely no human intervention possible? Having any human intervention is simply not acceptable.
I already have multiple ways of recovering my account, and I never, ever want human assistance on this. I use a password manager, and I will never, ever need FastMail assistance on login.
[1] https://blog.fastmail.com/2014/04/10/when-two-factor-authent...
Just wondering, is your FastMail login email the same email as what you typically use?
It's a good idea, and I do the same.
Except I actually just have Twitter via a RSS feed. I wrote some code that generates RSS from Twitter lists and I consume it and filter it just the same as any other RSS feeds.
When I had my internship at Amazon it was mostly cubicles. It's actually quite annoying and I had to have my earphones to get work done. Is it any different now?
Yes, I wish it worked this way! Even if with another shortcut that's ok too.
GitHub issue: https://github.com/mozilla/testpilot-containers/issues/462
I would pay for this as well.
Especially because GV was left for dead for so long. I'd like a company, that I can give money to, whose only motivation is to make a great GV-type product.
People don't have problem using an Apple account because they're not using that to track you everywhere and then use that against you in ads.
It's the same thing between Chrome vs Firefox. People also don't have a problem with their Firefox account used for syncing. Why? The scope is limited.
If you don't use Google Play as an app store, security quickly becomes an issue. And even if you are using Google Play, the inherent ability for apps to do whatever offers less privacy than the iOS equivalent.
Apple was very much criticized in the earlier days when apps would leak personal data out. They've since focused on giving the users more control about what to share. Android on the other hand, not so much.
I've used Android as my primary phone for a number of years. Privacy and security are some of the reasons that I will only buy Apple phones now. I wish that wasn't the case because I do want the variety of phone choices and the lower cost options. I also do like Android for its other aspect, but security and privacy ranks towards the very top of my criteria.
Yeah, I'm running Windows on my laptop and have Linux on my desktop.
I've tried Bash on windows multiple times and it's simply too slow. I ended up just running Linux VM as my development environment when I'm on my laptop.
I use uBlock Origin for adblocking and that extension comes with ability to hide elements on a page. I use it to hide news feed. Works great.
I mean my wife is still using my iPhone 3Gs (8 years old), so I get there are different needs. That's exactly my point.
Would you make the argument that everyone should be using $200 chromebooks?
If not, then why would one make the argument that anything more expensive than a chromebook is crossing some kind of threshold?
That misses a key point I was making: OS updates.
Yes, I too have a Nexus 4 (bought in 2012) and it still works fine. But no more updates. I don't consider that on par with say my previous work laptop, which was also 3 years before I upgraded.
I also own a Moto E (2nd Gen, $60-ish) and bought a Moto G+ for my brother this year, but I can't count on them to receive OS updates for as long.