Rendered at 20:32:41 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
jacquesm 1 days ago [-]
EU data regions are a reflexive action by companies that try to hold on to their EU customers (and more and more are leaving, surprisingly the larger ones seem to be leading here). Realize that as long as you are still hosted on US owned infrastructure or that if there are US (or: five-eyes) owned companies anywhere in the stack your data can still be forcibly pulled and often without you being aware that this happened. There are only very few such stacks that are 100% owned by EU entities.
> just stops shy of asking Australian tech companies, like Fastmail, to build backdoors into their products so that the government can "legally access" data from them
It stops just short of saying that you must do thispreemptively, but is pretty clear that you must do it if they ask you to.
sph 16 hours ago [-]
Why do I never hear about this ‘feature’ from American products like gmail which 99% of the HN audience is using? Isn’t USA a member of Five Eyes?
I admit it is a concern, as a Fastmail user, but this discussion only seems to happen on the Fastmail threads, yet no one bats an eye if one is suggested to open a gmail account like everybody else.
jurgenburgen 12 hours ago [-]
> Why do I never hear about this ‘feature’ from American products like gmail which 99% of the HN audience is using? Isn’t USA a member of Five Eyes?
Not sure why you haven’t heard about it but US Cloud Act is a big reason for EU companies not trusting US companies: https://en.wikipedia.org/wiki/CLOUD_Act
fauigerzigerk 9 hours ago [-]
Exactly, and it comes up in every single one of these debates.
DANmode 5 hours ago [-]
PRISM, etc
_jackdk_ 14 hours ago [-]
Because Fastmail is one of the relatively rare non-American companies that's managed to get a good position in a challenging market. The UK's "Snooper's Charter" also has a mechanism to send Technical Capability Notices that require tech companies to build things to spy on their users.
kylecazar 6 hours ago [-]
Because people who are using Fastmail care about privacy and have decided not to use Gmail (probably for that reason). Fastmail presents themselves as privacy-first. So people discuss where that might not be the case.
Their homepage:
Free email isn’t really free: you’re paying with your privacy. As a paid service, we only serve you, our customer. This means we have no split loyalties, no mining of your personal data, no sharing it with third parties, and no ads, ever.
jacquesm 16 hours ago [-]
Because everybody on HN is most likely aware that Google is an American company and that by using them you pretty much can assume that your data can be compromised without your knowledge or recourse. Post Snowden there should be zero doubt about that. Fastmail is worthy of scrutiny because people might believe that they are materially different when in practice they probably are not.
inigyou 6 hours ago [-]
Why would a US company tell you that it's going to spy on you for the government?
American products in particular are often mass consumer products that aren't particularly privacy focused. Everyone who cares about privacy already knows that Gmail isn't private - not only is it American, it's also owned by a domestic espionage conglomerate - but might be expecting Fastmail to be private, so that one is newsworthy.
Altern4tiveAcc 8 hours ago [-]
> Why do I never hear about this ‘feature’ from American products like gmail
I can't relate, I hear people complaining about American spyware online all the time in tech circles like HN.
omnifischer 11 hours ago [-]
> Why do I never hear about this ‘feature’ from American products like gmail which 99% of the HN audience is using? Isn’t USA a member of Five Eyes?
There is lot of hate toward Google (and other top US companies). Especially due to autobanning of accounts, 2FA etc. at the moment people have fastmail as their darling - because they are the underdog, no AI forcing in products (at the moment) etc. It is like stripe from 5 years ago.
Most have given up in snooping. Or you need to go to proton mail but it has other issues. Every company is subject to some regulations.
at the end, if the receiver of email has to also keep it safe. Do they?
jb1991 8 hours ago [-]
What issues do you refer to for Proton?
inigyou 6 hours ago [-]
No access via standard protocols. Supposedly this is because they E2EE your emails as soon as they receive them, meaning you need a special client to read the emails.
Also it got busted for funding some right wing movements.
Also it got busted for sharing data with governments leading to some activists getting arrested.
eastbound 14 hours ago [-]
Because it's a criteria for choosing Fastmail.
girvo 17 hours ago [-]
And you can’t tell anyone if you do, on pain of jail.
leonidasrup 10 hours ago [-]
Almost any goverment can force any company to build backdoors into it's products, only protection is to use open source (it's much harder to implement backdoor in open source) on own physical hardware, not in cloud (computers owned and controled by some else).
ffsm8 1 days ago [-]
> your data can still be forcibly pulled and often without you being aware that this happened
as a german i feel the urge to point out that this technically also applies to european companies...
With more hurdles for the US, but still technically applicable
jacquesm 1 days ago [-]
That's true but the EU still has a - mostly - functioning legal system. See 'Schrems' and other lawsuits that came out as they should have.
perks_12 24 hours ago [-]
Take a look at how they play with regards to chat control. The EU is just the same corrupt BS like D.C., only with a lot more virtue signaling.
jacquesm 24 hours ago [-]
Sorry, I don't agree with that. The amount of corruption in the USA right now is simply off the scale.
sneak 22 hours ago [-]
Nah, it’s just more visible. It’s not that much of a sea change. And it’s ridiculously naive to pretend that the major countries in Europe don’t have their own mechanisms to regularly and effectively bypass any democratic inconveniences when necessary. They regularly push through things that no constituent would ever want or vote for.
FireBeyond 19 hours ago [-]
Meanwhile the President sits in the Oval Office and says, in a televised interview, with absolutely no shame, that all of his kids and family are insider trading, all the time.
ffsm8 16 hours ago [-]
Meanwhile in Germany insider trading is completely legal for politicians. Well, not insider trading - but it's definition supposedly doesn't extend beyond internal business information.
(At least that's what people keep telling me, im not a lawyer)
dubbel 16 hours ago [-]
Insider trading is it course not legal for politicians in Germany, as you could have found out without being a lawyer.
That being said, transparency/reporting duties for members of parliament/ministers can and should definitely be improved.
ffsm8 14 hours ago [-]
The point was that the definition of insider trading does not extend to politicians buying/selling from their "insider knowledge" as it's not internal business knowledge. Hence it is legal (in Germany) for politicians to buy/sell right before passing laws which influence the valuation of companies.
Which I may add: you could've easily found out yourself too if you looked up what I wrote.
lxgr 10 hours ago [-]
> Hence it is legal (in Germany) for politicians to buy/sell right before passing laws which influence the valuation of companies.
Are you sure about that? European legal theory for insider trading implicitly covers more cases than the US without needing to explicitly enumerate them as far as I understand (in a nutshell, trading on insider information is illegal regardless of the source or whether any fiduciary duty was breached), and I'd be surprised if this case were not covered.
phatfish 11 hours ago [-]
Which laws get passed under complete secrecy that politicians can trade based on? They are usually debated for months/years. Even if something is rushed through fast (like during COVID?) it is public knowledge.
The issue in America is the president has more power to act unilaterally (maybe to address his/her own interests, maybe not) than any European politician.
Lio 13 hours ago [-]
Trump just dropped the part of his lawsuit against the BBC where he claimed it damaged his business because he would have to expose what his business is.
The Trump regime a way more corrupt than anything currently seen in Europe.
He currently attempting to steal Greenland so he can strip it of mineral assets for fucks sack.
No politician in Europe is starting wars for personal gain.
> No politician in Europe is starting wars for personal gain.
Isn't that that basically the history of Europe? A short French or German or English or Roman dude starting a war for personal gain?
inigyou 6 hours ago [-]
Not recently though. Unless you count Putin.
Lio 3 hours ago [-]
That's the history of every country and every empire, not just Europe.
Is that the standard we're holding Trump to though?
Do you really think it's OK for him to invade other countries for personal enrichment because historic tyrants also did the same?
nalekberov 13 hours ago [-]
[flagged]
LastTrain 21 hours ago [-]
Nah, it’s worse now than ever.
jacquesm 21 hours ago [-]
You're right, just the other day our MP lined his pockets to the tune of a couple of billion, pumped his shitcoin, tipped off his friends about about the stock market movements he was going to cause, sent a couple of good deals to his kids and threatened war on a couple of countries just to please his buddies. And that's just the last couple of months... /s
FireBeyond 19 hours ago [-]
Oh, and will sell you access to his market-moving tweets for $100K a month, so you know and can get your stock trades set before the plebes do.
A parliamentary process where a law is being proposed, amended and voted upon isn't "corruption".
Just because you disagree with a law, that doesn't make it "corruption" - it does make you an authoritarian that attacks democracy as soon as other people don't vote like you want.
hulitu 13 hours ago [-]
> A parliamentary process where a law is being proposed, amended and voted upon isn't "corruption".
If the law is initiated by the parliament and not by some company through lobby. Lobby is corruption.
inigyou 18 hours ago [-]
Chat control 1 was rejected by the parliament and then passed anyway because parliament doesn't matter. Hardly democratic.
izacus 17 hours ago [-]
That's a lie - chat control was amended and then passed via parliament vote.
Please stop spreading fabrications - even when you dislike the result. That's fascist behaviour.
inigyou 11 hours ago [-]
The majority of parliamentarians voted against it. This was considered a pass, because it didn't meet some arbitrary threshold to block it.
izacus 10 hours ago [-]
With 276 MEPs in favor. Vote them out in 2029 if you want to change that.
inigyou 9 hours ago [-]
And 314 voted against.
"Chat control 1" is the deliberately misleading name for "Facebook is not banned from using CSAM scanners on your DMs if it wants to" - I don't think it's worth voting someone out based on that. The one that bans encryption is called "chat control 2". I assume they've both got the same name as part of a deception tactic.
inigyou 18 hours ago [-]
Chat control 1 or 2?
sscaryterry 23 hours ago [-]
Not nearly the same thing. Trump and his family have made billions. I cannot say the same of von der Leyen.
carlosjobim 20 hours ago [-]
Which of those two leaders were elected by the people?
beezlewax 18 hours ago [-]
The European Parliament is elected by vote and has to ratify the chosen members of the EU council. The president of the council included.
eastbound 14 hours ago [-]
No, he has a point. There are various degrees of democracy, between direct and many degrees of indirection. VDL is certainly not a good level of democracy:
- Elections are so rare (every 5 years) and encompass so many huge life-altering choices (VDL being one of the criteria only) that it's not democratic. The Swiss vote every important law, like "Should we buy fighter jets".
- De facto, party health is part of democracy (look at the Rwanda: It is absolutely possible to have a genocide made by democracies, and it is in fact more frequent than dictatorships) and network effects have made that European parties don't represent the people's will,
- Europe dispatches money to countries that need convincing, like Scottland, while wearing the mature members' citizen to the bone. We can't even have decent roads or internet here, while newcomers are super-happy to join ("I'm happy because Europe brought wealth and economic development!!!" - yeah look in 20 years). Money flushing around Europe trying to bribe citizens groups into staying, which makes opposition impossible. The EU is too chicken to let citizen vote every 20 years on whether we should stay in Europe, because then answer would be a big NO.
- The kill switch didn't even work, countries can't leave, or there is retaliation. Not only UK but France voted against the new treaties in 2005, the president still signed them.
The EU is the most lazy level of democracy. It's a knee-jerk reaction to say that VDL can be removed from office by the citizen.
pepperoni_pizza 10 hours ago [-]
Your username is telling.
benj111 10 hours ago [-]
>The EU is too chicken to let citizen vote every 20 years on whether we should stay in Europe, because then answer would be a big NO.
Well us Brits tried that experiment and it isn't seen as a success.
eastbound 8 hours ago [-]
It is a success. UK leaving the EU is a form of democracy. People should have the means to choose their destiny, just like the Bengladeshi or the Timor people.
What is not a success is:
- The EU taking retaliation against them,
- The EU parties overturning members of the Leave party into the Libdem, AFTER being elected (yes, it happened for 16 members, plus the ones who didn't officially switch but stalled the Leave party's proceedings),
- From the moment they clearly voted NO, it took 3 more votes until they could be allowed to leave. Basically, it was until it was clear the UK citizenry would be entirely blocking the democratic process until the EU-Leave decision was enacted. You can understand people's despair of democracy when a clear LEAVE vote isn't enacted, like in France 2005.
In the rest of the EU, they're too chicken to let us vote. But they will let us vote... one day... only in areas where they're guaranteed a large STAY result.
The EU is only letting us vote when the answer is Yes.
inigyou 6 hours ago [-]
The EU hasn't retaliated against the UK for leaving, and it hasn't messed with UK elections as you allegedly.
Taking several votes for such a big decision is good. It prevents impulsive hotheadedness from making a ruinous decision. The UK did vote to leave and then left.
And it ruined the UK. That's why other people are saying it was a bad idea. Not because they didn't vote, but because the thing they voted for ruined them.
benj111 5 hours ago [-]
>clear LEAVE vote isn't enacted
Except the catchphrase of the day was "Brexit means Brexit", because no one bothered to define what we were voting for until we'll after the fact. There were plenty of options such as a soft Brexit or a hard Brexit. Even the hard Brexit kept us in some institutions so what we got was harder than the hardest Brexit discussed.
So in what way did we get what we voted for?
izacus 14 hours ago [-]
There is no country in the world that fits your definition of democracy, so why are you attacking EU specifically?
ywain 14 hours ago [-]
> look at the Rwanda: It is absolutely possible to have a genocide made by democracies,
Rwanda has never been a democracy. Habyarimana was "elected" with 99% of the votes ffs.
> and it is in fact more frequent than dictatorships
It is trivially easy to verify that this is not true.
eastbound 8 hours ago [-]
You may have a black eye about History.
Rwanda came for help to France 2 years before, and France conditionned its financial help to a democratisation process.
- From here, about 150 parties got born.
- The previous dictatorship, even of the majority, was protecting the minority, because they knew the international consequence on countries who don't protect the minorities.
- Once a democracy, it was a leadership of the majority ethnicity (90% Hutu) so you bet they had no qualms about protecting the Tutsis. Tensions and invitation to violence soared immediately, but in a coveted speech.
- A plane containing half the government was bombed, the country woke up without clear leadership, elections didn't happen fast enough. Citizen acted with their own machetes.
Democracy means the majority owns the decisions. Doesn't mean they'll be good people.
hamper653 6 hours ago [-]
American presidents are notoriously not elected by the people.
izacus 20 hours ago [-]
Certainly Van Der Leyen.
I suggest you show up for next EU election if you don't like the option.
Silhouette 16 hours ago [-]
How should EU citizens vote at that next election if they are unhappy with von der Leyen's actions as President of the European Commission in order to remove her if enough other voters agree?
dubbel 16 hours ago [-]
They should vote for parties that are not organized in the EPP (European people's party). The exact party options depend on the country you're voting in.
Silhouette 15 hours ago [-]
And what would happen next to ensure that von der Leyen was removed from office?
It is worth remembering at this point how von der Leyen first became Commission President. She was controversially nominated by the European Council - who are not directly elected representatives within the EU system - deviating from the spitzenkandidat convention in a way that surprised and angered many MEPs - who are. Her own national government (Germany) did not support her in the Council voting because one of the parties in the governing coalition opposed her. She was eventually confirmed by a narrow majority in a secret ballot of the European Parliament from which little can therefore be determined about who did or didn't vote for her except that quite a lot of MEPs who were expected to support her candidacy based on public statements did not in fact do so in the secret vote.
So she was essentially proposed by a group of people who aren't directly elected at EU level and in some cases aren't even directly elected by the nations they represent - in violation of the normal convention expected by the only people who are directly elected at EU level - and was then narrowly confirmed by that directly elected group only in a secret ballot from which the vote of each individual representative was not recorded and there is therefore no possibility for their own electorates to hold those representatives to account personally for how they voted. Given that we are talking about the most influential political post in the EU this is not exactly a powerful demonstration of democratic legitimacy and a clear popular mandate no matter how you look at it.
jurgenburgen 12 hours ago [-]
I think the EU should be reformed in a more democratic direction, no question about that.
Still, calling the system undemocratic is a stretch since anyone who pays attention can see how EU policies have shifted after the far right increased the number of their seats in the previous election. Climate ambition has been dialed way down and immigration is being curtailed.
jq-r 13 hours ago [-]
As one of the most openly corrupted Croatian politician is Von Der Leyen's commissioner, it tells me all I need to know about her choices and influence.
9 hours ago [-]
izacus 14 hours ago [-]
Everything she does has to be confirmed by the parliament you're electing.
Everything else she does needs to be confirmed by representatives of your own member state.
Just like EVERY OTHER democracy.
Silhouette 7 hours ago [-]
Just like EVERY OTHER democracy.
Not really.
In most representative democracies it is the elected representatives who initiate new law. In the EU the elected MEPs have no power to do this and it is the role of the unelected Commission to start the process.
Meanwhile the Commission is also the "executive branch" of the EU. A great deal of what the commissioners do is not directly subject to approval by the European Parliament.
inigyou 6 hours ago [-]
The EU, like most union governments including the USA, was designed to be conservative and not pass things by default. For something to pass the EU, it has to be wanted by both the leaders of all the EU countries (the commission) and the people in all the countries (the parliament). It's similar to the house and senate of the USA
Silhouette 3 hours ago [-]
You are misunderstanding the leadership structure of the EU. There are three main bodies that lead it - the Council of the European Union, the European Commission, and the European Parliament.
The Council is the one that generally consists of the leaders of each member state. It has important roles in the system including selecting candidates for key roles and as part of "trilogue" negotiations (which are themselves sometimes controversial for being secretive and unaccountable) but has little formal participation in the normal legislative process.
The Parliament is the one whose members are elected by the citizens of the EU. Its best known role is to debate and vote on new legislation.
The Commission holds much of the real power as it serves as both the leadership of the executive branch and the origin of new legislative proposals - and yet its members are chosen via much less transparent means and have little personal accountability to EU citizens.
Many EU commissioners have been politicians whose national political careers were struggling and - like appointment to the House of Lords here in the UK - they may have been put forward for the Commission by their national political leadership as a position of influence that required less confirmation than winning a popular vote. This is relevant here because von der Leyen herself is arguably in this category.
krick 19 hours ago [-]
Clearly you have no idea how the head of EC is chosen. Because of the two only Trump was actually elected by the people.
Aeolos 11 hours ago [-]
Trump was elected by the electors, not by the people. Not entirely dissimilar from how VDL was elected.
izacus 17 hours ago [-]
Remember that Chat control has gone through vote through directly elected parliament like any other legislation.
The next election is in 2029. I suggest you show up instead of spreading fabrications online.
abc123abc123 8 hours ago [-]
Of course the EU is not democratic. The sheep, the common people, are only allowed to vote on pre-defined options that are decided entirely in private by the new political nobility, the EU politicians.
Should they happen to vote incorrectly, like when the EU constitution was voted about in ireland and france ,they will just have to vote again and again until by exhaustion, the right result is guaranteed.
The EU has nothing to do with democracy. No, putting a paperslip in a box is not democracy.
I think perhaps switzerland is the country on the planet that is closest to democracy, and they also have the highest incomes ,highest living standards and lowest taxes in europe.
The EU has choose the path of soviet like socialism, and of course the economy will slowly decrease until it collapses, and then we'll get a Hitler 2.0 to "fix" the problems that were caused by the EU dictators.
The best thing you can do if you care about europe, is to move outside of the EU, avoid paying tax, do not feed the beast, and spread the truth, so that fewer and fewer people want to move there. Then it will hopefully collapse in time.
hamper653 5 hours ago [-]
> People are only allowed to vote on pre-defined options that are decided entirely in private
That’s democracy in its purest form.
ywain 18 hours ago [-]
What's your point? You'd rather have a democratically elected but corrupt leader than an appointed but honest one?
Barrin92 17 hours ago [-]
I'm not sure what that's supposed to imply because if Ursula von der Leyen manages to be less corrupt without being elected by the people that has some uncharitable consequences for the quality of the American electorate, I think HL Mencken had something to say on this
jacquesm 16 hours ago [-]
Technically, the US president is also not elected by the people but by the electors, which in many ways is comparable to how the EU elected the EU Commission President.
benj111 10 hours ago [-]
So? If you're directly elected by the people you can behave how you damn well please? Except trump isn't because you have the electoral college.
I live in the UK, on paper we have an absolutely terrible version of democracy. No constitution, and un elected head of state. Compared to pre pull out Afghanistan it sucks. And yet we are still here. Perfect on paper democracy isn't the be all and end all. It's about institutional culture. The EU has a much better democratic culture than the US does.
usernomdeguerre 1 days ago [-]
True, I think the calculus is more about who you think is more trustworthy than what tools they have to damage you.
throwawayffffas 1 days ago [-]
I am almost positive things are not the way they were and requests for data access especially if the subjects background is "suspect" are more highly scrutinized.
And as the Americans are choosing to interfere in European domestic politics and trample their own laws and constitution the more scrutiny their requests will get.
slow_typist 1 days ago [-]
Especially if European companies have an office and significant share of customers in the US.
yieldcrv 16 hours ago [-]
europeans like it more when just european governments are doing it
V__ 1 days ago [-]
For anyone curious, it's the CLOUD act:
> The CLOUD Act primarily amends the Stored Communications Act (SCA) of 1986 to allow federal law enforcement to compel U.S.-based technology companies via warrant or subpoena to provide requested data stored on servers regardless of whether the data are stored in the U.S. or on foreign soil.
The point of control is Congress, until we stop electing corpratist politicians, we will continue to get bad legislation.
redserk 23 hours ago [-]
It doesn't matter if it's Congress. At the end of the day America's internal governance systems are America's problem. The rest of the world should not care if a certain branch is causing issues, and frankly, is starting to come to that conclusion.
It's unfortunate for us, but we very rarely isolate individual government systems for other nations.
tzs 21 hours ago [-]
It's weird how everyone focuses on that part of the CLOUD Act. The CLOUD Act actually did two things: (1) that, and (2) provided an expedited way for the US to enter into Mutual Legal Assistance Treaties (MLATs) with other countries.
It was the MLAT thing that the various civil liberties groups object to (I'll cover the problems with those down below). There was very little objection to the first part.
The first part was not controversial because pretty much every country has something equivalent (for reasons I'll cover below), as did the US except specifically in the case of data covered by the SCA due to poor drafting.
One of the big reasons for the SCA was created was the emerging "third party doctrine" meant that instead of having to get a warrant or subpoena against you to get your data they could simply subpoena it from any of your service providers that had it. The SCA made it so the third party doctrine subpoenas would not apply to stored communications.
There were still cases where the government would need to compel the service provider to turn over the data. They wanted something with the probable cause requirements of a warrant but the delivery method of a subpoena. (A subpoena asks someone who controls the data to turn a copy over. A warrant is for when the government wants to raid the data center and seize the data. Since that involves the government directly acting where the data is located it only applies to someplace where they have jurisdiction).
So they created a new thing, the SCA warrant. The called it a "warrant" because it had the probable cause requirements of a warrant, but neglected to add something saying that in other respects it functions like a subpoena. I'll call this a pseudo-warrant.
The SCA was not the first pseudo-warrant. That would be the warrants under the Wiretap Act of 1968. Territoriality questions did not arise under that because by its nature the data it sought copies of was always in the US.
With the SCA the data might not necessarily be in the US. Years later Microsoft argued that because it is a "warrant" it should have the territorial restrictions that normal warrants have. The CLOUD Act clarified that it was indeed supposed to be like a subpoena as far as territoriality goes.
There have been some more pseudo-warrants created since then, but their drafters learned from the SCA and made sure the original legislation was clear on just what they were.
The reason pretty much every country has something like that, going back well before online documents, is because not having such a thing leads to big problems. If anyone in the country could shield documents from subpoenas (or whatever the equivalent is called in that country) by merely storing them across a border every company with documents that it needs to keep but that might be incriminating later would get sent to a storage facility across a border as soon as they were no longer actively using them.
For example as soon as a car company in Detroit releases a new car all the documents where during development engineers brought up safety concerns which management decided to not address would be sent across the bridge to a storage facility in Canada.
With electronic documents it is even easier. You would not have to wait until you aren't actively using the documents to stick them outside the country. Just stick your file server across a border and make sure you only have copies in country when someone is actively reading or editing them.
And so pretty much everywhere subpoenas compel someone in the country who controls the documents to fetch them (or copies) and turn them over. The actual location of the documents is completely irrelevant.
The thing that was worrying about the CLOUD Act was the MLAT provisions. MLATs are treaties where the participating countries agree on law enforcement. They include things like sharing information and cooperating on investigations. Normally these are enacted just like any other treaty. The executive branch negotiates them and then the Senate votes on ratification.
The CLOUD Act adds an expedited process where the Attorney General and the Secretary of State can sign an MLAT. Congress is not involved. These agreements allow foreign law enforcement to make requests directly to US service providers instead of going through the diplomatic channels normal MLAT requests go through, and they allow them access to stored communications that the SCA would normally block.
There are some safeguards. The foreign government is not supposed to intentionally target US people who are in the US and are not not supposed to use the data they get to infringe freedom of expression. There's also a 180 day window before these executive MLATs take effect during which Congress can block them by passing a joint resolution to do so.
Civil rights groups and many others were not impressed with those safeguards.
braiamp 1 days ago [-]
Which wouldn't matter where the data is located, so I don't think that this is the reason Fastmail is doing it, because a savvy enough company would know that the problem is that the company is US based.
kid64 1 days ago [-]
They're Australian
petcat 1 days ago [-]
Australian companies are also subject to the USA Cloud Act. As is the UK, with Canada coming on board soon too.
Even the entire EU is in the process of negotiating the same agreement.
That is plain wrong, and on top of that, the CLOUD act doesn't really solve anything because if the order to obtain data is legal for the US arm but illegal for the EU arm, releasing the data from say Ireland to the US would immediately lead to steep monetary and legal penalties for the EU arm.
The same agreement is in place with the UK. Canada and EU are currently in the process of negotiating it.
yborg 1 days ago [-]
Your linked information doesn't indicate anywhere that Australia or any other foreign government is subject to US law. The latter states that negotiation with the EU on this topic was suspended in 2019.
Things have changed. With Chinese law in regards to data within Chinese jurisdiction a long-standing thing and an unfriendly American government potentially in power for an extended period, other countries are realizing the importance of data sovereignty.
> The latter states that negotiation with the EU on this topic was suspended in 2019.
Dated 2023:
> Justice Department and European Commission Announces Resumption of U.S. and EU Negotiations on Electronic Evidence in Criminal Investigations
The negotiations are still ongoing. Canada is further along than the EU.
perpetuallunch 1 days ago [-]
That’s not going to help anyone.
The Five Eyes is an Anglosphere intelligence alliance comprising Australia, Canada, New Zealand, the United Kingdom, and the United States. These countries are party to the multilateral UKUSA Agreement, a treaty for joint cooperation in signals intelligence.
Even being stored in EU doesn't preclude your data from being targeted by signals intelligence. Which is different than requiring US based companies to provide non-US data to American government.
Does fastmail have a US presence? If no - then they're not bound at all by US jurisdiction.
defrost 20 hours ago [-]
Meanwhile, in realPolitik, they are Australian, they are subject to AU government pressure, and the AU government is deeply intertwined with and compliant to US government wishes, AUKUS, Pine Gap, Harold Holt Sub communications, Over the horizon radar on China, etc.
> Does fastmail have a US presence? If no - then they're not bound at all by US jurisdiction.
This hasn't been true for several years. All Australian companies (and UK companies) are under jurisdiction of the US Cloud Act. Just the same as American companies are.
They didn't even manage to extradite Kim Dotcom for years.
petcat 6 hours ago [-]
Kim dotcom was extradited from New Zealand, not Australia. They're different places.
inigyou 6 hours ago [-]
They're both Five Eyes
petcat 4 hours ago [-]
Sure, but the point was that the US doesn't even need to exercise their capabilities under the five eyes treaty. They have a separate Cloud act agreement with Australia already which is a more direct route to get what they want.
perpetuallunch 18 hours ago [-]
The question isn’t whether a service has a presence in the sense of employees or regional office, or headquarters.
The question is: do they office services to residents of said country / state.
If so they may well be subject to certain laws that, if broken, could result in penalties up to an including extradition of the responsible officers.
america_sux 11 hours ago [-]
As an Australian, all I can say is stop being naive.
wolfi1 1 days ago [-]
isn't there this five eyes thingy?
inigyou 6 hours ago [-]
that's surveillance orgs agreeing to cooperate, but they're still just surveillance orgs, all they can do is surveil
microtonal 1 days ago [-]
Yeah, this does absolutely not solve the CLOUD Act issues. However, it is good to look at what the ramifications of the CLOUD Act is for e-mail:
- The US could request your data. You probably shouldn't use e-mail for anything sensitive anyway for many reasons. E-Mail was traditionally not encrypted and I think that many servers still allow plain-text communication. The protocols are old and there are all kinds of downgrade attacks. Aside from that, even if your service does not fall under the CLOUD Act, you are probably f*cked anyway, because most people you communicate with are using services that fall under the CLOUD Act.
- The US can force the provider to block your account. The workarounds are: regularly backup your e-mail (easy for services that offer IMAP) and, most importantly, use a domain with an extension that is not under the control of a US (or probably five eyes) registrar.
Use an E2E-encrypted messenger with perfect forward secrecy, etc. for most personal communication.
hn_submit 8 hours ago [-]
Email itself is not encrypted but the links between email servers are. That makes it non-trivial to intercept email.
However, most people these days are using webmail from the big-tech companies which makes it relatively easy for LEA and intelligence agencies to read your email.
1over137 22 hours ago [-]
Something like 99% of email is now done over TLS.
SoftTalker 21 hours ago [-]
Yes but it will almost always work with self signed or expired certificates, or downgrades to clear text if that's what it takes to deliver the message.
inigyou 6 hours ago [-]
I thought a few years ago Gmail started demanding TLS so now any mail server that anyone cares about supports TLS.
SoftTalker 2 hours ago [-]
I had a mail server running with a LetsEncrypt cert. I never set up the cron job to renew it, and months later realized that the certificate had expired. Gmail never glitched sending mail to my server. This was some time in 2025, so not too long ago.
DarrenDev 1 days ago [-]
EU sovereign clouds are taking off right now - especially when it comes to sensitive data (government, healthcare, etc.). Lots of players moving into the space. The common denominator - nothing touches the US.
AWS, Azure, GCP, Oracle, Schwarz Digits, SAP
easton 1 days ago [-]
Requiring that you believe those companies that they won’t hand the keys over to the US at the first ask.
Like, the critical problem with the AWS sovereign pitch is that you must believe that they won’t give the keys to the US, and they also won’t give the source code that’s hosted in the US to the government either for them to find vulnerabilities in. I don’t know if that’s good enough unless you just need the data to stay in the EU and you don’t care if another country sees it.
I know they probably did some work on it (what if primary AWS goes rogue and the EU entity must work without it) but I don’t know if they explained how they’re safe to the public.
jacquesm 1 days ago [-]
The harder problem here is that any real EU sovereign platform would have to come with ironclad guarantees that it isn't going to be directly or indirectly sold to a US party. And when enough customers move that marketshare is affected the bags with money tempting shareholders will get larger and larger.
rufasterisco 18 hours ago [-]
Isn’t that counterbalanced by the fact that the reason they exist in the first place is to be a sovereign platform?
I am assuming the reason companies switch to them is not price or tech. US cloud providers have the advantage on both.
Selling EU companies data would mean destroying trust over their main selling point, not to mention incur on EU wrath.
Feels like living one whistleblower away from doom.
I refer to fully EU clouds, parent list includes US clouds that do not need bags of money, Clouds Act in enough.
jacquesm 1 days ago [-]
You can strike at least four of those.
walthamstow 8 hours ago [-]
Don't forget Lidl!
martin_a 24 hours ago [-]
> AWS, Azure, GCP, Oracle
What? Those are US companies, they will have to give out your data under the Cloud Act. Only Schwarz and SAP are free from that by being German companies.
everfrustrated 22 hours ago [-]
> Only Schwarz and SAP are free from that by being German companies.
Not true. You also have to be sure that the company directors will never travel to the US even for a holiday or any third party country that would uphold an extradition request from the US.
It's just email. Nobody is going to jail to protect your email.
If you care that much run your own email server.
fragmede 8 hours ago [-]
What, in my basement?
hn_submit 9 hours ago [-]
You're spreading misinformation since AWS, Azure, GCP (Google) and Oracle are all U.S. companies which are subject to the CLOUD Act.
Just because they pretend to be European-based by setting up a European subsidiary with so-called firewalls means exactly...nothing.
fragmede 8 hours ago [-]
The Double Irish Dutch Sandwich means € billions in tax liability saved. Unless you're a corporate lawyer that has put up those firewalls and can talk at length as to what they even are, why should believe you when you say it means exactly nothing?
justincormack 8 hours ago [-]
The double irish dutch sandwich has not existed for many years, and tax law is different from data access.
inigyou 6 hours ago [-]
Five Eyes is only surveillance, right - they don't transfer court orders or arrest warrants?
So Australia may spy on data entering and leaving the Australian server that serves US customers, but they can't just seize the server based on the Five Eyes agreement.
BTW it's expanded to Fourteen Eyes and it's generally good to assume that all Western governments are cooperating to about this degree.
rufasterisco 1 days ago [-]
Can you point me towards some resources that show EU customers moving?
Not that I don’t trust the statement, I just would like to know more.
And many others besides, pretty much every company I've looked at in the last year is either acutely aware of the problem or they are already executing on it. With Trump and his merry band of criminals repeatedly stating they're going to take Greenland by force you can't blame them either, that would effectively put the EU on a war footing with the United States (I still can't believe I'm writing this sort of thing and it is not entirely fiction), the end result of that would be that there would be an absolute run on EU hosted capacity. They're just trying to beat the rush and hope they'll never be proven to be right.
rufasterisco 22 hours ago [-]
Tnx!
mlrtime 10 hours ago [-]
"This is not Airbus abandoning US big tech. It will keep AWS for its Skywise aviation-data platform and a customer-support tool. It also still runs Microsoft and Google productivity suites, plus Salesforce, Coupa and Workday."
I was up to date on noyb, but not aware that actually companies are moving at this speed and size.
Thanks all for some great resources
rufasterisco 22 hours ago [-]
Thank you su much, wow
MYEUHD 14 hours ago [-]
What about the 9-eyes and the 14-eyes?
All the added eyes are European (Denmark, France, the Netherlands, Norway; Germany, Belgium, Italy, Spain, and Sweden)
kisamoto 1 days ago [-]
Does this still apply if there are separate legal entities for US & EU operations? Take Hetzner as an example. They have a separate US company to deal with their US data center. Would their EU servers be vulnerable to the CLOUD Act?
kvemkon 23 hours ago [-]
> Take Hetzner as an example.
Similar happened already with OVH Canada vs France.
> In an affidavit, Xavier Barriere, corporate counsel at OVH in Paris, describes the dramatic situation: If the important proponent of European data sovereignty were to comply with the Canadian order, those responsible in France would be committing a criminal offense. They face up to six months in prison and fines of up to 90,000 euros per violation. However, if OVH ignores the Canadian court, it faces contempt of court proceedings in Ontario, which can also lead to severe sanctions.
Well, for sure they can pressure them but I highly doubt Hetzner would break the law in Europe to satisfy the US government, they are a lot more to lose here than there. I realize that that is not proof.
yread 12 hours ago [-]
I dont share your optimism: The US can just say: let us access this one customer or we will ruin your vpcs in the US.
What can you do about it? FDE? Can you keep the keys away from Hetzner? How much hacking would they need to do to get them? Can US government break SecureBoot?
Im just happy my business is not important enough
inigyou 6 hours ago [-]
Hetzner US would have no power over Hetzner EU, that's the point. All they can do is beg their parent company the same way law enforcement could beg them directly.
kazen44 11 hours ago [-]
the alternative being hetzner giving away EU based information to the US? which would absolutely destroy their reputation in the EU. (which is a far larger market for them).
The only way to spin this as hetzner is to go public with this and make it a political point for geopolitics between the EU and the US, and take the loss /call the bluff on the US threat.
jacquesm 8 hours ago [-]
Let me tell you about that time when I walked around in a DC in NL and ran into an unaccompanied FBI liaison officer...
I don't think any of us have the total picture, but the bits that I do have are sufficient to worry me about the degree to which I am automatically breaking the NDAs I sign by using a computer, email, online data rooms and so on.
inigyou 18 hours ago [-]
The relevant fact about Hetzner is that it's an EU company with US branch, not a US company with an EU branch.
A difference could be that Germany might not have such blocking law as France. At least I have never heard of it.
jacquesm 10 hours ago [-]
Canadian judges can rule whatever they want, it isn't going to make a difference in practice: if Canada or a Canadian entity wants data from an EU company they're going to have to go through the proper channels to do so. Taking shortcuts like this, even with the backing of a judge just isn't going to fly.
inigyou 6 hours ago [-]
Yes. Canada only gets to affect the Canadian subsidiary of OVH. Otherwise they can't do a whole lot. Maybe they can do enough though - maybe they can seize the profits from the subsidiary going to the parent company, which the parent company would want to avoid. They have no direct control though.
If it had been the European one that was the subsidiary, then Canada could order the OVH parent company to order the subsidiary to do things.
prism56 13 hours ago [-]
I just try hard to pick e2e or encrypted at rest then I guess it doesn't matter to some extent if there's a breach or where it's hosted... I hope
BrandoElFollito 1 days ago [-]
The French head of Microsoft ctor not, under oath, say that Microsoft can guarantee sovereignty. This is the evidence that until you have a EU company, under EU rules and not present in the US at all, you cannot have sovereignty.
mrtesthah 1 days ago [-]
Ok, but Fastmail is an Australian company based in Melbourne.
petcat 1 days ago [-]
Australia and the US entered into a bilateral agreement in 2024 which made Australian companies subject to the US CLOUD Act.
As a FastMail customer who spends a portion of the year in the US, I am happy to pay to move my data to the EU region, even if they cannot yet fully guarantee all my data will remain outside of US access at this time. Defense and mitigations in depth, over time. We must always start somewhere, and perfect is never the target (as it does not exist).
tmgldn 1 days ago [-]
Agree - small steps always positive here
OJFord 1 days ago [-]
But whose cloud infrastructure do they use? (I don't know, but it might likely be AWS, GCP, or Azure.)
microtonal 1 days ago [-]
That it described in the linked post:
We’ve installed our own servers, co-located in a secure facility in Amsterdam, set up by our own engineers.
calvinmorrison 1 days ago [-]
None. It's racked and stacked old school
realo 24 hours ago [-]
pCloud is an example.
Swiss corporation with data centers in Luxembourg.
sureglymop 10 hours ago [-]
I wonder how much a European company would care?
I mean to say, perhaps this is more about customer sentiment and image than something maybe benign to their profits like five eyes involvement.
amelius 1 days ago [-]
How does Apple handle it?
xnickb 1 days ago [-]
Why would apple care? Eu is what a quarter of their business? And where exactly will those people move? They're locked into the Apple infra.
calvinmorrison 1 days ago [-]
Fastmail is an Australian company
gib444 1 days ago [-]
And hosted on US infrastructure, satisfying the "or" clause in their post
sodapopcan 1 days ago [-]
The article says they installed their own servers, though. What am I missing here?
selectively 1 days ago [-]
[dead]
atmosx 1 days ago [-]
That’s true and Fastmail runs on AWS. But it’s a start and a “feature” many have requested for years. It’s funny because the HQ and I believe their workforce is located in Australia.
jph00 1 days ago [-]
Not only is that not true, but in fact FastMail predates AWS by some years.
Source: I founded FastMail.
jph 23 hours ago [-]
Great username :-) I'm a happy longtime Fastmail customer and I'm migrating to the new EU area.
chrismorgan 1 days ago [-]
Fastmail has never used AWS, and this article is pretty clear about how they have always used their own hardware and traditional colocation.
Fastmail used to be based in Melbourne only, but after the Pobox merger it ended up with an office in Philadelphia too. No idea how the balance of things is between the offices now.
atmosx 1 days ago [-]
That’s interesting, I thought they were hosted on AWS. Thanks for sharing.
13 hours ago [-]
preisschild 1 days ago [-]
But how is it actually "a start" or improves anything at all? It doesnt matter where the "physical location" of the data is. It matters who has access to it.
calvinmorrison 1 days ago [-]
Fastmail runs on its own infra.
altairprime 1 days ago [-]
EU folks, note the warnings threaded throughout this post: this is not currently any sort of panacea against US or AU data hosting risks, but it will make your data noticeably closer to home. Fastmail (Australia) merged with Pobox (Philadelphia) resulting in a complex tri-national law/risk surface when the EU is involved, so go in eyes wide open having read this in full. That everyone will overinterpret “EU data region” to mean “for privacy” here until reading the article is completely understandable; I empathize, having done the same.
usernomdeguerre 18 hours ago [-]
I think it's not unreasonable to see this as a first, positive, step.
It's certainly giving them some benefit of the doubt, but it doesn't seem unreasonable that, say, the EU server and the US backup will in some time be an EU server and an EU backup.
inigyou 6 hours ago [-]
It's either a positive step or it's a deceptive step. It could be to actually improve data security, or it could be to make it look like they're improving data security.
Posted on the previous submission for this: it’s a good start, but from the article:
If what you need is a guarantee that your data remains only in the EU, we don’t have that, and we’d rather tell you directly than let you assume otherwise.
intothemild 1 days ago [-]
Wow they completely missed the ball on why people want reassurances that their data stays in the EU
fodkodrasz 1 days ago [-]
For me this is already a better value proposition, as less value add happens in the US. With the US being a perpetrator in trade war against the EU, even this matters. Everything counts, in large amounts...
xnickb 1 days ago [-]
I think they just know what they can and can't guarantee.
linux2647 1 days ago [-]
Agreed. I imagine they’ll announce an EU-only option later once they get more EU infrastructure in place
jeffrallen 7 hours ago [-]
As long as they are owned by a 5-eyes nation, there's no alternative they can offer.
Instead, look to Exoscale, Proton, Infomaniak, or Scaleway.
Disclaimer: I work for one of 'em.
nektro 23 hours ago [-]
they also said in the article it is dependent on them standing up a second EU region. this is simply an announcement of their first.
carlosjobim 8 hours ago [-]
They found a cheap way to please the kind of customers who care much about their activism and not much about reality. A good business decision with little risk and a potential upside.
To believe your data is any better protected here or there is already unrealistic, and the admiration for the European Union for data privacy among hacker circles is unfounded. But if many people believe something false, you as a business should give them what they ask for and not try to educate them.
intothemild 8 hours ago [-]
Yeah this I think captures my initial feelings in my post better than I could have put it.
Any business that has strict guidelines won't touch this. As there's no real guarantee, and more importantly they have given themselves an out.
Whilst I like fastmail as a product, personally I would have waited to get everything in the EU before I launched this, as you've now got to relaunch it once you solve that last mile problem. Which is hard and costly.
rdm_blackhole 5 hours ago [-]
Absolutely spot on.
To think that your data is safe in the EU while the EU is actively pursuing ID checks for social media and pushing Chat control every 6 months is delusional. No, your data is not safe here. If the EU wants it, it will get it.
This cult of the EU privacy needs to stop. The EU wants the same access that the US intelligence has but for some reason, some people don't believe it and defend tooth an nail this idea that things are better here.
Just so you are aware, Europol was lobbying to have access to all text messages/emails in the EU at will without a warrant as part of Chat Control V2. Say what you want about the 5 eyes countries, this is no better.
If tomorrow the EU wants access to your data, Fastmail will give it just like it will give it to the US, to the UK or to Australia.
globular-toast 14 hours ago [-]
Anyone who cares about security won't accept "reassurance" anyway. They would use end to end encryption like PGP or similar and not worry about the middlemen.
calvinmorrison 1 days ago [-]
One needs multiple data centers in europe for backup and DR, sounds like they have one
tumdum_ 24 hours ago [-]
Or you can just use any of the actual European companies (I’m using Tuta).
Any providers that don't provide SMTP/IMAP/JMAP are just a boring way of giving away control over your mail and the client software you use.
I don't know about Tuta specifically, but Protonmail is practically intentionally hostile against anyone using their own keys. Which is the biggest sign that their marketing and actual intent do not align.
dwedge 23 hours ago [-]
I started using tuta until I realised they don't support IMAP. Something to do with not guaranteeing encryption (which isn't even enabled by default) but has the convenient effect of locking you into their apps
FireInsight 12 hours ago [-]
https://mailbox.org/ is great. It's the only provider recommended by privacyguides.org that supports IMAP/SMTP.
justinclift 19 hours ago [-]
IMAP can do TLS though (IMAPS).
Did they say what's stopping them from using that (and requiring the encryption!)?
crossroadsguy 17 hours ago [-]
They didn't need to. When you start denying IAMP to your customer in the name of "encryption" at that point it becomes privacy theatre, instead of privacy, irrespective of how nobly activist their intensions are. It is probably slightly worse than a mail provider assuming they can't trust their users with encrypting their emails when needed.
gertop 22 hours ago [-]
Tuta is always encrypted I don't know where you got the impression that it was optional or that they could somehow magically make it work over IMAP without a bridge like proton.
dwedge 12 hours ago [-]
> Tuta does not support the use of third-party email clients or the protocols IMAP/POP3/SMTP as we cannot guarantee end-to-end encryption of your data.
So it "breaks end to end encryption" even with smtps and imaps apparently. The few emails I received weren't from tutamail users so presumably came over SMTP.
It's confusing to know what they mean because they confuse terms. They say emails are "stored end to end encrypted".
They don't pass my smell test
mr_mitm 9 hours ago [-]
And here I thought using open source client software is the only way I, the user, can guarantee E2EE of my data.
tumdum_ 11 hours ago [-]
They offer similar product to a more well known Proton.
I call this "sovereignty washing": American companies pretending they can magically free themselves from the U.S. CLOUD Act by setting up a paper European presence.
Anyone who falls for this is a fool wanting to be fooled.
pigbearpig 8 hours ago [-]
Interesting take considering Fastmail is very clearly not an American company.
_tk_ 7 hours ago [-]
Unfortunately, even if all data lives in the European Union, as long as a company is conducting business in the US, the Cloud Act makes it possible to compel them to hand over any information. This can include making administrative personnel sign NDAs or face heavy repercussions. Conducting business in the US includes advertising to US citizens e.g through maintaining a website in English.
At this point it’s unclear what a future digitally sovereign infrastructure should look like. Even if a company or a European state somehow manages to store data that is out of reach for the US Government, an amendment to FISA or the Cloud Act is something that any Congress should be able to put together.
telmo 6 hours ago [-]
I am pretty sure that European states are already storing data that is out of reach for the US government, and I don't understand how Congress could legislate against this, short of an act of war.
_tk_ 6 hours ago [-]
There are certainly exceptions, but a lot of European Governments use Azure or Google for their office applications, including different law enforcement agencies and militaries.
cube2222 1 days ago [-]
Nice, as a European customer, I appreciate this.
Side note, I moved to Fastmail a couple years ago, and so far I’ve been very happy with it! The Gmail migrator works great, too.
EPWN3D 19 hours ago [-]
Love them, but I wish they had a way to upload new sieve rules via an API. I'm probably going to try them with my own domain at some point since I think they have an option to just deliver all mail bound for that domain, which makes setting up random emails for dodgy sites really easy.
cube2222 11 hours ago [-]
Yep, you can enable a catch-all for anything that’s not a predefined alias.
I’m using that setup and have no issues with it, for exactly the use-case you mentioned.
> Resilient replicas of your data will live in the US (for now). As we only have one location in Europe so far, the geographically separate copy will remain on servers in one of our US locations.
Wow, it's nothing. How about writing your PR after the data is not going to the US at all?
tikkabhuna 8 hours ago [-]
Isn't it a step in that direction? The first data centre in Europe shows a commitment and it will likely be easier to do the next data centre(s).
rzerowan 1 days ago [-]
Seeing a lot of detail in the comments about the CLOUD act which applies as they(fastmail) themselves have an equivalent that was signed between USgov and Australia.
The more concerning issue as far as Australian based tech is The Assistance and Access Act 2018 which
"...permits government enforcement agencies to force businesses to hand over user info and data even though it’s protected by cryptography.
If firms don’t have the power to intercept encrypted data for authorities, they will be forced to create tools to allow law enforcement or government to have access to their users’ data."
As far as i know this has not been challenged or walked back and with the rise of ChatControl like laws doesnt seem it will.
chrismorgan 1 days ago [-]
The Assistance and Access Act is completely irrelevant to Fastmail, because Fastmail doesn’t offer end-to-end encryption. Fastmail was always subject to the Telecommunications Act, which allows Australian police access with warrants, and Fastmail has always made it clear that it complies with legal warrants.
denismi 19 hours ago [-]
The article you're quoting [1] concerns itself with the creation of systemic "encryption-breaking" capabilities and exploits which said law bends over backwards to expressly prohibit [2].
The local government cannot get access to the servers in Amsterdam?
I use Fastmail but just consider it safe from third party advertisers. If I wanted safety from governments I would use something else, or at least encrypt my email contents.
PeterStuer 1 days ago [-]
Five Eyes country are subject to local data disclosure orders and gag clauses, forcing them to hand over user data that may then enter the shared intelligence pool
skywal_l 1 days ago [-]
There are no Five Eyes country in the EU.
r_lee 1 days ago [-]
the company is based in Australia, which is part of FVEY
PeterStuer 1 days ago [-]
Is fastmail not australian?
anon48293 1 days ago [-]
No, but there are nine eyes and fourteen eyes with EU countries.
throw1234567891 1 days ago [-]
they offer services in the EU
senderista 1 days ago [-]
Not sure Five Eyes will outlast Trump, the UK has reportedly stopped sharing some intelligence with the US:
Actually thrilled that I can choose US data residency. Apparently, it was always that way? Happy that I can choose it though as I would prefer my data not be stored somewhere else.
igl 20 hours ago [-]
Australian company so: lol. Snowden triggered a few narrow real wins but the broader surveillance apparatus adapted, survived, and in some ways grew. Things were just legalised.
doener 23 hours ago [-]
As long as the company's legal headquarters are in the U.S., U.S. agencies have access to the data under the Cloud Act—and non-U.S. citizens have absolutely no legal recourse when it comes to U.S. services
hinata08 23 hours ago [-]
their HQ is supposed to be in Melbourne, Australia
They mention it only briefly in their publication.
Their about page is clearer about that.
tremon 4 hours ago [-]
Which means that not even a European subsidiary will prevent data exfiltration by FVEY. Australia can just issue a TCN to the parent company to add a backdoor to the software used by the European subsidiary.
doener 13 hours ago [-]
Ah, thanks for the hint! Probably better than, but still Five Eyes. The legal details I‘m not aware of in this case.
8by3 13 hours ago [-]
Its not only a question of five eyes access. There is also the concern of being subject to the whims of a regime that might decide you shouldn't have access to services hosted in their country.
procaryote 12 hours ago [-]
This does nothing to resolve that
greenleafone7 1 days ago [-]
The article states that they do not offer any guarantee that my data will stay in the EU!
I feel that that's the whole point. And the whole point of them making this article/advertisement.
petcat 1 days ago [-]
How could they possibly guarantee such a thing?
Do you only send and receive emails with people in the EU?
greenleafone7 22 hours ago [-]
Your reply is dishonest. I obviously couldn't replicate the entire article, but I'm assuming everyone that reads my comment also has read the article. And so you know very well what I meant.
If you advertise foolproof safes, but they end up not in fact being exactly that very thing you advertised then I'm sure you will have a great reason as to why actually your 'foolproof' safe can not be foolproof and you never guaranteed such a thing in your tos.
But at the end of the day, you promised foolproof safes, and you did not deliver.
Your argument is "well if you leave the lock open then...". And the reply to that argument is that "yes, we all know". The fact that I the user can make a mistake, does not excuse the company from saying "well, anyway, he would have made a mistake anyway so why bother"
monsieurbanana 1 days ago [-]
At the moment all your data is still replicated in the US (they say it will change in the future, sure) and all the logs are also stored there, with no plans to change it or more details into what they contain.
As of now there's no guarantee of... anything, really.
Obviously if you decide to send an email to the US you're choosing to send your data there, that's a strawman.
preisschild 1 days ago [-]
Its not about the people you send emails to, its about who has access to your entire mailbox.
In the moment that would be the Trump Administration for example.
1 days ago [-]
plqbfbv 1 days ago [-]
As a customer, thank you, Fastmail. I recall reading a few months back that this was rumored to be in the works, glad it panned out.
rb666 1 days ago [-]
Finally! I have been asking for this since the US started to lose its mind. Great they are listening.
preisschild 1 days ago [-]
But this is completely worthless, they still fall under the cloud act. Trump Admin still has access to your mailbox.
lschueller 1 days ago [-]
If what you need is a guarantee that your data remains only in the EU, we don’t have that, and we’d rather tell you directly than let you assume otherwise.
Is there an alternative that really keeps data in the EU? (And not only in the sense it serves a sales promotion)
Among these runbox is quite good and my friend has used migadu for a few years and likes it even though he says the "soft" limits still make him uncomfortable even though so far he has never hit them; so I guess that should be fine. Posteo doesn't support custom domains (I've used them and otherwise they are good). I wouldn't go with Proton ever. Mailo seems new - never heard of them. Would love to get a review.
mailbox.org can be avoided if you need to send and receive emails from domains where the mail admins might not be email admin savants and/or privacy activists (sometimes that's not a choice in case of Govt services etc and you may not live in a country when you can get those changes done). Also, if you ever face an issue and send them an email, expect the reply to come in weeks (if you are lucky) and that too a flippant (sometimes even terse) nothing-mail and then if you respond the cycle repeats until you give up.
lschueller 23 hours ago [-]
Splendid, thank you. the european-alternatives.eu is exactly what helped! Appreciate it!
atmosx 1 days ago [-]
Depends on the definition and your threat model but to make a very large story short; it’s email, others have copies (your gmail friends?). Metadata is public by default the body can be encrypted and encrypted at rest (comes with many limitations) and that’s the highest level of security you can realistically achieve.
If that works fine if not, use another method of comm. Email wasn’t designed to be secure.
lschueller 1 days ago [-]
Thank you. Sure. In Europe the "euro stack" approach becomes more and more relevant. So, the issue is more a compliance topic in the way of making use of service provides, who are best-case "eu-headquartered", but at least with a guarantee that processing on my side stays within the european realm. Doesn't mean very little in a technical understanding of security, I agree.
1 days ago [-]
vzaliva 1 days ago [-]
I do not know any EU-only, but ProtonMail is in Switzerland.
petcat 1 days ago [-]
Proton is leaving Switzerland because of surveillance and privacy issues.
> Because of legal uncertainty around Swiss government proposals to introduce mass surveillance — proposals that have been outlawed in the EU — Proton is moving most of its physical infrastructure out of Switzerland.
They are moving to Germany, but will quickly find that they are going to face the same surveillance and privacy issues since the EU is in the process of negotiating a data sharing agreement under the US Cloud Act.
That was 2023 before the 2nd Trump Admin and before the Privacy and Civil Liberties Oversight Board that was supposed to be independent and protect against abuse has resigned.
egorfine 1 days ago [-]
Can't wait to verify my age before reading emails!
In all seriousness though, what are the chances Fastmail won't require KYC at some point? I have sent them a support request with that question and got a non-answer.
PS: Am a paying customer for like a decade
crossroadsguy 17 hours ago [-]
No one would know that other than Fastmail and regulators. But what I can say is keeping different emails for different purposes might be the way. Unless your domain also has none of your PII attached to you, neither is any of your email interactions. It's not ideal but I finally stopped fighting it and use few emails that offers both privacy and anonymity if I ever need that.
trocado 21 hours ago [-]
This may not have much practical consequence, but still there's some symbolic value which is welcomed in today's geopolitical climate.
crossroadsguy 1 days ago [-]
I have never understood their 50+10 GB storage as the starting plan. Anyone storing a lot of emails, please don't come at me screaming, but know that not everyone keeps every email and every attachment ever received right there in that email account (especially the attachments). For me, email is just communication i.e timed information, not data storage, except for very personal emails, and very very rare, some non-personal important emails. So some people do like to simply delete the emails they no longer need. Also their pricing almost feels like "unlimited storage" backup solutions mass pricing strategy.
tene80i 1 days ago [-]
You mean why isn’t there a cheaper tier than $5/mo? Not much to be gained by offering it, I would think.
3eb7988a1663 1 days ago [-]
Even at cloud prices, 50GB of storage is ~$1/month. Offering an additional tier with pathetic storage to save $0.80 or whatever is muddling the offering.
I guess they could offer a 0GB storage option that only operated as a relay?
kmfrk 1 days ago [-]
As a European and Fastmail user, this is great news.
I_am_tiberius 1 days ago [-]
And which company hosts the data? An American company like Aws, Azure, Google or a European company like OVH, Stackit?
fhdkweig 1 days ago [-]
The flagged/dead comment contains a copy of the entire page, but the relevant part is:
> Built by us, not rented from someone else
> We’ve installed our own servers, co-located in a secure facility in Amsterdam, set up by our own engineers. This new location is built to the same high standards as our existing infrastructure in Philadelphia and St Louis, with our own hardware and our own software — specified right down to the exact model of disks in each machine.
> In all our locations, data is stored encrypted at rest inside locked racks, and managed by our in-house team. We don’t rent computing or management services from a big cloud provider and pass on their assurances. That’s how we’ve approached privacy, reliability, and performance for more than 25 years.
techpression 1 days ago [-]
> We’ve installed our own servers, co-located in a secure facility in Amsterdam, set up by our own engineers. This new location is built to the same high standards as our existing infrastructure in Philadelphia and St Louis, with our own hardware and our own software — specified right down to the exact model of disks in each machine.
braza 12 hours ago [-]
Maybe it’s a silly question, but how much of those “EU Region” makeups that were seeing are enforceable in reality?
In extreme cases the US DoJ can reach, let’s say the CEO/CTO arrest them or pick up family members in case of some sort of non-compliance in some criminal investigation.
I can imagine something like
> US DoJ has some PoI with some account in Fastmail “EU region”
> Fastmail says “sorry we’re GDPR”
> US DoJ says “now” or…
> Fastmail refuses
Then what?
12 hours ago [-]
kazen44 11 hours ago [-]
then it becomes a political issue between the EU and the US?
mind you, prior to this administration the EU was more then happy to help the US DOJ in such cases.
considering the stuff that happened in the past year or so, i doubt that would happen again.
Actually calling bluff on the US is the only way to play this properly, because it gives the EU a mandate to strike back geopolitically if the US wants to retaliate for non-compliance by fastmail.
ln809 24 hours ago [-]
Secondary copy not in EU. So how exactly does that help with compliance?
leros 24 hours ago [-]
It sounded like a temporary situation until they get a second EU datacenter.
victorbjorklund 1 days ago [-]
Not more safe. Only safe way is to use a company not under US regulation.
tamimio 1 days ago [-]
Does it matter much? From one side, you are still in the 14 eyes countries (in fact, I would trust a Chinese server if i am living in the west and vice versa), on another side, emails as a protocol was never meant to be secure or private, so deal with it as that, if you are after private or secure communication, choose a protocol that provides that, adding more stuff to emails will only complicate it further plus giving false sense of privacy/security, gpg will leak meta data, receiver email server/client might expose you too, among many gaps, so just avoid it. Still, make sure your email spf dkim dmarc etc are set properly and carry on.
inigyou 18 hours ago [-]
Useless. US companies have to get EU citizen's data on request. They can and must do so. Only non-US companies can ignore US data requests.
hellcow 17 hours ago [-]
Fastmail is an Australian company.
inigyou 9 hours ago [-]
Then they're fucked. Session Messenger had to flee Australia.
philipwhiuk 7 hours ago [-]
> Emergency backups for everybody are stored in our Philadelphia location. As well as the live replicas of your data, we also keep a separate set of encrypted backups taken every few hours for every account. These are in Philadelphia for all users at the moment.
So all of this is pointless.
atmosx 1 days ago [-]
Okay, that solves two problems for me. Great news.
Cider9986 1 days ago [-]
Jurisdiction is an outdated way of looking at things. End-to-end encryption is what actually matters. Of course, people are stupid, so it continues.
tremon 4 hours ago [-]
E2E encryption is meaningless for an e-mail hosting provider; they are by necessity one of the E's.
KingOfCoders 1 days ago [-]
We offer EU data centers for customers that want their emails to stay in the EU but
"Resilient replicas of your data will live in the US"
?
crossroadsguy 1 days ago [-]
The US data replicas will be resilient, and when the FBI asks your data to reveal things about itself, your data will refuse to reveal anything about itself in the characteristic resilient manner. That's why the mention of "resilient".
KingOfCoders 1 days ago [-]
How is that possible if the OS/drive/vault is backdoored? Could you elaborate?
I think "resilient" just means "backup copy" and I do think (IANAL) it is illegal to destroy emails when asked for them in the US.
Or was your comment ironic? Sorry, German, irony impaired.
Night_Thastus 24 hours ago [-]
They're being sarcastic.
sparkling 1 days ago [-]
To me, jurisdiction matters more than physical location. I'd rather be with a EU-operated service that stores data on a non-EU server, than a non-EU operator with a German/french datacenter.
Marciplan 1 days ago [-]
using cirrux.me and very happy with an actual EU hosted option (Team is Dutch)
varispeed 1 days ago [-]
Data is still compellable through US Cloud Act (and other provisions). If you want true EU data region, you should buy from a company without presence in the US.
ThePowerOfFuet 22 hours ago [-]
Totally irrelevant because of the CLOUD Act.
Aussie law might be even worse than US; I would never use Fastmail.
wasabi359 9 hours ago [-]
[flagged]
jgeerts 1 days ago [-]
[dead]
cjs_ac 1 days ago [-]
[flagged]
honeycrispy 1 days ago [-]
[flagged]
lrae 1 days ago [-]
You mean Chat Control 1.0 that was already in place from 2021 to April 2026 and allows for voluntary scanning for CSAM in unecrypted data through hash-matching for existing and indexed CSAM material?
flexagoon 1 days ago [-]
Chat Control 1.0 is a permanent extension of a temporary law that already existed a year ago, allowing the companies to scan your messages if they want to. Nothing changed since then.
superq 1 days ago [-]
EU data regions are based on the insanely flawed idea that data is:
* a physical thing that can only live in one place
* not copyable
* can be 'contained'.
The whole thing reeks of bureaucratic 'best practices' that just aren't.
Even worse than that, trying to keep email restricted to the EU (or anywhere else) means that you effectively wouldn't be able to communicate with anyone in a different region, which is kinda the whole point.
Why not just make your own internet next? and then you can disconnect from everyone else who is trying to hack you. Just pull your network plug.
Email itself is hopelessly insecure by design anyway. Not just metadata when you are E2EE everything inside the envelope, but even basic vulns like downgrade attacks are simple because it's literally a violation of the RFCs (so you're not spec-compliant) to require TLS or any other encryption.. Why? because requiring modern crypto might interfere with deliverability and backwards compatibility. The real, deeper reason is that email is from a kinder, simpler time (well, at least simpler) and the design goals were never updated to keep up with the times.
Email is what we have. Just understand its flaws and then use other tools where you can. And who cares where your email lives - it's too easy to break anyway.
preisschild 1 days ago [-]
This is not an EU law anyways, this is snakeoil companies acting like having their data located in the EU will change who has access to it and will make it "GDPR compliant" (it wont since the CLOUD ACT still applies)
plqbfbv 1 days ago [-]
> The CLOUD Act authorizes bilateral agreements between the United States and trusted foreign partners that will make both nations’ citizens safer, while at the same time ensuring a high level of protection of those citizens’ rights.
I think the keywords are "trusted" and "citizens' rights". US burned a lot of trust in the last few years, and what's happening with ICE doesn't really scream "citizens' rights" either. I can see why many "trusted foreign partners" would now think twice rather than help out the US compared to just 5 years ago.
As a EU person, I'd really like to not have ties with US when possible, and I'd really like to foster the economy of non-US alternatives.
It stops just short of saying that you must do thispreemptively, but is pretty clear that you must do it if they ask you to.
I admit it is a concern, as a Fastmail user, but this discussion only seems to happen on the Fastmail threads, yet no one bats an eye if one is suggested to open a gmail account like everybody else.
Not sure why you haven’t heard about it but US Cloud Act is a big reason for EU companies not trusting US companies: https://en.wikipedia.org/wiki/CLOUD_Act
Their homepage:
Free email isn’t really free: you’re paying with your privacy. As a paid service, we only serve you, our customer. This means we have no split loyalties, no mining of your personal data, no sharing it with third parties, and no ads, ever.
American products in particular are often mass consumer products that aren't particularly privacy focused. Everyone who cares about privacy already knows that Gmail isn't private - not only is it American, it's also owned by a domestic espionage conglomerate - but might be expecting Fastmail to be private, so that one is newsworthy.
I can't relate, I hear people complaining about American spyware online all the time in tech circles like HN.
There is lot of hate toward Google (and other top US companies). Especially due to autobanning of accounts, 2FA etc. at the moment people have fastmail as their darling - because they are the underdog, no AI forcing in products (at the moment) etc. It is like stripe from 5 years ago.
Most have given up in snooping. Or you need to go to proton mail but it has other issues. Every company is subject to some regulations.
at the end, if the receiver of email has to also keep it safe. Do they?
Also it got busted for funding some right wing movements.
Also it got busted for sharing data with governments leading to some activists getting arrested.
as a german i feel the urge to point out that this technically also applies to european companies... With more hurdles for the US, but still technically applicable
(At least that's what people keep telling me, im not a lawyer)
Which I may add: you could've easily found out yourself too if you looked up what I wrote.
Are you sure about that? European legal theory for insider trading implicitly covers more cases than the US without needing to explicitly enumerate them as far as I understand (in a nutshell, trading on insider information is illegal regardless of the source or whether any fiduciary duty was breached), and I'd be surprised if this case were not covered.
The issue in America is the president has more power to act unilaterally (maybe to address his/her own interests, maybe not) than any European politician.
The Trump regime a way more corrupt than anything currently seen in Europe.
He currently attempting to steal Greenland so he can strip it of mineral assets for fucks sack.
No politician in Europe is starting wars for personal gain.
Only Trump and Putin.
https://www.bbc.co.uk/news/articles/cly5wyynv9zo
Isn't that that basically the history of Europe? A short French or German or English or Roman dude starting a war for personal gain?
Is that the standard we're holding Trump to though?
Do you really think it's OK for him to invade other countries for personal enrichment because historic tyrants also did the same?
Just because you disagree with a law, that doesn't make it "corruption" - it does make you an authoritarian that attacks democracy as soon as other people don't vote like you want.
If the law is initiated by the parliament and not by some company through lobby. Lobby is corruption.
Please stop spreading fabrications - even when you dislike the result. That's fascist behaviour.
"Chat control 1" is the deliberately misleading name for "Facebook is not banned from using CSAM scanners on your DMs if it wants to" - I don't think it's worth voting someone out based on that. The one that bans encryption is called "chat control 2". I assume they've both got the same name as part of a deception tactic.
- Elections are so rare (every 5 years) and encompass so many huge life-altering choices (VDL being one of the criteria only) that it's not democratic. The Swiss vote every important law, like "Should we buy fighter jets".
- De facto, party health is part of democracy (look at the Rwanda: It is absolutely possible to have a genocide made by democracies, and it is in fact more frequent than dictatorships) and network effects have made that European parties don't represent the people's will,
- Europe dispatches money to countries that need convincing, like Scottland, while wearing the mature members' citizen to the bone. We can't even have decent roads or internet here, while newcomers are super-happy to join ("I'm happy because Europe brought wealth and economic development!!!" - yeah look in 20 years). Money flushing around Europe trying to bribe citizens groups into staying, which makes opposition impossible. The EU is too chicken to let citizen vote every 20 years on whether we should stay in Europe, because then answer would be a big NO.
- The kill switch didn't even work, countries can't leave, or there is retaliation. Not only UK but France voted against the new treaties in 2005, the president still signed them.
The EU is the most lazy level of democracy. It's a knee-jerk reaction to say that VDL can be removed from office by the citizen.
Well us Brits tried that experiment and it isn't seen as a success.
What is not a success is:
- The EU taking retaliation against them,
- The EU parties overturning members of the Leave party into the Libdem, AFTER being elected (yes, it happened for 16 members, plus the ones who didn't officially switch but stalled the Leave party's proceedings),
- From the moment they clearly voted NO, it took 3 more votes until they could be allowed to leave. Basically, it was until it was clear the UK citizenry would be entirely blocking the democratic process until the EU-Leave decision was enacted. You can understand people's despair of democracy when a clear LEAVE vote isn't enacted, like in France 2005.
In the rest of the EU, they're too chicken to let us vote. But they will let us vote... one day... only in areas where they're guaranteed a large STAY result.
The EU is only letting us vote when the answer is Yes.
Taking several votes for such a big decision is good. It prevents impulsive hotheadedness from making a ruinous decision. The UK did vote to leave and then left.
And it ruined the UK. That's why other people are saying it was a bad idea. Not because they didn't vote, but because the thing they voted for ruined them.
Except the catchphrase of the day was "Brexit means Brexit", because no one bothered to define what we were voting for until we'll after the fact. There were plenty of options such as a soft Brexit or a hard Brexit. Even the hard Brexit kept us in some institutions so what we got was harder than the hardest Brexit discussed.
So in what way did we get what we voted for?
Rwanda has never been a democracy. Habyarimana was "elected" with 99% of the votes ffs.
> and it is in fact more frequent than dictatorships
It is trivially easy to verify that this is not true.
Rwanda came for help to France 2 years before, and France conditionned its financial help to a democratisation process.
- From here, about 150 parties got born.
- The previous dictatorship, even of the majority, was protecting the minority, because they knew the international consequence on countries who don't protect the minorities.
- Once a democracy, it was a leadership of the majority ethnicity (90% Hutu) so you bet they had no qualms about protecting the Tutsis. Tensions and invitation to violence soared immediately, but in a coveted speech.
- A plane containing half the government was bombed, the country woke up without clear leadership, elections didn't happen fast enough. Citizen acted with their own machetes.
Democracy means the majority owns the decisions. Doesn't mean they'll be good people.
I suggest you show up for next EU election if you don't like the option.
It is worth remembering at this point how von der Leyen first became Commission President. She was controversially nominated by the European Council - who are not directly elected representatives within the EU system - deviating from the spitzenkandidat convention in a way that surprised and angered many MEPs - who are. Her own national government (Germany) did not support her in the Council voting because one of the parties in the governing coalition opposed her. She was eventually confirmed by a narrow majority in a secret ballot of the European Parliament from which little can therefore be determined about who did or didn't vote for her except that quite a lot of MEPs who were expected to support her candidacy based on public statements did not in fact do so in the secret vote.
So she was essentially proposed by a group of people who aren't directly elected at EU level and in some cases aren't even directly elected by the nations they represent - in violation of the normal convention expected by the only people who are directly elected at EU level - and was then narrowly confirmed by that directly elected group only in a secret ballot from which the vote of each individual representative was not recorded and there is therefore no possibility for their own electorates to hold those representatives to account personally for how they voted. Given that we are talking about the most influential political post in the EU this is not exactly a powerful demonstration of democratic legitimacy and a clear popular mandate no matter how you look at it.
Still, calling the system undemocratic is a stretch since anyone who pays attention can see how EU policies have shifted after the far right increased the number of their seats in the previous election. Climate ambition has been dialed way down and immigration is being curtailed.
Everything else she does needs to be confirmed by representatives of your own member state.
Just like EVERY OTHER democracy.
Not really.
In most representative democracies it is the elected representatives who initiate new law. In the EU the elected MEPs have no power to do this and it is the role of the unelected Commission to start the process.
Meanwhile the Commission is also the "executive branch" of the EU. A great deal of what the commissioners do is not directly subject to approval by the European Parliament.
The Council is the one that generally consists of the leaders of each member state. It has important roles in the system including selecting candidates for key roles and as part of "trilogue" negotiations (which are themselves sometimes controversial for being secretive and unaccountable) but has little formal participation in the normal legislative process.
The Parliament is the one whose members are elected by the citizens of the EU. Its best known role is to debate and vote on new legislation.
The Commission holds much of the real power as it serves as both the leadership of the executive branch and the origin of new legislative proposals - and yet its members are chosen via much less transparent means and have little personal accountability to EU citizens.
Many EU commissioners have been politicians whose national political careers were struggling and - like appointment to the House of Lords here in the UK - they may have been put forward for the Commission by their national political leadership as a position of influence that required less confirmation than winning a popular vote. This is relevant here because von der Leyen herself is arguably in this category.
The next election is in 2029. I suggest you show up instead of spreading fabrications online.
Should they happen to vote incorrectly, like when the EU constitution was voted about in ireland and france ,they will just have to vote again and again until by exhaustion, the right result is guaranteed.
The EU has nothing to do with democracy. No, putting a paperslip in a box is not democracy.
I think perhaps switzerland is the country on the planet that is closest to democracy, and they also have the highest incomes ,highest living standards and lowest taxes in europe.
The EU has choose the path of soviet like socialism, and of course the economy will slowly decrease until it collapses, and then we'll get a Hitler 2.0 to "fix" the problems that were caused by the EU dictators.
The best thing you can do if you care about europe, is to move outside of the EU, avoid paying tax, do not feed the beast, and spread the truth, so that fewer and fewer people want to move there. Then it will hopefully collapse in time.
That’s democracy in its purest form.
I live in the UK, on paper we have an absolutely terrible version of democracy. No constitution, and un elected head of state. Compared to pre pull out Afghanistan it sucks. And yet we are still here. Perfect on paper democracy isn't the be all and end all. It's about institutional culture. The EU has a much better democratic culture than the US does.
And as the Americans are choosing to interfere in European domestic politics and trample their own laws and constitution the more scrutiny their requests will get.
> The CLOUD Act primarily amends the Stored Communications Act (SCA) of 1986 to allow federal law enforcement to compel U.S.-based technology companies via warrant or subpoena to provide requested data stored on servers regardless of whether the data are stored in the U.S. or on foreign soil.
[1] https://en.wikipedia.org/wiki/CLOUD_Act
It's unfortunate for us, but we very rarely isolate individual government systems for other nations.
It was the MLAT thing that the various civil liberties groups object to (I'll cover the problems with those down below). There was very little objection to the first part.
The first part was not controversial because pretty much every country has something equivalent (for reasons I'll cover below), as did the US except specifically in the case of data covered by the SCA due to poor drafting.
One of the big reasons for the SCA was created was the emerging "third party doctrine" meant that instead of having to get a warrant or subpoena against you to get your data they could simply subpoena it from any of your service providers that had it. The SCA made it so the third party doctrine subpoenas would not apply to stored communications.
There were still cases where the government would need to compel the service provider to turn over the data. They wanted something with the probable cause requirements of a warrant but the delivery method of a subpoena. (A subpoena asks someone who controls the data to turn a copy over. A warrant is for when the government wants to raid the data center and seize the data. Since that involves the government directly acting where the data is located it only applies to someplace where they have jurisdiction).
So they created a new thing, the SCA warrant. The called it a "warrant" because it had the probable cause requirements of a warrant, but neglected to add something saying that in other respects it functions like a subpoena. I'll call this a pseudo-warrant.
The SCA was not the first pseudo-warrant. That would be the warrants under the Wiretap Act of 1968. Territoriality questions did not arise under that because by its nature the data it sought copies of was always in the US.
With the SCA the data might not necessarily be in the US. Years later Microsoft argued that because it is a "warrant" it should have the territorial restrictions that normal warrants have. The CLOUD Act clarified that it was indeed supposed to be like a subpoena as far as territoriality goes.
There have been some more pseudo-warrants created since then, but their drafters learned from the SCA and made sure the original legislation was clear on just what they were.
The reason pretty much every country has something like that, going back well before online documents, is because not having such a thing leads to big problems. If anyone in the country could shield documents from subpoenas (or whatever the equivalent is called in that country) by merely storing them across a border every company with documents that it needs to keep but that might be incriminating later would get sent to a storage facility across a border as soon as they were no longer actively using them.
For example as soon as a car company in Detroit releases a new car all the documents where during development engineers brought up safety concerns which management decided to not address would be sent across the bridge to a storage facility in Canada.
With electronic documents it is even easier. You would not have to wait until you aren't actively using the documents to stick them outside the country. Just stick your file server across a border and make sure you only have copies in country when someone is actively reading or editing them.
And so pretty much everywhere subpoenas compel someone in the country who controls the documents to fetch them (or copies) and turn them over. The actual location of the documents is completely irrelevant.
The thing that was worrying about the CLOUD Act was the MLAT provisions. MLATs are treaties where the participating countries agree on law enforcement. They include things like sharing information and cooperating on investigations. Normally these are enacted just like any other treaty. The executive branch negotiates them and then the Senate votes on ratification.
The CLOUD Act adds an expedited process where the Attorney General and the Secretary of State can sign an MLAT. Congress is not involved. These agreements allow foreign law enforcement to make requests directly to US service providers instead of going through the diplomatic channels normal MLAT requests go through, and they allow them access to stored communications that the SCA would normally block.
There are some safeguards. The foreign government is not supposed to intentionally target US people who are in the US and are not not supposed to use the data they get to infringe freedom of expression. There's also a 180 day window before these executive MLATs take effect during which Congress can block them by passing a joint resolution to do so.
Civil rights groups and many others were not impressed with those safeguards.
Even the entire EU is in the process of negotiating the same agreement.
https://www.justice.gov/archives/opa/pr/united-states-and-ca...
https://www.justice.gov/archives/opa/pr/justice-department-a...
You can read the text right here:
https://www.justice.gov/criminal/criminal-oia/cloud-act-agre...
The same agreement is in place with the UK. Canada and EU are currently in the process of negotiating it.
Things have changed. With Chinese law in regards to data within Chinese jurisdiction a long-standing thing and an unfriendly American government potentially in power for an extended period, other countries are realizing the importance of data sovereignty.
> The latter states that negotiation with the EU on this topic was suspended in 2019.
Dated 2023:
> Justice Department and European Commission Announces Resumption of U.S. and EU Negotiations on Electronic Evidence in Criminal Investigations
The negotiations are still ongoing. Canada is further along than the EU.
The Five Eyes is an Anglosphere intelligence alliance comprising Australia, Canada, New Zealand, the United Kingdom, and the United States. These countries are party to the multilateral UKUSA Agreement, a treaty for joint cooperation in signals intelligence.
https://en.wikipedia.org/wiki/Five_Eyes
Does fastmail have a US presence? If no - then they're not bound at all by US jurisdiction.
See: https://roncobb.net/img/cartoons/aus/k5092-on-Tucker_Box-cuu...
This hasn't been true for several years. All Australian companies (and UK companies) are under jurisdiction of the US Cloud Act. Just the same as American companies are.
https://www.justice.gov/criminal/criminal-oia/cloud-act-agre...
They didn't even manage to extradite Kim Dotcom for years.
The question is: do they office services to residents of said country / state.
If so they may well be subject to certain laws that, if broken, could result in penalties up to an including extradition of the responsible officers.
- The US could request your data. You probably shouldn't use e-mail for anything sensitive anyway for many reasons. E-Mail was traditionally not encrypted and I think that many servers still allow plain-text communication. The protocols are old and there are all kinds of downgrade attacks. Aside from that, even if your service does not fall under the CLOUD Act, you are probably f*cked anyway, because most people you communicate with are using services that fall under the CLOUD Act.
- The US can force the provider to block your account. The workarounds are: regularly backup your e-mail (easy for services that offer IMAP) and, most importantly, use a domain with an extension that is not under the control of a US (or probably five eyes) registrar.
Use an E2E-encrypted messenger with perfect forward secrecy, etc. for most personal communication.
However, most people these days are using webmail from the big-tech companies which makes it relatively easy for LEA and intelligence agencies to read your email.
AWS, Azure, GCP, Oracle, Schwarz Digits, SAP
Like, the critical problem with the AWS sovereign pitch is that you must believe that they won’t give the keys to the US, and they also won’t give the source code that’s hosted in the US to the government either for them to find vulnerabilities in. I don’t know if that’s good enough unless you just need the data to stay in the EU and you don’t care if another country sees it.
I know they probably did some work on it (what if primary AWS goes rogue and the EU entity must work without it) but I don’t know if they explained how they’re safe to the public.
I am assuming the reason companies switch to them is not price or tech. US cloud providers have the advantage on both.
Selling EU companies data would mean destroying trust over their main selling point, not to mention incur on EU wrath.
Feels like living one whistleblower away from doom.
I refer to fully EU clouds, parent list includes US clouds that do not need bags of money, Clouds Act in enough.
What? Those are US companies, they will have to give out your data under the Cloud Act. Only Schwarz and SAP are free from that by being German companies.
Not true. You also have to be sure that the company directors will never travel to the US even for a holiday or any third party country that would uphold an extradition request from the US.
It's just email. Nobody is going to jail to protect your email.
If you care that much run your own email server.
Just because they pretend to be European-based by setting up a European subsidiary with so-called firewalls means exactly...nothing.
So Australia may spy on data entering and leaving the Australian server that serves US customers, but they can't just seize the server based on the Five Eyes agreement.
BTW it's expanded to Fourteen Eyes and it's generally good to assume that all Western governments are cooperating to about this degree.
Not that I don’t trust the statement, I just would like to know more.
https://thenextweb.com/news/airbus-scaleway-aws-sovereign-cl...
And many others besides, pretty much every company I've looked at in the last year is either acutely aware of the problem or they are already executing on it. With Trump and his merry band of criminals repeatedly stating they're going to take Greenland by force you can't blame them either, that would effectively put the EU on a war footing with the United States (I still can't believe I'm writing this sort of thing and it is not entirely fiction), the end result of that would be that there would be an absolute run on EU hosted capacity. They're just trying to beat the rush and hope they'll never be proven to be right.
Gov.uk has replaced Stripe with Dutch provider Adyen - https://news.ycombinator.com/item?id=48415217 - June 2026 (235 comments)
Netherlands reaches deal with European cloud company to decrease U.S. tech reliance - https://nltimes.nl/2026/04/24/netherlands-reaches-deal-europ... - April 24th, 2026
Wary of US Big Tech, the EU looks to build its “EuroStack” - https://sherwood.news/world/wary-of-us-big-tech-the-eu-looks... - March 18th, 2026
Why European Companies Are Leaving US Cloud Providers in 2026 — And Where They're Going - https://massivegrid.com/blog/european-companies-leaving-us-c... - March 12th, 2026
Europe gets serious about cutting digital umbilical cord with Uncle Sam's big tech - https://www.theregister.com/off-prem/2025/12/22/europe-gets-... - December 22nd, 2025
Schleswig-Holstein waves auf Wiedersehen to Microsoft stack - https://www.theregister.com/software/2025/10/15/schleswig-ho... - October 15th, 2025
EU Banks Launch Wero Payments to Dislodge Visa, Mastercard - https://news.ycombinator.com/item?id=41666833 - September 2024 (88 comments)
https://european-alternatives.eu/
https://euro-stack.com/
EU-US Data Transfers: First Reaction on "Latombe" Case - https://noyb.eu/en/eu-us-data-transfers-first-reaction-latom... (2025-09)
EU-US Data Transfers: Time to prepare for more trouble to come - https://noyb.eu/en/eu-us-data-transfers-time-prepare-more-tr... (2025-12)
US Supreme Court just blew up EU-US Data Transfers - https://noyb.eu/en/us-supreme-court-just-blew-eu-us-data-tra... (2026-06)
I was up to date on noyb, but not aware that actually companies are moving at this speed and size.
Thanks all for some great resources
All the added eyes are European (Denmark, France, the Netherlands, Norway; Germany, Belgium, Italy, Spain, and Sweden)
Similar happened already with OVH Canada vs France.
> In an affidavit, Xavier Barriere, corporate counsel at OVH in Paris, describes the dramatic situation: If the important proponent of European data sovereignty were to comply with the Canadian order, those responsible in France would be committing a criminal offense. They face up to six months in prison and fines of up to 90,000 euros per violation. However, if OVH ignores the Canadian court, it faces contempt of court proceedings in Ontario, which can also lead to severe sanctions.
https://www.heise.de/en/news/Canadian-Court-OVHcloud-from-Fr...
And one comment here: https://news.ycombinator.com/item?id=46060903
What can you do about it? FDE? Can you keep the keys away from Hetzner? How much hacking would they need to do to get them? Can US government break SecureBoot?
Im just happy my business is not important enough
The only way to spin this as hetzner is to go public with this and make it a political point for geopolitics between the EU and the US, and take the loss /call the bluff on the US threat.
I don't think any of us have the total picture, but the bits that I do have are sufficient to worry me about the degree to which I am automatically breaking the NDAs I sign by using a computer, email, online data rooms and so on.
A difference could be that Germany might not have such blocking law as France. At least I have never heard of it.
If it had been the European one that was the subsidiary, then Canada could order the OVH parent company to order the subsidiary to do things.
https://www.justice.gov/criminal/criminal-oia/cloud-act-agre...
We’ve installed our own servers, co-located in a secure facility in Amsterdam, set up by our own engineers.
Swiss corporation with data centers in Luxembourg.
I mean to say, perhaps this is more about customer sentiment and image than something maybe benign to their profits like five eyes involvement.
Source: I founded FastMail.
Fastmail used to be based in Melbourne only, but after the Pobox merger it ended up with an office in Philadelphia too. No idea how the balance of things is between the offices now.
It's certainly giving them some benefit of the doubt, but it doesn't seem unreasonable that, say, the EU server and the US backup will in some time be an EU server and an EU backup.
If what you need is a guarantee that your data remains only in the EU, we don’t have that, and we’d rather tell you directly than let you assume otherwise.
Instead, look to Exoscale, Proton, Infomaniak, or Scaleway.
Disclaimer: I work for one of 'em.
To believe your data is any better protected here or there is already unrealistic, and the admiration for the European Union for data privacy among hacker circles is unfounded. But if many people believe something false, you as a business should give them what they ask for and not try to educate them.
Any business that has strict guidelines won't touch this. As there's no real guarantee, and more importantly they have given themselves an out.
Whilst I like fastmail as a product, personally I would have waited to get everything in the EU before I launched this, as you've now got to relaunch it once you solve that last mile problem. Which is hard and costly.
To think that your data is safe in the EU while the EU is actively pursuing ID checks for social media and pushing Chat control every 6 months is delusional. No, your data is not safe here. If the EU wants it, it will get it.
This cult of the EU privacy needs to stop. The EU wants the same access that the US intelligence has but for some reason, some people don't believe it and defend tooth an nail this idea that things are better here.
Just so you are aware, Europol was lobbying to have access to all text messages/emails in the EU at will without a warrant as part of Chat Control V2. Say what you want about the 5 eyes countries, this is no better.
If tomorrow the EU wants access to your data, Fastmail will give it just like it will give it to the US, to the UK or to Australia.
https://european-alternatives.eu/category/email-providers
I don't know about Tuta specifically, but Protonmail is practically intentionally hostile against anyone using their own keys. Which is the biggest sign that their marketing and actual intent do not align.
Did they say what's stopping them from using that (and requiring the encryption!)?
So it "breaks end to end encryption" even with smtps and imaps apparently. The few emails I received weren't from tutamail users so presumably came over SMTP.
It's confusing to know what they mean because they confuse terms. They say emails are "stored end to end encrypted".
They don't pass my smell test
Anyone who falls for this is a fool wanting to be fooled.
At this point it’s unclear what a future digitally sovereign infrastructure should look like. Even if a company or a European state somehow manages to store data that is out of reach for the US Government, an amendment to FISA or the Cloud Act is something that any Congress should be able to put together.
Side note, I moved to Fastmail a couple years ago, and so far I’ve been very happy with it! The Gmail migrator works great, too.
I’m using that setup and have no issues with it, for exactly the use-case you mentioned.
Wow, it's nothing. How about writing your PR after the data is not going to the US at all?
The more concerning issue as far as Australian based tech is The Assistance and Access Act 2018 which
"...permits government enforcement agencies to force businesses to hand over user info and data even though it’s protected by cryptography.
If firms don’t have the power to intercept encrypted data for authorities, they will be forced to create tools to allow law enforcement or government to have access to their users’ data."
As far as i know this has not been challenged or walked back and with the rise of ChatControl like laws doesnt seem it will.
[1] https://fee.org/articles/australia-s-unprecedented-encryptio...
[2] https://classic.austlii.edu.au/au/legis/cth/consol_act/ta199...
I use Fastmail but just consider it safe from third party advertisers. If I wanted safety from governments I would use something else, or at least encrypt my email contents.
https://www.courthousenews.com/uk-faces-questions-on-complic...
https://nos.nl/artikel/2586859-aivd-en-mivd-delen-minder-inf...
They mention it only briefly in their publication. Their about page is clearer about that.
I feel that that's the whole point. And the whole point of them making this article/advertisement.
Do you only send and receive emails with people in the EU?
If you advertise foolproof safes, but they end up not in fact being exactly that very thing you advertised then I'm sure you will have a great reason as to why actually your 'foolproof' safe can not be foolproof and you never guaranteed such a thing in your tos.
But at the end of the day, you promised foolproof safes, and you did not deliver.
Your argument is "well if you leave the lock open then...". And the reply to that argument is that "yes, we all know". The fact that I the user can make a mistake, does not excuse the company from saying "well, anyway, he would have made a mistake anyway so why bother"
As of now there's no guarantee of... anything, really.
Obviously if you decide to send an email to the US you're choosing to send your data there, that's a strawman.
In the moment that would be the Trump Administration for example.
Is there an alternative that really keeps data in the EU? (And not only in the sense it serves a sales promotion)
more: https://european-alternatives.eu/category/email-providers
mailbox.org can be avoided if you need to send and receive emails from domains where the mail admins might not be email admin savants and/or privacy activists (sometimes that's not a choice in case of Govt services etc and you may not live in a country when you can get those changes done). Also, if you ever face an issue and send them an email, expect the reply to come in weeks (if you are lucky) and that too a flippant (sometimes even terse) nothing-mail and then if you respond the cycle repeats until you give up.
If that works fine if not, use another method of comm. Email wasn’t designed to be secure.
> Because of legal uncertainty around Swiss government proposals to introduce mass surveillance — proposals that have been outlawed in the EU — Proton is moving most of its physical infrastructure out of Switzerland.
https://proton.me/blog/lumo-ai
They are moving to Germany, but will quickly find that they are going to face the same surveillance and privacy issues since the EU is in the process of negotiating a data sharing agreement under the US Cloud Act.
https://www.justice.gov/archives/opa/pr/justice-department-a...
In all seriousness though, what are the chances Fastmail won't require KYC at some point? I have sent them a support request with that question and got a non-answer.
PS: Am a paying customer for like a decade
I guess they could offer a 0GB storage option that only operated as a relay?
> Built by us, not rented from someone else
> We’ve installed our own servers, co-located in a secure facility in Amsterdam, set up by our own engineers. This new location is built to the same high standards as our existing infrastructure in Philadelphia and St Louis, with our own hardware and our own software — specified right down to the exact model of disks in each machine.
> In all our locations, data is stored encrypted at rest inside locked racks, and managed by our in-house team. We don’t rent computing or management services from a big cloud provider and pass on their assurances. That’s how we’ve approached privacy, reliability, and performance for more than 25 years.
In extreme cases the US DoJ can reach, let’s say the CEO/CTO arrest them or pick up family members in case of some sort of non-compliance in some criminal investigation.
I can imagine something like > US DoJ has some PoI with some account in Fastmail “EU region” > Fastmail says “sorry we’re GDPR” > US DoJ says “now” or… > Fastmail refuses
Then what?
mind you, prior to this administration the EU was more then happy to help the US DOJ in such cases.
considering the stuff that happened in the past year or so, i doubt that would happen again. Actually calling bluff on the US is the only way to play this properly, because it gives the EU a mandate to strike back geopolitically if the US wants to retaliate for non-compliance by fastmail.
So all of this is pointless.
"Resilient replicas of your data will live in the US"
?
I think "resilient" just means "backup copy" and I do think (IANAL) it is illegal to destroy emails when asked for them in the US.
Or was your comment ironic? Sorry, German, irony impaired.
Aussie law might be even worse than US; I would never use Fastmail.
* a physical thing that can only live in one place
* not copyable
* can be 'contained'.
The whole thing reeks of bureaucratic 'best practices' that just aren't.
Even worse than that, trying to keep email restricted to the EU (or anywhere else) means that you effectively wouldn't be able to communicate with anyone in a different region, which is kinda the whole point.
Why not just make your own internet next? and then you can disconnect from everyone else who is trying to hack you. Just pull your network plug.
Email itself is hopelessly insecure by design anyway. Not just metadata when you are E2EE everything inside the envelope, but even basic vulns like downgrade attacks are simple because it's literally a violation of the RFCs (so you're not spec-compliant) to require TLS or any other encryption.. Why? because requiring modern crypto might interfere with deliverability and backwards compatibility. The real, deeper reason is that email is from a kinder, simpler time (well, at least simpler) and the design goals were never updated to keep up with the times.
Email is what we have. Just understand its flaws and then use other tools where you can. And who cares where your email lives - it's too easy to break anyway.
I think the keywords are "trusted" and "citizens' rights". US burned a lot of trust in the last few years, and what's happening with ICE doesn't really scream "citizens' rights" either. I can see why many "trusted foreign partners" would now think twice rather than help out the US compared to just 5 years ago.
As a EU person, I'd really like to not have ties with US when possible, and I'd really like to foster the economy of non-US alternatives.