• 0 Posts
  • 8 Comments
Joined 2 years ago
cake
Cake day: July 12th, 2023

help-circle

  • I’m a recent fastmail user:

    Pros: First off, they put me on a 30 day trial, so had a full 30 days to try out; I would suggest trying their trial as one of your first things.

    I do love that I can make so many aliases for different email things.

    I do love I can add an API key to my bitwarden account to auto-generate email masks for things: https://bitwarden.com/blog/use-bitwarden-to-generate-email-aliases-with-fastmail/

    Offer’s a reasonably priced family plan for up to 6 users (50 GB per user - after using Gmail from day one, including non-email storage, my Gmail is only up to 35 GB), and they have annual plan options which give you a discount over monthly for a better deal.

    Has a calendar feature, and notes, for which I am putting stuff I used to text to myself, or message to my wife on discord.

    Use multiple of my own domains (purchases elsewhere), and just set the nameservers to FastMail, and they handle setting up everything for modern email like DKIM, DMARC, and stuff. Though you are not obligated to purchase a domain, they have many you can choose from. They allow you to use a ton of custom domains (where as some other providers allow like 3, 10, or 30, depending on your plan).

    They have an import feature from your old mail accounts. I did not try it, as I decided to start fresh. I’m trying to move away from gmail incase they lock me out someday, but my account is in good standing, and I have access to everything there as storage; just proactively moving all my important accounts over to my own domains.

    I’ll put this at the end as it is a pro or con depending on your outlook: I trust FastMail to not use my data like google, and am okay with our business relationship. Because of this, I am okay with my data not being so hard locked down that FastMail is able to restore access/help users getting locked out of their accounts. For a true End-to-End encrypted option, I question if that recovery would be possible (which can be a good thing, if your purpose is protecting your data, even from warrants/court orders/subpoenas); they may have recovery keys, but what if you lost those?

    Con: Found out after my trial ended, that when I email my work, my emails go to Quarantine. Our work uses Microsoft Outlook, and they have a quarantine feature that keeps stuff from hitting even the spam folder; my work has phishing set to ‘aggressive’, which is what is quarantining my emails. Once i passed one email through quarantine, i’m recieiving them fine now. Also if the user adds the email to their contacts list.

    After looking around, this appears to be an ongoing issue with microsoft from fastmail emails. You cant email email the recipient to inform them of the quarantined email, because all emails are quarantined. Not a deal breaker, as it’s microsoft’s doing, not FastMail, but still annoying, especially if you have to tell them to add you as a contact first. May get better after your domain builds some reputation with their servers, I don’t really know yet. More of a reason for me to avoid recommending Microsoft as an email provider; quarantine is great for protecting users, but unless you have an IT person regularly checking and approving quarantined emails, it is so easy to miss legitimate emails from clients. I’ve also seen an email from my gmail account in the quarantine system, so it can catch up even big email providers.

    A lot of people recommend https://tuta.com/ as a more privacy conscious option, and if I did decide to leave FastMail, they are probably what I would switch to. They do have a free email. Tuta also has family options, which can be more generous storage wise depending on your plan, but their family option appears to just be pay the full price of your plan for each user to add them to your family plan, and Tuta (at least from their pricing page), only has monthly as an option, no discounts for commitments.

    For fastmail, I pay $132/year ($11/month equivalent - actually $14/month if on a monthly plan) for 50 GB for 6 users (300 GB total), For Tuta it appears to be €3/user/month for 20GB, or €8/user/month for 500 GB (so for 2 users, you are either paying €6 or €16). Ultimately I found FastMail to be a better choice for me. If you switch to business, they do have a €6/user/month option for 50 GB /user, which would be €12/month, so comparable to FastMail’s family plan if you only have 2 users, but less comparable if you need more than 2 users. Due to tuta’s pricing structure, you could just get each user the plan they need (not sure if that requires separate accounts, or if can be done on a family plan, which does have domain sharing implications, but maybe everyone wants their own domains).

    My recommendation would be to make a FastMail trial, make a free tuta account, and try both for a month, then make your decision.







  • OMG, I’m dealing with a developer right now that is dealing with patient collected samples in several timezones, allowing the patients to either enter the time they collected, or use current time, and storing it in UTC time.

    We do not receive any timezone data, patient collection data is showing different days than the patient could write on their samples depending on the time of day, and the developer said ‘just subtract X hours’ (our timezone)… for which not all patients would live in.

    I suppose I could, if they’d provide the patient’s timezone, but they don’t even collect that. Can you just admit your solution is bad? It’s fine to store a timestamp in UTC, but not user provided data… don’t expect average users to calculate their time (and date) in UTC please.


  • My first reaction is yeah, you don’t just plug into random Ethernet.

    The wi-fi is likely a visitor network setup for guests to the library. That ethernet port could provide access to their private intranet, and be a security risk to the library. Worst case scenario, it could result in malware, ransomware, and/or millions of dollars in expenses to recover (on a library budget, that could mean permanently shutting down the library even).

    After reading your post, I would say, no harm intended, just don’t do it again.

    After reading your comments about intentionally being vague about ‘plugging in’ to lead the librarian to think you were asking to plug in a power cord, and not specifically meaning ethernet connection… yeah, you’re clearly in the wrong. Just be up front; if they say no, so be it. They may be able to direct you to a visitor ethernet plug-in, or maybe not. If this were an AITA thread, i’d say yes, YTA in this case.

    Asking in an security community… I would assume some level of technical awareness, and you are likely well aware of network segmentation, and that no IT department would be happy about a guest plugging their laptop into random rj-45 jacks around the building. Maybe it’s not well designed, and that actually has access to firewall administration?