back to 2026-08-09
ᕼᑎ:49223082317 pts141 commentsProgrammingworth reading

Fastmail offers EU data region

Claude brief

HN 热门故事「Fastmail offers EU data region」进入今日前列,值得先打开原文和讨论串判断它真正有价值的部分。

模型分析没有产出可用结构化结果;页面保留了 HN 热度、原文入口和讨论信号,避免用空泛总结替代一手材料。

它在 HN 上获得约 317 分和 141 条评论,说明这个话题至少触发了社区讨论;真正的判断仍要回到原文证据和评论区的分歧点。

这是一条降级分析:它不冒充完整解读,只把可验证的元数据、原始链接和 HN 讨论保留下来,方便稍后重新生成或人工阅读。

评论区已经提供了一些读者反应,但这里还没有形成完整综合。

它进入 HN 前列本身就是一个社区信号,但这还不是结论;更可靠的判断来自原文细节和评论区反例。

deep insight

这条记录目前缺少模型生成的深层解读。更好的阅读方式是先问:它的热度来自真正的新信息、可迁移的方法,还是只来自标题与时机。

可以先读原文第一屏和 HN 最高赞评论,再决定是否值得重新生成完整分析。

top comments

EU data regions are a reflexive action by companies that try to hold on to their EU customers (and more and more are leaving, surprisingly the larger ones seem to be leading here). Realize that as long as you are still hosted on US owned infrastructure or that if there are US (or: five-eyes) owned companies anywhere in the stack your data can still be forcibly pulled and often without you being aware that this happened. There are only very few such stacks that are 100% owned by EU entities. reply: > your data can still be forcibly pulled and often without you being aware that this happenedas a german i feel the urge to point out that this technically also applies to european companies... With more hurdles for the US, but still technically applicable
EU folks, note the warnings threaded throughout this post: this is not currently any sort of panacea against US or AU data hosting risks, but it will make your data noticeably closer to home. Fastmail (Australia) merged with Pobox (Philadelphia) resulting in a complex tri-national law/risk surface when the EU is involved, so go in eyes wide open having read this in full. That everyone will overinterpret “EU data region” to mean “for privacy” here until reading the article is completely understandable; I empathize, having done the same.
Posted on the previous submission for this: it’s a good start, but from the article:If what you need is a guarantee that your data remains only in the EU, we don’t have that, and we’d rather tell you directly than let you assume otherwise. reply: Wow they completely missed the ball on why people want reassurances that their data stays in the EU
Or you can just use any of the actual European companies (I’m using Tuta).https://european-alternatives.eu/category/email-providers reply: I started using tuta until I realised they don't support IMAP. Something to do with not guaranteeing encryption (which isn't even enabled by default) but has the convenient effect of locking you into their apps
Nice, as a European customer, I appreciate this.Side note, I moved to Fastmail a couple years ago, and so far I’ve been very happy with it! The Gmail migrator works great, too.
The local government cannot get access to the servers in Amsterdam?I use Fastmail but just consider it safe from third party advertisers. If I wanted safety from governments I would use something else, or at least encrypt my email contents.
This may not have much practical consequence, but still there's some symbolic value which is welcomed in today's geopolitical climate.
As long as the company's legal headquarters are in the U.S., U.S. agencies have access to the data under the Cloud Act—and non-U.S. citizens have absolutely no legal recourse when it comes to U.S. services reply: their HQ is supposed to be in Melbourne, AustraliaThey mention it only briefly in their publication. Their about page is clearer about that.
Australian company so: lol. Snowden triggered a few narrow real wins but the broader surveillance apparatus adapted, survived, and in some ways grew. Things were just legalised.
Seeing a lot of detail in the comments about the CLOUD act which applies as they(fastmail) themselves have an equivalent that was signed between USgov and Australia.The more concerning issue as far as Australian based tech is The Assistance and Access Act 2018 which"...permits government enforcement agencies to force businesses to hand over user info and data even though it’s protected by cryptography.If firms don’t have the power to intercept encrypted data for authorities, they will be forced to create tools to allow law enforcement or government to have access to their users’ data."As far as i know this has not been challenged or walked back and with the rise of ChatControl like laws doesnt seem it will.
The article states that they do not offer any guarantee that my data will stay in the EU!I feel that that's the whole point. And the whole point of them making this article/advertisement.
As a customer, thank you, Fastmail. I recall reading a few months back that this was rumored to be in the works, glad it panned out.
Five Eyes country are subject to local data disclosure orders and gag clauses, forcing them to hand over user data that may then enter the shared intelligence pool
EU data regions are based on the insanely flawed idea that data is:* a physical thing that can only live in one place* not copyable* can be 'contained'.The whole thing reeks of bureaucratic 'best practices' that just aren't.Even worse than that, trying to keep email restricted to the EU (or anywhere else) means that you effectively wouldn't be able to communicate with anyone in a different region, which is kinda the whole point.Why not just make your own internet next? and then you can disconnect from everyone else who is trying to hack you. Just pull your network plug.Email itself is hopelessly insecure by design anyway. Not just metadata when you are E2EE everything inside the envelope, but even basic vulns like downgrade attacks are simple because it's literally a violation of the RFCs (so you're not spec-compliant) to require TLS or any other encryption.. Why? because requiring modern crypto might interfere with deliverability and backwards compatibility. The real, deeper reason is that email is from a kinder, simpler time (well, at least simpler) and the design goals were never updated to keep up with the times.Email is what we have....
If what you need is a guarantee that your data remains only in the EU, we don’t have that, and we’d rather tell you directly than let you assume otherwise.Is there an alternative that really keeps data in the EU? (And not only in the sense it serves a sales promotion)
Can't wait to verify my age before reading emails!In all seriousness though, what are the chances Fastmail won't require KYC at some point? I have sent them a support request with that question and got a non-answer.PS: Am a paying customer for like a decade
Jurisdiction is an outdated way of looking at things. End-to-end encryption is what actually matters. Of course, people are stupid, so it continues.
I have never understood their 50+10 GB storage as the starting plan. Anyone storing a lot of emails, please don't come at me screaming, but know that not everyone keeps every email and every attachment ever received right there in that email account (especially the attachments). For me, email is just communication i.e timed information, not data storage, except for very personal emails, and very very rare, some non-personal important emails. So some people do like to simply delete the emails they no longer need. Also their pricing almost feels like "unlimited storage" backup solutions mass pricing strategy.
Secondary copy not in EU. So how exactly does that help with compliance?
As a European and Fastmail user, this is great news.
Finally! I have been asking for this since the US started to lose its mind. Great they are listening.
And which company hosts the data? An American company like Aws, Azure, Google or a European company like OVH, Stackit?
Not more safe. Only safe way is to use a company not under US regulation.
Does it matter much? From one side, you are still in the 14 eyes countries (in fact, I would trust a Chinese server if i am living in the west and vice versa), on another side, emails as a protocol was never meant to be secure or private, so deal with it as that, if you are after private or secure communication, choose a protocol that provides that, adding more stuff to emails will only complicate it further plus giving false sense of privacy/security, gpg will leak meta data, receiver email server/client might expose you too, among many gaps, so just avoid it. Still, make sure your email spf dkim dmarc etc are set properly and carry on.
Okay, that solves two problems for me. Great news.
We offer EU data centers for customers that want their emails to stay in the EU but"Resilient replicas of your data will live in the US"?
To me, jurisdiction matters more than physical location. I'd rather be with a EU-operated service that stores data on a non-EU server, than a non-EU operator with a German/french datacenter.
Data is still compellable through US Cloud Act (and other provisions). If you want true EU data region, you should buy from a company without presence in the US.