Product Please update your FastMail password We’ve just sent the following announcement email to all FastMail users. Dear FastMail User You may have heard of a recent security bug in the OpenSSL library (that has been called 'Heartbleed')
Technical When two-factor authentication is not enough TL;DR: This is the story of a failed attempt to steal FastMail's domains. We don't publish all attempts on our security, but this one stands out for how much effort was put
Technical All SSL certificates updated Based on a recent security issue in the OpenSSL library, we’ve updated all our server software and taken the precaution of replacing all of our SSL certificates. Most users shouldn’t notice
Product FastMail housekeeping - removing little used features and simplifying others In maintaining a large system like FastMail, we often find ourselves coming across code or configurations that’s can be harder to modify and update than we expect because of the way they
Product Improved default search behaviour in classic interface When we introduced the current interface, one of the features we were really happy with was our vastly improved searching. Basically we implemented a full text index that allowed you to search the
Technical Cleaning up from an IMAP server failure This blog post is highly technical. I cover details about how our email storage system works and how it was impacted by a complex server corruption and failure. I explain why our normal
Technical Diary of an outage As some of you are no doubt aware, yesterday we had a fairly serious outage. It only affected a small number of users, but for them it meant some some 4-6 hours with
Technical Content Security Policy now on Beta At FastMail, we're always looking to increase security for our users. Cross-site scripting (XSS) attacks are one of the dangers that all websites must take care to mitigate against. HTML email is the
Technical Secure SSL/TLS access to LDAP and DAV now mandatory Over the last few years we’ve been phasing in mandating SSL/TLS encryption on all connections between user machines and our servers, ensuring that no one can eaves drop on your username