> a 24 hour lockout to allow the owner to notice an attempt on their account.
I've been pretty careful to ensure that I don't lock myself out of my account (multiple U2F keys, strong password saved in password manager with backups)
But if a determined attacker kicks this off just as I'm stepping on a flight from Sydney to London, 24 hours isn't going to be enough.
(I should add also - I'm a mostly happy Fastmail customer)
You can't even get to the 24 hour lockout unless you've successfully passed the security checks.
We add the 24 hour lockout as an additional level of protection for 2fa accounts (even though they've given two factors of recovery by then) or if we can't confirm that you are resetting from a computer which has successfully logged in to that account before.
It sounds like if I use Fastmail, and I go on vacation (and thus go a day without checking my email), someone can max out the automated system and then get a human being at Fastmail to potentially reset my recovery email. Is this the case?
Our procedures have to balance the concerns of very different groups of people.
Some people have explicitly directed us to enforce stringent account security requirements by enabling multi factor authentication. For those people, we assume that they have their own security practices and are diligent in maintaining them. Those people are aware of the risk of losing access to their mail if they lose their credentials.
The other, much larger group of our customers, come to use because they want email that has support. Many of these customers forget their passwords and still need to get to their email (which is more common than you might imagine if you are surrounded by a hacker-news demographic!)
Our procedures have to balance between those two sets of needs, and they evolve over time. This incident came up in a period of transition. It should never had happened, and it's a great object lesson to us about how to do better in future transitions.
Having said that, based on this conversation today we are reviewing all our processes around re-establishing access for regular people who haven't requested additional security by enabling second factors. We absolutely can and will do better than we did in 2016.
For an attacker to exploit this, they will have to know that you are going on such a trip. This means that attackers who don't know much about you already are less likely to bother, and also raises the bar for even the focus attackers.
Nothing is foolproof, but many things can be useful.
If a well-resourced attacker was targeting me specifically, it wouldn't be too difficult for them to find out about my short-to-medium term travel plans. A bit of social engineering with the airlines could tell them exactly which flight I'm on.
They could also compromise other people who need to know my plans and don't have the same security practises as me.
I think about this stuff and minimise as best I can, but my account security shouldn't be dependant on it.
This is like the employer I used to work with who said "well google has been hacked so therefore us storing passwords in plaintext is okay". Maybe I'm toast if the NSA takes an interest, but there are an awful lot of bad actors out there without the level of funding or resources of the NSA. Of course I'll never be "100% secure", but making it as impossible, or at least as difficult as possible, for someone in Russia to socially engineer their way into my email is worth spending time and money on.
I've been pretty careful to ensure that I don't lock myself out of my account (multiple U2F keys, strong password saved in password manager with backups)
But if a determined attacker kicks this off just as I'm stepping on a flight from Sydney to London, 24 hours isn't going to be enough.
(I should add also - I'm a mostly happy Fastmail customer)