Even allowing for some hyperbole, I think this is an overreaction. I agree that they made a mistake, but we only know of one user it affected. They didn't leak an entire database of user data or expose a vulnerability for which the attack can be automated.
You've commented many times that email is inherently insecure and that (IIRC the conclusion precisely) there is little point in focusing on securing it. Instead, use a secure messaging system such as Signal. Email just isn't going to be secure. Fastmail seems to put more effort into their security than most mail providers. For example, the proxied images [0] sound fantastic and they address a threat that affects almost every email user daily.
The inherent insecurity of e-mail doesn't change the fact that popping someone's email account means popping most of their services. Therefore it makes sense to hold e-mail providers to a higher standard than a median company.
Furthermore, while we only know 1 user affected, in the rest of the thread, Fastmail has been cagey at best about answering what they feel the process is now, let alone what it was back when this incident occurred.
Even allowing for some hyperbole, I think this is an overreaction. I agree that they made a mistake, but we only know of one user it affected. They didn't leak an entire database of user data or expose a vulnerability for which the attack can be automated.
You've commented many times that email is inherently insecure and that (IIRC the conclusion precisely) there is little point in focusing on securing it. Instead, use a secure messaging system such as Signal. Email just isn't going to be secure. Fastmail seems to put more effort into their security than most mail providers. For example, the proxied images [0] sound fantastic and they address a threat that affects almost every email user daily.
[0] https://blog.fastmail.com/2014/09/16/better-security-and-pri...