Live data from Hacker News

Google's Backdoor Access System into Gmail Accounts

schneier.com

91–96 of 96 posts

Re: Google's Backdoor Access System into Gmail Accounts

#91

Earlier quoted context omitted.

Yeah, I've been sorely tempted to make a Stackscript for this setup and make it public. There are two downsides: it's at least $20 a month to do it, and having your own mail server really isn't quite a set-it-and-forget-it deal. It requires an amount of attention that wouldn't make sense for a lot of people (or businesses).

> (or businesses) I'm surprised by how many businesses (even small ones) don't run their own mail server, or at least have a proper outsourcing arrangement rather than just using a public service. We run our own (well, I run our own...) because we work with banks and all contracts we sign with them have clauses regarding where information from them gets stored and who could possibly have access to it - this is to pro…

You have a good point. We just recently deployed an in-house mail server for a client with security concerns; they wanted all of their intra-office email to not leave the building. Our mail server does backup duty for their mail server, in case their connection drops or anything goes haywire, and we monitor their server and keep it healthy for a really low monthly amount.

I had only sorta-kinda considered trying to offer that to a wider audience, but I didn't really think the market for it was that big. I might be wrong.

Re: Google's Backdoor Access System into Gmail Accounts

#92

Could anyone recommend a hosted email service that does not allow spying on users? Alternatively I wonder what Bruce Schneier recommends? Do you have to host your own email server?

For me, I use TrulyMail. If another TrulyMail user sends me a message, it doesn't go through any email server (just TrulyMail's server). Everything is automatically encrypted /decrypted on the client so even if someone access their servers, there is nothing readable. They also have email encryption. They are also priced right: free.

PGP is great and I used to use it but, as many posters have said, if the other party doesn't use it (or if they use it and you don't know they use it) it doesn't do much good. This is really true of all encryption systems.

Re: Google's Backdoor Access System into Gmail Accounts

#93
post #27
post #14

Earlier quoted context omitted.

You could pgp encrypt anything that you really don't to be read in transit. Short of that, you might as well assume that your emails are being read and stored by third parties. Even if you personally use the most secure email server in the world, it doesn't matter because everyone that you send email to or from is likely using hosted services like gmail, verizon, hotmail, etc.

One big point here is that PGP only works when both sender and receiver and doing it. Try sending Bank of America a PGP encrypted email about your account. See what happens. Edit: Re-reading my response... I don't mean this in a condescending way and I agree that PGP is a good way to handle email privacy. I only meant to point out that the majority of people don't use it.

Try sending Bank of America a PGP encrypted email about your account.

Well, you have to use their web form anyway, which is encrypted. The reason they require a web form instead of email is for exactly the reasons PGP exists: they need to know that you are sending the email, and they need to know that someone else isn't reading their reply to you. Webs of trust are hard, a text box on their SSL website is easy.

Re: Google's Backdoor Access System into Gmail Accounts

#94
post #71
post #12

Earlier quoted context omitted.

Yes: sdf.lonestar.org. Been running since 1987.

I had a sdf.lonestar.org account. Once, when their mail servers appeared to me to be down for a day, I asked on the discussion forums if I was the only one experiencing problems. The site administrator posted a response right away on the forums. He told me to stop whining, then explained to everyone that I received too many emails per day. (I was receiving Not only would I not trust SDF not to leak the content of you…

hi i am mahesh

Re: Google's Backdoor Access System into Gmail Accounts

#95
post #36

Some people on this discussion mention that they simply run their own mail servers -- that's dandy for incoming mail. But how do you guys make sure your outgoing mail is not blacklisted/ignored/considered spam? That's been a non trivial problem for me in the past when I was running a mail server (and spam was not such a big problem back then). Also, is there any mail server you can run/recommend that has gmail-speedy…

If you are willing to pull your mail down into a local maildir one way or another, you can index and search it with notmuch ( http://notmuchmail.org/ ).

Thanks for that link, it's exactly what I have been (not very actively) looking for (in the back of my mind) for quite a while now :)

Re: Google's Backdoor Access System into Gmail Accounts

#96
post #76

Earlier quoted context omitted.

A good bet might be a Swiss hosted e-mail service such as Neomailbox which is what I use. Lavabit is another one which might be what you're looking for.

Living in Switzerland and knowing the laws, I would strongly recommend against that: since 2000 we have a law that forces all email providers to hand out communication logs to the authorities and to retain them for at least 6 months. Granted: that's not the message contents, but it's bad enough. Also, from my experience I can tell you that the authorities do make use of this law even if it's just to track down a stud…

That data-retention law is for the entire European Union.

6 months is the EU minimum, but for some reason the Netherlands decided to require triple that. I bet some idiot politician thought it must be "extra secure" ... :-/

Post reply on HN