Live data from Hacker News

Make Your Email Hacker Proof

codinghorror.com

141–150 of 161 posts

Re: Make Your Email Hacker Proof

#141

While you're thinking about the security of your email in the cloud, remember this: ANY of your email older than six months can be legally obtained by any U.S. law enforcement agency without any warrant or judicial oversight of any sort, even if you enable Google's new 46-factor authentication and use passwords that take minutes to type in. http://www.wired.com/threatlevel/2011/10/ecpa-turns-twenty-f... Do you have a…

And you think that Google actually deletes email when you tell it to? More likely they just mark it as deleted and retain it, in which case every email you ever received regardless of whether you think it has been deleted may be available. If you want better privacy, install and manage your own mail server and encrypt everything.

Yes. We do. Within 60 days.

See http://support.google.com/mail/bin/answer.py?hl=en&answe..., which is specific to g-mail, but the same rules apply for other products that store user information. There is a whole team that works on this to monitor the process and help product teams implement the policy.

Re: Make Your Email Hacker Proof

#142
post #123

Earlier quoted context omitted.

And you think that Google actually deletes email when you tell it to? More likely they just mark it as deleted and retain it, in which case every email you ever received regardless of whether you think it has been deleted may be available. If you want better privacy, install and manage your own mail server and encrypt everything.

It is well known that google do not delete old emails. They mentioned it around when gmail started/

See http://support.google.com/mail/bin/answer.py?hl=en&answe...

Deleted messages are wiped within ~60 days. The delay is needed to ensure that all copies of the message are deleted, including those that may be on tape.

Re: Make Your Email Hacker Proof

#143
post #31

>provided you own a cell phone. Well, crap. My only "phone" is my Google Voice number...

Could always use an iPod Touch, if you have one.

That's actually my current setup. It still kind of defeats the purpose though; I have to be logged in to Google Voice in order to authenticate logging in to Gmail with the same account. I'll wait for them to get a little more creative before I expect it to be much safer.

Re: Make Your Email Hacker Proof

#144
post #8

> Hey, This Sounds Like a Pain! Yes, because it is a pain. Try going on a vacation, you know the one where you don't use cell roaming. SMS is out, so then one must find a Wifi hotspot to use one of the smartphone time based tokens (edit: seems the token don't need a network connection, could have fooled me). And those time based tokens go out of wack if your phone didn't sync the timezone properly to match Google's s…

I recently traveled for 6 months without a data connection on my phone and used the Google Authenticator app without any problems at all. I changed the timezone setting many times too.

Re: Make Your Email Hacker Proof

#145

While you're thinking about the security of your email in the cloud, remember this: ANY of your email older than six months can be legally obtained by any U.S. law enforcement agency without any warrant or judicial oversight of any sort, even if you enable Google's new 46-factor authentication and use passwords that take minutes to type in. http://www.wired.com/threatlevel/2011/10/ecpa-turns-twenty-f... Do you have a…

It's worth noting what law enforcement wishes they could do and what they can do is pretty different. The only time this has been tested in court, the Sixth Circuit said it was unconstitutional. Which is because it's blatantly unconstitutional. My money says that any other appeals court will agree, including the Supreme Court if it gets that far.

Now, the government certainly does things that are unconstitutional sometimes, and manages to avoid having any court review them. I'm sure there are abuses here. It's disappointing that the Justice Department tried to oppose a warrant & probable cause standard for electronic searches as if there's room for dispute on that one. But the minute they try to take much advantage of this law it'll be struck down, and they know it.

It's possible that I'm (weirdly) less cynical about this as a defense attorney than most people are. In my line of work the constitution is constantly standing between police and what they wish they could do. I'm thinking of a particular case, not uncommon, where a three-hour confession was basically thrown out because the judge looked carefully at the recording and the police didn't quite handle it right. They didn't beat the guy, but they didn't do what they needed to do to make sure the confession was voluntary. And of course this drives the police nuts -- the executive branch's position is always that any limitation on their power is a threat to public safety. Resisting that position is why we have constitutional standards and separation of powers in the first place.

Incidentally, the DOJ testimony[1] is a little more nuanced than Wired makes out. The testimony makes some legitimate points -- that agencies like the SEC rely on their ability to use subpoenas (as opposed to warrants) to enforce financial laws, and that it's not clear how much evidence you should need that a particular email account contains evidence of criminal activity in order to obtain a warrant to search that account. (If I have 100 gmail accounts, and you know I've used five of them to run drug transactions, do you need independent evidence to search each of the others?) This means any law governing search of emails would have to be written carefully (or vaguely, so the courts could figure it out under the Fourth Amendment). But the DOJ's conclusion that maybe the law should try to exempt electronic records from search and seizure protections is typical executive branch posturing -- both absurd and unenforceable.

(This is not legal advice. It's just a thing I wrote on a forum. I could be totally wrong. Consult your doctor if effects last more than four hours.)

[1] http://www.wired.com/images_blogs/threatlevel/2011/04/bakere..., page 11.

Re: Make Your Email Hacker Proof

#147
post #90
post #23

Earlier quoted context omitted.

6. Cross your fingers and hope that you'll never use a machine afflicted with a keylogging trojan.

Perhaps a suggested approach might be to only log in from a USB linux boot drive? Again, these aren't for the most extremely cautious/savvy users out there, just the 99.9%.

Hardware keyloggers will still defeat the USB linux boot drive idea.

Re: Make Your Email Hacker Proof

#148
post #88

That cell phone you use for receiving the verification codes? It better not be a smartphone you also use to access GMail, or your 2-factor just became 1-factor, at least to any malware on that phone...

Your phone should never know your password; you log into Gmail from your phone using an application-specific password. If your phone is infected with malware and you don't trust it anymore, you deauthorize it and your account is safe. 2 factor authentication is an amazingly simple solution to a large number of complex problems.

  > If your phone is infected with malware
  > and
  > you don't trust it anymore
Those don't necessarily go hand-in-hand.

Re: Make Your Email Hacker Proof

#149
post #4

What I really want is for the second factor to kick on only in suspicious situations, e.g.: * I'm logging in from a computer that I've never logged in from before * I'm searching my mail history for terms like "password" * I'm opening an email that appears to contain a password-reset link * I'm messing with my mail-forwarding options * I'm accessing messages in bulk But I do not want to have to do second factor just…

Typing a six digit number every 31 days is too much work to add a significant layer of security to a very important account?

Typing a six digit number once adds a significant layer of security to a very important account.

Having to type it every 31 days (per browser, per device, per account) adds very little marginal security. In fact, in my case it actively hampers security, because it keeps me from using two-factor altogether.

Re: Make Your Email Hacker Proof

#150

I access my email from _one_ app over SMPT, using a unique password. For me, this 2-factor auth would just mean having a different and slightly longer password for SMPT.

SMTP is only for sending mail to and between mail servers. Did you mean something else?

And no, 2-factor is not the same as a long password, because it is less likely that both factors will get compromised at the same time. However long your password is, a single software flaw could expose it.

Post reply on HN