Live data from Hacker News

Congress, at Last Minute, Drops Requirement to Obtain Warrant to Monitor Email

allgov.com

101–110 of 199 posts

Re: Congress, at Last Minute, Drops Requirement to Obtain Warrant to Monitor Email

#101
post #98

Earlier quoted context omitted.

where are your servers located?

USA, with backups in Canada (we're a Canadian company). But the whole point is that not even us, with full server access, should be able to access your data (even under subpoena) so using third-party servers close to where we expect most of our users to be shouldn't raise any eyebrows. We would eventually like to offer multiple options for server location, but that isn't feasible in the short term.

I think there is a real business opportunity in hosting email offshore for US customers, out of the reach of US laws and subpoena's.

I know you preach encryption, but there is a lot that can still be subpoenad outside of the encrypted message payloads, such as login IP addresses, destination email adresses, frequency of messages, etc.

Re: Congress, at Last Minute, Drops Requirement to Obtain Warrant to Monitor Email

#102

Earlier quoted context omitted.

Using war to cure terror is like using cyanide to cure a headache. Osama bin Laden would have killed more Americans by investing in Ford and GM+. And after the bailout, he would have made a profit too! + I'm not picking on Ford or GM here, they make fine cars. But automobiles kill far more people every year than terrorism has in the last decade.

> But automobiles kill far more people every year than terrorism has in the last decade. Seems you rather missed the point of the whole thread; terrorism isn't about killing.

No, I got the point. And Osama was quite effective at terrorism. Though I think most of the credit goes to the US government and media. I don't believe it was an inside job, rather that similar motivations created similar outcomes: radicalizing war in the middle east.

If humans were rational, terrorism wouldn't work. Driving your car to work is more dangerous than taking the subway to the world trade center, even if the WTC was demolished every year. But we are afraid of what we fear, not what will actually kill us. There are a lot of people who are eager to exploit that cognitive defect.

Re: Congress, at Last Minute, Drops Requirement to Obtain Warrant to Monitor Email

#103
post #72
post #65

Earlier quoted context omitted.

In the "follow the money" line of thinking, looking at who takes most benefits from terrorism explains a lot of things. "Terrorists" didn't get much I think. Politicians, law makers, government agencies got to push forward their agenda by leaps and bounds.

Hmmm... I kinda wonder sometimes. This is a ludicrous idea, but have you ever thought about the recent HSBC scandal, where they were laundering billions and billions of dollars for terrorist organizations and organized crime? The same terrorist organizations and organized crime that is the primary justification for domestic spying, paramilitary police, huge prison populations, secret rendition and indefinite detentio…

The more links (or phrases to search for) you could provide for this, the more grateful I'd be.

Re: Congress, at Last Minute, Drops Requirement to Obtain Warrant to Monitor Email

#105
post #74

They demonstrated that they value police state ideals over the civil liberties. Wasn't it expected?

Obama State. FTFY.

Right. Because Obama totally didn't continue a long legacy, he basically kickstarted this all by himself..

My suggestion would be to more or less ignore the sock puppet of the day and instead pay attention to interest groups and whatnot. Those don't change nearly as much as the faces or slogans that are put on stuff.

Re: Congress, at Last Minute, Drops Requirement to Obtain Warrant to Monitor Email

#106
post #79

Earlier quoted context omitted.

Other than the government with it's war on terror, who has actually done anything to perpetrate fear in the population? Since 2001, there has been no terrorist activity against the US. You are told about threats the war on terror has dealt with, but no actual action or actors can be pointed to yet the government is keeps the fear of terror alive. They have done far more to that end than any terrorist organization has…

Well, we just disagree.

Do you disagree with anything specific, or are you just done discussing it?

I've not heard many people seriously argue that the TSA's mandate is to alleviate fear, much less argue that the TSA carries out said mandate successfully.

Re: Congress, at Last Minute, Drops Requirement to Obtain Warrant to Monitor Email

#107
post #2

I wish we would treat cyberspace analogues of established property with the same respect given to the original. For example, your e-mail inbox is the online equivalent of your mailbox. Yet, one being "on your lawn" and the other "at Google's data-center," all bets are off. While I believe the Supreme Court should do better job at explicitly addressing this (for instance, "responsible expectation of privacy" establish…

The Sixth Disctrict court of appeals did address this directly in US v Warshak [0]. What this scare article does a good job of is confusing the reader. Unopened email left on a 3rd party server for longer than 180 days was considered discarded or abandoned property. Discarded physical property has never retained a reasonable expectation of privacy (for instance, the police are free to dumpster dive once your property…

> The Sixth Disctrict court of appeals did address this directly in US v Warshak

Oh? And what addresses the NSA getting a copy of all traffic on the Internet?

Do you really think some silly rules on "unopened e-mail" matter at all?

Re: Congress, at Last Minute, Drops Requirement to Obtain Warrant to Monitor Email

#108
post #101

Earlier quoted context omitted.

USA, with backups in Canada (we're a Canadian company). But the whole point is that not even us, with full server access, should be able to access your data (even under subpoena) so using third-party servers close to where we expect most of our users to be shouldn't raise any eyebrows. We would eventually like to offer multiple options for server location, but that isn't feasible in the short term.

I think there is a real business opportunity in hosting email offshore for US customers, out of the reach of US laws and subpoena's. I know you preach encryption, but there is a lot that can still be subpoenad outside of the encrypted message payloads, such as login IP addresses, destination email adresses, frequency of messages, etc.

That's a really good point, and I agree. Offering multiple server locations is definitely on the road-map, but doing it well (ie. without providing a false sense of security) is an entirely separate and mostly legal challenge--as a Canadian company, we would be susceptible to mutual legal assistance treaties with the US, so we'd have to set up companies in a few different countries with different legal environments and then lay out the trade-offs in a transparent way.

Hopefully, we'll get to it, but if another startup gets there first we'd be much obliged ;) In the meantime we will focus on the big problem that's already right in front of us; I would encourage anyone who needs to operate outside of US legal influence to use a different mailserver (perhaps their own) and manage their own PGP keys.

Re: Congress, at Last Minute, Drops Requirement to Obtain Warrant to Monitor Email

#109
post #70
post #68

Earlier quoted context omitted.

Which contributes neither enlightening discussion nor useful solutions to the discussion at hand. You have expressed your contempt for people who don't run their own mailservers; but your contempt is only an ego assertion. Your contempt, unless based on facts, and rational arguments taking into account the reality of people who have other things to do than learn whatever esoteric skills you've chosen to base your sel…

Running your own mailserver is so basic of a technical skill that it is neither esoteric, nor is it something to be egotistical about. The name of the site is "hacker news" for Gods sake. Second, there's nothing I'm asking you to "listen to". My point was that a lot of the wringing of hands and gnashing of teeth has no legitimacy without having taken the simplest, most elementary, first order step towards fixing this…

I know how to run my own mail server - I have set up a couple. L still don't because my setups tend to be inferior security and feature wise to those of people that do nothing but run mailservers every day of the week. I could argue that building mailservers is such a basic skill that everybody should be capable of doing it. Or building a house. Or growing your own food. Neither you nor I do that even though growing your own food is the simplest, most basic step to solving a ton of problems in the food industry.

As I and others pointed out your most basic step does not solve the problem and you can just move to a different provider that is not subject to American laws to have the hsame effect.

You're also not required to have any technical skills at all to gnash your teeth about a government that tries to expand surveillance in every possible place. For some places you might have a technical solution such as running your own mail server at home, but what are you going to do once hacking of mail servers without a warrant is permitted and common place? Counter-Hack? As hackers we try to find technical solutions to social problems, but that's not going to work out in every place.

Re: Congress, at Last Minute, Drops Requirement to Obtain Warrant to Monitor Email

#110
post #69

Earlier quoted context omitted.

you can use encrypted mail, however that requires you to convince all people that you exchange mails with to use encrypted mail as well. You could use a hosted email service in another country where the american authorities don't have easy access. Europe might be an option. However, as with hosting your own email server, that's only a partial solution: If you communicate with other people, your mail is not only store…

Errr... the NSA is specifically charged with monitoring communications that cross US national borders. Using a mailserver in a foreign jurisdiction makes it more open to legal interception by the US government; not less.

Valid point. It's a different branch and a different issue though. Mails that are already on your server and stored there would be relatively safe. Make sure communication is encrypted.
Post reply on HN