Earlier quoted context omitted.
Except Google's servers and whatnot are not your property. The lock keeps other Google customers from accessing "your stuff" not Google itself.
The mailbox in the foyer of your building and whatnot are not your property. The lock keeps other tenants from accessing "your stuff" and not your landlord himself.
IRS claims it can read your e-mail without a warrant
91–100 of 186 posts
Re: IRS claims it can read your e-mail without a warrant
#92Earlier quoted context omitted.
It'll happen only when PGP isn't just used by .001% [1] of email users. It needs some really good integration with an email client somewhere, where addresses are picked up from a public key server and automatically encrypted. I'm picturing an iMessage style thing where as you're typing someones email address, the keyserver is getting pinged and the address turns a different color and a lock icon appears by it. Now al…
I think a better solution is identity based encryption, so that the sender can encrypt the message before the receiver has their private key. Senders should have multiple IBE services to choose from, and we should have standards that allow or even require threshold IBE (so that no single party can decrypt all messages). IBE services may fail to take verification seriously, but the sender of a message could simply ref…
gpg --auto-key-locate pka -ear mike(dot)cardwell(at)grepular(dot)com
gpg then automatically looks up the TXT record for "mike.cardwell._pka.grepular.com" in the DNS. Which gives it:
"v=pka1\;fpr=35BCAF1D3AA21F843DC3B0CF70A5F5120018461F\;uri=http://grepular.com/0018461F.pub.asc
It then automatically fetches my public key from the URL in that record, checks it matches the fingperint, and then imports it.
For extra goodness, the DNS for "grepular.com" is secured with DNSSEC also.
The technology exists for sharing public keys and using PGP. The major mail providers couldn't care less about providing user interfaces for it though.
Re: IRS claims it can read your e-mail without a warrant
#93Earlier quoted context omitted.
You don't own your gmail inbox, you don't own your twitter account, you don't own your facebook account. Google, Twitter, and Facebook own them. You don't even rent them. Google, Twitter, Facebook, etc, fully own them and fully control them at all times, retaining the right to do whatever they want with them at any time.
You just missed the point. The IRS is speaking to all email systems. If I have a private server in my private house, and I send another message to another user on the same server (i.e. local delivery only), then the IRS's claims still apply to that. I don't see how the Google/Twitter/Facebook come into play here.
Google, Twitter, etc, come into play because they are the kinds of communications the IRS is referring to--electronic communications stored on servers controlled wholly by unrelated third parties.
Re: IRS claims it can read your e-mail without a warrant
#94Earlier quoted context omitted.
> If you understand how SMTP works, it's hard to argue that it's a private means of communication. You send a clear-text message to a publically-accessible service that is empowered to forward the message to other publically-accessible servers if necessary. Whoa, hold it, I don't think so. Almost every SMTP server out there today requires authentication and quite a few require either SSL or TLS. That is the very defi…
Except that the mail server gets to see the body of the email, which is not even remotely private. Encryption gives you privacy; instead of politely asking people to not read your mail, why not politely ask people to encrypt messages?
Privacy should not (and in more enlightened countries and legal systems it does not) mean "others are not technically able to see it".
It should mean: "this piece of information should not be attempted to be seen by others without the owners implicit or explicit permission".
(And then legal formulas could be used to define "permission" (ie the recipient of an email has an implicit permission to read it)).
If we use the BS notion of privacy of the US courts, then copyright should not exist either (because, by the same logic, one can break the copyright protection easily). Even theft would be OK (hey, I can steal your stuff if you left your belongings in a public place).
So, no, whether my mails are in Google's servers or wherever else, it should be illegal to read them for any purpose I don't agree with. Much the same as if the postman delivers my email to the neighbor's box by mistake, he should not be allowed to open and read it.
Re: IRS claims it can read your e-mail without a warrant
#95Earlier quoted context omitted.
No, that's stupid. That's equivalent to claiming telephone calls aren't private, because they're transmitted in the clear by third party exchanges accessible to authorized users. (email servers generally aren't publicly accessible, rather they're only accessible to authorized (registered) users)
You don't lose your reasonable expectation of privacy by making something publicly available. You lose it by exposing it to a third party (note that e.g. nothing prevents the recipient of your letter from handing it over to the government without a warrant). When you send an e-mail, you make the complete clear text of the e-mail accessible to a third party. The extension of 4th amendment protections to telephone call…
It's true that this has always been the position of the Federal government, but that argument has always seemed pretty weak to me, and I don't accept it on principle, no matter how pervasive it's become. People don't expect their email to be read by others, especially the government, period. The reality that they are in fact doing this anyway just means citizens have to push harder to affect a change in the law.
This isn't a new fight. The government literally used the same exact argument when telephones were invented. It took years to work in protections for phone calls, I see no reason why the same can't be done for new modes of communications like email.
Re: IRS claims it can read your e-mail without a warrant
#96Earlier quoted context omitted.
While I would not argue against encryption giving you privacy, I think it is easy to argue that there is an expectation of privacy in sending emails. At least, as much of one as if you were sending actual correspondence. Consider, in a public restroom there is very little done to prevent people from seeing each other. However, one almost certainly has a reasonable expectation of privacy in such a situation. Hell, con…
We put doors on restrooms. Claiming that unencrypted email should carry a legitimate expectation of privacy is like claiming that people should expect privacy when they go to the bathroom on the side of the highway. People may want their email to be private, but that does not mean that we should pretend that email really is private. Really, we need encryption to be widely used, for people to learn about it in school,…
Why not? It's just a law away for this to happen.
We can fully well pretend that email really is private.
It doesn't matter if it is technically private (ie if someone can access it or not). What matters is for accessing it to be illegal.
Re: IRS claims it can read your e-mail without a warrant
#97This statement: "Newly disclosed documents prepared by IRS lawyers says that Americans enjoy 'generally no privacy' in their e-mail, Facebook chats, Twitter direct messages, and similar online communications" is entirely consistent with the existence of Warshack. Warshack covers the Sixth Circuit, which includes the following states: Kentucky, Michigan, Ohio, and Tennessee. The IRS is bound by this precedent in those…
Nice analysis. I tend to think the evolution of expectation of privacy from regular mail to email is similar to the evolution of expectation of privacy from land-line phones to cell phones. That is under the 4th Amendment land-line phone users have a reasonable expectation of privacy; therefore, Gov. must obtain a search warrant to use evidence gathered from such sources against the criminal defendant. Yet, Courts de…
This wasn't always the case. In fact the government argued the exact opposite for years.
Re: IRS claims it can read your e-mail without a warrant
#98Earlier quoted context omitted.
So by your reasoning, if I mail you a postcard, and you put the postcard in a locked container placed inside of the trunk of a rental car, it is OK for the police to bypass your access controls and read the postcard? How you transmitted or handled something at a point in time is not relevant to it's status at rest. This issue here is that the government asserts that email is a communications system only. The problem…
Your analogy is completely inapt: 1) A rental car, like a rented house, is still under your control. But your e-mail account on Google's servers is under their control. They can do whatever they want with it. It's more like your friend letting you use part of his garage to store stuff--a third party still retains full control over the space. 2) As far as I can tell, Google can access your e-mail whenever it wants, so…
Re: IRS claims it can read your e-mail without a warrant
#99Earlier quoted context omitted.
The interesting thing to me here is that the IRS is not claiming Google/Microsoft, it is claiming all email. Including that which is served by private servers that goes to other recipients on the same private servers. The fact that you own the box that email was delivered to and that email never left that box has no bearing in the matter for the IRS. They still claim the right to inspect it, without a warrant.
You don't own your gmail inbox, you don't own your twitter account, you don't own your facebook account. Google, Twitter, and Facebook own them. You don't even rent them. Google, Twitter, Facebook, etc, fully own them and fully control them at all times, retaining the right to do whatever they want with them at any time.
Google, Twitter, Facebook, etc., don't enter into the situation.
Re: IRS claims it can read your e-mail without a warrant
#100Earlier quoted context omitted.
I think a better solution is identity based encryption, so that the sender can encrypt the message before the receiver has their private key. Senders should have multiple IBE services to choose from, and we should have standards that allow or even require threshold IBE (so that no single party can decrypt all messages). IBE services may fail to take verification seriously, but the sender of a message could simply ref…
If you want to encrypt something with my public key. You would run the following command (email address obfuscated): gpg --auto-key-locate pka -ear mike(dot)cardwell(at)grepular(dot)com gpg then automatically looks up the TXT record for "mike.cardwell._pka.grepular.com" in the DNS. Which gives it: "v=pka1\;fpr=35BCAF1D3AA21F843DC3B0CF70A5F5120018461F\;uri= http://grepular.com/0018461F.pub.asc It then automatically fe…
We need a system that lets people encrypt messages without having to wait for the receiver to do anything. That's the point of IBE: your public key is your email address, you get your private key from the service of the sender's choice. The service clearly needs to do something to verify your identity, which is the weakness -- but it is still better than what we do now, and it does not require us to wait for everyone to upgrade their email clients.