Live data from Hacker News

IRS claims it can read your e-mail without a warrant

news.cnet.com

101–110 of 186 posts

Re: IRS claims it can read your e-mail without a warrant

#101
post #82
post #56

Earlier quoted context omitted.

Note to citizens of the USA: This is what you get when a government is afraid of it's citizens. Freedom fries, indeed. Guns not needed.

No, this is a good point. History suggests that the government of france should absolutely be afraid of french citizens.

To (mis-) quote Rick Steves, the city of Paris repaved its streets, removing the historic cobbles, to prevent the citizens from using the streets...as weapons.

Non-apathetic citizenry probably trumps well-armed citizenry.

Re: IRS claims it can read your e-mail without a warrant

#102
post #67

Earlier quoted context omitted.

The lock on my door is to prevent someone from pretending to be me to enter my property. This is not the same as trying to keep my stuff private or safe. Note how your statement does not hold in the real world.

We are talking about a transmission protocol, not a storage protocol. For storage, privacy and identity overlap. For transmission they do not.

So the true comparison might be standing naked on your walkway to your front door from the curbside, and saying people don't have a right to take your picture. It's prviate property that's publicly viewable. When expressed this way, then it's actually pretty easy to see how it extends to the real world (you have no expectation of privacy in the publicly viewable space).

Re: IRS claims it can read your e-mail without a warrant

#103

Earlier quoted context omitted.

If you want to encrypt something with my public key. You would run the following command (email address obfuscated): gpg --auto-key-locate pka -ear mike(dot)cardwell(at)grepular(dot)com gpg then automatically looks up the TXT record for "mike.cardwell._pka.grepular.com" in the DNS. Which gives it: "v=pka1\;fpr=35BCAF1D3AA21F843DC3B0CF70A5F5120018461F\;uri= http://grepular.com/0018461F.pub.asc It then automatically fe…

Yeah but you still had to generate and publish that key before I could send you an encrypted message. If I need to communicate with someone who has not done so, what I am supposed to do? Nag at them to do it? Try to explain the important of encryption? I have tried it, and I still try, and it is basically not going to work: people generally do not see the point, and they hate the fact that they cannot check their mai…

Yeah, what you say is true. That would be better than what we have now. Re your comments about smart card readers. You can have smartcard functionality on any machine with a USB port if you use one of these:

https://www.crypto-stick.com/

I received one a couple of weeks ago and it works great. I also have an OpenPGP v2 smart card, a USB smart card reader, and a reader built into my Thinkpad.

Re: IRS claims it can read your e-mail without a warrant

#104
post #58
post #54

Earlier quoted context omitted.

What if I FedEx a letter and a FedEx employee opens it and keeps a copy of it? (Replace FedEx with USPS if it makes a difference)

There is no reasonable expectation of privacy when it comes to private carriers like FedEx or UPS. The expectation of privacy only extends to First Class USPS mail, under the consideration that extra protections are needed given that the USPS is an organ of the federal government and that USPS workers are bound by the 4th amendment just as any other agent of the government (and unlike private mail carriers!)

> There is no reasonable expectation of privacy when it comes to private carriers like FedEx or UPS.

Absent an expectation of privacy, the government is entitled to search whatever and whenever it pleases. Are you suggesting there is court precedent establishing the government does not require a warrant to search a box being delivered by UPS?

Re: IRS claims it can read your e-mail without a warrant

#105
post #3

This statement: "Newly disclosed documents prepared by IRS lawyers says that Americans enjoy 'generally no privacy' in their e-mail, Facebook chats, Twitter direct messages, and similar online communications" is entirely consistent with the existence of Warshack. Warshack covers the Sixth Circuit, which includes the following states: Kentucky, Michigan, Ohio, and Tennessee. The IRS is bound by this precedent in those…

[deleted]

Re: IRS claims it can read your e-mail without a warrant

#106
post #36

Earlier quoted context omitted.

> You send a clear-text message to a publically-accessible service that is empowered to forward the message to other publically-accessible servers if necessary. This is how postal system works.

Uhh... In the postal system, your message is generally encapsulated in a tamper-evident envelope, carried in locked cars and trucks that enjoy Federal protection against intrusion, and end up in mailboxes that are almost always on private property and/or locked.

>> In the postal system, your message is generally encapsulated in a tamper-evident envelope...

Those are all mechanisms, not legal protections. All could be bypassed by a determined person.

In both email and physical mail, someone else can secretly read your mail if they try hard enough. In both, you expect them not to. In both, we have the same question: should the government need a warrant to violate that expectation?

I can plant a secret microphone in your house. That doesn't mean I have a right to.

Re: IRS claims it can read your e-mail without a warrant

#107

Earlier quoted context omitted.

And this is why you always use something along the lines of PGP end to end.

PGP needs to be more easily accessed by non-tech folk.

Absolutely. Some of the biggest failures in security is lack of ease of use by and large, in addition to ignorance. I think most people are willing to do the proper thing, but they'll actually do it only if it's easy.

Re: IRS claims it can read your e-mail without a warrant

#108
post #67

Earlier quoted context omitted.

The lock on my door is to prevent someone from pretending to be me to enter my property. This is not the same as trying to keep my stuff private or safe. Note how your statement does not hold in the real world.

We are talking about a transmission protocol, not a storage protocol. For storage, privacy and identity overlap. For transmission they do not.

So you don't mind if I wiretap all your phones?

Email being transmitted by 3rd parties is not different from voice calls being transmitted by 3rd parties. Yes, you are trusting a provider, with the expectation that your provider will send the data where you've asked it to send the data, and nowhere else. This is still true whether you're talking postal service, landline voice calls, SMS, cellular voice calls, Skype, etc.

Re: IRS claims it can read your e-mail without a warrant

#109
post #77
post #59

Earlier quoted context omitted.

No, that's stupid. That's equivalent to claiming telephone calls aren't private, because they're transmitted in the clear by third party exchanges accessible to authorized users. (email servers generally aren't publicly accessible, rather they're only accessible to authorized (registered) users)

email servers generally aren't publicly accessible, rather they're only accessible to authorized (registered) users Yes, sending email requires authorization to the SMTP server but MTA to MTA communications (as in when your mailserver actually sends your email to the recipients mail server) are clear text and can easily be intercepted. The difference between telephone calls and email is that you generally don't have…

The SMTP protocol is used both from client to server and from server to server. RFC 3207 (2002) complaint MTAs communicate with each other over a TLS (i.e. encrypted) connection.

Complaint MTAs include: sendmail (>= 8.11), postfix (>= 2.2), MS Exchange (>= 5.5). Patches have existed for qmail to add support since 1.01, though they aren't in the main distribution for reasons that I'm sure make sense to djb.

Re: IRS claims it can read your e-mail without a warrant

#110
post #94

Earlier quoted context omitted.

Except that the mail server gets to see the body of the email, which is not even remotely private. Encryption gives you privacy; instead of politely asking people to not read your mail, why not politely ask people to encrypt messages?

> Except that the mail server gets to see the body of the email, which is not even remotely private. Privacy should not (and in more enlightened countries and legal systems it does not) mean "others are not technically able to see it". It should mean: "this piece of information should not be attempted to be seen by others without the owners implicit or explicit permission". (And then legal formulas could be used to d…

> It should mean: "this piece of information should not be attempted to be seen by others without the owners implicit or explicit permission".

So WireShark is now illegal in your ideal world?

Email is computer technology and demands a technical answer: if you want something to not be eavesdropped on, encrypt it. This is why we use ssh and not telnet any more.

Post reply on HN