Live data from Hacker News

IRS claims it can read your e-mail without a warrant

news.cnet.com

111–120 of 186 posts

Re: IRS claims it can read your e-mail without a warrant

#111
post #71

Earlier quoted context omitted.

Uhh... In the postal system, your message is generally encapsulated in a tamper-evident envelope, carried in locked cars and trucks that enjoy Federal protection against intrusion, and end up in mailboxes that are almost always on private property and/or locked.

You can unglue an envelope over steam or on a hot surface. That's beside the point though. People in general expect their mail correspondence to remain private, although a motivated third party might be able to defeat security.

They expect their (physical) mail to remain private because there's a massive legal framework that protects it. There's an entire section of US code regarding the operation and authority of the post office (title 39) and a whole mess of criminal code about protecting the mail (in title 18).

http://about.usps.com/who-we-are/privacy-policy/intelligent-...

Re: IRS claims it can read your e-mail without a warrant

#112
post #65

Earlier quoted context omitted.

Also don't forget about Carnivore/Echelon and their ilk that presumably have the ability to intercept and store basically all email. Then once your email is duplicated in a government database somewhere, it being primarily housed on a Google or FB server is irrelevant.

It's not irrelevant. The 4th amendment is enforced primarily by the exclusionary rule. The fact that Carnivore, Echelon, etc, can get to your e-mail anyway doesn't mean that the government can introduce it as evidence in court. To the extent that the 4th amendment doesn't extend to the stuff you store on Google's, Facebook's, etc, servers, the government can introduce that as evidence against you.

But it does mean they could use your email contents to decide to audit you, then in the course of the audit find information which is permissible in court. I'd be shocked if given the revelation in this article, the IRS doesn't browse the email of some people before auditing them.

Re: IRS claims it can read your e-mail without a warrant

#113

Earlier quoted context omitted.

Uhh... In the postal system, your message is generally encapsulated in a tamper-evident envelope, carried in locked cars and trucks that enjoy Federal protection against intrusion, and end up in mailboxes that are almost always on private property and/or locked.

>> In the postal system, your message is generally encapsulated in a tamper-evident envelope... Those are all mechanisms, not legal protections. All could be bypassed by a determined person. In both email and physical mail, someone else can secretly read your mail if they try hard enough. In both, you expect them not to. In both, we have the same question: should the government need a warrant to violate that expectat…

No, they are legal protections, and mechanisms created and used in furtherance of the legal protections.

http://about.usps.com/who-we-are/privacy-policy/intelligent-...

Re: IRS claims it can read your e-mail without a warrant

#114

It's funny how in one breath the government tells us that there is no reasonable expectation of privacy for data on the internet and in another the DMCA says that the act of knowingly breaking any security, no matter how weak, is a serious crime.

And in the other breath say making a GET request to AT&T following some obvious pattern of IDs makes you a cyber criminal.

Re: IRS claims it can read your e-mail without a warrant

#115
post #3

This statement: "Newly disclosed documents prepared by IRS lawyers says that Americans enjoy 'generally no privacy' in their e-mail, Facebook chats, Twitter direct messages, and similar online communications" is entirely consistent with the existence of Warshack. Warshack covers the Sixth Circuit, which includes the following states: Kentucky, Michigan, Ohio, and Tennessee. The IRS is bound by this precedent in those…

>If you understand how SMTP works, it's hard to argue that it's a private means of communication.

Wrong. The users' providers can see the message, but they will only pass it to the next link in the chain to the recipient. That doesn't mean it's okay or expected that it'll be shared with anyone else.

Handing off your voice calls to AT&T does not eliminate the expectation or privacy, nor does handing off your letters to USPS. Both of these services will move your information around internally, and AT&T will route your voice call to a Verizon switch if necessary. This still does not negate the expectation of privacy.

Why should email be different?

Re: IRS claims it can read your e-mail without a warrant

#116
post #77
post #59

Earlier quoted context omitted.

No, that's stupid. That's equivalent to claiming telephone calls aren't private, because they're transmitted in the clear by third party exchanges accessible to authorized users. (email servers generally aren't publicly accessible, rather they're only accessible to authorized (registered) users)

email servers generally aren't publicly accessible, rather they're only accessible to authorized (registered) users Yes, sending email requires authorization to the SMTP server but MTA to MTA communications (as in when your mailserver actually sends your email to the recipients mail server) are clear text and can easily be intercepted. The difference between telephone calls and email is that you generally don't have…

[deleted]

Re: IRS claims it can read your e-mail without a warrant

#117

Earlier quoted context omitted.

You can easily demonstrate the veracity of your statement by letting us all know what publicly-accessible server we can access to read your email, without using violence and coercion (for which 'government power' is a euphemism) against a service provider to circumvent your 'authentication'.

I think you are making the same mistake as some other people in this chain. We are talking about SMTP, not IMAP. You don't need violence or coercion to sniff unencrypted mail in-flight. To prove to yourself that SMTP is primarily concerned about authenticity over privacy, just try setting up your own mail server. Ensuring your mail is not blocked and/or marked as spam is an involved process of establishing multiple c…

>You don't need violence or coercion to sniff unencrypted mail in-flight.

Google won't hand you a packet capture from eth0 on smtp.gmail.com because you asked nicely. You would have to coerce an insider (or exploit your way in).

The only situation in which your statement applies is if you're abusing a position of trust as a network administrator. While it's true that this is possible, it's also possible for someone to break into your (postal) mailbox. You still have an expectation of privacy.

Re: IRS claims it can read your e-mail without a warrant

#118
post #40

Earlier quoted context omitted.

So by your reasoning, if I mail you a postcard, and you put the postcard in a locked container placed inside of the trunk of a rental car, it is OK for the police to bypass your access controls and read the postcard? How you transmitted or handled something at a point in time is not relevant to it's status at rest. This issue here is that the government asserts that email is a communications system only. The problem…

Your analogy is completely inapt: 1) A rental car, like a rented house, is still under your control. But your e-mail account on Google's servers is under their control. They can do whatever they want with it. It's more like your friend letting you use part of his garage to store stuff--a third party still retains full control over the space. 2) As far as I can tell, Google can access your e-mail whenever it wants, so…

Because I know and expect that Google will use my emails to display targeted ads. And I also know that, under this process, my data remains in the custody of Google. I still fully expect Google not to send my data outside its servers, except to my recipient.

Re: IRS claims it can read your e-mail without a warrant

#119
post #94

Earlier quoted context omitted.

Except that the mail server gets to see the body of the email, which is not even remotely private. Encryption gives you privacy; instead of politely asking people to not read your mail, why not politely ask people to encrypt messages?

> Except that the mail server gets to see the body of the email, which is not even remotely private. Privacy should not (and in more enlightened countries and legal systems it does not) mean "others are not technically able to see it". It should mean: "this piece of information should not be attempted to be seen by others without the owners implicit or explicit permission". (And then legal formulas could be used to d…

"this piece of information should not be attempted to be seen by others without the owners implicit or explicit permission"

And we can do that with cryptography, with even more sophistication than a simple "yes/no" formula:

https://en.wikipedia.org/wiki/Attribute_based_encryption

The problem with relying on legal formulas here is that you need to rely on many people -- hundreds, maybe even thousands -- to not break the law over a long period of time. Your email is not really "sent," it is copied from system to system, and anyone with access to those systems could potentially read it. Backup tapes may be lost or stolen. Hard drives full of email may be sold off. This is not privacy; it is trusting hundreds of strangers to keep your confidence for an indefinite period of time.

Re: IRS claims it can read your e-mail without a warrant

#120
post #85
post #53

Earlier quoted context omitted.

All three of my email accounts (Outlook.com, Gmail, and AOL) require SSL, TLS, and STARTTLS (or any combination of the previous three) to send. SMTP is nothing next to encryption, but it's not the equivalent of leaving papers in a filing cabinet. Not even close.

Your SMTP server requires it to send email to prove it's really you and really them, yes, the mail server however sends your email to the recipient in clear text and can easily be intercepted if you happen to be inbetween the two servers.

>if you happen to be inbetween the two servers.

In which case you are a network administrator of a (probably tier 1) ISP and abusing your position of trust. As well as probably violating your contracts with the companies for which you have agreed to carry traffic.

It's also possible for me to read mail from my neighbors' mailboxes, and most of their PSTN demarcs are hanging off the side of the house and not protected by a fence or anything. Mail and voice calls are still private.

Post reply on HN