Live data from Hacker News

IRS claims it can read your e-mail without a warrant

news.cnet.com

131–140 of 186 posts

Re: IRS claims it can read your e-mail without a warrant

#131
post #3

This statement: "Newly disclosed documents prepared by IRS lawyers says that Americans enjoy 'generally no privacy' in their e-mail, Facebook chats, Twitter direct messages, and similar online communications" is entirely consistent with the existence of Warshack. Warshack covers the Sixth Circuit, which includes the following states: Kentucky, Michigan, Ohio, and Tennessee. The IRS is bound by this precedent in those…

That's a fine opinion, but it's no more than that, and fortunately the 6th Circuit disagrees with you, ruling that the ECPA's 180-day expiration date for an expectation of privacy is unconstitutional: > "Given the fundamental similarities between email and traditional forms of communication, it would defy common sense to afford emails lesser Fourth Amendment protection.... It follows that email requires strong protec…

The Sixth Circuit's decision certainly holds higher weight than mine, but that doesn't make it national law. Until more circuits agree with the Sixth, the IRS handbook is absolutely correct when it states that there is generally no privacy interest in e-mail and other electronic communications.

Re: IRS claims it can read your e-mail without a warrant

#132
post #71

Earlier quoted context omitted.

You can unglue an envelope over steam or on a hot surface. That's beside the point though. People in general expect their mail correspondence to remain private, although a motivated third party might be able to defeat security.

They expect their (physical) mail to remain private because there's a massive legal framework that protects it. There's an entire section of US code regarding the operation and authority of the post office (title 39) and a whole mess of criminal code about protecting the mail (in title 18). http://about.usps.com/who-we-are/privacy-policy/intelligent-...

So we can expect our email to be protected after we've successfully lobbied for the establishment of a massive legal framework that protects it, then?

Re: IRS claims it can read your e-mail without a warrant

#133

Earlier quoted context omitted.

That's a fine opinion, but it's no more than that, and fortunately the 6th Circuit disagrees with you, ruling that the ECPA's 180-day expiration date for an expectation of privacy is unconstitutional: > "Given the fundamental similarities between email and traditional forms of communication, it would defy common sense to afford emails lesser Fourth Amendment protection.... It follows that email requires strong protec…

The Sixth Circuit's decision certainly holds higher weight than mine, but that doesn't make it national law. Until more circuits agree with the Sixth, the IRS handbook is absolutely correct when it states that there is generally no privacy interest in e-mail and other electronic communications.

You're speaking of the third party doctrine, which isn't strictly law, more a collection of precedent, and has never been ruled to actually apply to retained email. If you read the 6th Circuit's decision, you'll see a number of statutes that directly contradict the 180-day provision, and which give an additional legal basis for the protection of emails beyond just an interpretation of the 4th as overriding the law and striking it as unconstitutional.

The IRS trying this would be a great benefit to us all, short of congress getting their act together and revising the ECPA, and the EFF would love nothing more than to take up the case. Considering that it has already been confirmed that Google is requiring warrants and Microsoft has taken such a strong stand while releasing their latest transparency report, it seems like we also have at least two corporate sponsors (and, actually, this is a bad position for most companies to be in, as many email providers can't easily figure out which Appeals Court their customer falls under. This exposes them to risk if they disclose email content without a warrant, which is another motivation to take the conservative approach and ask a court to decide if they have to disclose emails with only a subpoena).

Re: IRS claims it can read your e-mail without a warrant

#134
post #76

Earlier quoted context omitted.

We put doors on restrooms. Claiming that unencrypted email should carry a legitimate expectation of privacy is like claiming that people should expect privacy when they go to the bathroom on the side of the highway. People may want their email to be private, but that does not mean that we should pretend that email really is private. Really, we need encryption to be widely used, for people to learn about it in school,…

You can't normally read SMTP exchange between two arbitrary servers. Granted, there's a range of attacks possible to a motivated hacker, but they are exactly that: attacks. Your email is normally not exposed to third parties.

"Your email is normally not exposed to third parties."

Except for the mail servers...

Re: IRS claims it can read your e-mail without a warrant

#135
post #94

Earlier quoted context omitted.

> Except that the mail server gets to see the body of the email, which is not even remotely private. Privacy should not (and in more enlightened countries and legal systems it does not) mean "others are not technically able to see it". It should mean: "this piece of information should not be attempted to be seen by others without the owners implicit or explicit permission". (And then legal formulas could be used to d…

> Privacy should not (and in more enlightened countries and legal systems it does not) mean "others are not technically able to see it". This is really at the heart of the disagreement in this thread. Maybe this is what you think it should mean. But that's not what it means Constitutionally. The Constitution doesn't talk about privacy, it talks about unreasonable search and seizure. And the precedent is that if you'v…

>But that's not what it means Constitutionally.

Sure, but I don't care much about the constitution. I care about what's fair and right. Constitutions can be changed and amended, especially if they were written 3 centuries ago.

Re: IRS claims it can read your e-mail without a warrant

#136
post #58

Earlier quoted context omitted.

There is no reasonable expectation of privacy when it comes to private carriers like FedEx or UPS. The expectation of privacy only extends to First Class USPS mail, under the consideration that extra protections are needed given that the USPS is an organ of the federal government and that USPS workers are bound by the 4th amendment just as any other agent of the government (and unlike private mail carriers!)

> There is no reasonable expectation of privacy when it comes to private carriers like FedEx or UPS. Absent an expectation of privacy, the government is entitled to search whatever and whenever it pleases. Are you suggesting there is court precedent establishing the government does not require a warrant to search a box being delivered by UPS?

With UPS' consent, I'd guess.

Re: IRS claims it can read your e-mail without a warrant

#137
post #94

Earlier quoted context omitted.

> Except that the mail server gets to see the body of the email, which is not even remotely private. Privacy should not (and in more enlightened countries and legal systems it does not) mean "others are not technically able to see it". It should mean: "this piece of information should not be attempted to be seen by others without the owners implicit or explicit permission". (And then legal formulas could be used to d…

> It should mean: "this piece of information should not be attempted to be seen by others without the owners implicit or explicit permission". So WireShark is now illegal in your ideal world? Email is computer technology and demands a technical answer: if you want something to not be eavesdropped on, encrypt it. This is why we use ssh and not telnet any more.

>So WireShark is now illegal in your ideal world?

If if it's not your network and/or network traffic, or you don't have the network owners permission, then yes.

Why should it be legal? Because you like playing with it?

Re: IRS claims it can read your e-mail without a warrant

#138
post #37

Earlier quoted context omitted.

While I would not argue against encryption giving you privacy, I think it is easy to argue that there is an expectation of privacy in sending emails. At least, as much of one as if you were sending actual correspondence. Consider, in a public restroom there is very little done to prevent people from seeing each other. However, one almost certainly has a reasonable expectation of privacy in such a situation. Hell, con…

We put doors on restrooms. Claiming that unencrypted email should carry a legitimate expectation of privacy is like claiming that people should expect privacy when they go to the bathroom on the side of the highway. People may want their email to be private, but that does not mean that we should pretend that email really is private. Really, we need encryption to be widely used, for people to learn about it in school,…

Irrelevant. When you are in a restroom, you have an expectation of privacy. Period. Doesn't matter whose restroom you are at or what is going on. Hell, the door could be broken or just bad and you still have an expectation of privacy.

Consider, someone could have a camera mounted onto their foot or on a poll to get over the standard stall doors. Would you just claim that folks should be ok with this? Because, "hey, it was possible? Quite easily done, actually."

I am pushing this point so heavily especially because a large company is pushing cameras that are mounted on people's faces. If someone were going into a restroom taking pictures, people would feel rightfully violated. Soon, this is likely to be happening more than you'd care to consider. The ease with which it can be done is irrelevant to the legality of it.

Re: IRS claims it can read your e-mail without a warrant

#139
post #71

Earlier quoted context omitted.

You can unglue an envelope over steam or on a hot surface. That's beside the point though. People in general expect their mail correspondence to remain private, although a motivated third party might be able to defeat security.

They expect their (physical) mail to remain private because there's a massive legal framework that protects it. There's an entire section of US code regarding the operation and authority of the post office (title 39) and a whole mess of criminal code about protecting the mail (in title 18). http://about.usps.com/who-we-are/privacy-policy/intelligent-...

So clearly similar laws should exist to protect email, encrypted or not.

Re: IRS claims it can read your e-mail without a warrant

#140

Earlier quoted context omitted.

We are talking about a transmission protocol, not a storage protocol. For storage, privacy and identity overlap. For transmission they do not.

So you don't mind if I wiretap all your phones? Email being transmitted by 3rd parties is not different from voice calls being transmitted by 3rd parties. Yes, you are trusting a provider, with the expectation that your provider will send the data where you've asked it to send the data, and nowhere else . This is still true whether you're talking postal service, landline voice calls, SMS, cellular voice calls, Skype,…

Maybe I'm expressing myself in too cryptic of a fashion. I'm simply asserting that while privacy and authentication sometimes overlap, they are not the same thing.

From the parent of my original comment:

Almost every SMTP server out there today requires authentication ... That is the very definition of trying to keep things private.

Do you disagree with me? Do you believe that SMTP authentication contributes to privacy and not authenticity?

Post reply on HN