Earlier quoted context omitted.
I think you are making the same mistake as some other people in this chain. We are talking about SMTP, not IMAP. You don't need violence or coercion to sniff unencrypted mail in-flight. To prove to yourself that SMTP is primarily concerned about authenticity over privacy, just try setting up your own mail server. Ensuring your mail is not blocked and/or marked as spam is an involved process of establishing multiple c…
>You don't need violence or coercion to sniff unencrypted mail in-flight. Google won't hand you a packet capture from eth0 on smtp.gmail.com because you asked nicely. You would have to coerce an insider (or exploit your way in). The only situation in which your statement applies is if you're abusing a position of trust as a network administrator. While it's true that this is possible, it's also possible for someone t…
IRS claims it can read your e-mail without a warrant
141–150 of 186 posts
Re: IRS claims it can read your e-mail without a warrant
#142Earlier quoted context omitted.
> There is no reasonable expectation of privacy when it comes to private carriers like FedEx or UPS. Absent an expectation of privacy, the government is entitled to search whatever and whenever it pleases. Are you suggesting there is court precedent establishing the government does not require a warrant to search a box being delivered by UPS?
With UPS' consent, I'd guess.
So, again, what actual precedent exists to support rayiner's contention?
Re: IRS claims it can read your e-mail without a warrant
#143Earlier quoted context omitted.
> It should mean: "this piece of information should not be attempted to be seen by others without the owners implicit or explicit permission". So WireShark is now illegal in your ideal world? Email is computer technology and demands a technical answer: if you want something to not be eavesdropped on, encrypt it. This is why we use ssh and not telnet any more.
> So WireShark is now illegal in your ideal world? If if it's not your network and/or network traffic, or you don't have the network owners permission, then yes. Why should it be legal? Because you like playing with it?
"Impossible" trumps "illegal" every time.
Re: IRS claims it can read your e-mail without a warrant
#144Re: IRS claims it can read your e-mail without a warrant
#145Earlier quoted context omitted.
The data I put in Google is MY property, I want that data protected and don't care less about servers just as I do not claim ownership to the school locker.
If you want it protected, don't leave it in clear text in the custody of someone else who may or may not choose to hand it over to the authorities without your permission. In other news: you can't invoke the 4th amendment if you stash boxes of weed at a friend's house and he hands them over to the government when asked.
There are privacy policies and terms of service that cover what a service provider will share with whom and under what conditions. This represents an agreement between the user and the service.
However, that is wholly different from the rights held by the government (IRS) to compel the service provider to provide information at the government's demand.
Your analogy with the "boxes of weed" are similarly misguided and completely unrelated. The more relevant analogy would be that the government forced your friend's landlord to unlock his door without a warrant, entered, discovered the boxes of weed with your name on it, then arrested you.
And, to put your analogy back into the subject e-mail context, if you e-mailed something incriminating to your friend and your friend opted to turn you in to the authorities, that is entirely different from the government gaining access to your e-mail of its own volition, and without a warrant.
Re: IRS claims it can read your e-mail without a warrant
#146Earlier quoted context omitted.
So you don't mind if I wiretap all your phones? Email being transmitted by 3rd parties is not different from voice calls being transmitted by 3rd parties. Yes, you are trusting a provider, with the expectation that your provider will send the data where you've asked it to send the data, and nowhere else . This is still true whether you're talking postal service, landline voice calls, SMS, cellular voice calls, Skype,…
Maybe I'm expressing myself in too cryptic of a fashion. I'm simply asserting that while privacy and authentication sometimes overlap, they are not the same thing. From the parent of my original comment: Almost every SMTP server out there today requires authentication ... That is the very definition of trying to keep things private. Do you disagree with me? Do you believe that SMTP authentication contributes to priva…
Why can't it be both?
Re: IRS claims it can read your e-mail without a warrant
#147This statement: "Newly disclosed documents prepared by IRS lawyers says that Americans enjoy 'generally no privacy' in their e-mail, Facebook chats, Twitter direct messages, and similar online communications" is entirely consistent with the existence of Warshack. Warshack covers the Sixth Circuit, which includes the following states: Kentucky, Michigan, Ohio, and Tennessee. The IRS is bound by this precedent in those…
No. No. No.
The test is one of reasonableness. Is it reasonable to assume that an individual--who addresses a message directly to another individual by means of that individual's unique identifier--intends that only that individual will view the e-mail? Of course it is.
The suggestion that people should understand the vulnerabilities in the underlying technology is a red herring.
Perhaps this is why the Sixth Circuit concluded that e-mail is private.
Re: IRS claims it can read your e-mail without a warrant
#148Earlier quoted context omitted.
So you don't mind if I wiretap all your phones? Email being transmitted by 3rd parties is not different from voice calls being transmitted by 3rd parties. Yes, you are trusting a provider, with the expectation that your provider will send the data where you've asked it to send the data, and nowhere else . This is still true whether you're talking postal service, landline voice calls, SMS, cellular voice calls, Skype,…
The protections for phone calls arose back when phone lines were dumb analog wires between telephones. E-mail has never been like that, and it's always involved storing communications on a third party's systems.
Why should storing something on a third party's system obviate the need for a warrant? If I rent real property and use it to store my papers, does that mean the government should be entitled to seize them without a warrant because I'm storing them on the premises of a third party? If not, what's the difference?
Re: IRS claims it can read your e-mail without a warrant
#149Earlier quoted context omitted.
> Google's email isn't encrypted, it is sent as text over a network I just grepped my personal email server log to double check, here's an obfuscated entry from this morning: > localhost postfix/smtpd[14440]: TLS connection established from mail-xxxxxxxx.google.com[xxx.xx.xxx.xxx]: TLS v1 with cipher RC4-SHA (128/128 bits) Doesn't look like clear text to me.
Can you do an attack like ssl-strip, but on IMAP servers? Presumably you can.
Re: IRS claims it can read your e-mail without a warrant
#150Earlier quoted context omitted.
So you don't mind if I wiretap all your phones? Email being transmitted by 3rd parties is not different from voice calls being transmitted by 3rd parties. Yes, you are trusting a provider, with the expectation that your provider will send the data where you've asked it to send the data, and nowhere else . This is still true whether you're talking postal service, landline voice calls, SMS, cellular voice calls, Skype,…
So you're saying phone calls are only private because of a misguided adherence to tradition?