Live data from Hacker News

IRS claims it can read your e-mail without a warrant

news.cnet.com

141–150 of 186 posts

Re: IRS claims it can read your e-mail without a warrant

#141

Earlier quoted context omitted.

I think you are making the same mistake as some other people in this chain. We are talking about SMTP, not IMAP. You don't need violence or coercion to sniff unencrypted mail in-flight. To prove to yourself that SMTP is primarily concerned about authenticity over privacy, just try setting up your own mail server. Ensuring your mail is not blocked and/or marked as spam is an involved process of establishing multiple c…

>You don't need violence or coercion to sniff unencrypted mail in-flight. Google won't hand you a packet capture from eth0 on smtp.gmail.com because you asked nicely. You would have to coerce an insider (or exploit your way in). The only situation in which your statement applies is if you're abusing a position of trust as a network administrator. While it's true that this is possible, it's also possible for someone t…

You don't need a tap on smtp.gmail.com to listen to a message leaving smtp.gmail.com

Re: IRS claims it can read your e-mail without a warrant

#142
post #136

Earlier quoted context omitted.

> There is no reasonable expectation of privacy when it comes to private carriers like FedEx or UPS. Absent an expectation of privacy, the government is entitled to search whatever and whenever it pleases. Are you suggesting there is court precedent establishing the government does not require a warrant to search a box being delivered by UPS?

With UPS' consent, I'd guess.

That is your own speculation, not established precedent, and I would argue UPS is now acting as an agent of the government anyway.

So, again, what actual precedent exists to support rayiner's contention?

Re: IRS claims it can read your e-mail without a warrant

#143

Earlier quoted context omitted.

> It should mean: "this piece of information should not be attempted to be seen by others without the owners implicit or explicit permission". So WireShark is now illegal in your ideal world? Email is computer technology and demands a technical answer: if you want something to not be eavesdropped on, encrypt it. This is why we use ssh and not telnet any more.

> So WireShark is now illegal in your ideal world? If if it's not your network and/or network traffic, or you don't have the network owners permission, then yes. Why should it be legal? Because you like playing with it?

That's a strange, old school way of thinking. Why are you trying to legislate technology when you could just make the tech work the way you want?

"Impossible" trumps "illegal" every time.

Re: IRS claims it can read your e-mail without a warrant

#144
This thread is full of hackers eager to apply a technological solution - encryption - to a problem which is better solved legally. Encryption has rather obvious usability problems, such as being fundamentally incompatible with webmail (and remote access in general - even if you use a client that decrypts emails, you can't search without downloading your entire inbox); while it's highly valuable for myriad use cases, I shouldn't have to use it for all my random mail. Yes, email seems fundamentally insecure technically, SMTP servers bouncing messages to other SMTP servers in the clear, but older networks such as physical mail and telephone are even worse and harder to secure, yet I still have an expectation of privacy (even if I use a PO box to store my mail remotely...) because it has been established by law. There is zero reason this shouldn't apply to email.

Re: IRS claims it can read your e-mail without a warrant

#145
post #90
post #78

Earlier quoted context omitted.

The data I put in Google is MY property, I want that data protected and don't care less about servers just as I do not claim ownership to the school locker.

If you want it protected, don't leave it in clear text in the custody of someone else who may or may not choose to hand it over to the authorities without your permission. In other news: you can't invoke the 4th amendment if you stash boxes of weed at a friend's house and he hands them over to the government when asked.

You are consistently morphing the issue and providing bad analogies.

There are privacy policies and terms of service that cover what a service provider will share with whom and under what conditions. This represents an agreement between the user and the service.

However, that is wholly different from the rights held by the government (IRS) to compel the service provider to provide information at the government's demand.

Your analogy with the "boxes of weed" are similarly misguided and completely unrelated. The more relevant analogy would be that the government forced your friend's landlord to unlock his door without a warrant, entered, discovered the boxes of weed with your name on it, then arrested you.

And, to put your analogy back into the subject e-mail context, if you e-mailed something incriminating to your friend and your friend opted to turn you in to the authorities, that is entirely different from the government gaining access to your e-mail of its own volition, and without a warrant.

Re: IRS claims it can read your e-mail without a warrant

#146

Earlier quoted context omitted.

So you don't mind if I wiretap all your phones? Email being transmitted by 3rd parties is not different from voice calls being transmitted by 3rd parties. Yes, you are trusting a provider, with the expectation that your provider will send the data where you've asked it to send the data, and nowhere else . This is still true whether you're talking postal service, landline voice calls, SMS, cellular voice calls, Skype,…

Maybe I'm expressing myself in too cryptic of a fashion. I'm simply asserting that while privacy and authentication sometimes overlap, they are not the same thing. From the parent of my original comment: Almost every SMTP server out there today requires authentication ... That is the very definition of trying to keep things private. Do you disagree with me? Do you believe that SMTP authentication contributes to priva…

>Do you believe that SMTP authentication contributes to privacy and not authenticity?

Why can't it be both?

Re: IRS claims it can read your e-mail without a warrant

#147
post #3

This statement: "Newly disclosed documents prepared by IRS lawyers says that Americans enjoy 'generally no privacy' in their e-mail, Facebook chats, Twitter direct messages, and similar online communications" is entirely consistent with the existence of Warshack. Warshack covers the Sixth Circuit, which includes the following states: Kentucky, Michigan, Ohio, and Tennessee. The IRS is bound by this precedent in those…

>If you understand how SMTP works, it's hard to argue that it's a private means of communication.

No. No. No.

The test is one of reasonableness. Is it reasonable to assume that an individual--who addresses a message directly to another individual by means of that individual's unique identifier--intends that only that individual will view the e-mail? Of course it is.

The suggestion that people should understand the vulnerabilities in the underlying technology is a red herring.

Perhaps this is why the Sixth Circuit concluded that e-mail is private.

Re: IRS claims it can read your e-mail without a warrant

#148

Earlier quoted context omitted.

So you don't mind if I wiretap all your phones? Email being transmitted by 3rd parties is not different from voice calls being transmitted by 3rd parties. Yes, you are trusting a provider, with the expectation that your provider will send the data where you've asked it to send the data, and nowhere else . This is still true whether you're talking postal service, landline voice calls, SMS, cellular voice calls, Skype,…

The protections for phone calls arose back when phone lines were dumb analog wires between telephones. E-mail has never been like that, and it's always involved storing communications on a third party's systems.

>E-mail has never been like that, and it's always involved storing communications on a third party's systems.

Why should storing something on a third party's system obviate the need for a warrant? If I rent real property and use it to store my papers, does that mean the government should be entitled to seize them without a warrant because I'm storing them on the premises of a third party? If not, what's the difference?

Re: IRS claims it can read your e-mail without a warrant

#149
post #69
post #35

Earlier quoted context omitted.

> Google's email isn't encrypted, it is sent as text over a network I just grepped my personal email server log to double check, here's an obfuscated entry from this morning: > localhost postfix/smtpd[14440]: TLS connection established from mail-xxxxxxxx.google.com[xxx.xx.xxx.xxx]: TLS v1 with cipher RC4-SHA (128/128 bits) Doesn't look like clear text to me.

Can you do an attack like ssl-strip, but on IMAP servers? Presumably you can.

Presumably you can pick a lock or attach a lineman's handset to the POTS phone lines outside of someone's house too, but aren't we talking about the expectation of privacy?

Re: IRS claims it can read your e-mail without a warrant

#150

Earlier quoted context omitted.

So you don't mind if I wiretap all your phones? Email being transmitted by 3rd parties is not different from voice calls being transmitted by 3rd parties. Yes, you are trusting a provider, with the expectation that your provider will send the data where you've asked it to send the data, and nowhere else . This is still true whether you're talking postal service, landline voice calls, SMS, cellular voice calls, Skype,…

So you're saying phone calls are only private because of a misguided adherence to tradition?

He's not arguing against privacy; he's merely pointing out that requiring authentication to send emails isn't the same thing.
Post reply on HN