Live data from Hacker News

IRS claims it can read your e-mail without a warrant

news.cnet.com

151–160 of 186 posts

Re: IRS claims it can read your e-mail without a warrant

#151

Earlier quoted context omitted.

> So WireShark is now illegal in your ideal world? If if it's not your network and/or network traffic, or you don't have the network owners permission, then yes. Why should it be legal? Because you like playing with it?

That's a strange, old school way of thinking. Why are you trying to legislate technology when you could just make the tech work the way you want? "Impossible" trumps "illegal" every time.

>"Impossible" trumps "illegal" every time.

Indeed. Making something that could be made impossible (or extremely difficult) "only" illegal will tend to make people complacent. If the expectation is that bad people won't do something because it's against the law, good people may fail to ensure that they can't. And then bad people do it anyway, leading to outrage, panic and harmful reactionary legislation. Not to mention bad people getting away with doing bad things, which could all have been prevented with sound engineering.

This isn't to say that every problem can be solved with a technical solution -- but when the technical solution is extremely effective, a legal solution is surplus to requirements.

Re: IRS claims it can read your e-mail without a warrant

#152
post #136

Earlier quoted context omitted.

With UPS' consent, I'd guess.

That is your own speculation, not established precedent, and I would argue UPS is now acting as an agent of the government anyway. So, again, what actual precedent exists to support rayiner's contention?

I agree. If you sign an agreement with UPS that allows it to simply give your package to the government upon its request, then you've effectively waived your Fourth Amendment rights.

But, absent that, the government cannot simply compel UPS to hand over the package or relay its contents without a warrant. That would be a violation of the Fourth.

OTOH, if the UPS employee simply looked in the box, it wouldn't be a Fourth issue. It is only so if the employee did so at the behest of the government. In other words, you are correct: in that case the employee is acting as a government agent[1], which triggers the Fourth:

[1] http://www.fletc.gov/training/programs/legal-division/podcas...

Edit: Key clause:

Miller: Can private parties ever trigger the 4th Amendment?

Solari: Yes, as we discussed, if a private party were to be acting at the behest of the government -- if a government agent were to ask that FedEx person to open up a package and look inside, or to ask someone’s girlfriend to go through their things looking for evidence to turn over to the police, then that would be government activity. That would be the actions of a government agent because government agents can’t ask private parties to do something they themselves couldn’t do under the 4th Amendment, so in that type of instance it would be extended to that private party.

Re: IRS claims it can read your e-mail without a warrant

#153
post #3

This statement: "Newly disclosed documents prepared by IRS lawyers says that Americans enjoy 'generally no privacy' in their e-mail, Facebook chats, Twitter direct messages, and similar online communications" is entirely consistent with the existence of Warshack. Warshack covers the Sixth Circuit, which includes the following states: Kentucky, Michigan, Ohio, and Tennessee. The IRS is bound by this precedent in those…

> If you understand how SMTP works, it's hard to argue that it's a private means of communication.

This is true, and a great point. I often open my neighbors' postal mail using this same excuse. Sometimes you can even read the letters and notices right through the paper envelope!

Re: IRS claims it can read your e-mail without a warrant

#154

Earlier quoted context omitted.

> So WireShark is now illegal in your ideal world? If if it's not your network and/or network traffic, or you don't have the network owners permission, then yes. Why should it be legal? Because you like playing with it?

That's a strange, old school way of thinking. Why are you trying to legislate technology when you could just make the tech work the way you want? "Impossible" trumps "illegal" every time.

It's a matter of "Do I want to spend the time necessary to accomplish X?" Impossible is a very strong word, like hate. Very few things are impossible.

Re: IRS claims it can read your e-mail without a warrant

#155
post #138

Earlier quoted context omitted.

We put doors on restrooms. Claiming that unencrypted email should carry a legitimate expectation of privacy is like claiming that people should expect privacy when they go to the bathroom on the side of the highway. People may want their email to be private, but that does not mean that we should pretend that email really is private. Really, we need encryption to be widely used, for people to learn about it in school,…

Irrelevant. When you are in a restroom, you have an expectation of privacy. Period. Doesn't matter whose restroom you are at or what is going on. Hell, the door could be broken or just bad and you still have an expectation of privacy. Consider, someone could have a camera mounted onto their foot or on a poll to get over the standard stall doors. Would you just claim that folks should be ok with this? Because, "hey, i…

"Hell, the door could be broken or just bad and you still have an expectation of privacy."

So let's take that argument to its extreme: you are standing in an open field going to the bathroom. Do you still think you have an reasonable expectation of privacy?

The problem with your argument is that it is based on the idea that if people want privacy, they are entitled to it even if they do nothing to protect that privacy. There is nothing wrong with expecting people to be a bit proactive when it comes to their privacy -- closing doors, drawing their curtains, encrypting their email. People should not just shrug about someone filming them on the toilet, they should do something to prevent it (and if a person started to drill holes in the door, sure, prosecute them -- for destroying someone's property).

"If someone were going into a restroom taking pictures, people would feel rightfully violated"

No, if someone were going into a restroom taking pictures of other people going to the bathroom in a closed stall they would rightly feel violated. Any weaker standard is basically saying that nobody can take pictures in public, because they might accidentally catch a person peeing on a wall and thus violate their privacy.

"The ease with which it can be done is irrelevant to the legality of it."

No, it is very relevant to the legality, because when we make easy and popular things illegal we worsen an already out-of-control criminal justice system. We do not want to start arresting people just because they are using their cameras, even if their cameras are mounted on their heads, even if they wear their head-mounted cameras into bathrooms. If cameras are everywhere and used by everyone, the answer is to build bathroom stalls that go from the floor to the ceiling, not to open the door to waves of prosecution (which will almost certainly be used selectively against "undesirable" people).

The appropriate place to draw the legal line with privacy is with people taking proactive and reasonable measures to be private. Putting letters in envelopes, closing curtains, closing doors, and yes, encrypting emails. You have no expectation of privacy in public parks, nor if your door is left open, nor if your curtains are left open, so why should you expect privacy when you send unencrypted email?

Re: IRS claims it can read your e-mail without a warrant

#156
post #69

Earlier quoted context omitted.

Can you do an attack like ssl-strip, but on IMAP servers? Presumably you can.

Presumably you can pick a lock or attach a lineman's handset to the POTS phone lines outside of someone's house too, but aren't we talking about the expectation of privacy?

You should never expect privacy over an unencrypted connection.

However where I do disagree with rayiner is that you should be able to expect that third parties which you willingly entrust your communication to, should not be compelled to turn over that message without a warrant.

If they turn it over willingly that's caveat emptor, but email to me feels more like a hand-to-hand transfer of a postcard than dropping a postcard on a public desk (as used in a different example), and therefore you should be able expect that it's not treated as essentially public domain.

Re: IRS claims it can read your e-mail without a warrant

#157
post #3

This statement: "Newly disclosed documents prepared by IRS lawyers says that Americans enjoy 'generally no privacy' in their e-mail, Facebook chats, Twitter direct messages, and similar online communications" is entirely consistent with the existence of Warshack. Warshack covers the Sixth Circuit, which includes the following states: Kentucky, Michigan, Ohio, and Tennessee. The IRS is bound by this precedent in those…

> If you understand how SMTP works, it's hard to argue that it's a private means of communication. This is true, and a great point. I often open my neighbors' postal mail using this same excuse. Sometimes you can even read the letters and notices right through the paper envelope!

Postcards are the better analogy for SMTP, not "opening postal mail".

With that said, it's actually a Federal crime to remove mail from someone else's mailbox to obstruct or pry into their business (even for postcards), which would seem to support your overall point.

http://www.law.cornell.edu/uscode/text/18/1702

Re: IRS claims it can read your e-mail without a warrant

#158

Earlier quoted context omitted.

So you don't mind if I wiretap all your phones? Email being transmitted by 3rd parties is not different from voice calls being transmitted by 3rd parties. Yes, you are trusting a provider, with the expectation that your provider will send the data where you've asked it to send the data, and nowhere else . This is still true whether you're talking postal service, landline voice calls, SMS, cellular voice calls, Skype,…

Maybe I'm expressing myself in too cryptic of a fashion. I'm simply asserting that while privacy and authentication sometimes overlap, they are not the same thing. From the parent of my original comment: Almost every SMTP server out there today requires authentication ... That is the very definition of trying to keep things private. Do you disagree with me? Do you believe that SMTP authentication contributes to priva…

Hey, hey, what's with the "..." and cutting out the relevant parts? I explicitly mention SSL and TLS. Those are encryption standards that are designed exclusively for privacy.

If I am using them to communicate with a 3rd party, I have a reasonable expectation of privacy between myself and that 3rd party. You would most certainly need a warrant to turn around and try to get access to a message stored on their servers.

On top of that, quite a bit of email today doesn't even touch SMTP. If I'm sending an email from one GMail user to another GMail user, I'm pretty sure it is just shuffled around on Google's internal servers. And, of course, I'm connecting to Google using SSL, an encrypted connection.

How does that not scream private?

Re: IRS claims it can read your e-mail without a warrant

#159

Earlier quoted context omitted.

> So WireShark is now illegal in your ideal world? If if it's not your network and/or network traffic, or you don't have the network owners permission, then yes. Why should it be legal? Because you like playing with it?

That's a strange, old school way of thinking. Why are you trying to legislate technology when you could just make the tech work the way you want? "Impossible" trumps "illegal" every time.

>Why are you trying to legislate technology when you could just make the tech work the way you want?

Because I don't want technology to rule us, I want us, humans, to rule technology. We say a lot of times that "technology is a tool". If we have to adopt ourselves and our society to it, instead of adapting it to our preferences, goals and morals, then it's not a tool, it's a ruler.

In this case, cryptography might be a solution. But it's not a perfect solution for me. For one, it's not widespread and it's confusing for most people to integrate to their mailing habits. Second it breaks lots of workflows and conveniences (e.g full text search of emails).

Second, I don't want the government, Google, or anybody else to have it be legal to look into my email if they can break the cryptography or find the key. I want it to be illegal even at that case.

Third, while cryptography might be a case were technology can solve this problem (privacy) there are other issues just piling technology cannot be used to solve them -- where legislation is needed.

Re: IRS claims it can read your e-mail without a warrant

#160
post #95
post #62

Earlier quoted context omitted.

You don't lose your reasonable expectation of privacy by making something publicly available. You lose it by exposing it to a third party (note that e.g. nothing prevents the recipient of your letter from handing it over to the government without a warrant). When you send an e-mail, you make the complete clear text of the e-mail accessible to a third party. The extension of 4th amendment protections to telephone call…

> You lose it by exposing it to a third party It's true that this has always been the position of the Federal government, but that argument has always seemed pretty weak to me, and I don't accept it on principle, no matter how pervasive it's become. People don't expect their email to be read by others, especially the government, period. The reality that they are in fact doing this anyway just means citizens have to p…

> People don't expect their email to be read by others, especially the government, period.

That is inconsistent with the wide usage of GMail, which (robotically) reads your mail to give you directed advertising. So GMail users at least cannot claim that they expect no one else to read their email as they've opted-in to having their mail read by running the service at all.

Post reply on HN