Live data from Hacker News

IRS claims it can read your e-mail without a warrant

news.cnet.com

161–170 of 186 posts

Re: IRS claims it can read your e-mail without a warrant

#161
post #138

Earlier quoted context omitted.

Irrelevant. When you are in a restroom, you have an expectation of privacy. Period. Doesn't matter whose restroom you are at or what is going on. Hell, the door could be broken or just bad and you still have an expectation of privacy. Consider, someone could have a camera mounted onto their foot or on a poll to get over the standard stall doors. Would you just claim that folks should be ok with this? Because, "hey, i…

"Hell, the door could be broken or just bad and you still have an expectation of privacy." So let's take that argument to its extreme: you are standing in an open field going to the bathroom. Do you still think you have an reasonable expectation of privacy? The problem with your argument is that it is based on the idea that if people want privacy, they are entitled to it even if they do nothing to protect that privac…

But the problem with your argument is you are assuming they did nothing to protect their privacy. They specifically addressed the email to someone. Or had it specifically addressed to them.

As the other poster said, consider the urinal. Whether intended or not, there are about to be a lot of images of people at the urinal taken by a capture device. Should men just get used to this idea and expect these pictures online?

I roughly get and agree with what you are saying. But, consider, it is trivial to build a microphone that can pick up every word you said within your house. Do you feel that police should be able to use such a device from a van outside without a warrant? Hell, it is trivial to build a camera that can see through most clothes nowdays.

That is, the laws are there precisely to cover things which may be easy otherwise. Hell, it is trivial not to pay your taxes. Illegal. It is trivial not to honor a contract. Illegal. We don't make laws against jumping to the moon. Because... not exactly relevant from a legal perspective.

Re: IRS claims it can read your e-mail without a warrant

#162
post #36
post #3

This statement: "Newly disclosed documents prepared by IRS lawyers says that Americans enjoy 'generally no privacy' in their e-mail, Facebook chats, Twitter direct messages, and similar online communications" is entirely consistent with the existence of Warshack. Warshack covers the Sixth Circuit, which includes the following states: Kentucky, Michigan, Ohio, and Tennessee. The IRS is bound by this precedent in those…

> You send a clear-text message to a publically-accessible service that is empowered to forward the message to other publically-accessible servers if necessary. This is how postal system works.

And yet you enjoy no 4th Amendment protections for parcels you send by a private carrier such as UPS or FedEx. They can snoop in your stuff all the want and it would be at most a civil matter (with rare exceptions).

Your analogy would make better sense if you were talking about using a government-provided email service. But trust me, you don't want to do that, at least if it's anything like my government-provided work email.

Re: IRS claims it can read your e-mail without a warrant

#163

Earlier quoted context omitted.

That's a strange, old school way of thinking. Why are you trying to legislate technology when you could just make the tech work the way you want? "Impossible" trumps "illegal" every time.

> Why are you trying to legislate technology when you could just make the tech work the way you want? Because I don't want technology to rule us, I want us, humans, to rule technology. We say a lot of times that "technology is a tool". If we have to adopt ourselves and our society to it, instead of adapting it to our preferences, goals and morals, then it's not a tool, it's a ruler. In this case, cryptography might b…

"I don't want technology to rule us, I want us, humans, to rule technology"

Personally, I want technology to solve human problems. If technical solutions to problems exist, they should always be preferred over legal solutions. We do not need to increase the size of an already out-of-control legal code, and we do not need more laws that will be selectively enforced (as almost all laws are).

"it breaks lots of workflows and conveniences (e.g full text search of emails)."

That is not an insurmountable problem: get an email client that can do full text searches of your email by automatically decrypting it while the search is performed. If for some reason you need to export your search to some server, cryptographers have developed systems for doing that in a secure way, though their computation cost is a bit high (much more than searching the plaintext).

"I don't want the government, Google, or anybody else to have it be legal to look into my email if they can break the cryptography or find the key. I want it to be illegal even at that case."

I would be cautious about that. It is almost certainly the case that such a law would not be enforced when a government agency or large corporation are breaking it -- see e.g. the warrantless wiretapping program. More likely, such a law would be used when a whistleblower exploits a weakness in a cryptosystem to expose government wrongdoing.

Expanding the legal code is dangerous. We have so many laws that the government has lost track:

http://online.wsj.com/article/SB1000142405270230431980457638...

We have seen over and over how this vast legal code is abused to crack down on protesters and dissidents. Adding more laws to it is just asking for more trouble, and doing so when we have technical solutions is a pointless risk.

"while cryptography might be a case were technology can solve this problem (privacy) there are other issues just piling technology cannot be used to solve them -- where legislation is needed."

Sure -- but we are not talking about those problems, we are talking about a specific problems that is well studied and which has been solved for decades.

Re: IRS claims it can read your e-mail without a warrant

#164
post #161

Earlier quoted context omitted.

"Hell, the door could be broken or just bad and you still have an expectation of privacy." So let's take that argument to its extreme: you are standing in an open field going to the bathroom. Do you still think you have an reasonable expectation of privacy? The problem with your argument is that it is based on the idea that if people want privacy, they are entitled to it even if they do nothing to protect that privac…

But the problem with your argument is you are assuming they did nothing to protect their privacy. They specifically addressed the email to someone. Or had it specifically addressed to them. As the other poster said, consider the urinal. Whether intended or not, there are about to be a lot of images of people at the urinal taken by a capture device. Should men just get used to this idea and expect these pictures onlin…

"As the other poster said, consider the urinal. Whether intended or not, there are about to be a lot of images of people at the urinal taken by a capture device. Should men just get used to this idea and expect these pictures online?"

Yes, or else just walk to the stall and pee in the toilet. I see guys doing that all the time where I work -- some men want to be private about it, and urinals are not and have never been private.

"But, consider, it is trivial to build a microphone that can pick up every word you said within your house. Do you feel that police should be able to use such a device from a van outside without a warrant? Hell, it is trivial to build a camera that can see through most clothes nowdays."

I did say that closing your door should give you a reasonable expectation of privacy. I also said that things that are easy and popular should not be made illegal. If everyone walked around with a parabolic microphone or a millimeter wave scanner, we would have to adjust our laws, habits, and notions of what counts as a reasonable expectation of privacy accordingly. It is currently reasonable to expect that wearing clothes protects you from having your naked body photographed; that would have to change if it were common for people to carry cameras that could see through cotton.

Re: IRS claims it can read your e-mail without a warrant

#165
post #65

Earlier quoted context omitted.

Also don't forget about Carnivore/Echelon and their ilk that presumably have the ability to intercept and store basically all email. Then once your email is duplicated in a government database somewhere, it being primarily housed on a Google or FB server is irrelevant.

It's not irrelevant. The 4th amendment is enforced primarily by the exclusionary rule. The fact that Carnivore, Echelon, etc, can get to your e-mail anyway doesn't mean that the government can introduce it as evidence in court. To the extent that the 4th amendment doesn't extend to the stuff you store on Google's, Facebook's, etc, servers, the government can introduce that as evidence against you.

Carnivore/Echelon will never be introduced as evidence in court. These are tools of war. When they were hunting Bin Laden, they weren't planning on taking him to court in the end and introducing his emails as evidence against him...

Re: IRS claims it can read your e-mail without a warrant

#166
post #65

Earlier quoted context omitted.

It's not irrelevant. The 4th amendment is enforced primarily by the exclusionary rule. The fact that Carnivore, Echelon, etc, can get to your e-mail anyway doesn't mean that the government can introduce it as evidence in court. To the extent that the 4th amendment doesn't extend to the stuff you store on Google's, Facebook's, etc, servers, the government can introduce that as evidence against you.

Carnivore/Echelon will never be introduced as evidence in court. These are tools of war. When they were hunting Bin Laden, they weren't planning on taking him to court in the end and introducing his emails as evidence against him...

That's precisely why ordinary people don't need to worry about what information is collected by Carnivore/Echelon. The results are too valuable to risk disclosure by introducing them into evidence for prosecuting run of the mill crimes. It's highly unlikely that agencies like the IRS even have access to this information for those reasons.

Re: IRS claims it can read your e-mail without a warrant

#167
post #3

This statement: "Newly disclosed documents prepared by IRS lawyers says that Americans enjoy 'generally no privacy' in their e-mail, Facebook chats, Twitter direct messages, and similar online communications" is entirely consistent with the existence of Warshack. Warshack covers the Sixth Circuit, which includes the following states: Kentucky, Michigan, Ohio, and Tennessee. The IRS is bound by this precedent in those…

> If you understand how SMTP works, it's hard to argue that it's a private means of communication. No. No. No. The test is one of reasonableness. Is it reasonable to assume that an individual--who addresses a message directly to another individual by means of that individual's unique identifier--intends that only that individual will view the e-mail? Of course it is. The suggestion that people should understand the v…

To play the devil's advocate, do you expect any privacy with postcards? It is also addressed directly to another person by means of a unique identifier... why is email any different? IMAPS et al. is just for the connection between you and your email provider, everything after that is plaintext (till the recipient's email provider gets it.)

Now, the interesting question is: is IRS entitled to access emails if both the sender and receiver are using the same provider and it doesn't leave their servers? (I'm guessing the situation is similar to delivering a note by hand through a single third party... again, I wouldn't expect any privacy there.)

Re: IRS claims it can read your e-mail without a warrant

#168

Earlier quoted context omitted.

Maybe I'm expressing myself in too cryptic of a fashion. I'm simply asserting that while privacy and authentication sometimes overlap, they are not the same thing. From the parent of my original comment: Almost every SMTP server out there today requires authentication ... That is the very definition of trying to keep things private. Do you disagree with me? Do you believe that SMTP authentication contributes to priva…

>Do you believe that SMTP authentication contributes to privacy and not authenticity? Why can't it be both?

Well, authentication simply doesn't provide any privacy. It just doesn't. However, SSL/TLS do, which are widely used -- but not authentication.

Re: IRS claims it can read your e-mail without a warrant

#169

Earlier quoted context omitted.

> If you understand how SMTP works, it's hard to argue that it's a private means of communication. No. No. No. The test is one of reasonableness. Is it reasonable to assume that an individual--who addresses a message directly to another individual by means of that individual's unique identifier--intends that only that individual will view the e-mail? Of course it is. The suggestion that people should understand the v…

To play the devil's advocate, do you expect any privacy with postcards? It is also addressed directly to another person by means of a unique identifier... why is email any different? IMAPS et al. is just for the connection between you and your email provider, everything after that is plaintext (till the recipient's email provider gets it.) Now, the interesting question is: is IRS entitled to access emails if both the…

I don't believe your analogy holds. Reasonable people understand that other humans will necessarily see the exposed-in plain-sight content of a postcard in the process of delivering postal mail.

However, reasonable people know that no humans are required in the process of delivering e-mail, and further, the average person doesn't necessarily believe that other people will read an email even if they know it is technically possible.

Re: IRS claims it can read your e-mail without a warrant

#170

Earlier quoted context omitted.

So you don't mind if I wiretap all your phones? Email being transmitted by 3rd parties is not different from voice calls being transmitted by 3rd parties. Yes, you are trusting a provider, with the expectation that your provider will send the data where you've asked it to send the data, and nowhere else . This is still true whether you're talking postal service, landline voice calls, SMS, cellular voice calls, Skype,…

Maybe I'm expressing myself in too cryptic of a fashion. I'm simply asserting that while privacy and authentication sometimes overlap, they are not the same thing. From the parent of my original comment: Almost every SMTP server out there today requires authentication ... That is the very definition of trying to keep things private. Do you disagree with me? Do you believe that SMTP authentication contributes to priva…

While you are making your point, you're being overly pedantic, and the point is irrelevant. Email should not be able to be accessed by a third party without warrant period. Whether or not the analogies line up.
Post reply on HN