Live data from Hacker News

IRS claims it can read your e-mail without a warrant

news.cnet.com

181–186 of 186 posts

Re: IRS claims it can read your e-mail without a warrant

#181
post #175

Earlier quoted context omitted.

"Your email is normally not exposed to third parties." Except for the mail servers...

Yes, in the way your snail mail is exposed to postal trucks, mail handling agents and office clerks.

Not when the snail mail is in an envelope. When you send plaintext email, you are exposing the entire body of the message to casual inspection by any of the mail servers that are involved in delivering it. Unlike the postal system, however, your email is copied and stored by the servers involved in sending it, and you have little control over how long it is stored.

It would be as though you communicated by sending post cards, and the postal works took every post card and ran it through a copy machine, leaving them all in a neatly organized (by sender and receiver) pile somewhere.

Re: IRS claims it can read your e-mail without a warrant

#182
post #156

Earlier quoted context omitted.

You should never expect privacy over an unencrypted connection. However where I do disagree with rayiner is that you should be able to expect that third parties which you willingly entrust your communication to, should not be compelled to turn over that message without a warrant. If they turn it over willingly that's caveat emptor, but email to me feels more like a hand-to-hand transfer of a postcard than dropping a…

>You should never expect privacy over an unencrypted connection. What does "should" have to do with it? A landline telephone isn't encrypted, people still expect their conversations to be private. And I don't see why email should be different -- if it came out that human Google employees have been reading your emails it would be a huge scandal. > If they turn it over willingly that's caveat emptor I don't know about…

Phone connections used to be an actual end-to-end circuit that you had to have very specialized knowledge to be able to tap into, which is where that expectation comes from. Email is very much like handing a postcard to your secretary to pass to the mail room to walk up and leave in a bin labeled with the destination address. There are multiple stops en route, and the data just sits there instead of existing transiently. So yes, people shouldn't expect that it magically stays private.

But I'll take it further, to the extent that a secure channel isn't possible by phone today, people shouldn't expect privacy there any more either.

Being able to keep the government from using your information is different from privacy, and that's my big point. These conversations always go the route that Big Brother knowing about something is the worst thing that can happen to you, but really it's not. How many people get fired from their jobs without one bit of government intervention based solely on their employer becoming aware of a message they sent? That's what I'm talking about, you should not expect privacy from unencrypted email. Even if your provider is awesome, the recipient and the recipient's provider might not be, and that's beyond your control in most cases.

> > If they turn it over willingly that's caveat emptor

> I don't know about that. Do you think it would also be reasonable without a court order for them to provide your private emails to a party other than the government, like a reporter or your company's customers or suppliers?

Do I think it would be reasonable? Not at all. But it's certainly not illegal, which is why I say caveat emptor. Pick your contractors carefully and vote with your wallet for the one that will guard your data.

Re: IRS claims it can read your e-mail without a warrant

#183
post #65

Earlier quoted context omitted.

Also don't forget about Carnivore/Echelon and their ilk that presumably have the ability to intercept and store basically all email. Then once your email is duplicated in a government database somewhere, it being primarily housed on a Google or FB server is irrelevant.

It's not irrelevant. The 4th amendment is enforced primarily by the exclusionary rule. The fact that Carnivore, Echelon, etc, can get to your e-mail anyway doesn't mean that the government can introduce it as evidence in court. To the extent that the 4th amendment doesn't extend to the stuff you store on Google's, Facebook's, etc, servers, the government can introduce that as evidence against you.

Wait, sorry - I don't quite get that, what am I missing here? The logic I'm hearing:

1. Because your emails are "open" (like a postcard) when being transferred over a network, you do not enjoy an "expectation of privacy" for them

2. Therefore if the government "sees it go by" (like a postcard in the mail), they can read it

3. So if the government plants themselves in the middle of a bunch of networks to "see emails go by" and then stores them in a big database, that should be admissible, no?

It seems like the postcard analogy should hold all the way through, right? Ie the government could photograph all mail going through, store it, and look it up later to use in court if they wanted to.

Sure - the IRS may or may not actually look into those databases it in practice due to national security concerns, etc - it's just that they could. [edit: formatting]

Re: IRS claims it can read your e-mail without a warrant

#184
post #65

Earlier quoted context omitted.

It's not irrelevant. The 4th amendment is enforced primarily by the exclusionary rule. The fact that Carnivore, Echelon, etc, can get to your e-mail anyway doesn't mean that the government can introduce it as evidence in court. To the extent that the 4th amendment doesn't extend to the stuff you store on Google's, Facebook's, etc, servers, the government can introduce that as evidence against you.

Carnivore/Echelon will never be introduced as evidence in court. These are tools of war. When they were hunting Bin Laden, they weren't planning on taking him to court in the end and introducing his emails as evidence against him...

As I understood it, Carnivore was a system for the FBI to use against domestic criminals, not as a tool of war: http://email.about.com/od/staysecureandprivate/a/carnivore.h...

Then the only question is whether the FBI and IRS will cooperate in their investigations - the answer there seems pretty clear.

Re: IRS claims it can read your e-mail without a warrant

#185
post #175

Earlier quoted context omitted.

Yes, in the way your snail mail is exposed to postal trucks, mail handling agents and office clerks.

Not when the snail mail is in an envelope. When you send plaintext email, you are exposing the entire body of the message to casual inspection by any of the mail servers that are involved in delivering it. Unlike the postal system, however, your email is copied and stored by the servers involved in sending it, and you have little control over how long it is stored. It would be as though you communicated by sending po…

SMTP does not inspect the body, it's outside of scope of the protocol.

Also, unsealing an envelope on a hot surface is trivial. Nitpicking aside, both mediums are not inherently secure.

Re: IRS claims it can read your e-mail without a warrant

#186
post #174
post #162

Earlier quoted context omitted.

And yet you enjoy no 4th Amendment protections for parcels you send by a private carrier such as UPS or FedEx. They can snoop in your stuff all the want and it would be at most a civil matter (with rare exceptions). Your analogy would make better sense if you were talking about using a government-provided email service. But trust me, you don't want to do that, at least if it's anything like my government-provided wor…

Substituting the postal service with private carrier services, the point still stands. People just not expect their correspondence to be peeked into, no matter how technically easy is that. When you have a conversation in a busy mall, you have no expectation of privacy. When you communicate one on one in confines of private apartment, your speech isn't meant for others to be heard, even if that would be laughably eas…

I agree that people expect discretion from their couriers (electronic or otherwise), but I wasn't talking about technical limitations this time. Privacy is something that encompasses even more than government.

The 4th Amendment is specifically a limitation on government power to compel unreasonable search or seizures. That's why I said having a private courier give up your information (not at the demand of the government) would be at best a civil matter such as breach of contract.

Now does FedEx and UPS routinely give up our parcels to the wrong party? No, but the reason isn't the 4th Amendment. The reason they try to deliver to the right party is because of the incredible market reaction that would occur if they were known to be routinely diverting deliveries or snooping.

But your expectation of privacy in general (as opposed to privacy against government interception) does not have any backing in law AFAIK (sadly), which is what I think rayiner was pointing out. From the perspective of the law, if you're willing to disclose information to some "random" third-party then why wouldn't you be willing to disclose it to anyone else (incl. the government)?

I agree that we should be able to expect privacy even in these cases, as it seems like a fairly large loophole if rayiner is right, especially in a world that is far advanced from the days where long-distance communications of any sort required government services and so privacy really did mostly mean "privacy from government".

Post reply on HN