> The government seeks to sidestep these rules, asserting that emails you store in the cloud cease to belong exclusively to you. In court filings, it argues that your emails become the business records of a cloud provider. So, how long until Dropbox contents are just a matter of business records?
We're Fighting the Feds Over Your Email
51–60 of 94 posts
Re: We're Fighting the Feds Over Your Email
#52Earlier quoted context omitted.
> The "reasonable expectation of privacy" in things like safe deposit boxes or storage units is based on the actual fact that service providers generally do not and cannot access the contents of those rented spaces. And the "reasonable expectation of privacy" in cloud email is based on the fact that, while computers necessarily have access to the data (it is not possible to provide email service otherwise), humans ge…
If you don't think that humans have access to the contents of your cloud hosted email service then I've got a bridge to sell you.
(That is, at least for employees at one of the big ones. ;-)
Re: We're Fighting the Feds Over Your Email
#53Earlier quoted context omitted.
> your emails become the business records of a cloud provider That is simply ridiculous. Email stored by a cloud provider isn't a business record of the provider any more than the contents of a physical letter stored in a rented mail box is a business record of the box provider.
A physical letter in a rented mailbox is also generally not data-mined for the commercial purposes of the service provider. I think cloud companies essentially want the 4th amendment benefits of treating the cloud like real world private areas (e.g. bank lock boxes), without any of the obligations that come along with that. The "reasonable expectation of privacy" in things like safe deposit boxes or storage units is…
These sorts of things are all capabilities I expect in a local mail client; I think it's a reasonable to apply 4th amendment protections to the user's data, even if computation done on behalf of the user (including selecting relevant ads) happens in a remote datacenter using code the user didn't write.
It is pretty ridiculous to treat users' emails the same as a grocery store's payroll when deciding whether customers have constitutional privacy safeguards.
Re: We're Fighting the Feds Over Your Email
#54Earlier quoted context omitted.
> your emails become the business records of a cloud provider That is simply ridiculous. Email stored by a cloud provider isn't a business record of the provider any more than the contents of a physical letter stored in a rented mail box is a business record of the box provider.
A physical letter in a rented mailbox is also generally not data-mined for the commercial purposes of the service provider. I think cloud companies essentially want the 4th amendment benefits of treating the cloud like real world private areas (e.g. bank lock boxes), without any of the obligations that come along with that. The "reasonable expectation of privacy" in things like safe deposit boxes or storage units is…
and...
>That said, I think they're ultimately going to win.
Warning: Total Conspiracy Theory Ahead
Could this be an end-around by Microsoft to eliminate one of Google's main revenue streams? Follow me for a second.
1. Let's assume Microsoft wins this court case. By doing so, e-mails will be afforded the same protection, under the law, as physical letters.
2. A Microsoft backed plaintiff sues Google for data-mining her email's content, arguing under the same 4th Amendment ruling.
3. After years of legal procedures and court battles, Google (and all other e-mail providers) are forced throw away their master keys. Essentially all email is blind to the providers.
4. Google loses one of their larger revenue streams.
Everyone loves a good conspiracy theory, so indulge me for the moment. Why would this not work (And for the record, I'm sure it wouldn't. But I would honestly like to know why.)?
Re: We're Fighting the Feds Over Your Email
#55Earlier quoted context omitted.
They did indeed have a warrant for the info. The problem was how they chose to pursue obtaining the info- that is, installing a MitM black box that could read all customer email going through it, not just the citizen for whom they had the warrant. I'm not sure if they promised or not to only snoop on that one individual, but even if they did you would have no way of knowing if they're telling the truth or not. From w…
What other options were there? There was only one SSL key. Once you can MitM one user in that scenario, you can MitM them all. To my understanding Lavabit didn't have a system in place for separating out one user like that, and the feds would likely have been disinclined to wait for the development of one. So perhaps we should take this as a lesson in designing systems to be as secure as possible even with legitimate…
According to Wikipedia, just one month prior, Lavabit had complied with a search order for one user suspected of child pornography. I'm not exactly sure what the difference was between these two cases, but it does show he had at least some capability to do what they asked.
I do agree that "one SSL key to rule them all" is perhaps not the best practice. That said, the design of the system doesn't matter as much to me. Reality is that the system was designed in the way it was, and when offered two methods of getting their data, the feds decided to take the wrong one. (In my opinion.)
Re: We're Fighting the Feds Over Your Email
#56Earlier quoted context omitted.
End users need to and can take control over their own email privacy. GPG. Ten minutes to download, install, and generate a key pair is all you need to secure your email. Perhaps the willingness to do so will increase when the government successfully argues that non-encrypted mail posted through an email server is the same as posting your thoughts on a public peg board... If you want full compatibility, you can pay a…
Pffft, GPG doesn't work if you want to communicate with other people. It's very difficult to get people to use it, and the UX is horrible for it. On top of that it's even harder to use on mobile platforms. GPG also doesn't have forward secrecy.
Re: We're Fighting the Feds Over Your Email
#57Earlier quoted context omitted.
If you don't think that humans have access to the contents of your cloud hosted email service then I've got a bridge to sell you.
They have access to it yes, they just risk being fired if they nose into data unrelated to their job. (That is, at least for employees at one of the big ones. ;-)
Re: We're Fighting the Feds Over Your Email
#58Earlier quoted context omitted.
What other options were there? There was only one SSL key. Once you can MitM one user in that scenario, you can MitM them all. To my understanding Lavabit didn't have a system in place for separating out one user like that, and the feds would likely have been disinclined to wait for the development of one. So perhaps we should take this as a lesson in designing systems to be as secure as possible even with legitimate…
My understanding was that he offered them his programming services to create a method to do exactly what they wanted- pull the email info out for just one user. True, he was going to charge them for it, but it was only $2000. A laughably small sum for the people he was dealing with. Supposedly, they denied this offer because they couldn't control it. From my perspective, $2k and a couple day wait is a paltry sum to p…
If I were to guess, I would say control is actually a huge issue. If it's their equipment and software that's certified for this use, it probably satisfied chain of custody and certification requirements. If it's someone else's, who knows? It's almost certainly not certified and so it might not stand up in court at all. Certification is a big deal in the government and a court is likely to be skeptical about the use of an unproven and uncertified magic software black box in executing a warrant.
So what it comes down it is that the feds may not have actually had a choice of how they got that data.
Re: We're Fighting the Feds Over Your Email
#59Earlier quoted context omitted.
A physical letter in a rented mailbox is also generally not data-mined for the commercial purposes of the service provider. I think cloud companies essentially want the 4th amendment benefits of treating the cloud like real world private areas (e.g. bank lock boxes), without any of the obligations that come along with that. The "reasonable expectation of privacy" in things like safe deposit boxes or storage units is…
>they want the 4th amendment benefits of treating the cloud like real world private areas (e.g. bank lock boxes), without any of the obligations that come along with that. and... >That said, I think they're ultimately going to win. Warning: Total Conspiracy Theory Ahead Could this be an end-around by Microsoft to eliminate one of Google's main revenue streams? Follow me for a second. 1. Let's assume Microsoft wins th…
I think a more likely scenario is that we end up with a court ruling that says something along the lines of: "In order to preserve the customer's 4th amendment rights, the company hosting the e-mail mustn't be using it for business purposes." So, Google wouldn't be able to simultaneously mine your e-mails and guarantee that your e-mails are protected under the 4th amendment.
Re: We're Fighting the Feds Over Your Email
#60Earlier quoted context omitted.
A physical letter in a rented mailbox is also generally not data-mined for the commercial purposes of the service provider. I think cloud companies essentially want the 4th amendment benefits of treating the cloud like real world private areas (e.g. bank lock boxes), without any of the obligations that come along with that. The "reasonable expectation of privacy" in things like safe deposit boxes or storage units is…
>they want the 4th amendment benefits of treating the cloud like real world private areas (e.g. bank lock boxes), without any of the obligations that come along with that. and... >That said, I think they're ultimately going to win. Warning: Total Conspiracy Theory Ahead Could this be an end-around by Microsoft to eliminate one of Google's main revenue streams? Follow me for a second. 1. Let's assume Microsoft wins th…
(Also, as I understand it, Google works hard to limit access to email, but I don't think they have anything you would want to describe as a master key. It would be "Google deletes all customer data", not "Google blinds itself to customer data".)