Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I've had GC (general counsel) after GC tell me, both in company wide announcements, as well as during all-hands, to never send anything in email that you wouldn't be comfortable seeing on the front page of the New York Times. Indeed, I've had at least one colleague who sent something a little "off color" to our internal lawyer (where you would think it would be protected) at Netscape, actually land up in the New York Times - so this isn't just a theoretical perspective.

In general, I consider email to be a public forum - It's probably been at least 15 years since I wrote down anything that I wouldn't be completely comfortable being published in public newspapers.

So, Yahoo (and google) are free to scan my email at will - I long ago gave up any thought of it being secure.



There is a gulf of difference between company email and personal email. Company email is provided by the company and others may need to read someone elses' for many reasons.

Personal email has an expectation of privacy. You can argue from the point of view of cynicism and that's fine but it doesn't change my expectation.


I think the point I was trying to get across, is that unlike a personal conversation, either on the phone, or, ideally, in person - I've personally been trained to believe that email has the potential to be in a public forum. I'm not suggesting others are wrong to believe otherwise, I'm just saying that, when I type email to anyone - friend, mother, lover, or colleague - I do so with the expectation that the contents will be published.

If I want to communicate something personal, secret, embarrassing, or private for any reason, I do so in a conversation or phone call.

BTW, maybe my personal life is just boring - but this has very little impact on interpersonal communication, but a drastic impact on business communications, where I frequently find that I'm self-censoring, and asking my self, "Do I really want to commit that to email?"

Now, if my phone calls start getting published in the NYT, then I'm going to be very irate.


FYI With the advent of smart phones, phone call recording is very easy.

Possibly time to update that personal training of yours?

disclaimer: I agree, I believe everything online has potential to be public domain. I do; however, leave the tinfoil at home and realise not many people care what porn I watch or what the latest trite shit I post to my facebook wall is.


There's a difference between US and UK law that's interesting. In the UK, article 8 of the human rights act states that "Everyone has the right to respect for his private and family life, his home and his correspondence." A strict interpretation of this is that a company that monitors emails and intercepts an email between a husband and wife on a work email account violates article 8 [1].

In the US, I believe the government employees have more privacy rights with regard to email and communication than private employees, since private employers are not subject to the same constitutional restrictions - instead they're bound by contract law.

I do agree with you, however. Instead of the front page of the New York Times, however, my personal test is whether I'd be ok with it being projected in a congressional hearing, which actually happened to someone I know. It amounts to the same thing, however.

[1] It's mentioned in an appendix to "Unauthorised Access: Physical Penetration Testing For IT Security Teams," which is an interesting read. There's a particularly good story about an RSA SecurID key fob and a webcam...


never send anything in email that you wouldn't be comfortable seeing on the front page of the New York Times

This was the standard advice -- in exactly those words -- given to students receiving computing accounts at my university at least 20 years ago. I always wondered where it came from; did someone a few decades ago send an email which ended up on the front page of the New York Times?


Email that people thought would be private, has been appearing every year on the front page of the NYT, ever since lawyers realized that it was discoverable, and it was admitted into evidence.

My earliest recollection was 1997, when Eric Bradley, my colleague in Desktop Support, sent a ranting email to one of our top lawyers, pissed off that Microsoft's Browsers were screwing around with Netscape's configuration without asking the user.

http://query.nytimes.com/search/sitesearch/#/lessig+microsof...


Reminds me of this: https://www.jottit.com/v5wux/


How then does one handle matters that are commercially sensitive?


Phone calls, in person meetings. The contracts are usually privileged, so those can be shuffled around in email (the contents are still discoverable, but things like pricing are usually redacted.)

At least two of the very largest deals in one company I worked for were never discussed in email, and all parties met in person, and paper (!) notes were taken. It was only once all the essential details were agreed to (Memorandum of Understanding) and hammered out, that the final details were locked down by attorneys via standard electronic means.

Note, this is particularly important, if you are discussing things that might be coming close to (if not actually crossing) the lines of legality.

See: http://community.seattletimes.nwsource.com/archive/?date=199... for details of one such meeting.


Of course, that is only a workaround, not a fix.


Encrypted email (PGP) has been really easy to set up and use for about a decade now, particularly Enigmail.


PGP would not be a good choice for this. The mail archives are still discoverable, and I imagine the decryption keys would be as well.

Something closer to OTR would be a better choice. Deniability and forward secrecy are the important properties here.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: