Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I've never owned a gmail account but have sent to plenty. Gmail is like the 21st century party landline but only a relative few people can listen in.

> Because I talked to Julian Assange, all information held by Google relating to my user account with them can be handed over to US prosecutors—not just the contents of my conversations with Julian.

There it is: If you have online contact with someone that's of interest, there's a chance all of your info will be of interest also.



Have you considered the possibility that we hear about surveillance of GMail accounts only because so many people happen to use GMail? Is there any particular property of Google that makes it more likely to cooperate with government than any other email provider?

Or, if you're in the "host your own email" crowd, what makes you think your ISP won't cooperate with the government just like Google does?


Here is the difference between GMail and a self-hosted email system: when you delete messages over IMAP, they do not get deleted in GMail. "All Mail" keeps all your mail, forever, unless you log in via the web interface and delete it manually. You could always use the web interface, but now encrypting your messages is much harder.

These are the sort of design decisions that can have far-reaching implications. Google was not thinking about protecting its users from government surveillance when it designed GMail.


As others have noted elsewhere, that's not true: you can have it delete emails on delete, but you do have to turn that on yourself.

It's not the default, and defaults matter, but it is an option that appears as soon as you click "enable IMAP" in gmail (go ahead and try it in your gmail settings). You'll have to read the options, yes, but considering the whole UX thing for gmail has been "never have to delete an email again", it's not an unmotivated default.

Also, I hope your email client does secure deletes on local disk by default.


Frankly, I missed the option, and usually I am pretty good with noticing if the defaults are what I want. The only reason I even noticed that "delete" was not actually deleting mail was that I had to search through All Mail one day, and I noticed some messages that I was sure I deleted. What makes this worse is the completely counterintuitive nature of deleting messages from All Mail: they just come back. I suppose it should have occurred to me that this is a setting I can change, but considering the other oddities I have seen in GMail's IMAP support I just jumped to the assumption that it is another weird "feature."

Really though, the point still stands: Google was not considering protecting its users from government surveillance to be a priority here. They probably had other reasons, maybe even well-justified reasons, for the defaults they chose, but those reasons only make sense in the context of their engineering requirements.

"Also, I hope your email client does secure deletes on local disk by default."

I do something better: whole disk encryption. Actually, since I use an SSD now, "securely deleting" anything is non-trivial; it is better to just negate the need for it by never storing plaintexts anywhere.


However, the option is there, and you're a person who notices if the defaults are what you want but didn't read one of only three options presented to you when enabling IMAP, basically the only settings that were even important if you're not using web mail. It's possible that the options screen was different when you originally turned on IMAP, though.

However, because of the historical lack of an "archive" IMAP function, it's still not clear that the default isn't the correct one for the average user, just like PGP on by default with private keys managed by the user wouldn't be the correct default because most users would be locked out of their own email within the week.


The lack of an "archive" function is pretty easy to fix: create an "Archive" folder. That is basically what "All Mail" is, at least for me.

The problem with this default is that it makes no sense. Most email clients already have an option to "delete" mail by moving it to the Trash folder (which Google has), and most users expect that deleting something from Trash means deleting it for good. I am just not seeing the use-case for someone wanting to "delete" a message from Trash or All Mail just to have the message reappear in All Mail (why on Earth would anyone want a message deleted from All Mail to come right back to All Mail?!).


> Or, if you're in the "host your own email" crowd, what makes you think your ISP won't cooperate with the government just like Google does?

They don't have the information Google does because it's on an e-mail server under your bed. And you enjoy certain legal protections as a citizen in your home country.

It's not a particularly enticing solution but it does have its upsides.


If your email server were under your bed, the FBI would just serve the warrant on you in person, seize your computer and all other computers in the same building, any spare disk drives, routers, appliances, and whatnot laying around, and probably half of the rest of your belongings besides.

For those of you outside the USA, the NSA/DIA will just hack into your server and take your email.


The NSA isn't the almighty spirit of the internet. They can't just clap their hands and magically get access to any server on earth. And even if they can, it certainly doesn't make the evidence obtained that way acceptable in court.

I don't like this argument that since the NSA is almighty, avoiding Gmail for security reasons is stupid. For the US government, accessing emails stored under my bed may not be impossible, but it's orders of magnitude more difficult than if they were on Gmail servers.


Yes and no. In some circumstances I agree with you, in other circumstances I think you have it backward.

I shall enumerate some cases (note that US citizens always count as "inside the US" in this case breakdown):

* inside the US, old-school warrant exists * inside the US, secret warrant exists * inside the US, no legal authority * outside the US, no legal authority * outside the US, weird US-logic legal authority

1) If you're inside the US, and the cops have a non-gag-order warrant, you're no safer with your own server. With your server, they serve you, you know about it; with gmail, they serve Google, and Google tells you about it. No difference.

2) If you're inside the US, and they use a secret warrant, in this case your own server might be better. They can probably still do something tricky to you, without you knowing, but using GMail makes it slightly easier for them to get your information without your knowledge.

3) If you're inside the US, and they have no legal authority, then you're fine in both cases. Unless they break into your server illegally. In this case, their job will be orders of magnitude easier if you run your own server.

4) If you're outside the US, and they have no legal authority at all, same as the previous point: if they try to break in, their job will be orders of magnitude easier if you run your own server.

5) If you're outside the US, they might get FISA clearance to get your stuff. In this case, I think you're better off with your own server. This is comparing Google's legal pushback vs breaking into your server. It's totally possible that breaking into your server is orders of magnitude harder than convincing Google that they have legal authority.

In an ideal world, this last case would only apply to political enemies of the US. You'd be able to figure out for yourself if it applied to you, and act accordingly. What kind of idiot uses a US company to plan terrorist attacks on US interests, amirite? Or to leak things to wikileaks (categorize that however you like). But what is much much less clear is whether the US does in fact use this type of surveillance to unethically benefit US corporations, for example. We've heard unsubstantiated accusations to that effect; nothing in my life experience helps me to know if I do or do not live in that kind of world.


At least then you know.

Also it requires a much harder to get warrant as well as cost approvals.


It is worth noting that they often choose to do this the "loud" way, but the FBI has been granted warrants to pick people's locks and copy their hard drives without leaving traces. Alarm monitoring companies are also subject to the jurisdiction of the United States, so that won't help you either.


It is also worth noting that the problem here is how easily the FBI can access your mail from GMail. Sneaking into a house requires sending agents into the field, watching a person to make sure they are not going to walk in on you, being very careful not to leave a trace or wind up on a security camera they set up, etc. The FBI only has so many people it can dedicate to these sorts of activities. They are not going to be able to do this to you, and your friends, and their friends; it's too costly and runs too high a risk of tipping off the target.

With GMail, the agents do not even need to leave their desks. Just fax the court order to Google, and a few hours later you have thousands of emails waiting for you to read. Want to read the emails of the targets' acquaintances? Just send another fax! Nobody has to know, just call it a national security matter!


Relying on inefficiency as protection against the government is rarely a good bet. We've already seen a dramatic increase in national security spending; they will obtain the resources they need.

We need a new Wiretap Act to apply to non-voice communications.


Inefficiency is the most important protection we have against tyranny. The entire design of our government reflects this: three branches, two houses of congress, checks and balances, limits on how laws can be enforced, etc. Inefficiency is the only thing that ever stood between the USA and tyranny.

The real problem is that we have allowed the government to become far too efficient over the past few decades.


Someone could rig up their own system to notify themselves which is very doable. I can see the situation where someone gets notified, then emails their server to backup offsite, and wipe the hard drives (and for those well versed in demo, there's always that option…).


Why wipe the hard drives? Use WDE, and have the alarm (a) unmount the drive, (b) overwrite the system's RAM with 0s (or at least the portion of RAM where the keys are stored), and (c) power down the system. That is a lot faster that making a backup and wiping the drives; by the time an agent has snuck in and located the computer, the process should be over.

Also, it might help to install a security camera, so you can tell the difference between a rat triggering the alarm and an FBI agent (I'll leave it to the audience to make a few jokes). Alarm is triggered, the camera starts sending pictures of the intruders to your smartphone or to Usenet (encrypted, using a key you keep on a smartcard) or whatever.


Evidence tampering is a federal felony. In this case it doesn't matter how well you covered your tracks - if they can prove you rigged a failsafe, you're going to jail anyway.


I think it might be hard to prove the evidence tampering charge. It is not at all unreasonable to claim that you were trying to protect important secrets from criminals who might break into your home or office.

To put it another way, this is not an illegal device:

http://www.ironkey.com/en-US/secure-portable-storage/250-per...


If you had video confirmation that it was the police who tripped your alarm before firing a degausser, that would be pretty cut and dried. If it were automatic, maybe not.


>if they can prove you rigged a failsafe, you're going to jail anyway

Because if someone is willing to go to those lengths on their own system, there's no possibility for the odds to be stacked in their favor…


It depends on what you mean by "host your own email." Sure, a server at, say, RackSpace, might be vulnerable to government intrusion without your knowledge, but if you have a physical server at your home, then the best that the government can do (without your knowledge) is to tap your upstream connection, which does little for past emails.


>the best that the government can do (without your knowledge) is to tap your upstream connection, which does little for past emails.

Really only applies to emails before Room 641A. It might be easier to go after email at the provider level, but NSA is capable of capturing all internet traffic if it wants to.


You assume they can't just rootkit and browse your server at will?

On one hand, government agencies are notoriously ineffective with technology. On the other hand, I'd rather assume competence and be incorrect than the opposite.


> If you have online contact with someone that's of interest, there's a chance all of your info will be of interest also.

Yes, I believe two degrees of separation is the rule of thumb here. McCarty is one degree, so to complete the graph, they need all his data.

William Binney mentioned this two-degree rule in his recent interview w/ USA Today (warning, autoplay):

http://www.usatoday.com/story/news/politics/2013/06/16/snowd...

Note that two degrees was Binney's conservative proposal at the time to help preserve the privacy of the general population. The higher-ups weren't interested. But I assume there has been some research into how many degrees of separation are required to reach some threshold of confidence, and 2 degrees is pretty good.


"There it is: If you have online contact with someone that's of interest, there's a chance all of your info will be of interest also."

Aside from the obvious chilling effect this has, how do you know if the people you speak to will become "persons of interest" later? Anyone you speak to now could be a high-profile activist in a year. That means that anyone could be the subject of this sort of surveillance.


He was working in the same organization as Assange, let's not act like he was some random fan who sent a one-off email.


What's a "person of interest"? Can they obtain a (normal) warrant for that? What's the charge brought against Assange from the US government?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: