If you're using Gmail or sending to a gmail address[1], you know what you are in for, and if you don't you should at least know that anything you send to someone else is no longer in your control and you have very little control over who sees it.
1: Google Apps for business accounts are not scanned for ads.
If you want free email, expect to pay in some other way. There's no such thing as a free lunch.
No, I'm serious about this. I wasn't trying to be flippant. If you care enough about the integrity of your email content and it not being used to further a company's profit, the only way to be sure of that, to the extent that you can (which may not be much), is to run your own mail server. If that seems like it's way too much trouble, I think a you should take a close look at your motives for wanting a gmail alternative. Is it about the integrity of your email, or sticking it to Google? If it's avoiding Google because they specifically cause you concern, that's fine, and there likely plenty of choices, but I'm not sure what they are (as I said, I just use Gmail because I don't care).
> By your logic even a private mail server isn't enough, you'd have to use PGP.
Well, by my logic you have to do enough to make yourself comfortable. Depending on your reasons for avoiding some other companies that will be different things.
> If you don't have any recommendations just say so.
I don't have any recommendations for Gmail if you consider a good UI, responsively web based, and free as major components of that. If you are willing to give up one or more of those, there are options. The local ISP I mentioned is Sonic.net. By all accounts (including mine, I've worked there multiple times in the past), a great company, and with great EFF ratings. An email account there is not free though.
Do you have any source for that claim, or is it just pure libel?
Seriously: this is calling out Google in a way that's comical since it's equally applicable to your own computer.
Single point of failure.
Government entities have to go through physical work to seize multiple mail servers distributed geographically. This keeps the cost of fishing expeditions high enough that they won't just do it by default.
With everything at Gmail, Yahoo, and Microsoft, you only need to serve 3 entities, who already are known to roll over.
However, far more concerning to the HN crowd should be this fact: Do you want the companies most likely to buy you out for a large value to be the ones holding all of your internal emails?
At this point, Google probably knows more about the quality of business than the businesses do. It would be an interesting question as to whether Google could be considered a corporate insider for a vast number of companies.
Okay?
> Government entities have to go through physical work to seize multiple mail servers distributed geographically. This keeps the cost of fishing expeditions high enough that they won't just do it by default.
Except they seem pretty seize-happy and the only thing protecting your house is the say-so of a judge.
> With everything at Gmail, Yahoo, and Microsoft, you only need to serve 3 entities, who already are known to roll over.
That seems quite unfair, as at least 2 have been very public about their expenditures to try and make such attacks impossible in the future, and have vocally fought subpoenas.
> Do you want the companies most likely to buy you out for a large value to be the ones holding all of your internal emails?
Yes. The lawsuit should I discover it would probably make me richer and more famous than all the buyout events I've experienced.
You're being obtuse. Even if every judge rolls over, if you have to seize multiple email servers in multiple jurisdictions, the paperwork represents expense and time that law enforcement simply will not do unless they have a really strong reason. "People are lazy" is the universal constant. We fear computerization of things precisely because computers aren't lazy.
> That seems quite unfair, as at least 2 have been very public about their expenditures to try and make such attacks impossible in the future, and have vocally fought subpoenas.
That's what they say publicly. However, if they roll over for governments like China, they're going to roll over for the US who can genuinely affect their revenue stream.
> The lawsuit should I discover it would probably make me richer and more famous than all the buyout events I've experienced.
Your naivete is touching. Google wouldn't do anything actionable. They scan your email store and know not to invest. You'll never prove anything for a passive non-action like this.
Even for positive action failures, it's very difficult to prove. This is the whole point of "parallel construction". You dragnet to find something incriminating, and then build the legal path to what you now know to search for.
Your trivial additional inconvenience running what sounds like a non-trivial geographically dispersed non-cloud-service email system warrants not calling out services with poor mail transit security. So millions of customers improved security vs you figuring out how to use LetsEncrypt. Because Google subsidizes the free service with ads.
I do not follow this logic, but what's more:
> Google wouldn't do anything actionable. They scan your email store and know not to invest. You'll never prove anything for a passive non-action like this."
Yeah well having sold a few companies to a few mega-nationals, we try to be honest and deserve the acquisition, as opposed to trying to fleece people. Lame-duck acquisitions shit on employees for investor gain, often for investment clawback and exit.
But also, if you are a paying edu or org customer, they stop scanning for and serving ads.
So forgive me if I don't feel a ton of empathy towards your strong desire to be dishonest in a hypothetical google acquisition where they hypothetically do this.
It won't count for anything if the emails your server is sending/receiving are not encrypted, which exactly is what Google is advocating. I don't understand GP's smug rejoinder, as if encrypting emails in transit is a bad thing.
You're one judge's pen-stroke away from having personal property seized and then it's just a matter of how real your machine's physical security measures are.
Quite true. If you, personally, are a target of the NSA, you are totally fucked. We know that they will make up evidence if they cannot find some.
However, we put locks on our doors even though most of them can be picked very easily. Why?
Security best practice is "defense in depth". You defend at each level to make it more expensive for an attacker. The goal is to make attacks against your stuff more expensive.
If you make the government have to dispatch someone physically, there is a vast amount more friction. There was an inspector from Scotland Yard who once commented that "If your drives are encrypted such that it takes us more than 40 hours of work, your drives are not going to convict you. We will spend our time on gathering other evidence." Physically seizing a server is annoying paperwork.
So, the goal is to prevent them from being able to dragnet low-level offenses for cheap. If you're a murder suspect and they have good reason to come after you, then they're coming after you irrespective of the cost.
Google is likely to have more legal resources to fend off unjust requests to access to your data.
We all know Google is doing it, though.
What, precisely, do we "know" Google/Microsoft/FUDCo is doing? Certainly not willingly collaborating with every quasi-legal search and seizure presented to them.
But you (or perhaps upthread) are implying that Google willingly hands over data to government authorities.
The evidence would point to the contrary: Google (and Microsoft I might add) are complying with the law, but are not simply rolling over and handing out whatever is asked of them.
Their ability to fight back against unwarranted requests is probably much better than someone running their own mail server in their basement.
I doubt that there is a way to build a webmailer without processing the emails content at some point. And as it is processed anyway; using it to adjust your ads doesn't appear to me as something significant.
It is disingenuous and/or ignorant to suggest that temporarily loading an email into memory for the purpose of displaying it on the users screen is the same as parsing and catagorising the text and storing the results of the analysis in a database for the purpose of manipulating the user.
I may be wrong, but I think they were referring to things like spam detection, malware detection, possibly search indexing, and such rather than just "temporarily loading an into memory for the purpose of displaying it."
At best, you could search headers if they aren't encrypted.
Until a viable ciphertext search scheme arrives. (there are some, but everyone I've seen has some caveat or hole)
I don't think users actually care though. Google's attempt to redefine "end-to-end encryption" to include decrypting something mid route bothered me. This... meh.
Still no comment on Turing?