Secret Text in Senate Bill Would Give FBI Warrantless Access to Email Records
theintercept.com
theintercept.com
Fast forward 10 years...
"Blah blah national security just this one time in this focused fashion. Plus we've been doing it for 5 years already."
Fast forward 20 years...
"...intelligence bill will give the FBI the right to enter your house and confiscate your possessions, without a warrant, in total secret..."
But the 4th amendment is different than the 1st and the 2nd. It has balancing built into it, by only prohibiting "unreasonable" searches and seizures. It's as if the 1st amendment said "Congress shall make no law ... abridging the freedom of reasonable speech" or if the 2nd amendment said "the right of the people to keep and bear arms reasonably, shall not be infringed."
That'd be great. Each commit would be pushed by the attesting legislator and they could even put the corporate lobbyist that actually wrote the change in the author field!
"The Senate hearing over controversial bill 4ad57b ..."
Ha! That'd be a nice side effect this approach.
Taking the concept one step further, there should be a CI environment to test out new laws.
When you can push your own (or your sponsors') interests in relative secrecy, transparency is anathema.
And no, one does not simply suggest to a business person (or politician) that they should learn "markdown" or LaTeX...because reasons.
How could subject lines possibly be considered metadata? It is quite clearly content.
Bruce Schneier's take on the distinction between "data" and "metadata": https://www.wired.com/2015/03/data-and-goliath-nsa-metadata-...
If so, a simple physical mail server with a battery / cellular network connection for power or network outages seems like a good technical solution.
The more reasonable solution is a legal one, of course: treat treat third party email the same way one treats a third party mailbox (PO box). Safety deposit boxes are a good comparison, as well: http://arstechnica.com/tech-policy/2014/12/microsoft-tells-u...
Running a Sandstorm instance in your home with backup network / power is a separate story, however.
I also ran a sandstorm instance locally for a few months and it was boring in a good way.
Run your own mailserver, in your home or a semi-trusted local colo. Full disk encryption, fully encrypted offsite backups. Cabinet door reed switch triggers immediate power-down in the absence of a cryptographically signed override.
What we've really got is a protocols/software/UI problem. The end-to-end nature of the Internet came out of engineering sense, which was necessary to bootstrap it but not necessary for its continued functioning (hence it's slide back toward centralization eg DPI gear). What we need are better protocols that explicitly protect the end-to-end principle.
One should be able to have an untrusted cloud "mail server" that knows only what it needs to, passing messages to a slightly more trusted home server (your half-hardened hardware is really only protected by it's unique nature, so not scalable). A message only needs to be fully unlocked when it is being read. And the system needs to work this way out of the box with a minimum of configuring, because sysadmin work is an annoyance when you're just trying to get something done.
It is, but it doesn't have to be. Someone could make a <$100 device which has a power backup for running through power outages and a backup network connection via the cellular network, which should provide high enough uptime for all practical purposes. Messages between mail servers are encrypted most of the time, more and more so every year [1]. This is a technical solution for a legal problem, though.
I'm not sure if I understand the system you are proposing, but email protocols seem secure enough now as they are now, it's just the third party principle that doesn't align with the obvious expectations of privacy in mail [2]. To me, it's pretty clear that my email account is like a PO box. Just because my email is held by a third party doesn't make it any less private than being delivered to my home, just as mail arriving at a "third-party" PO box isn't all that different from my mailbox.
1. https://www.google.com/transparencyreport/saferemail/ 2. http://techcrunch.com/2014/04/30/google-will-also-stop-scann...
Protocols "seem" secure enough, because you don't seem to be focused on the technicals (which is fine, as per what I just said. Just don't nay-say). For example, even if messages are encrypted between servers, the graph of who is talking to who is still revealed to a passive adversary, and this problem only gets worse with individually-run servers.