Alternatively I wonder what Bruce Schneier recommends? Do you have to host your own email server?
Alternatively I wonder what Bruce Schneier recommends? Do you have to host your own email server?
Even if you personally use the most secure email server in the world, it doesn't matter because everyone that you send email to or from is likely using hosted services like gmail, verizon, hotmail, etc.
Edit: Re-reading my response... I don't mean this in a condescending way and I agree that PGP is a good way to handle email privacy. I only meant to point out that the majority of people don't use it.
https://grepular.com/Automatically_Encrypting_all_Incoming_E...
So if my mail server or any of my imap clients are compromised, my mail isn't.
Even for those who don't, having my mail encrypted on all of my clients and on my own server is still a big gain for me security-wise.
Just because I can't secure the senders system, doesn't mean I shouldn't bother securing my own.
Well, you have to use their web form anyway, which is encrypted. The reason they require a web form instead of email is for exactly the reasons PGP exists: they need to know that you are sending the email, and they need to know that someone else isn't reading their reply to you. Webs of trust are hard, a text box on their SSL website is easy.
If that's a major issue, then your only recourse is to host it yourself.
Running a mail server isn't terribly hard, but it does mean that when the server dies you're on the hook for fixing it. If you're not a sysadmin, then the pragmatic choice is probably to accept that Google doesn't care about the details of your email and will only be spying on you in aggregate to determine what adverts to display.
their support was also friendly, helpful, and technically clued up when i discussed some issues (i didn't go with them in the end because i've hosted my own email before, know how to do it, and decided it wasn't worth paying anyone else).
[edit: to be clear, not only do i have more faith in the impartiality and openness of a scandinavian govt than the usa, there's an advantage in simply not using a host in your own country, imho.
also, running your own server isn't hard. with opensuse, for example, it's pretty much just a case of (1) clicking the right options in yast and (2) configuring getmail to pull your email from your isp. although to get something anywhere close to gmail in functionality you also need to understand (and use) procmail and mairix. then you need a client - i use mutt over ssh, but you can also install a webmail soln like squirrelmail if you want.]
Also, rackspace has a hosted email offering - http://www.rackspace.com/apps/email_hosting/
http://googlesystem.blogspot.com/2009/02/gmail-tests-pgp-sig...
It also doesn't secure the email on the client side. If your IMAP client stores the email on disk, then you need to make sure it is encrypting it in a secure fashion first.
Lavabit should offer an extra layer of encryption whereby they allow you to upload a public pgp key which they encrypt all your incoming email with using PGP/MIME.
I think fundamentally you can't circumvent the law with technical measures. You need to change the law to require warrants.
For everyone who thinks they're an email pro, or never come across problems, there's thousands of users calling any support number they can to try to understand why their junk mail folder won't empty.
PGP is great and I used to use it but, as many posters have said, if the other party doesn't use it (or if they use it and you don't know they use it) it doesn't do much good. This is really true of all encryption systems.
Another option is to give a certificate to your contact and send all conversations encrypted.
edit: oops, I did not notice bhousel's post (posting the same in other words)
Granted: that's not the message contents, but it's bad enough. Also, from my experience I can tell you that the authorities do make use of this law even if it's just to track down a student anonymously badmouthing their teacher.
No. Stay away from Switzerland if you want your correspondence to be hidden.
6 months is the EU minimum, but for some reason the Netherlands decided to require triple that. I bet some idiot politician thought it must be "extra secure" ... :-/
If you want privacy, the last place to host your email is on a shared shell box (especially a free one).
He told me to stop whining, then explained to everyone that I received too many emails per day. (I was receiving <100 emails per day, and I was nowhere near my disk quota) He then named the most common sender of the emails I received. He did all of this in a public forum.
Not only would I not trust SDF not to leak the content of your emails to unauthorized parties, I would not trust SDF not to simply read your emails for shits and giggles, or leak their contents in order to teach you a lesson for asking rude, nosy questions like, "Hey, is anyone else having problems with the mail server?"