Yahoo Starts Scanning Emails
jottit.com
jottit.com
In general, I consider email to be a public forum - It's probably been at least 15 years since I wrote down anything that I wouldn't be completely comfortable being published in public newspapers.
So, Yahoo (and google) are free to scan my email at will - I long ago gave up any thought of it being secure.
This was the standard advice -- in exactly those words -- given to students receiving computing accounts at my university at least 20 years ago. I always wondered where it came from; did someone a few decades ago send an email which ended up on the front page of the New York Times?
My earliest recollection was 1997, when Eric Bradley, my colleague in Desktop Support, sent a ranting email to one of our top lawyers, pissed off that Microsoft's Browsers were screwing around with Netscape's configuration without asking the user.
http://query.nytimes.com/search/sitesearch/#/lessig+microsof...
Personal email has an expectation of privacy. You can argue from the point of view of cynicism and that's fine but it doesn't change my expectation.
If I want to communicate something personal, secret, embarrassing, or private for any reason, I do so in a conversation or phone call.
BTW, maybe my personal life is just boring - but this has very little impact on interpersonal communication, but a drastic impact on business communications, where I frequently find that I'm self-censoring, and asking my self, "Do I really want to commit that to email?"
Now, if my phone calls start getting published in the NYT, then I'm going to be very irate.
Possibly time to update that personal training of yours?
disclaimer: I agree, I believe everything online has potential to be public domain. I do; however, leave the tinfoil at home and realise not many people care what porn I watch or what the latest trite shit I post to my facebook wall is.
Something closer to OTR would be a better choice. Deniability and forward secrecy are the important properties here.
At least two of the very largest deals in one company I worked for were never discussed in email, and all parties met in person, and paper (!) notes were taken. It was only once all the essential details were agreed to (Memorandum of Understanding) and hammered out, that the final details were locked down by attorneys via standard electronic means.
Note, this is particularly important, if you are discussing things that might be coming close to (if not actually crossing) the lines of legality.
See: http://community.seattletimes.nwsource.com/archive/?date=199... for details of one such meeting.
In the US, I believe the government employees have more privacy rights with regard to email and communication than private employees, since private employers are not subject to the same constitutional restrictions - instead they're bound by contract law.
I do agree with you, however. Instead of the front page of the New York Times, however, my personal test is whether I'd be ok with it being projected in a congressional hearing, which actually happened to someone I know. It amounts to the same thing, however.
[1] It's mentioned in an appendix to "Unauthorised Access: Physical Penetration Testing For IT Security Teams," which is an interesting read. There's a particularly good story about an RSA SecurID key fob and a webcam...
GMail, on the other hands, is where the problem lies. Too bad not that many people care
I have not spend enough time them to see if they provide all the granulated and edge case features I have come to enjoy on gmail, but they have definitely come a long way and I would say in some cases even better than gmail.
Gmail is starting to look old and has been really slow for me.
5 secs for gmail. (used for junk, lots of mail) 2 secs for yahoo mail. (main email) 1 sec, almost instant for outlook. (empty)
So, I think we can forget the outlook speed. But I was surprised at the difference between gmail and yahoo. The cynical brain cells are also shocked that gmail isn't some how accelerated in chrome.
As long as you do not see your email as exactly the same as your ordinary mail: i.e. "your letters" you will not understand what it means that they are "kept" by someone different from you.
Yes, this is a problem (no one has a private mail server out there except a couple of people). But that is reality.
"Oh, my letters, aunt Anna keeps them after I read them and the ones I send, she keeps a copy".
But Brutus is an honest man, as Mark Anthony says.
The only new thing seems to be that the same automated procedures that protect the user against spam, viruses and phishing will now also provide targeted advertising.
I find your rhetoric of relaxed indifference "I don't care much about X reading my mail" very similar to the "I've got nothing to hide" rhetoric. It pisses me off because a couple years back when everyone was grilling me about not wanting a facebook account and me mentioning all the privacy implications, their response was: "oh, I have nothing to hide!" but at the same time they didn't feel like sharing with me their computer password.
Finally, in 2008 when I was looking to buy an apartment I had to pay the inflated price just like everyone else. It didn't matter that I paid cash. Why was the price inflated? Well, because people didn't bother to care much for the price of the apartment as long as they could get the loan from the bank. I had a friend that wanted to buy a house and all he could think about was what to do to be able to take the highest loan he could get. Never mind how he was going to pay for it later. Fast forward a couple years and now all those who bought apartments with the bank's money are looking for my sympathy because it's so hard for them to pay their mortgage and the bank might take their home.
I wish there was a country for people who cared. I'd move there.
Default encryption is not that hard. In the earlier days, key management was seen as the major hindrance to ubiquitous encryption but in 2013 that is not as big issue anymore. There are workable solutions, be that through extending what's in DNS, exchanging QR codes between smartphones, BTNS or even the mess of using the centralized systems of CA's.
Mail servers can have certificates. Domain names can have DNSSEC. DNS can even have keys for mail addresses (RFC 4398). So how hard would it really be to for mail relays to automatically retrieve a key and encrypt the email before sending it forward to its destination?
Was email ever 'secure' in the way you're describing? As far as I'm aware, email gets sent in the clear. The analogy to the postal system would be sending postcards (as opposed to sealed letters).
Edit: fwiw I'm thinking about mail servers, online identity and DNSSEC with a view to pulling together a product in this space.
The Stored Communications Act [1] makes a distinction between unread mail stored on a server for more than 180 days, and does not require a warrant to access such email. It appears that read email still does require a warrant, however, as it is considered a "Remote Computing Service." I didn't know that until just now, and am not sure how the legal requirements for accessing that differ from a hard drive sitting on my desk at home.
A secure email product would be interesting. I'd be interested to know where deniability (i.e. OTR) would fit into your plans.
[1]http://www.itnews.com.au/News/342446,kim-dotcoms-mega-workin...
Some companies have been good enough to provide email that appears to be private and reliable, and some people have made the mistake of thinking that email is now private and reliable.
Changing terms at a provider aren't much fun, but people should have been assuming that their email was being scanned anyway.
This new email targeting change is making me believe more and more that the purchase of tumblr was in fact related to yahoo's shift towards improving revenues from advertising.
I have used yahoo mail for something like 15 years. Mail comes in, mail goes out. It is stored, and very easily manageable. On top of that, I have never ever been let down by it.
So, what are talking about? How is it broken.
And you switched to gmail? I have one of those too. Cant stand it. Yeah, it works perfectly well, but I personally cant get on with its design and interface at all.
Any reason for that or is it just an attractive application/service to you? I mean, if it's something we should have a better look at, let us know.
All I see here is them belatedly catching up with all the other privacy abuses by larger internet companies. Given that is how they make money to run and exist, and it is perfectly legal, sadly, yahoo would be stupid not to. I'm too tight to pay for a service and appreciate that it is free, so right there I give up my right to complain about how they finance their service.
Good to know, sure, but I don't see any thing to get especially concerned about over an above everything else large internet companies get up to. Its not like Im going to get better privacy easily else where.
I'll pay. I'd upgrade to Yahoo pro if it'd get rid of the scanning.
And incidentally, I still don't understand the gmail preference. Yahoo's interface works flawlessly, is fast, and much better than gmail for the basics.