Google handed over years of e-mails belonging to WikiLeaks chatroom admin
arstechnica.com
arstechnica.com
> Because I talked to Julian Assange, all information held by Google relating to my user account with them can be handed over to US prosecutors—not just the contents of my conversations with Julian.
There it is: If you have online contact with someone that's of interest, there's a chance all of your info will be of interest also.
Or, if you're in the "host your own email" crowd, what makes you think your ISP won't cooperate with the government just like Google does?
On one hand, government agencies are notoriously ineffective with technology. On the other hand, I'd rather assume competence and be incorrect than the opposite.
Really only applies to emails before Room 641A. It might be easier to go after email at the provider level, but NSA is capable of capturing all internet traffic if it wants to.
They don't have the information Google does because it's on an e-mail server under your bed. And you enjoy certain legal protections as a citizen in your home country.
It's not a particularly enticing solution but it does have its upsides.
For those of you outside the USA, the NSA/DIA will just hack into your server and take your email.
Also, it might help to install a security camera, so you can tell the difference between a rat triggering the alarm and an FBI agent (I'll leave it to the audience to make a few jokes). Alarm is triggered, the camera starts sending pictures of the intruders to your smartphone or to Usenet (encrypted, using a key you keep on a smartcard) or whatever.
Because if someone is willing to go to those lengths on their own system, there's no possibility for the odds to be stacked in their favor…
To put it another way, this is not an illegal device:
http://www.ironkey.com/en-US/secure-portable-storage/250-per...
With GMail, the agents do not even need to leave their desks. Just fax the court order to Google, and a few hours later you have thousands of emails waiting for you to read. Want to read the emails of the targets' acquaintances? Just send another fax! Nobody has to know, just call it a national security matter!
We need a new Wiretap Act to apply to non-voice communications.
The real problem is that we have allowed the government to become far too efficient over the past few decades.
I don't like this argument that since the NSA is almighty, avoiding Gmail for security reasons is stupid. For the US government, accessing emails stored under my bed may not be impossible, but it's orders of magnitude more difficult than if they were on Gmail servers.
I shall enumerate some cases (note that US citizens always count as "inside the US" in this case breakdown):
* inside the US, old-school warrant exists * inside the US, secret warrant exists * inside the US, no legal authority * outside the US, no legal authority * outside the US, weird US-logic legal authority
1) If you're inside the US, and the cops have a non-gag-order warrant, you're no safer with your own server. With your server, they serve you, you know about it; with gmail, they serve Google, and Google tells you about it. No difference.
2) If you're inside the US, and they use a secret warrant, in this case your own server might be better. They can probably still do something tricky to you, without you knowing, but using GMail makes it slightly easier for them to get your information without your knowledge.
3) If you're inside the US, and they have no legal authority, then you're fine in both cases. Unless they break into your server illegally. In this case, their job will be orders of magnitude easier if you run your own server.
4) If you're outside the US, and they have no legal authority at all, same as the previous point: if they try to break in, their job will be orders of magnitude easier if you run your own server.
5) If you're outside the US, they might get FISA clearance to get your stuff. In this case, I think you're better off with your own server. This is comparing Google's legal pushback vs breaking into your server. It's totally possible that breaking into your server is orders of magnitude harder than convincing Google that they have legal authority.
In an ideal world, this last case would only apply to political enemies of the US. You'd be able to figure out for yourself if it applied to you, and act accordingly. What kind of idiot uses a US company to plan terrorist attacks on US interests, amirite? Or to leak things to wikileaks (categorize that however you like). But what is much much less clear is whether the US does in fact use this type of surveillance to unethically benefit US corporations, for example. We've heard unsubstantiated accusations to that effect; nothing in my life experience helps me to know if I do or do not live in that kind of world.
Also it requires a much harder to get warrant as well as cost approvals.
These are the sort of design decisions that can have far-reaching implications. Google was not thinking about protecting its users from government surveillance when it designed GMail.
It's not the default, and defaults matter, but it is an option that appears as soon as you click "enable IMAP" in gmail (go ahead and try it in your gmail settings). You'll have to read the options, yes, but considering the whole UX thing for gmail has been "never have to delete an email again", it's not an unmotivated default.
Also, I hope your email client does secure deletes on local disk by default.
Really though, the point still stands: Google was not considering protecting its users from government surveillance to be a priority here. They probably had other reasons, maybe even well-justified reasons, for the defaults they chose, but those reasons only make sense in the context of their engineering requirements.
"Also, I hope your email client does secure deletes on local disk by default."
I do something better: whole disk encryption. Actually, since I use an SSD now, "securely deleting" anything is non-trivial; it is better to just negate the need for it by never storing plaintexts anywhere.
However, because of the historical lack of an "archive" IMAP function, it's still not clear that the default isn't the correct one for the average user, just like PGP on by default with private keys managed by the user wouldn't be the correct default because most users would be locked out of their own email within the week.
The problem with this default is that it makes no sense. Most email clients already have an option to "delete" mail by moving it to the Trash folder (which Google has), and most users expect that deleting something from Trash means deleting it for good. I am just not seeing the use-case for someone wanting to "delete" a message from Trash or All Mail just to have the message reappear in All Mail (why on Earth would anyone want a message deleted from All Mail to come right back to All Mail?!).
Yes, I believe two degrees of separation is the rule of thumb here. McCarty is one degree, so to complete the graph, they need all his data.
William Binney mentioned this two-degree rule in his recent interview w/ USA Today (warning, autoplay):
http://www.usatoday.com/story/news/politics/2013/06/16/snowd...
Note that two degrees was Binney's conservative proposal at the time to help preserve the privacy of the general population. The higher-ups weren't interested. But I assume there has been some research into how many degrees of separation are required to reach some threshold of confidence, and 2 degrees is pretty good.
Aside from the obvious chilling effect this has, how do you know if the people you speak to will become "persons of interest" later? Anyone you speak to now could be a high-profile activist in a year. That means that anyone could be the subject of this sort of surveillance.
(Specifically in regards to this case. And assuming they pushed back on orders like this, like they claim to do.)
The 4th amendment includes this part:
"particularly describing the place to be searched, and the persons or things to be seized"
Describing what you want as " all e-mails " is exactly the type of description this part of the amendment is meant to prevent. It's way too broad.
Imperfect warrants are a problem for the state at trial. Outside of trial, any old warrant will do.
In this case, the problem is not investigators overreaching the law. The problem is the amount of information consolidation modern technology enables and encourages.
Except that people do not typically do that, and it is reasonable to expect that a filing cabinet will contain only important or current documents. With GMail, you typically see personal messages that date back years, probably long before whatever crime the person is suspected of.
"The problem is the amount of information consolidation modern technology enables and encourages."
I think for once, we might agree. The relevant laws were written with a very different model of communication in mind.
If H&R Block had Whitey Bulger's tax returns, would the warrant be required to describe those documents, or, would all of the small, baggable disk drives at their data center be subject to seizure?
It feels like some people won't be satisfied unless Google says "well, our existence has many benefits, but it also makes it slightly easier for the government to spy on people, so we're closing up shop".
Google has a business model whose entire premise is to push the envelope on privacy and to collect as much as possible and hold it forever--to make a few extra pennies per user. Get off your high horse. Google (and FB) is /are a menace to us all, even if only because they gather so much private data about us.
That's reasonable. A blanket warrant impacting all emails since the beginning of time is not reasonable.
If the cant name a crime and give a date or dates then they shouldn't be asking for a warrant.
No way would that be considered an over-broad warrant. If, e.g., you suspected someone of financial fraud, it would be totally okay to get a warrant for the contents of all the filing cabinets in his office.
If they are surprised by this then they obviously shouldn't have been using google in the first place.
This is all probably inadvertent, but it indicates that protecting users from this sort of surveillance is not a priority.
When a message is marked as deleted and expunged from the last visible IMAP folder:
* Archive the message (default)
* Move the message to the Trash
* Immediately delete the message forever
Ok then.
[citation needed]
Seriously, I have trouble believing that anyone would complain about "delete" carrying any meaning other than "delete." I also find it hard to take such people seriously, given the existence of a Trash folder as a first stop for deleted messages, and All Mail as a second stop (and what is the default for deleting from All Mail? Having the message come right back to All Mail! Brilliant...).
Thanks for the tip on how to fix this behavior. It is an easy option to miss...
I was just trying this, I moved something to trash and then did a 'Delete Forever'. Nothing appeared in trash or all mail again.
No, I don't have a citation, but is it so hard to believe that lots of people want an undelete? I accidentally delete emails all the time and I go into the trash and fish them out. Not giving users an undo seems ... unfriendly.
EDIT: I see, it applies to Custom Folders and delete only removes the label; doesn't move it to the trash. Here's what Google has to say about it. Is this a default IMAP behavior or Gmail-IMAP specific? https://support.google.com/mail/answer/78755?hl=en
As for "undelete," I believe the purpose of the Trash folder is to support that. I have yet to find the email client that does not, as a default, store deleted messages in the Trash folder. I am not disputing that people want that functionality, what I am saying is that I do not think people want the behavior that I am seeing.
The fact that GMail treats "delete" as "remove labels" is very problematic. IMAP supports labels, including client-defined labels. Treating folders as "labels" only breaks the abstraction IMAP presents. I suppose this was part of Mark Crispin's gripes with GMail.
Also Gmail is the only webmail that offers server-to-server encryption: http://news.cnet.com/8301-13578_3-57590389-38/how-web-mail-p...
And as mentioned in another comment you can delete messages over IMAP.
So in the future make sure you do some research as to avoid spreading false information.
Nobody is talking about sidestepping laws. You are not breaking laws, nor breaking the spirit of the law, if your users cannot store many years of their personal communications on your server. Encouraging people to delete mail would have the effect of limiting the government's surveillance power, in an entirely legal fashion.
"aren't the laws at fault here?"
It is not that simple. The relevant laws were written at a time when mail quotas were commonly measured in megabytes, when people had to delete their mail in order to stay under the limit. Back then, if a few personal messages happened to be on the server when a court order was received, it was not such a big deal; those messages probably pertained to very recent things anyway. Now, when a court order for "all of Joe's email" is received, that will very likely include messages dating back years, long before whatever crime Joe is suspected of was even committed. The laws have not been updated in light of these new privacy implications.
"If there is an action item on the list, it should be to change unjust laws not to circumvent them. The latter is both defeatist and useless."
Why not do both? Why should we suffer while we wait for the deliberately slow wheels of government to turn? Neither action excludes the other, you can both circumvent unjust laws and work to take those laws off the books.
> "you can both circumvent unjust laws..."
and
> "aren't the laws at fault here?"
> list of reasons why the laws are at fault...
you have a point in there (work to fix laws while protecting yourself), but you're being weirdly (and ineffectually) contrarian in this thread.
As for the point of the laws being faulty, what I was saying was that the laws were designed with a particular communications model in mind. Google's system is designed very differently from that model, but despite Google's popularity and despite other services adopting a model similar to Google's the law has not changed. Just saying that the law is at fault is too simplistic; the laws may have good reasons behind them and may have made sense at the time they were passed (and had technology not changed, the laws might still make sense now).
I wasn't suggesting that either. Sidestepping is avoidance not evasion.
> The laws have not been updated in light of these new privacy implications. ... the deliberately slow wheels of government to turn?
So change the law. And speed up your justice system. Don't elect individuals who slow down progress deliberately.
> you can both circumvent unjust laws and work to take those laws off the books.
And fight the laws and its usage, which is what Google does. It was also the entity that disclosed the original order in this particular case, so that the person in question can also take some action if possible. It also publishes transparency reports and it was the first one to do that, which gives you an idea about how frequent usage of the unjust laws are so that you, as a community, has more information about what your government is doing. If I am not wrong, there have been 2 elections since the FISA was passed and the voting population of US was aware of the broad surveillance since the first election (Obama based some of his campaign on it). If he hadn't acted on it, then it should have become a point of debate in the reelection. But it was celebrated on Hacker News as much as anywhere else, without a single mention of his inability of reducing the scope of such laws. So guess what? Overboard surveillance didn't seem to be a priority for most of the people here and Google has been more transparent and more vigilant about it since longer than the PRISM episode. The gist is that it is easy to transfer blame in this case, but the root cause it solely the astoundingly broad laws and the undoubted trust that voters put in the current government that used them instead of removing them as it had promised.
Now, before you say "What, do you expect them to break the law?", consider that they routinely push the boundaries of US law (securities law, copyright law, tax law, etc.) and lo and behold they are usually successful.
Now, I expect you might say "What you're suggesting is still nonsensical because resisting orders related to national security is, among other things, far too controversial and not in the interests of shareholders." And I would not disgaree with you.
My point is simply that Google, with its vast resources, is in a much better position than Ed Snowden to take on this fight for the future of the Internet and privacy of communications.
You could even argue Google has more skin in the game than Mr. Snowden, or any of us individually (aside from those who exploit others' private information for profit, of course)... because if this controversy brings about knee-jerk changes in privacy law, it could materially affect their bottom line.
"We notify users about legal demands when appropriate, unless prohibited by law or court order."
The government asks for people's data all the time, and Google is legally obligated to provide the requested data. They then go the extra step and tell the users as soon as they are allowed to.
There's nothing here to "get in front of."
Anyway sounds like it's generally a good guy move, just wanted to check what others thought.
This is far beyond me.
" 'Thankfully, neither of us use our Google accounts for anything remotely sensitive,' McCarthy wrote on his blog on Friday."
This is exactly the kind of thing, along with recent events, that will eventually deal a major blow to US based tech.