Or, if you're in the "host your own email" crowd, what makes you think your ISP won't cooperate with the government just like Google does?
Or, if you're in the "host your own email" crowd, what makes you think your ISP won't cooperate with the government just like Google does?
These are the sort of design decisions that can have far-reaching implications. Google was not thinking about protecting its users from government surveillance when it designed GMail.
It's not the default, and defaults matter, but it is an option that appears as soon as you click "enable IMAP" in gmail (go ahead and try it in your gmail settings). You'll have to read the options, yes, but considering the whole UX thing for gmail has been "never have to delete an email again", it's not an unmotivated default.
Also, I hope your email client does secure deletes on local disk by default.
Really though, the point still stands: Google was not considering protecting its users from government surveillance to be a priority here. They probably had other reasons, maybe even well-justified reasons, for the defaults they chose, but those reasons only make sense in the context of their engineering requirements.
"Also, I hope your email client does secure deletes on local disk by default."
I do something better: whole disk encryption. Actually, since I use an SSD now, "securely deleting" anything is non-trivial; it is better to just negate the need for it by never storing plaintexts anywhere.
However, because of the historical lack of an "archive" IMAP function, it's still not clear that the default isn't the correct one for the average user, just like PGP on by default with private keys managed by the user wouldn't be the correct default because most users would be locked out of their own email within the week.
The problem with this default is that it makes no sense. Most email clients already have an option to "delete" mail by moving it to the Trash folder (which Google has), and most users expect that deleting something from Trash means deleting it for good. I am just not seeing the use-case for someone wanting to "delete" a message from Trash or All Mail just to have the message reappear in All Mail (why on Earth would anyone want a message deleted from All Mail to come right back to All Mail?!).
They don't have the information Google does because it's on an e-mail server under your bed. And you enjoy certain legal protections as a citizen in your home country.
It's not a particularly enticing solution but it does have its upsides.
For those of you outside the USA, the NSA/DIA will just hack into your server and take your email.
Also, it might help to install a security camera, so you can tell the difference between a rat triggering the alarm and an FBI agent (I'll leave it to the audience to make a few jokes). Alarm is triggered, the camera starts sending pictures of the intruders to your smartphone or to Usenet (encrypted, using a key you keep on a smartcard) or whatever.
Because if someone is willing to go to those lengths on their own system, there's no possibility for the odds to be stacked in their favor…
To put it another way, this is not an illegal device:
http://www.ironkey.com/en-US/secure-portable-storage/250-per...
With GMail, the agents do not even need to leave their desks. Just fax the court order to Google, and a few hours later you have thousands of emails waiting for you to read. Want to read the emails of the targets' acquaintances? Just send another fax! Nobody has to know, just call it a national security matter!
We need a new Wiretap Act to apply to non-voice communications.
The real problem is that we have allowed the government to become far too efficient over the past few decades.
I don't like this argument that since the NSA is almighty, avoiding Gmail for security reasons is stupid. For the US government, accessing emails stored under my bed may not be impossible, but it's orders of magnitude more difficult than if they were on Gmail servers.
I shall enumerate some cases (note that US citizens always count as "inside the US" in this case breakdown):
* inside the US, old-school warrant exists * inside the US, secret warrant exists * inside the US, no legal authority * outside the US, no legal authority * outside the US, weird US-logic legal authority
1) If you're inside the US, and the cops have a non-gag-order warrant, you're no safer with your own server. With your server, they serve you, you know about it; with gmail, they serve Google, and Google tells you about it. No difference.
2) If you're inside the US, and they use a secret warrant, in this case your own server might be better. They can probably still do something tricky to you, without you knowing, but using GMail makes it slightly easier for them to get your information without your knowledge.
3) If you're inside the US, and they have no legal authority, then you're fine in both cases. Unless they break into your server illegally. In this case, their job will be orders of magnitude easier if you run your own server.
4) If you're outside the US, and they have no legal authority at all, same as the previous point: if they try to break in, their job will be orders of magnitude easier if you run your own server.
5) If you're outside the US, they might get FISA clearance to get your stuff. In this case, I think you're better off with your own server. This is comparing Google's legal pushback vs breaking into your server. It's totally possible that breaking into your server is orders of magnitude harder than convincing Google that they have legal authority.
In an ideal world, this last case would only apply to political enemies of the US. You'd be able to figure out for yourself if it applied to you, and act accordingly. What kind of idiot uses a US company to plan terrorist attacks on US interests, amirite? Or to leak things to wikileaks (categorize that however you like). But what is much much less clear is whether the US does in fact use this type of surveillance to unethically benefit US corporations, for example. We've heard unsubstantiated accusations to that effect; nothing in my life experience helps me to know if I do or do not live in that kind of world.
Also it requires a much harder to get warrant as well as cost approvals.
On one hand, government agencies are notoriously ineffective with technology. On the other hand, I'd rather assume competence and be incorrect than the opposite.
Really only applies to emails before Room 641A. It might be easier to go after email at the provider level, but NSA is capable of capturing all internet traffic if it wants to.