Goldman Sachs Demanding E-Mail be Deleted
schneier.com
schneier.com
Bruce isn't adding very much here.
gs.com > gmail.com > nsa.gov > irs.gov who will love to see those accounts
What horrible injustice, being known as failure in security for being failure in security. Poor Goldman Sachs.
We give companies a hard time for lax security practices. GS recognizes an error and is trying to take steps to reduce the likelihood of a data breach. What's wrong with that?
Google wants to protect its users from unnecessary interference in there email accounts, so it asked for a court order. What's wrong with that?
There are many interesting questions raised here. It could be interesting to see how it plays out in the end.
It's interesting to think about this email landing in my Gmail inbox. I'm pretty sure I'd reply and inform the sender that they screwed up and ask if they want me to delete it.
source - http://www.reuters.com/article/2014/07/03/google-goldman-lea...
Fun fact: The VA's system was called Decentralized Hospital Computer Program (DHCP). When that acronym was overloaded by Dynamic Host Configuration Protocol, they changed it - to VistA. Either they had really bad luck picking names, or were very prescient.
Even Whatsapp works this way: once you've sent a message, you can't unsend it. The message is first relayed to their servers and then relayed to the client, but even if the recipient isn't online and the message is only on the server, deleting it only removes it from your conversation. You'd think that in 2014 we would have addressed these kinds of flaws.
> "there should be a way for the SMTP/IMAP server to notify the client and remove it."
As long as the protocol requires the client to obey a command to delete, it's not going to work.
With such a protocol, nothing is stopping me from choosing to disregard any messages to delete already received (and downloaded) messages. In fact, I'd probably have the client highlight them for me if they got a "delete this" request. There's probably something good someone is trying to hide in that message.
If I recall correctly, Twitter had a similar issue with their API. They have a method to delete a Tweet, but the Twitter client has to honor the delete client-side since it has a cache of tweets it has seen.
Of course, in a closed environment like Twitter, Twitter can choose to revoke a non-compliant client's API keys if they don't follow the rules. Not so much with email.
Because internet email is mostly designed as a highly fault-tolerant low-trust network, so the basic design is unauthenticated forwarding, so once its sent, there's no generally-applicable way to prove that you are the sender to ask for it to be deleted. Inside something like a particular Exchange server, email can be implemented that way (and basically is), and that works because its a single centralized database with client authentication.
It is weird to see an email sitting in your Inbox disappear as you watch!
It's (also) a privacy issue as it discloses when one of the recipient has read the email.
2) If it's "okay" for your machine to receive and keep the misdirected email message, how is it "not okay" for someone sending a correctly directed message asking your MUA to remove the message? Your MUA allows the behavior; you allow it by use of that MUA; no access control mechanisms were broached. To look at it literally, all email is "reaching into your machine to suit the sender".
Its not that much of a bastardization, as a modernization -- the original seems to have been "possession is 11 points in the law (and they say there are but 12)", which was decimalized from 11 and 12 to 9 and 10, sometimes used with the "9" alone and the last part omitted, and later simplified to 9/10. The original sense of the statement is preserved, which is why I wouldn't call it a "bastardization".
I suppose on the one hand something like that is a solution for gs.
On the other hand, while I understand the model, I'm not 100% it's the right one.
GS has zero excuses, they could very easily code a Microsoft Outlook version of it that is seamlessly integrated. Instead they fail at proper risk management and rely on government intervention, sound familiar?
I bet a lot of firms fail in this case.
I am imagining this program that looks through your To: field for recipients in your address book that have shared their public key with you. If it finds any, those people get a copy sent to them which is encrypted and only they can read...
Now what happens if you accidentally try to send mail to someone not in your address book?
I guess hopefully you get a big popup that says "Warning: mail will not be encrypted!" Maybe not?
I've used the command-line tools to encrypt files and send encrypted attachments. It's nothing like "automatic" and it's certainly not an envelope for the whole message.
"fred@example.com would like to recall the email 'Foo bar'"
[OK] [Cancel]
I'm yet to find a single legal case where an email signature made or broke the case. It strikes me more as legal mumbo jumbo voodoo at this point than anything of merit.
Not least of all as a contract is between two parties, the recipient cannot be auto-magically placed into a contractual position just by receiving the email.
That would be like me sending a snail mail letter to someone with the words "By reading this mail you agree that all your stuff is now mine" and pretending like any court in the world (any country) would take that "contract" seriously.
That's essentially what these signatures do. Try to set up a contractual arrangement with one party "agreeing" to that arrangement just through the virtue of receiving an email?
The reason I used "The Bat!" for ages, and now prefer Thunderbird/Postbox-inc.