We're Fighting the Feds Over Your Email
m.us.wsj.com
m.us.wsj.com
Microsoft believes you own emails stored in the cloud, and that they have the same privacy protection as paper letters sent by mail...
The U.S. government can obtain emails only subject to the full legal protections of the Constitution's Fourth Amendment...
A search warrant cannot reach beyond U.S. shores...
[The US government] argues that your emails become the business records of a cloud provider. Because business records have a lower level of legal protection, the government claims that it can use its broader authority to reach emails stored anywhere in the world.
That is simply ridiculous. Email stored by a cloud provider isn't a business record of the provider any more than the contents of a physical letter stored in a rented mail box is a business record of the box provider.
Granted, they already track all metadata without opening it (if you believe that). This is attrocious. I come from a family of attorneys and I have told them I lost all respect for the system in which they operate, and Jeffersonian calls to refresh the tree of liberty have started to seem very real and urgent these days.
In short, fuck these animals. I hope they choke.
I think cloud companies essentially want the 4th amendment benefits of treating the cloud like real world private areas (e.g. bank lock boxes), without any of the obligations that come along with that.
The "reasonable expectation of privacy" in things like safe deposit boxes or storage units is based on the actual fact that service providers generally do not and cannot access the contents of those rented spaces. To apply that same reasoning to data stored in the cloud, we have to indulge in the fiction that various bots and sysops cannot in fact access that data, and do not routinely do so.
That said, I think the cloud folks are ultimately going to win, on the basis of Riley v. California (which is noted in Brad Smith's op-ed). I think Riley is technologically ignorant in glossing over technical distinctions between local and cloud storage that are relevant to privacy, but it all but says the cloud is protected under the 4th amendment. I don't know what's left to fight over.
And the "reasonable expectation of privacy" in cloud email is based on the fact that, while computers necessarily have access to the data (it is not possible to provide email service otherwise), humans generally don't.
(That is, at least for employees at one of the big ones. ;-)
These sorts of things are all capabilities I expect in a local mail client; I think it's a reasonable to apply 4th amendment protections to the user's data, even if computation done on behalf of the user (including selecting relevant ads) happens in a remote datacenter using code the user didn't write.
It is pretty ridiculous to treat users' emails the same as a grocery store's payroll when deciding whether customers have constitutional privacy safeguards.
With that in mind, I just don't see how you can say you have an objectively reasonable expectation of privacy over e-mails in the cloud, when a system operator can pull up all your personal information going back years at the touch of a button. When the e-mail service not only has incidental access to the data, but actively looks into that "private" data and uses that "private" data for commercial purposes. It's a distorted, results-oriented definition of "privacy."
That said, you're likely going to get precisely that results-oriented interpretation, because apparently the Supreme Court, like most users, doesn't fully understand the scope of how cloud providers access and use and commercialize your data.
and...
>That said, I think they're ultimately going to win.
Warning: Total Conspiracy Theory Ahead
Could this be an end-around by Microsoft to eliminate one of Google's main revenue streams? Follow me for a second.
1. Let's assume Microsoft wins this court case. By doing so, e-mails will be afforded the same protection, under the law, as physical letters.
2. A Microsoft backed plaintiff sues Google for data-mining her email's content, arguing under the same 4th Amendment ruling.
3. After years of legal procedures and court battles, Google (and all other e-mail providers) are forced throw away their master keys. Essentially all email is blind to the providers.
4. Google loses one of their larger revenue streams.
Everyone loves a good conspiracy theory, so indulge me for the moment. Why would this not work (And for the record, I'm sure it wouldn't. But I would honestly like to know why.)?
I think a more likely scenario is that we end up with a court ruling that says something along the lines of: "In order to preserve the customer's 4th amendment rights, the company hosting the e-mail mustn't be using it for business purposes." So, Google wouldn't be able to simultaneously mine your e-mails and guarantee that your e-mails are protected under the 4th amendment.
This went off the rails well before I started to write it. But let me push back on your thoughts.
If I am understanding Microsoft's argument correctly for this court case, they are trying to equate e-mails to letters. And, by extension, equate themselves to UPS/USPS/FedEx whathaveyou. E-mails are private correspondence, just like letters in the post. And please, correct me if I'm wrong in this assessment.
It is also a felony in the US to open someone's mail. So wouldn't that same protection exist in email? Which would mean nobody can look at an email correspondence unless they were either the sender or receiver of said email.
So here are some better analogies:
snail mail letter == encrypted email
snail mail postcard == plain text email
publicly posted diary == plain text gmail
I'm all for privacy in email, but if we're doing analogies, unencrypted email is more like postcards, than letters. And metadata is more like what's written on the letter than in it. (And SMTP over TLS would be like the mailboxes you're not allowed to look in, unless you're delivering mail, or are the recipient...)
As far as I can gather, the US has pretty shoddy laws guarding personal information from corporations -- so a change wrt email might be a win. But I don't know if this is the best way.
As long as there doesn't appear to be any viable way to get most people to use gpg/smime -- I'm not sure we're likely to get anywhere. Perhaps that is what Microsoft should do: leverage S/MIME for outlook.com (with the caveat that they would have to keep the encrypted private keys, and being a web service, could be forced to backdoor the clients in order to get the pass-phrases/passwords...).
Hm, I wonder if there's an IMAP extension for storing encrypted key-pairs?
It is a crime for other people to read your mail, though that protection comes from the legislative branch, not the constitution. Specifically, Title 18, Part I, Chapter 83, § 1702 [2]. If you could convince a judge that § 1702 applied to e-mail, you might be able to ruin Google's day. It'd be a very different legal argument than the fourth amendment legal claim. Whatever comes from Microsoft's legal arguments about the 4th amendment won't have a bearing on this line of argument.
I still think the best avenue for a conspiracy theory motive for Microsoft is to get a ruling that says "if the e-mail provider examines the communication for any purposes other than facilitating mail delivery, then the communication loses its 4A protections." That would allow other competitors to advertise strong 4A protections, and force Google to choose between that sweet, sweet personal data or also advertising 4A protections.
[1] http://www.nytimes.com/2013/07/04/us/monitoring-of-snail-mai...
(Also, as I understand it, Google works hard to limit access to email, but I don't think they have anything you would want to describe as a master key. It would be "Google deletes all customer data", not "Google blinds itself to customer data".)
Interestingly, I predict that if your outcome were to happen then Google will rapidly invest in Gmail to turn it into more than an email system, so that they'd have reason to argue that the messages are business records.
What if I also employ them to (going a step further), pay any bills that come in from my bank account?
I think that this line has already been drawn.
Tangential question: since the Supreme Court recently decided "do it with software" by itself is not sufficient (by itself) for software patents, can that precedent also be used for differentiating between letters and email? E.g. - letters with software is not enough distinction for 4th amendment bypass?
But do they, really?
Well, that is also part of this case. The court is going to determine how to fit data into the current caselaw. There is good reason for why the US can't order searches in another country.
But if Microsoft has servers in the United States that can routinely access their cloud servers, there is a good argument that data is really in the United States as well.
The business records argument is a bad one. However, I don't see any good reason for why the government shouldn't be able to access American companies cloud data with valid warrant.
I haven't read the DOJ's brief, do they raise that argument?
Northwestern lawyers per capita on this chat bort is out of control.
The difference with cloud hosting is that, unlike your landlord, your cloud host does have unregulated and unrestricted access to your cloud storage.
In any case, your analogy doesn't work either way you phrase it. If you're the landlord, and Google is the tenant, then the government doesn't need your permission to access the property, just Google's. The government can't break in and search the servers, but it can get the documents with a valid subpoena duces tecum (subpoena for documents).
> Giving someone access to your property does not automatically give the government the right to search it.
No, but giving potentially hundreds of people you don't know and have never met access to your property does undercut any argument that you have an objectively reasonable expectation of privacy with regards to that property.
"On Thursday Microsoft will oppose the U.S. government at a hearing in federal court in New York, arguing that it can't force American tech companies to turn over customer emails..."
Embrace your future state of slavery, it is invariable.
If you use AWS, is all the data (S3, EC2 filesystems, RDS data+backups, etc.) now a business record of Amazon?
What about renting dedicated servers at your local datacenter? You're basically renting bare hardware at that point, but the hard drives are still technically owned by the datacenter. Is the data on those hard drives business records of the datacenter?
Not being able separate the owner of the hardware and the owner of the data on the hardware seems like it would have a ton of modern consequences.
EDIT: Here's a fun thought experiment. Say I bought a license to analyze some music dataset from a record label. That license requires that can't share the music data with anyone. When I upload the dataset to S3 to run my Elastic Map Reduce script on it, did I just violate my license because that data is now a business record of Amazon?
Apparently they check the referer header.
Mandatory link for lazy people:
https://www.google.com/?q=We%27re+Fighting+the+Feds+Over+You...
(forget about "i'm feeling lucky", that doesnt work, hit search.)
Clarification: Microsoft now believes this (or claims to). They had no problem handing PRISM the keys to the kingdom while it was still secret.
http://www.theguardian.com/world/2013/jul/11/microsoft-nsa-c...
It's not a signal of the end of our battle for privacy, but it's something.
But because they aren't doing this, it just shows they are more concerned about not losing business overseas than "fighting for your e-mail".
Fighting them on the legal front to stop such practices from starting may well be the best option right now. Even though Microsoft may be doing this for business reasons, it'll still help everyone.
To my understanding Lavabit didn't have a system in place for separating out one user like that, and the feds would likely have been disinclined to wait for the development of one.
So perhaps we should take this as a lesson in designing systems to be as secure as possible even with legitimate warrants rather than as a sign of warrants being abused.
According to Wikipedia, just one month prior, Lavabit had complied with a search order for one user suspected of child pornography. I'm not exactly sure what the difference was between these two cases, but it does show he had at least some capability to do what they asked.
I do agree that "one SSL key to rule them all" is perhaps not the best practice. That said, the design of the system doesn't matter as much to me. Reality is that the system was designed in the way it was, and when offered two methods of getting their data, the feds decided to take the wrong one. (In my opinion.)
If I were to guess, I would say control is actually a huge issue. If it's their equipment and software that's certified for this use, it probably satisfied chain of custody and certification requirements. If it's someone else's, who knows? It's almost certainly not certified and so it might not stand up in court at all. Certification is a big deal in the government and a court is likely to be skeptical about the use of an unproven and uncertified magic software black box in executing a warrant.
So what it comes down it is that the feds may not have actually had a choice of how they got that data.
However, I'll ask you this: is it constitutionally agreeable to trample the rights of others for the sake of gathering evidence? I would say no. Just like how I would say searching all personal mail coming from a certain zip code because you know of someone sending secrets would be, in my viewpoint, wrong. I can chalk up the initial issue of a warrant to the judge not understanding technology, but as soon as it was explained in a courtroom how it was tied together, he should have told the feds to seek evidence elsewhere.
I think it's about collecting evidence in the least invasive way possible. To me, the priority is limiting damage while still allowing law enforcement to function. One of the key privacy advantages of how LE access to phone companies or gmail or similar is implemented that it allows them to be granted access to just the data in question and little more.
What really becomes a problem is when the evidence in question is only available from one source and there's no way to do it that doesn't run the risk of what I'm going to term information bycatch. At that point there are really only two viable options - allow the collection with bycatch or disallow the collection due to bycatch.
The first is a significant privacy risk. That said, it's also not a new one. As long as people have kept records or written letters, a search has run the risk of exposing the private information of other unrelated people. Certainly, the same concern applies to tapping phone calls, and that's permitted by courts.
The second runs the risk of hobbling law enforcement entirely. Without perfect knowledge of what a given document, packet, phone call, etc. might contain, it's impossible to say that a search will or will not invade the privacy of another person in addition to the subject.
My understanding is that a warrant is for information or items because it's known and understood that information bycatch isn't always avoidable. This is considered unfortunate but unavoidable, as there cannot always be assumed to be other and better options.
I think this goes back to my earlier point about design. If a system isn't designed to contain any breach, then any breach - legal or otherwise - will be uncontained. I think this is less a constitutional problem than it is a technology one.
If you want full compatibility, you can pay a small yearly [extortion] fee to the Verisign gatekeepers... but I prefer not to...
So, how long until Dropbox contents are just a matter of business records?
This makes a good argument for open source software development and decoupling storage. Software-as-a-service may end up being Commodity-as-a-service. Terrible for enterprises like Microsoft, Oracle, and IBM who want to be global "cloud" providers.
It's also the same Microsoft that was found to have provided the greatest aid to the NSA in accommodating their mass wiretap requests (compared to Yahoo, Google, and other webmail providers).
The irony is delicious.
To put it very mildly, I question Microsoft's integrity and wouldn't trust them with my data. Want to showcase a hero who actually went to great lengths to fight the feds over your email? Try Ladar Levison.
Or maybe he just doesn't want to? You know, on principle? Even skirting the paywall, you're boosting the WSJ's viewership stats which in turn, helps them sell more advertising/contributes to their "value".
That would be the case whether or not they had a paywall.
I eagerly contribute to online publications that use other types of business-models: wikipedia, democracynow, TVO, individuals with high-quality blogs, etc.
Paying a for-profit company to do work is not a moral good, it's not a charity. If they can't stay in business, that's hardly my problem. If they want to be a non-profit or charity, then I'd be more inclined to contribute, and that structure might help them produce a higher-quality work anyway.