Hacker News new | ask | show | jobs
by zazerr 26 days ago
I have the same issue and found this worked great https://unattach.com/ (no affiliation, just a user)
1 comments

Oh nice, if everything they say is true, this seems like a good match but it seems like it has 1 big potential downside.

THE GOOD:

Their FAQ says it uses OAuth to connect to your Google account and the emails never leave your browser.

It also costs 83 cents for 1 month so you can go nuts. Alternatively you can pay 1 cent per email if you have a handful.

I see another HN thread about it here from a few years ago: https://news.ycombinator.com/item?id=32462878

THE BAD:

I don't know if it can be used with total confidence because that HN thread makes it sound like they delete the original email and create a new email with the same meta data but some of the comments indicate that's not quite the same as the original. If you had to present this email as evidence, you could run into friction since the original no longer exists. Technically it looks like you can back the original up but as someone mentioned in a comment that seems like it would add a lot of friction in a legal case.

I have no intent on ever needing to use old emails with large attachments in a legal case but knowing this could be a problem makes me hesitant. Although on the bright side, it would be fine to use for anything you 100% know won't ever be used legally.

Founder of Unattach here.

Just to clarify: Unattach does not corrupt or mangle emails. Because Gmail does not expose an API for modifying the original email in place, Unattach creates a new version of the email with attachments removed/downsized while preserving the email's content and metadata.

If you need the original email for legal/evidence purposes, you can back it up first, either through Gmail or Unattach.

> If you need the original email for legal/evidence purposes, you can back it up first, either through Gmail or Unattach.

Yes, that was covered in the other thread. Presenting a backup as evidence has a lot less strength than the original.

If the other person doesn't have the email (they deleted it) and you don't have the original because Unattach deleted it to replace it with a different copy then we're only left with an offline backup on 1 person's machine. Who's to say that offline backup wasn't tampered with (modifying headers, etc.)?

Are you in the U.S.? Which state?

You're trying to establish a chain of custody here. The only person who remotely cares about the forensic integrity of the message is the judge (and the jury if it's a jury trial) and it seems like an argument you would like to make is "this email came from Google's servers so we didn't tamper with it" - but the judge won't take your word for it, you will need Google to substantiate that and they won't unless it's a workspace account.

If it's a workspace account, then your org already has a retention policy.

So again, what problem are you trying to solve and in which jurisdiction?

I'm in the US / NY, with a normal personal account.

I think the issue with localizing it to a specific state is oftentimes contracts or working agreements have jurisdiction locations that align with the company. In other words, it might not be in NY. It could be anywhere, including different countries.