Hacker News new | ask | show | jobs
by magicalist 4664 days ago
I'm not sure what your point is. If you don't want your email accessed, don't send it unencrypted from your client, and definitely don't send it via a service that has features (search, spam, google now, etc) and is payed for by a system (contextual advertising) that explicitly accesses the contents of your email.

Download Thunderbird and a PGP client[1]. Boom, done.

Use another email service. Boom, done.

I'm not objecting to the idea that you'd find it objectionable to have your email contents used for advertising. I'm objecting to a useless quote that tries to turn this into a soundbite-off instead of an actual discussion (little hope as this thread has).

[1] https://support.mozillamessaging.com/en-US/kb/digitally-sign...

2 comments

Diluting the expectation of privacy about e-mail in general has implications under constitutional law. The 4th amendment only protects against unreasonable searches by the governmnet. The use of mail connotes private communication. As in contrast to post (which is presumed public). Implied consent to forfeighting the right to stop 3rd parties reading your e-mail is not something the public has an interest in establishing. Regardless of the purpose of such 3 party incursion. I don't want to get into a side-bar explanation or legal debate TBH, but its not mindless fear mongering.[1]

[1] http://www.nytimes.com/2013/09/07/us/politics/legislation-se...

“This has been the stuff of wild-eyed accusations for years. A lot of people are heartbroken to find out it’s not just wild-eyed accusations.”

No, this is not correct. The particulars of your agreement with a third-party for storage of your email does not extend government rights to examine that data (the ads in your inbox are as non-public as the email in there too). Even the horribly flawed ECPA recognizes that (it buttresses it, in fact). Moreover, Google[1] is currently standing behind the US v Warshak shield and requiring warrants for email contents.

The problems with the third-party doctrine are much more fundamental than the ways in which that third-party is storing and displaying your data, activities that continue for any webmail client even in the absence of ads when doing spam filtering, searching, etc. Merely the fact that a third-party is involved at all is enough for the outdated sections of the ECPA to rear their ugly heads. Here's hoping the Supreme Court takes up a case like US v Warshak soon.

[1] http://arstechnica.com/tech-policy/2013/01/google-stands-up-...

No, this is not correct.

Your talking statutes, not the constitution. Obviously the constitution trumps both statute and executive readings. Reasonable is per the constitution, an it is plastic in case law. That's why the questions are important, fundamentally. In any event, its worth keeping in mind the right level of abstraction.

> Your talking statutes, not the constitution

I'm talking both. The ECPA was important in that Congress avoided decades of court cases by making explicit the protections afforded electronically stored media, though they did not extend those protections far enough (which today in practice weakens protections that may have been more clearly delineated by now had the ECPA not been enacted).

Constitutional protection superseding (among other things) the fairly arbitrary 180 day requirement for a warrant set by the ECPA was clearly recognized by the Sixth Circuit in the US v Warshak second (criminal) case, stating that "The government may not compel a commercial ISP to turn over the contents of a subscriber’s emails without first obtaining a warrant based on probable cause."[1]

In both US v Warshak cases, though, the Sixth Circuit emphasized the higher protection afforded content over transactional data just for being content by the the tests established by both Katz v US and Smith v Maryland. They laid out that even the supremely terrible precedent of Smith v Maryland (which is the proud parent of allowing the government to seize "metadata" without a warrant) did not allow the government to "bootstrap" limited access to full access, including the access needed for automated processing of email contents by the email provider:

"The government also insists that ISPs regularly screen users’ e-mails for viruses, spam, and child pornography. Even assuming that this is true, however, such a process does not waive an expectation of privacy in the content of e-mails sent through the ISP, for the same reasons that the terms of service are insufficient to waive privacy expectations. The government states that ISPs “are developing technology that will enable them to scan user images” for child pornography and viruses. The government’s statement that this process involves “technology,” rather than manual, human review, suggests that it involves a computer searching for particular terms, types of images, or similar indicia of wrongdoing that would not disclose the content of the e-mail to any person at the ISP or elsewhere, aside from the recipient. But the reasonable expectation of privacy of an e-mail user goes to the content of the e-mail message. The fact that a computer scans millions of e-mails for signs of pornography or a virus does not invade an individual’s content-based privacy interest in the e-mails and has little bearing on his expectation of privacy in the content. In fact, these screening processes are analogous to the post office screening packages for evidence of drugs or explosives, which does not expose the content of written documents enclosed in the packages. The fact that such screening occurs as a general matter does not diminish the well-established reasonable expectation of privacy that users of the mail maintain in the packages they send."[2]

I have not personally seen a good argument for differentiating between spam filtering and contextual advertising in terms of access. Regardless, this is a clear argument for automated access being immaterial to the question of an expectation of privacy of the contents of an email.

[1] http://www.ca6.uscourts.gov/opinions.pdf/10a0377p-06.pdf

[2] http://www.ca6.uscourts.gov/opinions.pdf/07a0225p-06.pdf

I have not personally seen a good argument for differentiating between spam filtering and contextual advertising in terms of access.

Are you seriously proposing free e-mail and/or a spam filter is a good trade for one of the major pillar Bill of Rights? So goes my spam filter, so goes the constitution? What's ironic is that the spam guys use 1st amendment to justify the spam (same as junk mail and the credit rating agencies).

> Are you seriously proposing free e-mail and/or a spam filter is a good trade for one of the major pillar Bill of Rights?

What? Where are on earth are you getting that from what I'm writing?

I'm saying that the Sixth Circuit has ruled that just because you use an email provider that scans your email contents for things like spam (or ads), you have not given up your 4th amendment right for that content to be secure against searches without a warrant.

What you quote is me arguing that your premise that contextual advertising is somehow distinct compared to scanning for spam both in function and legal implication is flawed. The next statement states that even if such a distinction could be made, the above quote from US v Warshak I is a perfect explanation of why agreeing to automated scanning of your email does not imply consent to an abrogation of your rights.

I really don't see how I can be clearer than "The government also insists that ISPs regularly screen users’ e-mails for viruses, spam, and child pornography. Even assuming that this is true, however, such a process does not waive an expectation of privacy in the content of e-mails sent through the ISP...."

Ditto for Google Drive, encrypt it with something like Syncdocs[1] to keep files private.

Encryption keys are like car keys - you need to own them, not Google.

[1] http://syncdocs.com