7 ms·
I came to a similar conclusion. You should write every email as if it were public, because it's entirely likely that it will be. They can be forwarded, made pub
by mdp 7y ago
I came to a similar conclusion. You should write every email as if it were public, because it's entirely likely that it will be. They can be forwarded, made public through legal discovery, or exposed in a data breach (eg. Sony/North Korea).
Forget security for a second, imagining every email as public record will make you more considerate and less biased writer. And from a business perspective, email should be viewed as a public legal record, because in some cases it will be used that way.
That's not to say that there shouldn't be private messaging options, it's just that email isn't one of them and was never really built to be. PGP was always sort of a tacked on solution with a lot of faults (no forward secrecy, plenty of meta data leakage, usability issues)
All that being said, I still left Gmail for Fastmail. Just because I consider every email I write to be public doesn't mean I want Google getting a free pass to mine and sell my data.
- decebalus1 7y ago> Forget security for a second, imagining every email as public record will make you more considerate and less biased writer. And from a business perspective, email should be viewed as a public legal record, because in some cases it will be used that way. > Just because I consider every email I write to be public Cool. Can I have the creds to your Fastmail account then? I'm curious what you're up to these days. If you're not comfortable doing that (I promise I won't send any emails - not that it matters, I could still spoof your address anyway), I could settle with a dump of all the emails you've sent. I get the whole 'write every email with the mindset that it could one day end up on the front page of NY Times' but that doesn't dismiss security requirements for locking down your email/calendar account.
- tptacek 7y agoThis is not a very strong argument. Here's a specific refutation: the credentials to their primary email account are likely equivalent to the credentials of many other services that they use, because of password reset. None of those emails are encrypted, or ever will be; further, they're of little value just a day or two after they're sent. That commenter could coherently expect both that their mail spool would eventually be "public" and that it was safe to use email for password resets. More generally: it's reasonable both to expect that your mail spool could eventually be public, and still not to want people to read it. There are things I don't want people to read, and there are things I need to be as careful as I can to ensure everyone can't read. Email works for the former and not the latter, and the latter is what encrypted messaging was invented for. Comparatively: I don't know many people who trust Twitter DMs, and "let's move this off Twitter DMs" is a constant refrain. But my answer to "can I read all your Twitter DMs" is still "no".
- decebalus1 7y agoNo credentials is fine, I understand. As I specified, I would also settle with a dump of the emails. Public means public, right? If we're talking in hyperboles, then let's go all the way, right? Or 'public' means 'eventually public'? Or what? The reason I'm asking is that the original comment is basically dismissing efforts to make personal productivity products more secure for the reason that they can become public at any time anyway, so why bother, right? Well fuck it, let's all pack it up and go home then, make email public and unencrypted and reallocate the development effort to something more lucrative like desktop apps in Javascript.
- techsupporter 7y ago> Can I have the creds to your Fastmail account then? I'm curious what you're up to these days. This is just as specious of an argument as the retort of "ah so you claim you have nothing to hide but you have curtains on your windows, checkmate, I am very smart." The issue is not one of what specific measures are or are not taken, it's about having the informed choice to make decisions based on information use. I wager that a lot of people would make the choice to pay with actual cash when shown the actual cost in data of how their personal information is being used. But, conversely, a bunch of people probably don't truly care or mind, and the loss of information control is worth less to them than the loss of money to be paid. That doesn't then imply that a person has zero care about the information under their control, nor that their refusal to give you control of that data makes them a hypocrite.
- decebalus1 7y agoDid you misunderstand the meaning of the word 'public'? It's not really that nuanced.. I am part of the 'public', no?
- techsupporter 7y agoNo, I didn't, and I think you know that but you're trying to bolster a point you know isn't on the mark. You showed your true motivations in your reply to someone else: > If we're talking in hyperboles, then let's go all the way, right? Or 'public' means 'eventually public'? Or what? We're not talking in hyperbole. At least, most of us aren't. We're trying to discuss reality as it is on the ground. The person you replied to before said to imagine the contents of my e-mail box as though it is a public record. To imagine does not make it so. I imagine myself as James Bond whenever I put on a suit coat and tie; I am not James Bond. I can imagine my e-mails as ones that, through no intent of my own, are exposed and made as part of the public record but treating them as though that possibility might happen does not implicitly make them public. It also doesn't mean I don't want them to remain my own secure property.
- deleted 7y ago[deleted]
- fauigerzigerk 7y agoIf that is so then "public" and "private" are insufficient categories to describe messaging options. I'm forced to send proof of identity as well as proof of address via email. I'm receiving bank statements and countless other sensitive documents via email. And I have absolutely no other choice. Whoever gets a hold of my email can impersonate me in almost every context. So no, I do not consider the contents of my email public. Absolutely not! I'm not willing to consider a service completely insecure just because it can never be completely secure.
- wyclif 7y agoIn fairness, I don't think he meant the contents of your email account should be public, he said you should write and behave as if it could be because who knows what a webmail provider will do with your data. That's a very different thing than saying it should or will become public.
- fauigerzigerk 7y agoThe question was whether or not it makes sense to make email services as secure as possible and prefer more secure email providers to less secure ones. Some say we should give up making email more secure, because it can never be as secure as more modern messaging services. That doesn't make sense to me, because we don't have a choice other than to use email in ways that require very high levels of security. I cannot behave as if my email could become public any moment. I would love if the world were to move on to more secure messaging platforms. But it's simply not the world we live in right now.
- wstrange 7y agoI agree with most of what you have written, but this: > doesn't mean I want Google getting a free pass to mine and sell my data. AFAIK, they don't do that with gmail. Do you have any evidence to the contrary? We need to hold Google's feet to fire on privacy, but it is also important that we do not exaggerate or distort the facts.
- mdp 7y agoYou're right, "Sell my data" might have been too strong. But they are certainly mining it to train things like their "suggested responses". In my view, it's an ad company, and while they might not be doing it today, there's nothing stopping them from using my data in the future, hence the "free pass".
- cle 7y agoIMO the burden should be on Google to prove that they don't. The flow of personal data through their systems is opaque and they have plenty of incentives to monetize the data.
- mdszy 7y agoYou can't prove a negative.
- rgbrgb 7y agoYou definitely can [0], but this one would probably be hard for google without significantly modifying the architecture of gmail in ways that would remove its revenue model. For example, they could open source a client that had audit-able end-to-end encryption, but then they couldn't optimize ad revenue by aggregating and mining large email datasets. [0]: https://en.wikipedia.org/wiki/Proof_of_impossibility https://en.wikipedia.org/wiki/Proof_of_impossibility
- mdszy 7y ago> a proof demonstrating that a particular problem cannot be solved as described in the claim, or that a particular set of problems cannot be solved in general did you even read the article you linked
- newnewpdro 7y ago> You should write every email as if it were public, because it's entirely likely that it will be. They can be forwarded, made public through legal discovery, or exposed in a data breach (eg. Sony/North Korea). None of these are unique to email. This is the attitude one should take for any electronic form of communication. Even old-fashioned ink on paper letters of significance have made it into the public record for all to see.
- nirui 7y ago> I came to a similar conclusion. You should write every email as if it were public, because it's entirely likely that it will be I think this is mainly governed by expectation and received benefits. I would let my doctor see me naked, because I'm expecting the doctor will fix my problem if I agreed to do so, and I assume the doctor will respect my privacy by not leaking information about my physical characteristics and private parts with others. But what if it's for example the owner of my favor restaurant asking to see the same? I don't think I would go there anymore.