4 ms·
IANAL. If you run your own mail server, then they would serve the subpoena to you, and you would have the opportunity to contest it. The subpoena assumptions
by elehack 15y ago
IANAL.
If you run your own mail server, then they would serve the subpoena to you, and you would have the opportunity to contest it. The subpoena assumptions - that those holding the data have an interest in it - hold, and the system works as it's supposed to.
Now, I don't know if they can issue blanket subpoenas to Google to request e-mails you have sent to Google customers. Certainly, they could for specific Google users, but it'd be interesting to know if they can issue open-ended ones in hopes you sent something incriminating to someone using GMail.
I would also like to know how VM hosting providers like Rackspace, Amazon, and prgmr.com fit in to this. They provide hosting and storage, but do so opaquely without knowledge of what I've stored or how I have done so. Can they serve a subpoena against prgmr.com to rifle through my disk image looking for mail, or would they serve it against me as the manager of the mail server?
- mike-cardwell 15y agoIf the mail server which stores your email is doing this: https://grepular.com/Automatically_Encrypting_all_Incoming_Email https://grepular.com/Automatically_Encrypting_all_Incoming_E... Then the person running the mail server couldn't hand over your email even if they wanted to.
- sc68cal 15y agoHoly moly, that is awesome! I'm going to look into this. EDIT: Oh, this is so cool - a true UNIX utility, it just reads from STDIN. I don't even need to play with my sendmail config. I can integrate it with my .procmailrc. This is fantastic! EDIT 2: Overall - it's a very cool idea. I love playing with procmail stuff, but from a security point of view it's encryption after the fact. Most e-mail is transported in the clear. I'll probably use it as part of a cron job to move stuff from my inbox into an archive.
- mike-cardwell 15y agoYeah, there's a guy in the comments who has apparently had it working with procmail. He provided an example procmail recipe.
- mike-cardwell 15y agoRegarding your second edit. It doesn't provide end to end encryption, which is what people immediately think of when PGP encryption of email is discussed. End to end encryption is still the best possible option, but it requires both parties to be involved. What it does provide however is the next best thing, for people who receive non-encrypted email. It protects your mail content even if your IMAP account details are compromised. It protects your mail if the mail server is compromised, and it protects your mail if one of your mail clients is taken.
- sliverstorm 15y agoIn theory Amazon cannot access your AWS instances. Everything is encrypted - communications, the virtual disk itself. How well this holds up in practice, I don't know, because the only key they don't have saved for you on their websites (in case you should lose it of course) is your SSH private key.