3 ms·
It's defence against legal compliance with the NSA. Emphasis is privacy and compliance, not security.
by namank 13y ago
It's defence against legal compliance with the NSA.
Emphasis is privacy and compliance, not security.
- richardwhiuk 13y agoNo it isn't. The email passes through the server unencrypted (between Postfix and Dovecot), so it's still a potential tap point. In fact, running encryption to the server simply says to the NSA: Ask Linode for access to this disk.
- varikin 13y agoHe used an encrypted FS I believe, but the NSA could just ask to monitor all mail to and from his instance at Linode (or any ISP) since he didn't encrypt the mail.
- cenhyperion 13y agoAnd they probably have most of the mail anyways because odds are he's mostly communicating with people using google, yahoo, microsoft, etc.
- handsomeransoms 13y agoI wonder how effective this advice would even be at achieving that goal. Consider, for instance, that what meager protections are afforded electronic communications (by the Stored Communications Act, etc.) only apply to providers that "serve the public". [1] Others, such as Jake Appelbaum, have argued that hosting with Gmail or other large providers offloads the legal burden onto their well-equipped legal teams to defend against subpoenas, FISA requests, NSL's and the like. [2] The problem here is that it is very difficult to protect yourself when you don't understand your adversary's capabilities. We need transparent legislation and accountability in both government agencies and tech industry corporations. A lot of this advice boils down to an assumption that the NSA/DOJ/FBI will "play fair", and there is really no reason to expect them to do that. [1]: https://ssd.eff.org/3rdparties/govt/stronger-protection https://ssd.eff.org/3rdparties/govt/stronger-protection [2]: http://youtu.be/HHoJ9pQ0cn8 http://youtu.be/HHoJ9pQ0cn8
- namank 13y agoWell, with that consideration, the advice is moot since it isn't outside government regulation. Hmm...good point. We really need an open-source ISP for privacy to start to work. A fool-less system where the executing code is available to the public with read-only access with write permissions to appointed admins.