Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Google routinely hands out the entirety of your gmail data to the US. I don't think that's really doing their best to side with users.


So what does Google not do for their users that they could legally do?


patraeus


It's different if the main country you're operating in has warrants to access your data. As a counter example, Google left China and instead operates out of HK now because they weren't willing to let the government eavesdrop on your search results.


It's different if the main country you're operating in has warrants to access your data.

-- No warrants needed for gmail, are there? Gmail older than 6m is like "public garbage" and feds can go thru it all they want.


That overstates the case a little.

Public garbage is literally public. I can go to your cans (if they're on the street) and grab stuff. The government can. Zero restriction.

Email over 6m old (under ECPA) doesn't require a warrant, but it's still protected more than trash. A private citizen can't just grab it -- it would require something like a subpoena (depending on terms of service). Even the government needs to assert the information is needed for some lawful purpose. Far less than a warrant, but still more than trash.


Thanks for the clarification. I do think the comfort of requiring a warrant comes form the fact it is Judicial (so check and balance applies). If all it takes is a prosecutor signing off, for example, a "lawful purpose" would run the risk of being pre-texted.


I'm still vastly more afraid of regular criminals than I am of any part of the US Government. I'm also more afraid of specific foreign governments acting in the US (or to me when I leave the US) than I am of the US Government. That's not to say the USG is a great friend or anything.


Agree with you on the whole here. A criminal would need to steal, not ask the data. Again, this is a good point. Its not that easy to get by google for a basic criminal, etc. The issue with the Gmail/cloud data & the fed's is that the pre-text can be off-topic. Once they are "in" your email/data (like, your multi-year archive or cloud storage) for some minor infraction, you have no privacy for your whole life in all areas. Even if you are not requiring a warrant, how do you protect from something like the bradley manning case? One person with access to stuff well beyond his need to know...just one bad apple all it takes in that case...all of that follows is ripe for abuse. So that is the issue in part as well.


But Gmail only first offered HTTPS about two years ago...


Available for over 4 years, default for nearly 3 years:

http://gmailblog.blogspot.com/2008/07/making-security-easier...

http://gmailblog.blogspot.com/2010/01/default-https-access-f...

Please save your criticism for Yahoo, which still does not use SSL for anything except the login form and account info editing. Only premium accounts get the privilege of SSL for mail.

Hotmail might have been improved since then, but about a year ago SSL was disabled by default in account settings.

Google wasn't the first to offer SSL encryption for webmail access, but Google is far better than the other major U.S. based email providers.


What a load of marketing BS. big deal if it was 2 years or 4 years, it was still trivial to implement even on 10 year old hardware.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: