Slashdot Mirror


Appeals Circuit Ruling: ISPs Can Read E-Mail

leviramsey writes "The US Court of Appeals for the First Circuit (covering Massachusetts, Maine, New Hampshire, and Rhode Island) has ruled that e-mail providers are not violating the law by reading users' e-mail without the user's consent. The decision finds that the Wiretap Act does not cover interception of communications where the communications are being stored, not transmitted. Perhaps OSDN should send the defendant, accused in 2001 of reading users emails in order to find out what they were interested in purchasing from Amazon, a T-shirt from ThinkGeek?"

113 of 527 comments (clear)

  1. Two words by VinceWuzHere · · Score: 5, Insightful
    Two words: HOLY SHIT!

    More words: This most certainly has to be overturned on a privacy bill of some sort. Imagine the widespread mail-reading that is now determined -at least in the mentioned juridstictions- to be legal. I wonder what ever happened to the privacy laws and how they match up to this new ruling (the ones that say a conversation is deemed to be confidential and cannot be disclosed outside of the circle in which it originated?)

    I completely agree with "And he acknowledged that "the line that we draw in this case will have far-reaching effects on personal privacy and security."

    1. Re:Two words by Anonymous Coward · · Score: 2, Interesting

      Holy SHIT is right..

      This is complete Bullshit..

      OK so Joe Blow from AOL just saw the email i was writing to a customer and then writes to that same customer and offers them a better deal.

      The posibilities for abuse are rediculious

    2. Re:Two words by aardvarkjoe · · Score: 4, Insightful
      More words: This most certainly has to be overturned on a privacy bill of some sort.

      Why? It seems much smarter to start encrypting your email than to simply trust a private company to not watch what is done with their equipment.
      --

      How can we continue to believe in a just universe and freedom to eat crackers if we have no ale?
    3. Re:Two words by 0racle · · Score: 5, Insightful

      You mean that you can say with a straight face that you thought E-Mail was a private medium to begin with? Its sent plain text, through who knows how many intermediaries, then stored on a system you don't have control over. At any one of those points it could be read, even accidentally.

      --
      "I use a Mac because I'm just better than you are."
    4. Re:Two words by matth · · Score: 3, Interesting

      I see nothing wrong with this. You are paying the provider to use their mail server. You are storing your mail on THEIR machines. It is THEIR machine they may do whatever they like with it. It's like when you rent a house, the landlord may come by at any point and perform an inspection of the property. It is a private network. Likewise they are completely within their bounds to block mail from say all of AOL or EARTHLINK. Customers may not like it, but it's a PRIVATE NETWORK that you have payed for access to.

    5. Re:Two words by Honest+Man · · Score: 5, Insightful

      Holy Shit is right!

      I'll tell you what though - If we start having people at isp's reading email from the First Circuit's personal email accounts and using any information they receive thats interesting and forward 'tips' to the LA Times and Seattle Times reporters and see how long this kinda garbage legal action continues.

      I cant believe we have people this stupid working in our legal system...

    6. Re:Two words by NigritudeUltramarine · · Score: 5, Insightful
      Two words: HOLY SHIT!
      One word: Postcard.
      More words: ... Imagine the widespread mail-reading that is now determined -at least in the mentioned juridstictions- to be legal.
      More words: If you don't want people reading your mail, you use an envelope. If you don't want people reading your email, you use encryption. Simple as that. It's always been that way, from the days of ARPANET. Nothing's changed.
    7. Re:Two words by liquidsin · · Score: 4, Insightful

      You mean that you can say with a straight face that you thought snail mail was a private medium to begin with? Its sent plain text, through who knows how many intermediaries, then stored in a building you don't have control over. At any one of those points it could be read, even accidentally.

      --
      do not read this line twice.
    8. Re:Two words by flibuste · · Score: 5, Insightful

      There is still a huge difference between what you are ABLE to do and what your are ALLOWED to do.
      My company's database probably contains your credit card information - I am ABLE to access them - do you think I should be ALLOWED to use it?
      Let's face it - this court judgement is either a result of plain ignorance, or a lack of laws AND judgement.
      Again a nice example of freedom - brought to you by Big Corporation America. Thank whoever, I am not living there.
      Let freedom reign GW - June 2004

    9. Re:Two words by flibuste · · Score: 4, Informative

      > It's like when you rent a house, the landlord may come by at any point and perform an inspection of the property.
      I am not sure where you are from, but where I live, your landlord has absolutely NO RIGHT to come to your house - even for any kind of inspection. They are not even allowed to keep a copy of the keys. And if you find that he came to your home without your authorisation, it is considered breaking in and punished as a thief would be.
      Thanks whoever, I am not living at the same place as you do.

    10. Re:Two words by 0racle · · Score: 3, Interesting

      E-Mail is less of a letter and closer to a postcard since a letter is sent sealed and a postcard is a message sent in the clear. It wouldn't surprise me in the least if a postcard was read by every person that it comes in contact with.

      --
      "I use a Mac because I'm just better than you are."
    11. Re:Two words by AJWM · · Score: 4, Insightful

      Not quite. Most snail mail has an envelope, and it's a violation of federal laws to open that envelope unless you are or are authorized by the addressee (or warrant, etc).

      Postcards, however, are another matter. Unencrypted email is like postcards.

      --
      -- Alastair
    12. Re:Two words by pilgrim23 · · Score: 5, Funny

      I think this is absolutely the ISP (or admin's) right to read whatever they need to in a customer's email to better provide service and further the casue of communication..
      -signed Apeals Court Sysadmin

      PS : Justice Smith: Zelda's email had some tech difficulties getting through, but what she said was:
      She couldn't get the chocolate stains out of her purple tutu so she will have to wear the red one for the usual Thursday session. be sure to wear your fishnets and don't forget the whips.

      --
      - Minutus cantorum, minutus balorum, minutus carborata descendum pantorum.
    13. Re:Two words by matth · · Score: 2, Insightful

      Sure.. if it's a postcard they can read it.

      Postcard == regular e-mail
      Sealed letter == encrypted e-mail.

    14. Re:Two words by iammaxus · · Score: 5, Insightful

      Why? It seems much smarter to start encrypting your email than to simply trust a private company to not watch what is done with their equipment. That's ridiculous! Why don't you start filling out forms to sign up for auto insurance in garbled alpha-numeric characters and just tell them to get a verisign key? If you can't rely on a private company keeping your information safe, you are screwed. Just like an insurance company wouldn't dare give the kind of info you put on those forms to anyone else because of legal repercussions, an ISP wouldn't dare read your email if the proper laws were in place. Insightful my ass.

    15. Re:Two words by gumpish · · Score: 5, Insightful


      From the point of view of a systems admin, I'll be honest. I look at users' email from time to time. ...

      I dont see the big fuss here.


      Then why post anonymously?

    16. Re:Two words by A_Random_Factor · · Score: 2, Interesting

      If this thing is not overturned, how does it impact VOIP? Does this mean that any federal/state agency or ISP can listen to all of your conversations without any kind of prior court approval?

    17. Re:Two words by Le+Marteau · · Score: 4, Insightful

      Why? I'm just fscking currious. I stopped after everyone started getting only spam and virii though.

      What an anal opening.

      It has been my observation that those who are most interested in others lives generally have none of their own.

      Those who have power will use it.

      No, not all will, as you imply. Only those without any sense of decency, which is perhaps most sysadmins, but not all. Any admin who aspires to being a good man would not invade other's privacy because they're 'just fscking currious'.

      --
      Mod down people who tell people how to mod in their sigs
    18. Re:Two words by aardvarkjoe · · Score: 2, Interesting
      how about this: phone company starts listening to high executives phone lines and uses the same bullshit reasoning that they weren't listening to the actual call but a STORED version of the call(like it made any difference) - they then use gained information in mayhem on the stock market.
      Strangely enough, this would be illegal for reasons that have nothing to do with privacy.
      or, using an installed version of a program they push to normal users they read the STORED email on the customers machine after the encryption(through whatever billyboo means). should they be able to try that? should they?
      Shockingly, this would too.
      and I suppose you don't mind your neighbour trying to break into your mailbox either, because it is your fault after all if he succeeds, right?
      Guess what? This too! You're zero for three, my friend.

      And this is all ignoring that telephone and US mail have specific privacy laws attached to them, due to their being government-sponsored monopolies, and thus come with an expectation of privacy. E-mail, on the other hand, is not covered by the same laws, is not a government-sponsored monopoly, and thus there should be no expectation of privacy.

      Maybe you want the government to be your babysitter, but I'll take my freedom like a big boy, thanks.

      --

      How can we continue to believe in a just universe and freedom to eat crackers if we have no ale?
    19. Re:Two words by joranbelar · · Score: 5, Insightful

      But the issue here is not comparable - the guy in question wasn't reading the emails while they were "in transit" a la a postal worker glancing at a postcard coming through. A more accurate analogy is saying the guy went up to every user's physical mail box, opened it, rifled through the contents (whether they were postcards or not) and used the data he gained for his own purposes.

      Whether the email is encrypted or cleartext, the bottom line is that you have to go to a lot more trouble to read someone's email than to read someone's postcards. And since email is sorted, routed, and delivered without human intervention, there *IS* a valid expectation of privacy.

    20. Re:Two words by liquidsin · · Score: 4, Insightful

      But it's not like you often "accidentally" read email. It's understandable that you'd have no expectation of privacy with a postcard, since everyone who handles it could conceivable read it. Email doesn't need to be "handled" by anyone - the software can do it all. Going out of your way to read plain text email is like going out of your way to steam open envelopes (except that, apparently, the former is perfectly legal while the latter would land you in jail).

      --
      do not read this line twice.
    21. Re:Two words by MrLint · · Score: 4, Insightful

      I have to agree, but on more general grounds, I am still somewhat bewildered why nearly all internet traffic isn't encrypted by default in 2004? I mean only 'relatively' recently, has telnet been given the boot as default text connections to ssh. Its a mind shift that took a while to tip the balance. Why is everything else taking so long?

      Of course even in my earliest days on the internet i has always assumed that it was a given that the administrator can read any file on the system.

    22. Re:Two words by Honest+Man · · Score: 2

      Fear is an awfully strong word; however, I 'fear' any person or group with a great deal of power and no respect for how it effects others as is being done in this case. Like many other tech-decisions, the courts are brainless when it comes to what should and should not occur.

      Great example there with Bush, with the exception that, like the majority of Americans, I did not vote for him.. though you were simply trying to be a troll with your comment.

      This email law mockery is only one of many steps in the wrong direction - as have many of the laws from Clinton and Bush Jr. have been.

      No need to presume that we love Bush Jr. just because you want to blame that for everything though.... He bought his way in and he'll be gone after one term - Hopefully the people in Florida learn how to fill in circles before the next election.. lol

    23. Re:Two words by aardvarkjoe · · Score: 4, Insightful
      Because despite all the screaming on Slashdot, most people really don't care that much. I don't encrypt my e-mail because it makes no difference to me if someone reads it or not. (My comment was simply that if I did care, I'd take responsibility for it myself rather than asking the government to [ineffectively] protect me from the big bad ISP.)


      Like you said, it took forever for ssh to replace telnet, and that's a problem which system administrators thought was pressing. Nobody considers email, web surfing, IM, or whatnot to really be all that important, and so nobody's going to go to the trouble to secure it.

      --

      How can we continue to believe in a just universe and freedom to eat crackers if we have no ale?
    24. Re:Two words by New_Syntax · · Score: 2, Insightful

      "I cant believe we have people this stupid working in our legal system..." Where have you been? Dont you remember the debacle four years ago when the supreme court selected our president? This is just a sample of the idiotic things that happen through our legal system.

    25. Re:Two words by Anonymous Coward · · Score: 3, Interesting

      Agreed, I administer several webmail systems (not any of the biggies) and it is necessary to sometimes go into people's mailboxes if they are suspected of spamming/scamming etc. Naturally this is in the T&Cs at sign up.

      We have two things that trigger an account check, one is if lots of emails with lots of recipients are sent in one session (particularly if they put lots of addresses in the BCC field) we will check that they aren't spamming. The other trigger to check an account is when someone complains.

      While will come across to many as a privacy invasion it is sadly the only way to catch and prevent spammers and scammers. We must have deleted over 200 people trying to do Nigerian scams over the past few months. Normally we replace their account with an auto-response so anyone responding to the scam gets a message from us explaining the con.

      It could be worse, we could be like Hotmail and delete accounts without even checking they have been used for abuse.

      One guy tried to get us to delete an account claiming it was being used by someone to bid on Ebay auctions without paying. A quick inspection of this mail account revealed it was being used by an Ebay scambuster, and thanks to him the guy complaining had all of his scam auctions closed. :)

    26. Re:Two words by samantha · · Score: 2, Insightful

      This is moronic. I am paying for email service. I am not paying for them to read my email for whatever reason or no reason whenever they wish. That it is their machine hasn't anything at all to do with it. They are providing a service that I pay for. They have already received compensation for use of their resources as per the contract. They have no justification for also mining the email they contracted to service. And no, it is very much NOT like renting a house. Please don't use worthless analogies. You may hurt yourself.

    27. Re:Two words by AJWM · · Score: 3, Interesting

      Email doesn't need to be "handled" by anyone - the software can do it all.

      Except when the software doesn't, and then someone (usually read as "sys admin") may have to look at it to see what the problem is. Which happens rather more often than, say, the Post Office having to open a letter to figure out the addressee (or sender) because the front of the envelope smeared. (Had to do that today, as a matter of fact -- a bunch of undelivered messages stuck in the mail queue.)

      Furthermore, "the software" can -- and frequently does -- also scan all the email looking for items of interest before reporting same to its human master(s). This could be something gov't mandated like Carnivore, or benign like a virus filter, or questionable like a corporate-mandated scan of outgoing email for certain keywords (trade secrets, spam, pr0n, whatever), but it happens. (In the latter case, encrypted email might just be blocked except from certain authorized users.)

      --
      -- Alastair
    28. Re:Two words by DroppedPacket · · Score: 2, Funny
      WHY? WHY? Because next they start listening to your phone...

      Dude, they are already listening on your phone. What bugs me is they keep listening in on my mind. And I've been hearing some crosschat from their thoughts too. It's really scary...

      --
      I am not a resource! I am a free man!
    29. Re:Two words by TRACK-YOUR-POSITION · · Score: 3, Interesting

      The post office probably doesn't do that. Employees of the telephone company, on the other hand, are permitted to listen to any call for maintainnance purposes, and generally have a lot of discretion in determining exactly what maintainance is.

    30. Re:Two words by NigritudeUltramarine · · Score: 2, Informative

      You seem to have missed my point entirely, I'm afraid.

      You're talking about envelopes. Like I said, email is not like mail in envelopes.

      Email is like postcards. It's sent as plain text that anyone along the way can read. Having a "law" that says people can or cannot read it doesn't change the technical reality.

      If you want to do the equivalent of putting your email in an envelope, you've got to encrypt it.

      Simple as that. And if you do it properly, neither your ISP nor your government can read it.

    31. Re:Two words by drsmithy · · Score: 2, Insightful
      I dont see the big fuss here. From the point of view of a systems admin, I'll be honest. I look at users' email from time to time. Its not that I care, nor do i get some kind of voyeristic pleasure out of it. Its part of the debugging process at times. 99% of mail I've seen is completely uninteresting anyway.

      The big fuss is what happens when you see something that *isn't* completely uninteresting and, in particular, act upon it. This is even more important when talking about customer - as opposed to employee - communications.

      Better to just avoid temptation altogether, rather than have to make the difficult decisions of what to do should it someday strike. What mail problems are you debugging that requiring reading the *content* of *other people's mail* ?

    32. Re:Two words by Le+Marteau · · Score: 5, Insightful

      There was one other thing I meant to put in my original reply, but did not.

      Check this guy out. Study him, and those like him. You will find a similar trait, which I have observed most often in liars. Chronic liars think that everyone else lies like they do. That is key to understanding them. Likewise, this guy. He blithly goes on about how he reads other people's mail, as if it was a 'well, duh' situation, and as if ANYONE would do the same thing.

      This shithead is like the liars I've observed. He thinks that HIS 'natural tendency' to invade another's privacy is the way EVERYONE thinks. Well, his mode of thought is certainly common, but it is NOT the way everyone thinks. He thinks otherwise, which is one of the reasons guys like this are so pathetic. I've been a sysadmin. The thought HAS crossed my mind; hey, I could read anyone's email. But I CONCIOUSLY decided not to. This is what makes HUMANS different from ANIMALS. Animals do what comes natural to them, like the shithead parent. Human beings, true human beings (in the Dune sense here) actually have control of themselves and can aspire towards nobility instead of wallowing in animalistic voyeurism.

      Thank you for listening. I needed to get that off my chest. I'm just sick and tired of dickheads like the parent being the standard by which humanity is judged.

      --
      Mod down people who tell people how to mod in their sigs
    33. Re:Two words by Bazzargh · · Score: 2, Funny

      Thank you for listening. I needed to get that off my chest. I'm just sick and tired of dickheads like the parent being the standard by which humanity is judged.

      Earthling compassion surprise Morvo. Morvo will spare your puny world.

    34. Re:Two words by ThaReetLad · · Score: 2, Interesting

      The problem is, and IANAL but my brother is, and this is what he tells me, that under the US constitution only the government can violate your rights, not private individuals or corporations. Therefore having a right to privacy, or anything else for that matter doesn't help you very much against your ISP or even telco.

      I've just realised something though. Technically every email you write is copyrighted to you, and therefore your ISP storing it or archiving it is a breach of copyright. Anyone got a view on that?

      --
      You can't win Darth. If you mod me down, I shall become more powerful than you could possibly imagine
  2. Isn't it about time... by Nea+Ciupala · · Score: 5, Insightful

    ... to start using strong crypto for our email? The technology has been available for free for years now, so what's stoping us? Why this inertia?

    1. Re:Isn't it about time... by NanoGator · · Score: 3, Interesting

      ".. to start using strong crypto for our email? "

      Screw that. Use instant messaging. The reason why ISPs can read the mail is because it sits on their servers. Find an IM program that doesn't use a server to store the messages (i.e. I think that rules out ICQ...) and you're set. The only real problem then is packet sniffing.

      --
      "Derp de derp."
    2. Re:Isn't it about time... by Nspace13 · · Score: 2, Informative

      and on top of that you can always use AIM Encrypt

      --
      steal this sig
    3. Re:Isn't it about time... by cutecub · · Score: 5, Insightful

      Why the inertia?

      Confusion
      Complexity
      Laziness
      Cluelessness


      For me its always been a tossup between complexity and laziness. None of my friends would know what to do with a GPG public key if it hit them in the head, nor would most of them bother learning how to use it. You got it right with "Inertia". Overcomming this is like pushing a black-hole up-hill.

      -Sean

    4. Re:Isn't it about time... by DrEldarion · · Score: 3, Informative

      There are many problems with using instant messaging - You can't leave a message for a user that's offline (unless the message gets stored on a server, which defeats the purpose). You generally are subjected to a limit on how much text you can transfer in one message. File transfer doesn't work a lot of the time if someone is behind a router or firewall. Companies won't IM you instead of e-mailing you.

      The list goes on and on...

    5. Re:Isn't it about time... by Ark42 · · Score: 2, Informative


      You can leave a message offline using ICQ, and thats one of the biggest reasons I still use the ICQ network.

    6. Re:Isn't it about time... by nsandver-work · · Score: 3, Informative

      The only real problem then is packet sniffing.

      Even that's not an issue for GAIM users, thanks to the GAIM Encryption plugin.

    7. Re:Isn't it about time... by chill · · Score: 2, Insightful

      He was reading mail sent by Amazon. You expect Amazon to start using PGP for every e-mail query?

      No mention is made if he was reading other mail. I use GnuPG w/KMail regularly and I can't think of why I'd encrypt a book request to Amazon.

      I only use signatures and encryption on stuff that I think should have it.

      -Charles

      --
      Learning HOW to think is more important than learning WHAT to think.
    8. Re:Isn't it about time... by leviramsey · · Score: 3, Informative

      True, but the storage on an intermediate server places the IM outside (at least at that point) any protection afforded by the Wiretap Act.

    9. Re:Isn't it about time... by Tet · · Score: 2, Insightful
      I can't think of why I'd encrypt a book request to Amazon.

      So that when you do need to encrypt something, it doesn't stand out like a sore thumb, but rather it looks just like every other message you send.

      --
      "The invisible and the non-existent look very much alike." -- Delos B. McKown
    10. Re:Isn't it about time... by cloudmaster · · Score: 3, Insightful

      A stored message is not readable until the user has received it and elected to leave it on the server. Until the user has seen it, it's considered to be "still in transmission".

      While it can still be read, there are more restrictions on when that's legal if it's in transmission rather than in storage. /glad that the supreme court finally holds up the claims I've been making in flame wars with people who don't read the law ;)

  3. I'm confused by Anonymous Coward · · Score: 5, Funny

    There are people that don't run their own mail servers? Well, I suppose that might change now.

  4. We don't need any analogies. by h4rm0ny · · Score: 3, Insightful


    We don't need to say that this is like opening postal mail, or that RAM holding the email temporarily is like a modem caching the data. We don't need to compare this to anything to explain it.

    It is plainly and utterly stupid and wrong.

    Enough said.

    --

    Aide-toi, le Ciel t'aidera - Jeanne D'Arc.
    1. Re:We don't need any analogies. by drtomaso · · Score: 5, Insightful

      Sorry for not including citations of cases, but I believe the courts have held that email users have no expectation of privacy when sending mail over others systems (I think most pertained to University systems, but dont quote me). In fact, this makes sense- SMTP is inherently insecure, from a privacy perspective. If you want to compare it to snail mail, imagine mailing private letters with no envelope. Anyone between point A and B can read it. You cant complain if you later learn the postman read it when he was bored.

      That said, you must take the case in context- all that was ruled here was that a (technologically speaking) ancient wire tapping law didnt apply to this specific case of email, because the message was stored in RAM, not actually in transport. If the company had been snooping on packets coming from *your* mail server, I suspect the result might have been different. Further, no other law was tested here- the case was solely over this wiretap law.

      In a perfect world, no one would do this, and we'd all be sending encrypted mails anyway. What should be required is a privacy policy clearly stating the administrator's policy on email reading (ala Gmail), so that the educated consumer may choose the provider most suitable for his/her needs. If a company wants to read your mail in exchange for a free gig of mail space, I whole heartedly believe that to be within their rights, providing they are upfront about it. That this provider gave no warning of it was a non-issue as far as the case was concerned- only the wire tap law was ever used.

      Given the context of the case in regards to the wire tap laws, and the history of expectation of privacy in email, this ruling shouldnt suprise anyone. What we should be doing is pushing for European-style privacy acts and some sort of required disclosure for service providers pertaining to email snooping.

      I also dont see this as a danger to the common carrier status of ISP's-if indeed they ever had this status with regard to email. This ruling is very specific, and does not mandate that ISPs *must* read their users mail, only that if they do, they arent in violation of a specific wire-tap law. I believe what we have here is a judge who just refused to legislate from the bench.

  5. good thing... by chachob · · Score: 2, Insightful

    google isn't an ISP :D

  6. Implications for google? by Richard_at_work · · Score: 5, Insightful

    If ISPs are not breaking any laws reading users stored email without consent, then why was there a huge fuss about Google using a parsing engine to do the same?! I would have thought that a parsing engine was more in line with privacy than someone reading your mail!!

    I feel a tremendous schizm forming within the ranks of the American Legislature over this, with one side determined to force restrictions upon 'publicised' companies in an effort to make names for themselves, while the other side making rulings like this that will bearly make the main press. Something tells me not everyone is singing off the same hymnsheet.

    Something died a little today. That something was common sense.

    1. Re:Implications for google? by jgs · · Score: 2, Insightful

      why was there a huge fuss about Google using a parsing engine to do the same?!

      AFAIK this is the first case law on the subject, and up until now everyone assumed the courts would rule the other way. In other words, up until today most people assumed that it was a violation of the law for ISPs to read email.

      Now that the First Circuit has ruled otherwise, it'll be interesting to see what happens.

      Of course, if the ISP's terms of service indicate they won't read your email, you've still got civil law on your side, anyway. For what that's worth.

  7. oh no! by 2057 · · Score: 5, Funny

    Oh god now they will know about my massive addiction to penis enlargers! seriously i don't use my isp account for anything important if they wanna know about penis enlarging treatments go fer it.

    --
    For The Best Jazz/Hip-hop fusion > COlD DUCK
  8. Wait a minute by MoneyT · · Score: 4, Interesting

    If ISPs can read your emails, that stops them from being a common carrier anymore doesn't it? Which then means that they could be held legaly liable for any damages caused by illegal activity via email couldn't they?

    --
    T Money
    World Domination with a plastic spoon since 1984
    1. Re:Wait a minute by nate1138 · · Score: 2, Informative

      You didn't read the article, did you? BAD SLASHDOTTER! BAD! BAD! Now go sit in the corner and think about what you've done.

      Seriously, if you had read it, you would realize that the headline was completely misleading. The company reading the emails isn't an ISP. They are a web site that sells books. They also offer a free email service. They were reading the emails of the customers that signed up for the free email service, looking for Amazon.com orders and using that data to figure out how to compete more effectively. Immoral as hell? Yup. Illegal? Apparently not. ISPs, however, have different sets of rules, and it would probably be illegal for an ISP to do this.

      --
      Where's my lobbyist? Right here.
  9. isn't this irrelevant? by happyfrogcow · · Score: 3, Insightful

    Email is plain text. clear text. not encrypted. Now if this covered IPS right to read their users mail if it were encrypted, then that would be something else.

    It's clear text though, what do you expect?

    encrypt it

    1. Re:isn't this irrelevant? by happyfrogcow · · Score: 4, Insightful

      let me append this with the statement, don't put the government in a position to legislate something when we have the ability fix the problem ourselves.

    2. Re:isn't this irrelevant? by arkanes · · Score: 3, Insightful
      It's about expectation of privacy. People expect privacy in regular mail (because you have to open the envelope), but not in postcards (because it's right there for the world to see). The problem with email is that while technically, it's barely more secure than a postcard (a little bit. It's very hard to accidentally read email in-transit, almost unavoidable with a postcard), it doesn't APPEAR that way to the end user.

      Personally, I would have ruled the other way. Technical details notwithstanding, you DO have to proactively attempt to read other peoples email (misdelivered/misaddressed email is a different issue). The guy in the case certainly wasn't glancing at a post card on his way to deliver it - he was actively seeking out and reading these emails.

  10. Encryption by funk_phenomenon · · Score: 3, Insightful

    I think it may be a good time for people to start looking into ecryption.

    --

    Even the samurai
    have teddy bears,
    and even the teddy bears
    get drunk

  11. Fortunatly... by Mind+Booster+Noori · · Score: 5, Funny

    Fortunatly...

    1) I'm not in USA;
    2) I use gpg;
    3) I'm wearing that t-shirt.

    This is just as wrong as stupid: makes me remember how 2600 lost in court making links to illegal stuff illegal, when, after, others won in the same court prooving linking is just linking, not illegal (good for Google :-))

    It's frustrating when we clearly see that the laws are just bendable...

  12. So the loophole is... by Amiga+Lover · · Score: 3, Insightful

    The decision finds that the Wiretap Act does not cover interception of communications where the communications are being stored, not transmitted

    So now the loophole is telecomms carriers can store messages, and by storing messages they're allowed to listen to them.

    Of course, it's no use just to listen to a message to get info on what a subject is up to, it has to be stored for later use, so simply the fact of listening in to a phone conversation and recording it for later use makes it legal to listen to and store for later use.

    bah

  13. It'll never stand by Noose+For+A+Neck · · Score: 5, Insightful
    Hopefully, if the Supreme Court doesn't overturn this decision, then at least people will get outraged enough that they will write to their lawmakers to quickly remedy this problem. It's not just Slashbots that worry about privacy in email, this is a clear enough danger that I'm sure the non-IT public would be shocked if they heard about what was going on.

    And to those who think encrypting your email is the answer - it's not. The email sent to you can still be read, and many sites like Amazon, which is mentioned in the article, send automated emails to whatever address you provide them, making your communications easy pickings for unscrupulous ISPs.

    Of course, on the other hand, I'm sure some people here won't be surprised, and will in fact welcome such intrusion into their email, as evidenced by the enthusiasm here and elsewhere in geek circles for Google's Gmail service, which at least as intrusive and does the exact same thing with a user's emails (i.e. reads them for the purposes of marketing other products they think the user would be interested in). I'm still not sure what causes this cognitive disconnect in the technical community, but it is both puzzling and worrisome.

    --

    Software piracy is victimless theft.

    1. Re:It'll never stand by drgreg911 · · Score: 2, Insightful

      I can't speak for everyone else, but I think Gmail's intrusion is more benign because I was informed about it up front and it is something I have to accept with a free service. An ISP providing a paid service that I entered into with at least slightly more of an expectation of privacy....that's a different story.

    2. Re:It'll never stand by WuphonsReach · · Score: 2, Interesting

      Hopefully, if the Supreme Court doesn't overturn this decision, then at least people will get outraged enough that they will write to their lawmakers to quickly remedy this problem. It's not just Slashbots that worry about privacy in email, this is a clear enough danger that I'm sure the non-IT public would be shocked if they heard about what was going on.

      Ha ha ha ha!

      You want to know how lawmakers will "fix" it? Go look at what happened with analog cell phones and radio scanners. Instead of forcing the cell companies to protect their customer's voice traffic via encryption, they outlawed the devices which were able to eavesdrop on the plaintext transmissions.

      Now, imagine them applying that same tortured logic to SMTP and e-mail.

      --
      Wolde you bothe eate your cake, and have your cake?
  14. All my future emails by grunt107 · · Score: 2, Funny

    will be using Ray Romano's encryption scheme:

    I ehat het su ourtc fo ppealsa!!

    It's time to start skimming the gene pool

  15. Excellent by Quasar1999 · · Score: 3, Funny

    And to think I used to read all the cute girls emails at school when I was a temp sysadmin... it was all legal! w00t... I wonder if the extortion I did using the information I gleaned from their emails was equally as legal... oh well, I guess I'll never know... besides, how else is a geek supposed to get action in highschool? :P

    --

    ---
    Programming is like sex... Make one mistake and support it the rest of your life.
    1. Re:Excellent by cerberusss · · Score: 2, Funny

      We just read their mail too. It seems you need the penis enlargement that is commonly referred to in other threads here.

      --
      8 of 13 people found this answer helpful. Did you?
  16. cd /var/mail by DrSkwid · · Score: 4, Insightful

    grep -i -n -A 3 username * > password_list

    thanks for that

    --
    There are places where the networks are not touching,and there are places where they are-Boeing's Lori Gunter
  17. Let's make lemonade form these lemons by orthogonal · · Score: 4, Insightful

    The US Court of Appeals for the First Circuit (covering Massachusetts, Maine, New Hampshire, and Rhode Island) has ruled that e-mail providers are not violating the law by reading users' e-mail without the user's consent.

    In a way, I suppose, this ruling is a good thing, because it underscores the need for a comprehensive privacy and data retention law.

    What's needed is something along the lines of The European Union's privacy law: that is, something that is explicitly mandated, rather then the "penumbras" of privacy that some judges can, and some judges won't, see lurking between the lines of the Ninth Amendment.

    We can hope that this defeat in the courts can be -- with our hard work -- turned into a victory in the U.S. Congress.

  18. No problem by nizo · · Score: 3, Funny

    Simply include a picture of the goatse guy or tubgirl in every email and they will be sorry they ever read it.

  19. When will people learn by silas_moeckel · · Score: 2, Informative

    Email is not mail it's a post card at best. I see peoples mail regularly as part of work as it's going down the wire, it's not illegal as I'm performing maitence and troubleshooting for the companies that own the routers. Same goes for a random sys admin that needs to say fix an email box or generaly run the system. Your service provider has allways been able to do this. The post office can read your mail if they need to what do you think dead letter offices are for? Dont like it encrypt the contents and use anon remailers.

    --
    No sir I dont like it.
  20. Because email encryption has FAILED by Noose+For+A+Neck · · Score: 3, Insightful
    The technologies for encrypting email that have been offered up, most notably PGP, require too much learning and intervention on the part of the user while offering far too few tangible benefits ("Why encrypt my email? I have nothing to hide!") to make it worth the effort.

    I'm speaking here about an average user, rather than the tech-saavy crowd that populates Slashdot.

    --

    Software piracy is victimless theft.

    1. Re:Because email encryption has FAILED by garcia · · Score: 3, Insightful

      I'm speaking here about an average user, rather than the tech-saavy crowd that populates Slashdot.

      And the people that need to be encrypting their emails wouldn't be leaving them out in the open before this ruling anyway.

      Those that were concerned about privacy would have encrypted them or used their own service to deliver messages. I am *sure* ISPs are going to just love grepping through emails to look for whatever it is they are looking for.

      I seriously hope that ISPs have something better to do than that.

      [tinfoilhat]
      If anything, this was funded by the RIAA/MPAA/US Government to find out the subversive terrorists at the expense of those people that don't send important shit in email anyway.
      [/tinfoilhat]

  21. Re:Eh? by bladernr · · Score: 4, Insightful
    It has been ruled that ISPs are simply a carrier, but they can read the email?

    Wow, that got me thinking. ISPs are not held liable for piracy, hacking, etc, because they are a "common carrier." Common carriers have no knowledge of the traffic they carry, they are simply moving things from point A to point B. That limits their liability.

    Now, though, the court (in those jurisdictions) has ruled it is legal for ISPs to, at the least, read e-mail. Since it is ruled legal, and they are able, does that confer some responsibility to them?

    Thinking this through to conslusion, what are the odds that the ISP defending itself in reading the e-mail, has in fact increased its liability in all things its customer's do and have done to them?

    --
    Sarcasm and hyperbole are the final refuges for weak minds
  22. How about VOIP providers? by phr2 · · Score: 2, Interesting
    VOIP packets are temporarily stored in ram at the different routers they visit as they travel the network. Does that mean that VOIP providers can listen in on phone conversations?

    And what about the ECPA provision on unauthorized access to stored communications (Steve Jackson case)? Don't they apply here?

    1. Re:How about VOIP providers? by Jay+L · · Score: 3, Interesting

      How about VOIP providers? (Score:2, Interesting)
      by phr2 (545169) on Wednesday June 30, @05:04PM (#9575331)
      VOIP packets are temporarily stored in ram at the different routers they visit as they travel the network. Does that mean that VOIP providers can listen in on phone conversations?
      And what about the ECPA provision on unauthorized access to stored communications (Steve Jackson case)? Don't they apply here?


      I'm fairly sure they do - we always assumed we were bound by ECPA at AOL. It wasn't even questioned.

      I wonder if they just prosecuted the guy under the wrong law - wiretap instead of ECPA.

  23. Stored, not transmitted? Voicemail is the same... by Cytotoxic · · Score: 4, Interesting

    I don't think the judge understood what he was saying. In ruling that email messages are being stored, not transmitted he completely ignores the fact that the only reason that email is sent to an ISP is so that it will be transmitted. The asynchronous method of delivery really shouldn't enter into it. However, if that is the language of the law, then that is that...

    This ruling would also mean that you voicemail at your cellphone provider is wide open to being listened to as well... Nice...

  24. Lets be rational here... by dan_sdot · · Score: 5, Insightful

    Lets try to be a little rational here. I know that everyone is going to scream in the typical slashdot style about "invasion of privacy!!!!!", but lets really look at the problem.

    The first thing is to understand what the Judicial Branch's job is. It is to interpret the meaning of existing laws! And looking at the law, it seems that they did a pretty good job of this.

    So does this mean that I want my ISP's reading my email? Of course not!

    The problem is that the legislative branch is not creating laws that keep up to speed with the ethical problems presented by technology. Lets not get on the Judges' cases for the ISPs reading our email, get on the LEGISLATORS.

    In fact, I want to congratulate the judges in this case for making the ruling. Even though it is obvious that it is absurd that the ISPs are reading people's email, the judge did not overstep his authority by trying to create laws, rather than interpret them. This is one of the largest tyrannies that happens in US Politics, judges effectively creating legislation.

    So here is a call to all legislators: GET ON THE BALL! New technology has created many new ethical dillemas, and we need the legislators to start dealing with them.

  25. This is insane by 0x0d0a · · Score: 4, Interesting

    Wow. This is a huge, huge, huge deal.

    Among other things, this means:

    * Email, the dominant form of online communication, which most of us have regarded as fairly secure, is now grabable by federal authorities or police *without a warrant*.

    * Your employer may now read all your email -- previously, he had to at least inform you that he was going to monitor your network traffic ahead of time (admittedly, including such a clause in the usage policy was depressingly common, but still).

    * Free email providers like Yahoo, Microsoft, and Google now are free to do anything they want with all the mail that you've ever sent or has been sent to you.

    I'm sure that the EFF is scrambling to try and do something at the moment -- it'll be their most important case yet.

    *IF* this is not overturned, it means that it is *impossible* to have legal privacy protection for any form of communication that is asynchronous across hosts. This affects a vast number of potential protocols.

    This means that voicemail systems are *not* protected by federal wiretapping law. If you *ever* leave a message for anyone, your privacy protections are out the window.

    It's debatable over whether or not this applies to web caching -- if police and federal agents can now swipe the content of your ISP's web cache (yeah, the transparent proxy that your cable ISP uses, even though you don't think you're using a proxy), they can obtain web browsing data without warrant.

    This is the biggest argument I've seen yet for use of PGP. If you are not using PGP, you *have* no privacy.

    1. Re:This is insane by alienw · · Score: 4, Insightful

      which most of us have regarded as fairly secure

      True, if by "most of us" you mean "those of us who happen to be morons." Guess why nobody sends credit card numbers over e-mail?

      Your employer may now read all your email

      Most already do.

      Free email providers like Yahoo, Microsoft, and Google now are free to do anything they want with all the mail

      It's a free service. They should be able to do whatever the hell they feel like. Read the usage agreement.

      they can obtain web browsing data without warrant.

      If you think an ISP wouldn't cooperate with the FBI without a warrant, then you are a moron. If you happen to piss off the FBI, they can (after obtaining the warrant) seize all your computers and network equipment for analysis. This will pretty much mean the ISP won't exist anymore -- they generally take a few months to a few years to return the stuff.

    2. Re:This is insane by Rorschach1 · · Score: 2, Insightful

      Worse than that, where do you draw the line for 'storage'? IP uses packets. Between receiving a packet on one interface and sending it out another, a router STORES packets. Does it have to be non-volatile storage? Does that mean a mail server with a ramdisk spool isn't subject to this ruling? How long does a piece of information need to sit in one place during transit to be 'stored'?

      Looks like you're out of luck unless you've got a switched circuit all the way through to your destination.

      Let's hear it for analog...

  26. My Secrets are out. by cbovasso · · Score: 2, Funny

    Now my ISP will know I have a small penis, credit card debt, hair loss and can't function sexually.

    Chris.

    --
    I ask for a car and I get a computer. How's about that for being born under a bad .sig?
  27. slippery slope argument by KillerCow · · Score: 3, Insightful

    The decision finds that the Wiretap Act does not cover interception of communications where the communications are being stored, not transmitted.

    That's nice. So now they can use this precedent to listen to your voicemails.

    And if we move to VoIP on the telecom's backbone, then they can listen to your conversations... since it is being stored in the router's buffers alone the way.

  28. privacy? by rhaig · · Score: 4, Insightful

    so is there anyone out there who actually thinks your email to me is actually private and won't be read by an admin of a server that queues it for delivery somewhere along the way??

    it's email. there should not be any real expectation of privacy. deal with it.

    --
    "We are not tolerant people. We prefer drastically effective solutions"
  29. Re:Eh? by eaolson · · Score: 4, Insightful
    Wow, that got me thinking. ISPs are not held liable for piracy, hacking, etc, because they are a "common carrier." Common carriers have no knowledge of the traffic they carry, they are simply moving things from point A to point B. That limits their liability.

    There's a minor problem with your argument. ISP's are not common carriers

    http://www.cctec.com/maillists/nanog/historical/00 10/msg00012.html

  30. Maybe this is a Blessing in Disguise by dmarx · · Score: 2, Interesting

    Maybe this ruling will finally convince people to use freely avaiable encryption. I PGP as many messages as I can (I don't have anything to hide, I just don't like the idea of people snooping on me), but not many of the people I email use PGP.

    --
    "Do I dare disturb the universe?"
  31. Would you rather Spam Filters were Illegal? by Em+Adespoton · · Score: 2, Interesting
    Everyone seems to be commenting on how this invades privacy... however, did anyone stop to think what would happen if the decision had been the reverse?

    Suddenly, ISP-run antivirus filters and spam filters could make them liable for invading people's privacy. After all, even though these filters are automated, the server admins need to be able to verify they are working correctly.

    Plus, if nobody is allowed to read the mail, what about automated data miners? It's a slippery slope in both directions.

  32. Seems like it applies to phones too by RhettLivingston · · Score: 4, Interesting

    What about analog signal delay chips? What about digital phone systems that temporarily store signals in RAM? And if volatile memory is considered transmission instead of storage, what if they used MRAM in the future?

    Others summed it up with "stupid", but "stupid" just doesn't seem to come close.

    I'll bet some ISPs are madly looking at what they have that they could market to the tabloids. Anyone out there have some Senators or Representatives as clients? Publishing all of their email might get a law out quicker than you can say "stupid".

  33. I know this guy by Anonymous Coward · · Score: 2, Informative

    I know Mr. Councilman. He was a selectman in the town of Montague, MA and ran an ISP (www.valinet.com). The ISP was initially running on DEC Alphas and one day it went poof. It came back the next day running Linux on intel. The ISP claimed they went down due to a software upgrade gone wrong. What really happened was the FBI raided their office and took all of the hardware. I remember the call from the FBI agent in charge when he wanted to have me look over some files they found on the computers. It turns out that not only was Mr. Councilman reading peoples e-mails, He was also hacking into all of the other local ISPs to steal their customer lists. The FBI agent showed me a particial list of my /etc/passwd file. I could date it by looking into billing to find when the customers were created. I remember sitting in small claims court trying to get money from a customer when our servers crashed because of his hacking. I remember when Mr Councilman forwarded my CERT report of the event to a local newspaper and I recieved a call by an over zealous reporter. I remember when he was arrested and fined $250,000. I thought it was sweet justice for the greif he caused me and the other ISPs in the area. Mr. Councilman is not only a theif but a hacker. It is a shame that all he got was a slap on the wrist. His old ISP was purchased by another company and is still around. They purchased it about a month before the arrest.

    I really wished he saw some jail time. The guy is a jerk.

  34. Re:Eh? by leviramsey · · Score: 2, Informative

    As the original submitter, I've seen nothing to indicate that the ruling does not cover those who provide internet connectivity. As far as the law is concerned, providing e-mail makes you an ISP.

    Perhaps, in hindsight, it may have been more clear to say something like "e-mail providers" or "e-mail server operators."

    The ruling is essentially that any operator of an e-mail server may read at their discretion any e-mail stored on said server. There's no distinction between, say, Comcast or Verizon and Hotmail for this purpose.

  35. wronge charge maybe? by LuckyJ · · Score: 2, Interesting

    Seems like the charge under the Wiretap Act was not enforceable, but a charge of violation of the Electronic Communications Privacy Act should be:

    http://www4.law.cornell.edu/uscode/18/pIch119.ht ml

    Why didn't they t also charge a violation of the ECPA? Seems like the ISP would have gotten slammed into the ground on that one.

  36. ISPs can read e-mail? Finally. by Random+BedHead+Ed · · Score: 5, Funny

    ISPs can read e-mail? Finally. Now maybe someone at an ISP will reply to the several dozen "One of your customers is sending me spam" messages. It's about time ISPs got around to reading e-mail.

    Now to read the article ...

  37. encryption by CrimsonAvenger · · Score: 2, Informative
    This is why we have encryption software. This ruling pretty much reduces to "encrypt, or consider your email to be a postcard".

    And anyone who thinks it is illegal for the mailman to read postcards he is delivering is deluding himself.

    --

    "I do not agree with what you say, but I will defend to the death your right to say it"
  38. Okay Thunderbird, time to step up to the plate by Nom+du+Keyboard · · Score: 4, Interesting

    Okay Thunderbird, here's your chance to shine. Make sending and receiving of encrypted e-mail as easy as regular e-mail is now.

    --
    "It's the height of ridiculousness to say for those 9 lines you get hundreds of millions."
  39. And the REAL comedy is... ISPs should HATE this! by ChiefPilot · · Score: 3, Interesting

    I wonder if ISPs can now be held responsible for what passes over their network? An interesting collision between their Common Carrier status and their ability (perhaps implying responsibility) to read email.

  40. Implications for Gmail by Jonathan+Quince · · Score: 2, Interesting

    Wouldn't this automatically solve Gmail's potential legal problems, at least within Fifth Circuit jurisdiction?

    Now all we need is the Nineth Circuit ruling the same thing... ;-)

    I'm surprised that more people haven't mentioned this.

    --
    Microsoft Windows is, fittingly, the official Desktop OS of Olig
  41. Electronic Communications Privacy Act by bug · · Score: 4, Informative

    This ruling is just plain wrong. Here's text directly from the Electronic Communications Privacy Act. Straight from the definitions:

    (1) "wire communication" means any aural transfer made in
    whole or in part through the use of facilities for the
    transmission of communications by the aid of wire, cable, or
    other like connection between the point of origin and the point
    of reception (including the use of such connection in a switching
    station) furnished or operated by any person engaged in providing
    or operating such facilities for the transmission of interstate
    or foreign communications for communications affecting interstate
    or foreign commerce and such term includes any electronic storage
    of such communication;


    and then later...

    (17) "electronic storage" means--

    (A) any temporary, intermediate storage of a wire or
    electronic communication incidental to the electronic
    transmission thereof; and


    So, it pretty clearly states that wire communications includes storage incidental to the communication, such as the email temporarily existing in RAM on a system before being sent. Given that RAM is typically volatile, I don't see how you could NOT call it temporary, intermediate storage.

    There are no exemptions that I can find in the ECPA that might give this scumbag a way out of this. Either the judges are smoking crack, or the prosecutors failed to use the ECPA properly. I suspect it's more of the latter, as even the dissenting judge said that "the law has failed to adapt to the realities of Internet communications." This simply isn't true, because it's quite well defined in the law. The law HAS adapted to the realities of the Internet, and the ECPA is mostly quite adequate.

    Here's a mirror of the full ECPA text for those curious:

    ECPA text

  42. HIPAA by charnov · · Score: 2, Interesting

    Actually, if insurance or medical records are involved, HIPAA laws apply and the fines are big enough to make any company shudder.

    I tell you, if a company discloses any personal info of mine even with a subpeona involved, they can expect one heck of a long and vicious lawsuit.

    --
    [RIAA] says its concern is artists. That's true, in just the sense that a cattle rancher is concerned about its cattle.
    1. Re:HIPAA by iammaxus · · Score: 3, Interesting

      There are things they can do to oppose a subpoena and a contract they sign with their customer may require them to do whatever they can to keep information private. If they don't try, they may be in breach of contract.

  43. Karma Whoring by bani · · Score: 2, Interesting

    From a recent post on NANOG:

    Date: Wed, 30 Jun 2004 17:35:54 -0400
    From: Matthew Crocker
    To: "'nanog@merit.edu'"
    Subject: Re: E-Mail Snooping Ruled Permissible

    I know Brad Councilman, This all happened in my back yard. He ran a competing ISP with me (www.valinet.com). Not only was he reading his customers e-mail and harvesting Amazon.com orders he also hacked into 4 of the local area ISPs. I still remember the day I received a call from the FBI office in Boston. 'Sir, you are not in trouble but we would like to talk to you about an important matter. I'll be out tomorrow, when will you have time?' He came in with a old copy of my /etc/passwd file (this was hacked from me back in '95,'96). I was happy when the arrested him, he is a jerk. The ISP he ran has since been sold to another company, still local and run as an honest business.

    Sorry for the rant, I just wish he got more than a slap on the wrist. They didn't prosecute him on the hacking attempts because the e-mail theft was a bigger crime.

    Grrrrr

    -Matt

  44. Try Enigmail by RT+Alec · · Score: 2, Informative

    I disagree. I was a big proponent of PGP back in the old days (mid-90's). Back then, it was more cumbersome than complicated. Regardless of the effort to set it up, it still required too much effort on my part to encrypt or sign or decrypt each and every message. My circle of co-workers, contractors, and friends gave up on it after a short while.

    Recently, I have begun using Enigmail with GPG. It integrates quite nicely with Thunderbird, and I assume it would with Mozilla as well. We use it companywide, with Macs and PCs (ie OSX and Windows), and we convinced a contractor that uses Linux to use it as well.

    While the initial configuration did require some degree of effort, it was not too tough. Encrypting, decrypting, signing, and verifying is almost automatic now, requiring very little effort per message. My PGP (I mean GPG) password is queued for 15 minutes, so from time to time I have to re-enter it. All my messages are signed, and if the recipients are in my keychain, it is encrypted as well.

    I think if it is set up by a Slashdot-type person (and let's face it-- that's what most of us are paid to do), an "average" user should have no problem with it.

  45. My mail server is in Canada! by farrellj · · Score: 3, Informative

    Thank the Gods!

    In Canada, it is not legal for a company to read your private email, as email is treated like snail mail. This applies even if they are your employer!

    I really hope the US courts get a clue about privacy!

    ttyl

    --
    CAN-CON 2019 - Ottawa's only book oriented Science Fiction Convention! October 18-20, Sheraton Hotel, Ottawa, Canada h
  46. All digital communications is "stored" by ThinkTiM · · Score: 2, Insightful

    At all points in a digital communication the packets composing the message are stored in the memory of the devices involved in transmission (albeit for a short period of time). So does this mean that the wiretap law does not apply to any form of digital communication other than point-to-point where the end-points are owned by the communicating parties? It's fun when non-technical people create laws about technology....

  47. I'm so patriotic, by gillbates · · Score: 3, Funny

    I feel like starting an ISP and offering free email accounts to congressmen, judges, FBI agents, etc...

    The time difference between an embarrassing email leak and legislation outlawing reading another's email is left as an exercise for the reader....

    --
    The society for a thought-free internet welcomes you.
  48. good luck! by glwtta · · Score: 2, Funny

    Judging by my Yahoo inbox, all they will get from this is the world's most gigantic penis.

    --
    sic transit gloria mundi
  49. How this happened by dtfinch · · Score: 2, Informative

    The USAPATRIOT act reworded to wiretap laws so that stored electronic communications are no longer protected, as in emails or depending on how you read it, even packets in a queue. The suspected purpose of this is to enable interception of data on a network by law enforcement without the need for a wiretap. This effectly renders the entire wiretap law null, so long as law enforcement is willing to jump through the right hoops, which are now technical rather than judicial. The couple sentences of the Patriot act that did this were perhaps the most significant in the entire document, but so benign in appearance that they would be overlooked by many and the act would be passed by congress. Today in the USA, protections against nearly all the forms of privacy invasion that we had just 5 years ago are now mostly just illusions. Every privacy law I know of now has some loophole which allows the government to circumvent requirements of probable cause and judicial approval. This is why we should not reelect Bush. I was a registered Republican in 2000, but they are not looking out for any of us.

    Notice that many router manufactures (eg Cisco) have plans to integrate lawful interception features into their products, in anticipation of future demands of the US or other governments.

  50. The call for GMail encryption: 100% more relevant by geekotourist · · Score: 2, Interesting
    Back in April this story covered Brad Templeton's essay on GMail, privacy and encryption. I was suprised at the number of "email is public, get over it" comments. Why should I have to get over it just because encryption wasn't designed in from the getgo? Technologies have gone from public (non-private) to private and protected before. Consider the switch from party lines to private lines in the telephone system- we went from "all phonecalls are open/public unless you buy your own expensive line" to "all calls are private and its usually illegal for anyone else to listen."

    We- the technical community- can demand a similar switch for email. Unfortunately the use rate of encryption for email is ridiculously low (less than 10% of incoming to Diffie or Zimmerman, they once said). So we've ended up in this strange zone where email could be encrypted as a matter of course, but it isn't. There is no inherent reason why email has to be public, but by our design (or lack thereof), this major massive system of communications is practically (and with this ruling- legally) public, and for what benefit? Why do people so casually accept the non-privacy of email? Its like we were still using party lines 120 years later.

    At the core of it, because privacy is a fundamental human right every communication system we use should have privacy built in. If its not, there should be a very good reason why not. "Oh no, it will take extra computational cycles" is not a good reason (not with crypto like ECC around). "Oh, Ashcroft doesn't want it" is even a worse reason. "Perfect encryption is too hard for the public to use": also bad.

    Crypto does need to become easier to use. As Templeton wrote here on what email crypto needs:

    The key to deploying encrypted mail is to make it happen with close to zero involvement by the user. This is hard, and requires some security compromises that have made cryptographers uneasy in the past.

    However, I have come down to the view that getting encryption widely deployed, even with some minor flaws, is better than getting perfectly designed encryption (if that's even possible) that hardly anybody uses.

    The reason is that I exchange mail with tons of people, not just my closest linux-using nerd friends. If I want my mail to be private, I have to get the general public encrypting. This is a particular concern with new laws just passed granting U.S. law enforcment the power to read the "header" of a message -- including the subject lines of E-mails without a warrant. In addition, other nations have always had such powers, and on top of it all, most ISP backbones and mail servers are poorly secured from snooping by almost any system cracker trying to invade your privacy [now including the ISP itself!]...

    Problem is, the current UI and ease of use for encryption add-ons aren't so good. It makes it a tough choice to use it other than with other geeks. Not that you force everyone to use crypto in email, but it should be as easy to choose it as to not choose it. As an analogy, if I say "lets start building doors and doorjams with locks built in," that doesn't equal "force everyone to lock their door." It does mean "its now as easy to choose to lock your door as to keep it unlocked." To me choice means the two alternatives are sitting there, equally available... If there were big "Send: This is Private" and "Send: This is Public" buttons on every email program. Right now the "choice" is "Send" vs "Spend hours retrofitting your system and writing to your recipient to explain to them how to read your email, and getting your grandpa to use it- just give up trying to go there..."
  51. Steve Jackson Games by SiliconEntity · · Score: 2, Informative

    This all goes back to the Steve Jackson Games decision of 1994. The Secret Service had seized a BBS belonging to Steve Jackson Games, and SJG sued because the computer also held some unretrieved private email. However, SJG lost on the same grounds as in this case, that email in storage is not protected by the literal language of the Wiretap Act. It may be a technicality, but it's been the law for over ten years.

  52. Not protected from your ISP as it is.... by Vancouverite · · Score: 2, Informative
    The calls for using the Stored Communications Act would probably have failed as well. Based on 18 USC 2701:

    (c) Exceptions.

    Subsection (a) [Offense] of this section does not apply with respect to conduct authorized -

    (1) by the person or entity providing a wire or electronic communications service;

    Since the person in question was the "... person ... providing a wire or communications service", the Offense section of the act does not apply to him, if he authorized the access. No offense, no crime.

    <bad music tune="Feelings">
    Loopholes,
    Nothing more than Loopholes,
    Trying to prevent those,
    Criminal Aaaaaaaaaaaaacts!
    </bad music>
    --
    We are the Music Makers, and We are the Dreamers of Dreams...
  53. I just know I'll get flamed for this one... but... by Reteo+Varala · · Score: 2, Insightful

    I actually agree with the ruling, for several reasons.

    1: This will bring more attention to privacy tools like any OpenPGP-compatible program, such as the GNU Privacy Guard, than any law preventing law-abiding citizens from thumbing through your emails.

    2: The ISP is providing a service using their own equipment. While laws might help, remember that it IS their OWN damn equipment, and if they choose to, there's little you can do if you're not aware of it.

    3: The ISP is not the only point in which any mail can be read. Any number of mail backbones can also store a message for perusing later. This is especially true in the case of those undeliverables that are logged for later review. To focus the blame on an ISP is a fallacy.

    Personally, I think that people should have little fire lit under them to get themselves protected. I will admit that it's a bit of a bother now, but as soon as vendors see the market value of such systems, how long until it's easy enough for aunt Maude?

  54. A new shirt design. by BlueTooth · · Score: 2, Interesting

    Thinkgeek should create a new shirt design.

    Front:
    i read your email.

    Back:
    legally.

    --
    SPAM
  55. I know him - he's not a bad guy by pestie · · Score: 2, Insightful

    I actually know the defendant in this case, Brad Councilman, personally (although it's been quite a few years since I've had any significant contact with him.) He's a good guy and he pretty much had his life torn apart for several years by overzealous prosecutors looking to make a name for themselves by looking tough on "computer crime." What he did wasn't necessarily right, but he certainly didn't deserve to be treated as a criminal for it. I'm not going to get into a debate with anyone about this right now - I doubt I'm going to change anyone's minds, but think about this: if this guy had the words "accused hacker" before his name in these headlines, how many of you would be rallying to his defense instead of looking to crucify him? If his name were Kevin Mitnick, how many of you would be complaining about how this country is turning into a police state instead of acting like some sysadmin reading your e-mail is a human-rights violation on a par with the Rodney King beating?

  56. Re:The judges are neither stupid nor ignorant by ky11x · · Score: 4, Informative

    Sorry, first time through all my quotation marks and apostrophes were swallowed.

    There are many comments here about how the judges must be stupid and don't understand the technology, and that's why they ruled this way, etc. etc.

    I find it obnoxious that many of the commenting /.ers apparently never bothered to read the opinion or try to understand what the court is really deciding and the grounds for their decision. The article submitter is himself one of the greatest sinners in this respect.

    Listen to me. Unless you try to understand what the law is and how judges are supposed to apply the law and read this decision carefully, you are not giving them the level of respect that you expect them to give to you, the technical community. The judges work with a technically complex and intricate art, much like us programmers. Moreover, the judges' actions have profound consequences: they send people to jail and make people pay millions of dollars to each other with their pronouncements. That's an awesome responsibility. Do you really think they are "stupid" just because you may not understand their decision at first glance?

    Let me try to explain what is going on in this case.

    First, this is a criminal case. The government is charging the defendant ISp with violating the Electronic Communications Privacy Act ("ECPA") or commonly called the "wiretap act." In a criminal case, the courts try to construe the statute as narrowly as possible so that they make sure the government is only sending people to jail when it's clear that's what Congress intended. That the courts are careful in this manner is a good thing , if you value our freedom.

    Next, the court looked at the statute carefully and found that it defines two types of communication: "wire communication" and "electronic communication." It then noted that the statute clearly gave different levels of protections for the two. Wire communication is given a lot more protection than electronic communication. Whereas "interception" of wire communications while in transmission and while in "electronic storage" is clearly illegal, only "interception" of electronic communication is made illegal. The statute made it clear that obtaining an electronic communication while it's in electronic storage is not covered as a punishable crime. Congress quite clearly meant for different treatment to be given to wire communication versus electronic communication. Electronic communication in electronic storage are just not covered by the statute.

    Thus, the court ruled that the government couldn't prosecute the defendant under the ECPA.

    THAT'S IT! Okay? That's all the court held. Just that the government can't prosecute the defendants under this particular law. They are not saying "ISPs Can Read Your Email" -- as the headline sensationally claims. They are not saying privacy is not important. They are not saying emails are equal to postcards. They are just saying that this particular law did not cover what the defendants did. That's all.

    And quite honestly, the court is doing its job correctly. For the court to rule the way most of you would like here, the judges would be making law, and what's worse, making a criminal law. Most of us would be appalled by that idea. Congress should do so, not the courts.

    Let me be clear, the judges here understood what was going on technologically very well. They recognize the force of your arguments and concerns about privacy, but their hands are tied. They lament, quite movingly, that "it may well be that the protections of the Wiretap Act have been eviscerated as technology advances" and go on to say, "We observe, as most courts have, that the language may be out of step with the technological realities of computer crimes." This is a clear call for Congress to do something about the problem.

    They are interpreting the law as they should, and the ancient wiretap act clearly was made at a time when people didn't care much about "electronic communication" and it is our duty to convince Congress to change the law so that the courts will have the power to hand out justice to these privacy violators.