Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Single point of failure.

Okay?

> Government entities have to go through physical work to seize multiple mail servers distributed geographically. This keeps the cost of fishing expeditions high enough that they won't just do it by default.

Except they seem pretty seize-happy and the only thing protecting your house is the say-so of a judge.

> With everything at Gmail, Yahoo, and Microsoft, you only need to serve 3 entities, who already are known to roll over.

That seems quite unfair, as at least 2 have been very public about their expenditures to try and make such attacks impossible in the future, and have vocally fought subpoenas.

> Do you want the companies most likely to buy you out for a large value to be the ones holding all of your internal emails?

Yes. The lawsuit should I discover it would probably make me richer and more famous than all the buyout events I've experienced.



> Except they seem pretty seize-happy and the only thing protecting your house is the say-so of a judge.

You're being obtuse. Even if every judge rolls over, if you have to seize multiple email servers in multiple jurisdictions, the paperwork represents expense and time that law enforcement simply will not do unless they have a really strong reason. "People are lazy" is the universal constant. We fear computerization of things precisely because computers aren't lazy.

> That seems quite unfair, as at least 2 have been very public about their expenditures to try and make such attacks impossible in the future, and have vocally fought subpoenas.

That's what they say publicly. However, if they roll over for governments like China, they're going to roll over for the US who can genuinely affect their revenue stream.

> The lawsuit should I discover it would probably make me richer and more famous than all the buyout events I've experienced.

Your naivete is touching. Google wouldn't do anything actionable. They scan your email store and know not to invest. You'll never prove anything for a passive non-action like this.

Even for positive action failures, it's very difficult to prove. This is the whole point of "parallel construction". You dragnet to find something incriminating, and then build the legal path to what you now know to search for.


So. Let's just put this in perspective.

Your trivial additional inconvenience running what sounds like a non-trivial geographically dispersed non-cloud-service email system warrants not calling out services with poor mail transit security. So millions of customers improved security vs you figuring out how to use LetsEncrypt. Because Google subsidizes the free service with ads.

I do not follow this logic, but what's more:

> Google wouldn't do anything actionable. They scan your email store and know not to invest. You'll never prove anything for a passive non-action like this."

Yeah well having sold a few companies to a few mega-nationals, we try to be honest and deserve the acquisition, as opposed to trying to fleece people. Lame-duck acquisitions shit on employees for investor gain, often for investment clawback and exit.

But also, if you are a paying edu or org customer, they stop scanning for and serving ads.

So forgive me if I don't feel a ton of empathy towards your strong desire to be dishonest in a hypothetical google acquisition where they hypothetically do this.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: