The Chinese Solar Machine Layer by Layer Fire in the Library The Mystery Behind Anesthesia
(Page 3 of 3)
Far more troubling for me, however, is Gmail's data security story.
Like privacy, security is a much deeper concept than most Internet users realize. Being free from spyware and viruses is important, certainly. But so is data integrity -- retaining data whole, without additions, deletions, or other modifications. While Google provides a ton of storage and great availability, there is no obvious way to back up your e-mail once it has been delivered, read, and archived. This means that you have no choice but to trust Google totally for your data integrity.
But nowhere in Gmail's "Terms of Use" does the company promise that it won't delete some or all of your mail -- now, or in the future. In fact, the termination clause of Gmail's policy gives the company the right to delete any account, for any reason, at any time, with no user recourse.
Gmail could provide a backup system, of course. Google Desktop already downloads mail in the background for offline access, and it would be trivial to let users save that e-mail in archive files on their hard drives, for subsequent burning onto CD-ROMs or DVDs. Perhaps Gmail will do this in the future. But it doesn't do it now.
The mere existence of that huge archive of personal e-mail -- an archive that can neither be backed up nor deleted on demand -- should give users pause. For example, such an archive could become a one-stop-shopping destination for subpoenas in civil litigation and criminal investigations. Gmail's early adopters now have nearly two years' worth of mail archived in the system -- an attractive body of evidence in, say, a nasty divorce proceeding.
The preservation of old messages wasn't previously a concern because earlier online e-mail providers like Hotmail didn't offer their users enough storage. Also, folder-based archives give users a strong incentive to throw most messages away rather than keeping them all. And of course, if you download your e-mail with POP (the post office protocol) and keep it on a hard drive in your living room, you are responsible for the security of your mail -- and you have the option of fighting a subpoena in court rather than turning over your files.
Many of my concerns could be addressed through the clever use of encryption. Mail could be encrypted while stored on Google's servers and only decrypted when it is displayed to Gmail users. This would dramatically reduce the risk of a subpoena: now an attorney fishing for incriminating documents would have to demand not just e-mail but also the user's decryption key. This would give users more opportunities to fight subpoenas -- or perhaps to "lose" their keys.
Whether or not these risks actually matter to you depends on what uses, if any, you make of the Gmail service. But how Google responds to persistent concerns about privacy and data security should matter to everyone who uses the Web. For better or worse, Google remains the hottest Internet company on the planet -- and the example it sets with Gmail will shape the products and policies of hundreds of other companies using Ajax technology to build new Web-based services.
Home page image courtesy of Jason Schneider.
Simson Garfinkel is a postgraduate fellow at Harvard University's Center for Research on Computation and Society.
Everybody wants to read your mail
Ever since there has been email, there has been controversy as to how private it is. In the early years thru the 90's many ISPs had no way of going through all of the data, so they hired 3rd party developers to create "sort-n-serve" tools that we now call search engines.
If you think that google is the only one looking for the keywords in your inbox, think again.
What do you think Hotmail, Yahoo, and AOL have been doing for years. They may not be as direct as google and TELLING you that they are doing it, but they are.
Fool yourself all u want, but the truth is everyone of the services u use wants to use your data as a way to advertise or to forcast trends and social movements.
As for me I don't care if they read my mail, so long as I can download the file into my thunderbird app and take it with me. The only real option for privacy is to stop using the internet and your cell phone. Good luck with that.
Manufacturing in the United States is in trouble. That's bad news not just for the country's economy but for the future of innovation.
Our list of the 50 most innovative companies, including the following:
Guest (Daniel)
This article has no point
There is no difference in security or privacy between gmail and other e-mail services. All e-mail, when not encrypted by the sender, can be stored and read by the e-mail service you use. There is no guarantee that POP e-mail is not stored for a long time after you download it. Nor is there any guarantee that messages aren't deleted before you download them. Also, gmail alows you to access it as a POP account and download messages that way. The article hilights problems with unencrypted e-mail in general but none of these are specific to gmail.
Reply
wut
5 Comments
Oh yes it does.
At least the other providers don't scan through my emails for the ads.
Reply