Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yeah, this does absolutely not solve the CLOUD Act issues. However, it is good to look at what the ramifications of the CLOUD Act is for e-mail:

- The US could request your data. You probably shouldn't use e-mail for anything sensitive anyway for many reasons. E-Mail was traditionally not encrypted and I think that many servers still allow plain-text communication. The protocols are old and there are all kinds of downgrade attacks. Aside from that, even if your service does not fall under the CLOUD Act, you are probably f*cked anyway, because most people you communicate with are using services that fall under the CLOUD Act.

- The US can force the provider to block your account. The workarounds are: regularly backup your e-mail (easy for services that offer IMAP) and, most importantly, use a domain with an extension that is not under the control of a US (or probably five eyes) registrar.

Use an E2E-encrypted messenger with perfect forward secrecy, etc. for most personal communication.



Email itself is not encrypted but the links between email servers are. That makes it non-trivial to intercept email.

However, most people these days are using webmail from the big-tech companies which makes it relatively easy for LEA and intelligence agencies to read your email.


Something like 99% of email is now done over TLS.


Yes but it will almost always work with self signed or expired certificates, or downgrades to clear text if that's what it takes to deliver the message.


I thought a few years ago Gmail started demanding TLS so now any mail server that anyone cares about supports TLS.


I had a mail server running with a LetsEncrypt cert. I never set up the cron job to renew it, and months later realized that the certificate had expired. Gmail never glitched sending mail to my server. This was some time in 2025, so not too long ago.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: