Skip to content

Policy

German firms aren’t allowed to say anything if they have to hand data over.

Last week, a United States federal appellate court unsealed a set of documents pertaining to Lavabit, the e-mail provider of choice for former National Security Agency contractor Edward Snowden. The documents show that Lavabit’s founder, Ladar Levison, strongly resisted government pressure that would have resulted in the privacy of all users being compromised as a way to get at Snowden’s e-mail. Levinson went so far as to shutter the company, destroying its servers entirely.

“People using my service trusted me to safeguard their online identities and protect their information,” Levison wrote in a press release last Wednesday. “I simply could not betray that trust.”

The Lavabit case is the best known example of a company willing to go to extreme lengths in order to protect its customers’ privacy. Since Lavabit has fallen (as has Silent Circle’s Silent Mail service), many journalists and business people have speculated that foreign e-mail providers might have policies that would theoretically be more resistant to government intrusion, particularly in Europe and especially in Germany and Switzerland, which have strong data protection and privacy laws.

But a closer look at German law in particular reveals that a German e-mail provider certainly wouldn’t offer more protection—and would likely offer less—than a similar American e-mail provider.

In recent weeks, I’ve set up e-mail accounts at two alternative mail services, and I’m considering switching away from Gmail to one or both of these companies as my primary personal e-mail account. (Here’s my PGP key.)

While there are many choices out there, we’re going to focus on one American service (Riseup.net) and one German service (Posteo.de) to better understand what foreign privacy policies state and what their legal requirements actually are. I chose Riseup because it’s a longstanding US-based alternative for the privacy-minded and Posteo because it’s a similarly marketed German alternative. Like nearly every other e-mail provider, both offer POP and IMAP support as well as a webmail interface—but they’re very different in the promises that they make.

Clearly, properly encrypted e-mail offers the best security for messages both in transit and at rest. But as many Ars readers who have acted as informal tech support for their non-techy friends and family can attest, relatively few people are going to be encrypting all their e-mails by default anytime soon. So the next best thing might just be to choose an e-mail provider that will collect as little of your information as possible and will not easily turn over what other information it does have, such as IP logs or even user e-mail accounts themselves. (And yes, you can roll your own mail server or have proper hosting—but a lot people want just turnkey e-mail. Again, think about what your family members use.)

“In terms of privacy, anything is better than Google, I’d guess,” Ralf Bendrath, a senior policy advisor to a German member of the European Parliament, told Ars. “In terms of usability, of course not. Everybody has to decide for himself or herself where the priorities are, I guess.”

“Y’know, principles”

Lavabit’s own privacy policy at the time that Snowden was believed to have been using it stated that “premium users” would benefit from having their e-mail secured with “an asymmetric encryption process that guarantees that it can’t be accessed by anyone except the holder of the account password. For these accounts, only the encrypted version of the message is ever saved to disk.”

Lavabit’s policy further stated:

It is also important to know what information Lavabit does NOT store. We do not keep a record of the IP addresses used to access our services (except in the web server logs), and we do not keep a record of what information was accessed during a particular session.

In other words, Lavabit was providing a very user-friendly way to protect its customers’ e-mail, even from Lavabit’s own staff, and it appeared to minimize its other data collection.

By contrast, Google says that it collects a ton of information about Gmail users:

When you use our services or view content provided by Google, we may automatically collect and store certain information in server logs. This may include:

Location information

  • Details of how you used our service, such as your search queries.
  • Telephony log information like your phone number, calling-party number, forwarding numbers, time and date of calls, duration of calls, SMS routing information and types of calls.
  • Internet protocol address.
  • Device event information such as crashes, system activity, hardware settings, browser type, browser language, the date and time of your request and referral URL.
  • Cookies that may uniquely identify your browser or your Google Account.

When you use a location-enabled Google service, we may collect and process information about your actual location, like GPS signals sent by a mobile device. We may also use various technologies to determine location, such as sensor data from your device that may, for example, provide information on nearby Wi-Fi access points and cell towers.

Perhaps as a result of the recent focus on privacy policies like these, I’ve recently noticed a couple of people in my social circles switch from Gmail to Riseup as their primary e-mail provider.

“It’s annoying, actually, but y’know, principles,” Jillian C. York, an activist at the Electronic Frontier Foundation, wrote to me recently when I remarked on the change noted in her e-mail signature.

“Two inboxes in Thunderbird is a pain in the ass. I’m constantly sending e-mails from one when I mean to from the other, which—when you address private mailing lists as much as I do—is a real problem.”

And will she be deleting her Gmail account?

“I probably won’t,” she said. “Frankly, Gmail is a far better organizer of data than any existing tool, so I’ll continue to use it for mailing lists. I am trying to shift all personal correspondence off, though (she says as she replies from Gmail…).”

“We would rather pull the plug”

Riseup’s details.

Riseup’s details.

Many privacy-minded e-mail users have long used Riseup, which since 1999 has described itself as a “friendly autonomous tech collective.” An archived copy of its website in 2000 notes that Riseup.net “offers permanent, free e-mail accounts to individuals and groups who are fighting the good fight against racism, sexism, environmental destruction, homophobia, corporate power, or capitalism.” The company promises:

We will never disclose your e-mail address to anyone without your permission.
We will never include advertising on our website or in your e-mail.
We will never charge for your e-mail account.
We will never go away and leave you without an e-mail account.

The entity behind the site is unknown, but the site’s lawyer appears to be Devin Thierot-Orr, a law professor at Seattle University. He was listed as a contact on a press release describing a 2012 seizure of one of Riseup.net’s shared servers in New York City.

He was also quoted in a 2010 story in the New York Times saying that Riseup was “started with a handful of accounts on a few donated PCs stashed in someone’s basement,” and that “ten years later, we are still volunteer-driven and have a large user base from all over the world.”

When Ars tried to contact Thierot-Orr, his voicemail said he was out on paternity leave, and he did not respond to a request for comment by e-mail.

Still, Riseup’s privacy policy clearly states that the group will take an aggressive stance: “We will actively fight any attempt to force Riseup Networks to disclose user information or logs.”

And it explicitly says that it would sooner commit a Lavabit-style shutdown than submit to government or court orders. “We will do everything in our power to protect the data of social movements and activists, short of extended incarceration,” the group wrote in an August 2013 newsletter. “We would rather pull the plug than submit to repressive surveillance by our government, or any government. We are doing everything we can, as quickly as possible, to forge forward with options that would prevent us from having to shut down, in case we are faced with making such a decision.”

So what’s the catch? Well, for one thing, Riseup only offers a pretty small amount of data storage.

Quota: Your quota will start at 25 megabytes and may increase over time. We have less storage space than most commercial providers because we do not believe in continuously throwing away good hardware to buy new hardware. Also, fast, high quality, redundant disk storage is very expensive.

When I signed up, Riseup actually gave me 92 megabytes of storage. That’s OK for now, but I’m certainly not going to be sending huge attachments with it anytime soon. Anyway, I’ve got Dropbox, WeTransfer, and other related services that I can use as backup if necessary. As Riseup reminds me: “If you increase your quota, we need you to increase your contribution!”

“We do not stand above the law”

What about Posteo or other European-hosted e-mail services?

First, getting started with Posteo is a bit trickier, as its site is entirely in German. I lived in Germany for two years, so I speak enough German to navigate my way around the website.

Second, from a financial perspective, Posteo makes a point of charging its users €12 (or $16.28) per year of usage in exchange for 2GB of storage. As a bonus, the company claims that its service is “100 percent green powered.” Paying €12 is also made significantly easier if you already have a eurozone bank account, which I do. But you can also pay completely anonymously by simply sending €12 in cash through your postal system of choice.

But while Posteo has the benefit of offering its customers the shield of German data protection and privacy laws, it explicitly acknowledges a sad truth that most e-mail providers don’t: it can’t really protect your e-mail from its own staff—or from law enforcement.

Posteo’s policy (originally in German) states:

All of your messages can be viewed at any time, from a technical point of view [by] us if they were not encrypted by you. We assure you that we won’t make use of this ability and will neither view nor use this data.

When I asked Posteo to explain this more fully, I got an e-mail back from Patrik Löhr, a spokesperson. He, like most independent security experts, recommended “personal encryption via PGP/GPG or S/MIME.”

“We don’t promise secure mail storage ‘against’ police investigations, [and] we do not stand above the law,” Löhr told Ars. “We don’t want to protect criminals—we want to give as much privacy as we can to our users. Not only police [are] a ‘problem,’ [we’re also worried about] criminals, like [those] you could see in the news about Adobe losing user data.” (You can read Ars’ coverage of the Adobe hack here.)

But, he notes, because Posteo never asks its users for names, addresses, or payment details, their accounts are more protected. (Riseup’s signup policy is the same.)

“This protects every mailbox in a simple way, because we can’t answer questions like ‘who owns mailbox XY?’ or ‘which mailbox belongs to XY?’” he said.

Löhr continued: “There is an exception for e-mail providers in German telecommunication law, which says that you don’t have to ask a customer for his or her name and address if you don’t need it. Telephone providers have to ask these things, for example. If the police investigate a serious crime—murder, money laundering, human trafficking, and so on—and [are] able to convince a judge to sign a user data request, we would have to hand over a mailbox manually. But only if the police knows the e-mail address, because we don’t know names. There is no automation and no direct access by police or intelligence agencies. There are no secret laws in Germany and no secret courts.”

But don’t forget that Germany and the United States have a Mutual Legal Assistance Treaty, which means that if the US wanted my data, it could fairly easily serve Posteo with an American court order through that process. The German judicial and law enforcement process would then take over, and it’s likely that I would never know about it.

A gag order by default

Signing up for a Posteo account.

Signing up for a Posteo account.

However, while Löhr may be convinced that there are no secret German court orders like those set by the Foreign Intelligence Surveillance Court, at present, even if Posteo got a court order, it couldn’t tell anyone.

“German law forbids providers to talk about inquiries for user data or handing over user data,” Löhr added. “We are currently investigating a possible way with our lawyer to issue a transparency report about questions from police like Google, Microsoft, and [many] other US providers do, but we can not promise we will be able to do so. We try hard.”

Indeed, the German Telecommunications Act of 2004 (PDF) states very clearly, “The person with obligations shall maintain silence vis-à-vis his customers and third parties about the provision of information.” In other words, German communications services would be under a gag order by default.

In America, the targets of criminal search warrants almost always don’t know those warrants are coming, as they’re typically sealed. The United States also has National Security Letters, which prevent recipient companies from speaking about searches publicly. And as the Foreign Intelligence Surveillance Court has come under greater scrutiny, it’s become more common knowledge that its orders are sealed as well.

So while Germany may not have secret courts, its e-mail services still have to adhere to court orders that cannot be disclosed to its targets. However, an American provider could notify its customer that he or she is the target of a judicial investigation. Google has a user notification policy, for instance, that stands unless the court forbids it from disclosing that information. (But Google also admits that it is tracking much more information about you!) German court orders, by contrast, appear to be sealed automatically.

Löhr also added that Posteo could challenge a secret court order after the fact, unlike in the case of the United States, where such challenges can be made before such a handover.

“If we think the order was not right, we can complain afterwards—and we would do so,” Löhr told Ars.

Worse still, it also seems that many other European Union countries also give providers the right to challenge a secret court order, but again, only after the data has been handed over.

“There is an option to challenge that request [in the Netherlands], but only after it has [been] given the data,” Ot van Daalen, the director of Bits of Freedom, a Dutch digital rights group, told Ars. “A successful challenge leads to an order of the court to destroy the data. In the case of possible privileged communication, in practice the data is sealed in an envelope pending challenge and only opened after the data is deemed to be unprivileged by the court.”

The other thing to keep in mind is that pesky national security exception.

“[European Union] law does not explicitly protect against access by European intelligence services, but member states law and practice does,” Ralf Bendrath, the senior policy advisor to a German member of the European Parliament, also told Ars. “So maybe you would not want to use a United Kingdom-based provider after what we know about [Government Communication Headquarters, the British counterpart to the NSA], but the German BND [Federal Intelligence Service] has legally and technically much more limited powers than the NSA. We are currently trying to figure out if and how handing over data to EU-based spooks agencies is also limited by EU law—this is part of the ongoing inquiry in the [European Parliament] into the Snowden files and related issues.”

So where’s my pen and paper?

Smári McCarthy. Credit: tomislavmedak

After talking with activists and lawyers alike, I’ve come down to one conclusion: protecting e-mail is hard. I encrypt my e-mail as a matter of course when I can, but the vast majority of my personal correspondence remains unencrypted. Of course, I’ve started to remind myself of a long-standing rule that I’ve had about things I post online: don’t do it unless you’re OK with it becoming public later on.

Of course, if that data isn’t collected to begin with, then there are fewer possible legal vulnerabilities.

“If you have thousands of similar databases from private companies profiling people everywhere all the time, law enforcement has access to those databases,” Amelia Andersdotter, a Swedish Pirate Party member of the European Parliament, told Ars. “If, on the other hand, the database creation is avoided, law enforcement will not have access to the database which isn’t there… I think the US is a perfect example of this: your private companies make loads of databases which then the government of course can expropriate. The best way to protect personal information is to not collect it in large quantities everywhere for privacy invasive purposes—that goes for both the public and the private sector.”

So the easiest way to make sure my e-mail isn’t transmitted to a third-party is obviously to not send it to begin with. After all, as Ladar Levison of Lavabit has said: “If you knew what I know about e-mail, you might not use it.”

At the end of the day, is Riseup the obvious best choice? Perhaps. But there’s also another problem: the service has become so well-known that some fear that simply by having a Riseup account, one automatically becomes suspect.

“With all due respect to the good folks at Riseup and the good work they’re doing, using a Riseup account is akin to drawing a big fat bullseye on your arse,” Smári McCarthy, an Icelandic-Irish data activist and the executive director of the International Modern Media Initiative, wrote to Ars. “A system designed by activists for activists is by definition a honey pot as far as law enforcement is concerned.”

So what would be a better alternative? In my case, I happen to be a former customer of Sonic.net, a small privacy-minded ISP in Northern California that many tech geeks (including the Electronic Frontier Foundation) love. Among other benefits, Sonic famously destroys user data after 14 days, which is not true of most providers. It is also notorious for going to court to stand up for the rights of its users.

It occurred to me while I was reporting this story that I could actually resurrect my old Sonic account. While I’m no longer a customer, Sonic has never turned off my e-mail capability, and when I asked them about this, they confirmed that former customers do get to keep their e-mail.

For now, for personal e-mail, I’m using a kludgy combination of Gmail, Sonic, and Posteo. Gmail for all new incoming mail (like Jillian York, I use it largely for e-mail lists), Sonic for sending new e-mail, and Posteo for its encrypted address book and calendar functions. It works, for now.

Photo of Cyrus Farivar

Cyrus is a former Senior Tech Policy Reporter at Ars Technica, and is also a radio producer and author. His latest book, Habeas Data, about the legal cases over the last 50 years that have had an outsized impact on surveillance and privacy law in America, is out now from Melville House. He is based in Oakland, California.

121 Comments

  1. Listing image for first story in Most Read: Former NASA chief turned ULA lobbyist seeks law to limit SpaceX funding