Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Encrypt the email, rotate and delete keys after 18months.


Public companies are required by law to retain email for 7 years I believe.


> Public companies are required by law to retain email for 7 years I believe

Public companies have to keep audit-related communications, but not something like this [1]. It comes more from civil litigation, where the standard of proof is the preponderance of evidence. If I sue you and produce partial records, and you say you deleted everything, that can be used against you.

[1] https://www.intradyn.com/email-retention-laws/


Based on what?


The aforementioned Sarbanes-Oxley act, plus the principle of "negative inference" in civil suits which dictates that a court can infer that someone refusing to testify (or destroying evidence) has something to hide. There's no 'plead the 5th' in civil suits.



This is exclusively about audits


That would explain it. But then again, why not use Signal or something similar for sensitive topics.


Several employees of the world's largest banks actually tried this. Result? Almost $2 billion in fines.

https://www.wsj.com/articles/wall-street-to-pay-1-8-billion-...


That’s interesting, thanks.

Article is paywalled, but how can it be proved they’re using something like Signal? There must be at least some discussion available to be disclosured on request by law? How do they define if the subject is relevant enough to require a formal exchange between executives?

The world of big public companies is fascinating.


I have to imagine any requirements on email retention would apply to signal too, and that your phone with its local plaintext database can be subpoenaed.

The threat model for signal is not to get you out of your legal obligation to comply with court orders.


I don't understand? As long as someone has the relevant decrypted message chain it can be subpoenaed.


Or just set a company policy around email retention. Then delete anything older than that?

Apple chose to keep these emails around because the value of the emails was greater than the risk of keeping them.


Apple is secretive not sneaky they aren’t trying to trick anybody. They are working on human centric computing. They have had human interface guidelines and the preservation of those guidelines is maintained through app review.

I’m sure that some form of side loading will appear soon. My guess is that all the privacy and integration will be held at arms length from the rest of the ecosystem and may just use webkit to access the user data.


The company to whom I'm currently contracted has a 2-month retention policy on inboxes and it drives me crazy.


Are they engaged in generally questionable behavior? Otherwise I can’t imagine why they’d have such a short retention policy.


No, and it can be worked around by copying emails to folders, it's just annoying.


Unlike Google, Apple isn't trying to hide anything (post-High-Tech Employee Antitrust Litigation)


How do you recover a deleted unencrypted email?


So why not just delete the emails?




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: