Live data from Hacker News

Lavabit Reloaded

lavabit.com

11–20 of 240 posts

Re: Lavabit Reloaded

#13
post #5

Trustful seems like a strange way to refer to the insecure mode. It is indeed full of trust, but not in the way a normal read would suggest: it requires full trust in Lavabit's hosting provider and administrator. If you're going to operate in "trustful" mode, lavabit isny offering any real security wins over any other mail host.

> Former Lavabit users will be able to access their accounts in “Trustful” mode Looks like Trustful mode is how the old lavabit operated. > If you're going to operate in "trustful" mode, lavabit isny offering any real security wins over any other mail host. This level of security apparently was enough to protect email contents against FBI. The reason this "insecure" mode is kept is to allow users to continue using th…

It may also be a very bad idea if Lavabit is compromised now. Don't try to connect to your old account if you had any sensitive emails.

Re: Lavabit Reloaded

#14
post #5

Trustful seems like a strange way to refer to the insecure mode. It is indeed full of trust, but not in the way a normal read would suggest: it requires full trust in Lavabit's hosting provider and administrator. If you're going to operate in "trustful" mode, lavabit isny offering any real security wins over any other mail host.

> Former Lavabit users will be able to access their accounts in “Trustful” mode Looks like Trustful mode is how the old lavabit operated. > If you're going to operate in "trustful" mode, lavabit isny offering any real security wins over any other mail host. This level of security apparently was enough to protect email contents against FBI. The reason this "insecure" mode is kept is to allow users to continue using th…

Oh I didn't know that the contents of old accounts were now accessible again. Was that not deleted by Lavabit when they got subpoenaed?

Re: Lavabit Reloaded

#15
If you NEED encryption, don't use email.

From: https://blog.fastmail.com/2016/12/10/why-we-dont-offer-pgp/

What's the tradeoff?

If the server doesn't have access to the content of emails, then it reverts to a featureless blob store:

    Search isn't possible
    Previews can't be calculated
    If you lose your private key, we can't recover your email
    Spam checking on content isn't possible
    To access mail on multiple devices, the private key needs to be shared securely between them
update: want->NEED

Re: Lavabit Reloaded

#16

>Lavabit believes in privacy and will always ensure your digital freedom. >Asks for your credit card information on the same page. Wew, at least let us use buttcoin, Levison.

This is being down voted but is an interesting point. Is a privacy service in which public record is available for its purchases ever truly private? Maybe its extremely difficult for others to see your communications, but if someone (or some law-enforcement agency) knows you have paid for a private communications service, does that make you a candidate for further scrutinization? I think so.

Re: Lavabit Reloaded

#17

If you NEED encryption, don't use email. From: https://blog.fastmail.com/2016/12/10/why-we-dont-offer-pgp/ What's the tradeoff? If the server doesn't have access to the content of emails, then it reverts to a featureless blob store: Search isn't possible Previews can't be calculated If you lose your private key, we can't recover your email Spam checking on content isn't possible To access mail on multiple devices, th…

Search and previews should be possible on the client side, but then you need a standalone app, not a web interface.

Re: Lavabit Reloaded

#18

If you NEED encryption, don't use email. From: https://blog.fastmail.com/2016/12/10/why-we-dont-offer-pgp/ What's the tradeoff? If the server doesn't have access to the content of emails, then it reverts to a featureless blob store: Search isn't possible Previews can't be calculated If you lose your private key, we can't recover your email Spam checking on content isn't possible To access mail on multiple devices, th…

Search is still possible. You can stem words and store their weights without storing the actual unencrypted text. This isn't perfect security, but it's good enough that it would be difficult for the government to successfully use the search metadata in a case against you without a lot of other evidence.

This is what we do on FWD:Everyone for email threads shared within private repositories.

Re: Lavabit Reloaded

#19
The explain document doesn't describe how key distribution works. How do I get a public key for somebody that I want to email, and how can I know that I am getting the right key?

This is the hard part of an modern cryptosystem and the usual source of weakness.

Re: Lavabit Reloaded

#20

If you NEED encryption, don't use email. From: https://blog.fastmail.com/2016/12/10/why-we-dont-offer-pgp/ What's the tradeoff? If the server doesn't have access to the content of emails, then it reverts to a featureless blob store: Search isn't possible Previews can't be calculated If you lose your private key, we can't recover your email Spam checking on content isn't possible To access mail on multiple devices, th…

Search and previews should be possible on the client side, but then you need a standalone app, not a web interface.

possible, but very expensive even on small datasets
Post reply on HN