Live data from Hacker News

Lavabit Reloaded

lavabit.com

111–120 of 240 posts

Re: Lavabit Reloaded

#111
Sensible choices in a nutshell: If you live in a 5-eyes nation, don't use or buy services hosted or operated from a 5 eyes nation. If you don't live in a 5 eyes nation, only use services hosted and operated from Iceland or Switzerland.( Nation states are the #1 threat, and your own nation is always the most dangerous one. )

Re: Lavabit Reloaded

#112

Earlier quoted context omitted.

> If you want encryption, don't use email. That's total nonsense. > Search isn't possible It absolutely is, in both theory and practice. The server stores an encrypted index, and the client walks it (requesting parts as needed). It's going to little slower, and a lot more complex but it's doable. > If you lose your private key, we can't recover your email This is a damn feature. I had my icloud account social enginee…

Fwiw search that way is (I think) patented by Proofpoint. So it might be hard to implement.

It is smart to not speculate on patents. You have now possibly poisoned everyone reading this thread.

Re: Lavabit Reloaded

#113

Earlier quoted context omitted.

Fwiw search that way is (I think) patented by Proofpoint. So it might be hard to implement.

It is smart to not speculate on patents. You have now possibly poisoned everyone reading this thread.

If patent law worked like coodies that comment would be awesome.

Re: Lavabit Reloaded

#115
post #111

Sensible choices in a nutshell: If you live in a 5-eyes nation, don't use or buy services hosted or operated from a 5 eyes nation. If you don't live in a 5 eyes nation, only use services hosted and operated from Iceland or Switzerland.( Nation states are the #1 threat, and your own nation is always the most dangerous one. )

No this is completely backwards. Use services that have security properties addressing the threats that matter to you. Simply adding 'hosted in Iceland' to something that's ineffective isn't going to help you. Having a server in Iceland did absolutely nothing for DPR, for instance.

Re: Lavabit Reloaded

#116

If you NEED encryption, don't use email. From: https://blog.fastmail.com/2016/12/10/why-we-dont-offer-pgp/ What's the tradeoff? If the server doesn't have access to the content of emails, then it reverts to a featureless blob store: Search isn't possible Previews can't be calculated If you lose your private key, we can't recover your email Spam checking on content isn't possible To access mail on multiple devices, th…

>Spam checking on content isn't possible

How does encrypted spam work? Spammers encrypt message with your public key?

Re: Lavabit Reloaded

#117

Is there any person as trustworthy as Ladar Levison for a service like email or chat? To my knowledge, he is one of the few that has gone to the mat for his users.

If Edward Snowden started a mail service, I'd probably trust it more. If you want to talk about "going to the mat" for people, I think Snowden has made the bigger sacrifice. Moxie and Whisper Systems probably would get my nod too. Perhaps even DJB or Bruce Schnier.

Snowden is not a security expert nor a cryptographer. He used Cryptocat and Lavabit, for instance - he was (like most people) unable to independently assess the quality of their security guarantees and believed their claims.

Re: Lavabit Reloaded

#118

Earlier quoted context omitted.

How often do you get email from somebody that you've never gotten email from before?

Exactly once for each contact that has ever sent me an email

Maybe a two-way 'add contact' feature would be useful, like a facebook friend request.

Re: Lavabit Reloaded

#119

Earlier quoted context omitted.

> If you want encryption, don't use email. That's total nonsense. > Search isn't possible It absolutely is, in both theory and practice. The server stores an encrypted index, and the client walks it (requesting parts as needed). It's going to little slower, and a lot more complex but it's doable. > If you lose your private key, we can't recover your email This is a damn feature. I had my icloud account social enginee…

Regarding Apple and security, their policy via AppleCare seems to be to ASK (over the phone, for instance) for your cleartext computer administrator password before you send in your laptop for repair, without any warning whatsoever of the implications.

I spilled soda on my mac once, and took it to the repair shop. the receptionist there asked me for my password. I laughed and I said of course not. she was shocked and asked: well, how are we going to test the new keyboard. I don't know maybe try to type random things in the password field?

Re: Lavabit Reloaded

#120
post #111

Sensible choices in a nutshell: If you live in a 5-eyes nation, don't use or buy services hosted or operated from a 5 eyes nation. If you don't live in a 5 eyes nation, only use services hosted and operated from Iceland or Switzerland.( Nation states are the #1 threat, and your own nation is always the most dangerous one. )

Schweiz is in the EU. We are subject to its data-retention laws. Consider Norway.
Post reply on HN