Live data from Hacker News

Lavabit Reloaded

lavabit.com

131–140 of 240 posts

Re: Lavabit Reloaded

#131
post #75

Earlier quoted context omitted.

Adding to the iCloud story, I forgot my security questions and I was able to have the AppleCare agent over the phone reset it for me after talking about what apps I've purchased recently.

I have experience at Apple with Account Security and that's a clear violation of SOP. That's a coaching opportunity for the advisor.

> I have experience at Apple with Account Security and that's a clear violation of SOP

It should be technically impossible. If it's a matter of choice for tech support reps, it's not secure for many reasons.

Re: Lavabit Reloaded

#132

Earlier quoted context omitted.

Regarding Apple and security, their policy via AppleCare seems to be to ASK (over the phone, for instance) for your cleartext computer administrator password before you send in your laptop for repair, without any warning whatsoever of the implications.

I spilled soda on my mac once, and took it to the repair shop. the receptionist there asked me for my password. I laughed and I said of course not. she was shocked and asked: well, how are we going to test the new keyboard. I don't know maybe try to type random things in the password field?

What if they install the keyboard but the drivers fail? Won't they need the admin password in order to complete the job?

Re: Lavabit Reloaded

#133
post #111

Sensible choices in a nutshell: If you live in a 5-eyes nation, don't use or buy services hosted or operated from a 5 eyes nation. If you don't live in a 5 eyes nation, only use services hosted and operated from Iceland or Switzerland.( Nation states are the #1 threat, and your own nation is always the most dangerous one. )

> If you live in a 5-eyes nation, don't use or buy services hosted or operated from a 5 eyes nation

The 5 eyes spy globally. U.S. citizens are the only ones with legal protection and (limited) recourse for U.S. government spying, AFAIK.

If a U.S. citizen uses a French or Icelandic mail host, I suspect the U.S. foreign intelligence agencies have free reign to spy on them. I wonder what the limits are for the FBI and other domestic agencies.

Re: Lavabit Reloaded

#134

Earlier quoted context omitted.

I spilled soda on my mac once, and took it to the repair shop. the receptionist there asked me for my password. I laughed and I said of course not. she was shocked and asked: well, how are we going to test the new keyboard. I don't know maybe try to type random things in the password field?

What if they install the keyboard but the drivers fail? Won't they need the admin password in order to complete the job?

If a keyboard needs drivers other than USB-HID, someone's doing something wrong.

Re: Lavabit Reloaded

#136
> Today is Inauguration Day in the United States, the day we enact one of our most sacred democratic traditions, the peaceful transition of power

Sitting here in West Africa, watching the news, we didn't see much peace during the rioting in the streets in (I assume) Washington

Re: Lavabit Reloaded

#137

Earlier quoted context omitted.

Exactly once for each contact that has ever sent me an email

I'm talking about now going forward. There are plenty of ways to make a person opt-in the first time they send you something. That process gets rid of more than 99% of spam.

This feels... parochial.

It wouldn't be so good if email turned into Facebook, where you can only contact somebody if the circuit has been established beforehand (i.e., both parties friend each other). What happens if this is the point of initial contact, and there's no other way to get in touch? I have to conspicuously friend this person from my otherwise dormant account and then not think about whether they're going to feel weird when I unfriend them later on?

I sent an unsolicited email a couple weeks ago. Academic-type, self published, personal webpages where I saw something that needed fixing, and so I did. There was no CMS, just a static site—and not the sort where you're running markdown sources through a generator and have a whole Git hosting service apparatus intertwined with hooks sunk into it. Plain, legacy HTML. I saved a local copy to my machine, made my changes, and mailed them in. They happened to be machine-readable patches, given the recipient, but it could have just as well been a message written in natural language. The changes were made, I was thanked, and done.

I'm still upset that in the 90s I could get in contact with almost anybody by looking in the phonebook, but when I tried doing that a few years ago for an old coworker, it was hopeless. Getting the listings for a city you've moved away from can prove to be harder than it seems, even when you know they have a landline.

These are the kinds of things you lose when you assume the world is already fixed in the form that it should maintain going forward.

Re: Lavabit Reloaded

#138
post #57

Earlier quoted context omitted.

This is all ridiculous. Download, index, and process your mail locally. Problem solved.

If we had more systems capable of resisting a local search and seizure this might be the case but as it stands almost none do.

Oh no, you're describing the solution rather than the problem: a global search, copy, and seizure converted to a local one that happens on per-target basis. Way better than mass collection with FISA warrants and systems like QUANTUM.

Re: Lavabit Reloaded

#139

Earlier quoted context omitted.

> If you want encryption, don't use email. That's total nonsense. > Search isn't possible It absolutely is, in both theory and practice. The server stores an encrypted index, and the client walks it (requesting parts as needed). It's going to little slower, and a lot more complex but it's doable. > If you lose your private key, we can't recover your email This is a damn feature. I had my icloud account social enginee…

> The server stores an encrypted index, and the client walks it (requesting parts as needed). It's going to little slower, and a lot more complex but it's doable. Going on a tangent, but do you know of any services that offer such a thing?

https://cryptag.org

Re: Lavabit Reloaded

#140

Earlier quoted context omitted.

Regarding Apple and security, their policy via AppleCare seems to be to ASK (over the phone, for instance) for your cleartext computer administrator password before you send in your laptop for repair, without any warning whatsoever of the implications.

I spilled soda on my mac once, and took it to the repair shop. the receptionist there asked me for my password. I laughed and I said of course not. she was shocked and asked: well, how are we going to test the new keyboard. I don't know maybe try to type random things in the password field?

Or just boot into single user mode.
Post reply on HN