Live data from Hacker News

Lavabit Reloaded

lavabit.com

151–160 of 240 posts

Re: Lavabit Reloaded

#151
post #117

Earlier quoted context omitted.

Snowden is not a security expert nor a cryptographer. He used Cryptocat and Lavabit, for instance - he was (like most people) unable to independently assess the quality of their security guarantees and believed their claims.

he has said that he used pgp in his emails with poitras and greenwald because he knew from personal experience that, properly implemented, nsa was unable to decrypt messages protected with it

Are you saying he didn't use Lavabit and Cryptocat?

Re: Lavabit Reloaded

#153

Earlier quoted context omitted.

I spilled soda on my mac once, and took it to the repair shop. the receptionist there asked me for my password. I laughed and I said of course not. she was shocked and asked: well, how are we going to test the new keyboard. I don't know maybe try to type random things in the password field?

What if they install the keyboard but the drivers fail? Won't they need the admin password in order to complete the job?

They have physical access to the device. They can enter recovery mode by holding down command r when restarting. It gives them a different copy of the os with multiple apps that you can type in (like the terminal) and would allow superuser access to whatever they wanted, however your encrypted home directory would remain encrypted and they would not be able to read it. In the olden days you would stick in a recovery cd and reboot onto that... you could also (historically and presently) stick a USB drive into the thing and boot into an os on that.... NEVER give out your password.

Re: Lavabit Reloaded

#155
post #45

Earlier quoted context omitted.

He gave up the cert, there was no PFS-only configuration, plus, presumably the FBI got to do their surveillance except instead of the target's email, they could read everyone's. So no, you are not right.

I was not aware he gave up the cert in the end. Thought he just closed website without disclosing TLS cert. Now it looks way worse than I imagined. Anyway, I really hope that it leads to adoption of backward-compatible and secure email protocols. Server encryption can't be trusted anymore anyway, we need end-to-end encryption.

Here is an article about that:

https://www.techdirt.com/articles/20131002/17443624734/lavab...

Re: Lavabit Reloaded

#157

Earlier quoted context omitted.

What if they install the keyboard but the drivers fail? Won't they need the admin password in order to complete the job?

If a keyboard needs drivers other than USB-HID, someone's doing something wrong.

Many laptops use an SPI touchpad device, so they don't need to go through the relatively expensive and complex USB stack.

Re: Lavabit Reloaded

#158

Earlier quoted context omitted.

Regarding Apple and security, their policy via AppleCare seems to be to ASK (over the phone, for instance) for your cleartext computer administrator password before you send in your laptop for repair, without any warning whatsoever of the implications.

I spilled soda on my mac once, and took it to the repair shop. the receptionist there asked me for my password. I laughed and I said of course not. she was shocked and asked: well, how are we going to test the new keyboard. I don't know maybe try to type random things in the password field?

I had this EXACT experience just this month. I went to have a screen replaced and I even explained (and apologized for the inconvenience) that I was very security focused. I set it up in advance so that would perform the repair in front of me, that the device wouldn't be plugged into any of their computers, and it wasn't to be taken out of sight.

Then, he straight up asked me for my password, "most customers write their password down so we can test that it works."

I feel a little bad because the look I must have given him was pretty absurd. I told him no, I'll just take the risk and test it myself.

Re: Lavabit Reloaded

#159

Earlier quoted context omitted.

> If you want encryption, don't use email. That's total nonsense. > Search isn't possible It absolutely is, in both theory and practice. The server stores an encrypted index, and the client walks it (requesting parts as needed). It's going to little slower, and a lot more complex but it's doable. > If you lose your private key, we can't recover your email This is a damn feature. I had my icloud account social enginee…

> > Spam checking on content isn't possible > This is probably your best point. It's definitely harder to do well I think it's possible, just slower and more complex (like search) - and would have to occur upon unlocking your inbox.

How often does spam come encrypted with your public key anyways?

Re: Lavabit Reloaded

#160
post #75

Earlier quoted context omitted.

I have experience at Apple with Account Security and that's a clear violation of SOP. That's a coaching opportunity for the advisor.

> I have experience at Apple with Account Security and that's a clear violation of SOP It should be technically impossible. If it's a matter of choice for tech support reps, it's not secure for many reasons.

It's icloud, not personal device storage. It has to be possible if you want recoverable content. If you don't like it, you can back up locally to itunes.
Post reply on HN