Earlier quoted context omitted.
Snowden is not a security expert nor a cryptographer. He used Cryptocat and Lavabit, for instance - he was (like most people) unable to independently assess the quality of their security guarantees and believed their claims.
he has said that he used pgp in his emails with poitras and greenwald because he knew from personal experience that, properly implemented, nsa was unable to decrypt messages protected with it
Lavabit Reloaded
151–160 of 240 posts
Re: Lavabit Reloaded
#152Re: Lavabit Reloaded
#153Earlier quoted context omitted.
I spilled soda on my mac once, and took it to the repair shop. the receptionist there asked me for my password. I laughed and I said of course not. she was shocked and asked: well, how are we going to test the new keyboard. I don't know maybe try to type random things in the password field?
What if they install the keyboard but the drivers fail? Won't they need the admin password in order to complete the job?
Re: Lavabit Reloaded
#154Re: Lavabit Reloaded
#155Earlier quoted context omitted.
He gave up the cert, there was no PFS-only configuration, plus, presumably the FBI got to do their surveillance except instead of the target's email, they could read everyone's. So no, you are not right.
I was not aware he gave up the cert in the end. Thought he just closed website without disclosing TLS cert. Now it looks way worse than I imagined. Anyway, I really hope that it leads to adoption of backward-compatible and secure email protocols. Server encryption can't be trusted anymore anyway, we need end-to-end encryption.
https://www.techdirt.com/articles/20131002/17443624734/lavab...
Re: Lavabit Reloaded
#156Why would they ask for name, address etc?
Re: Lavabit Reloaded
#157Earlier quoted context omitted.
What if they install the keyboard but the drivers fail? Won't they need the admin password in order to complete the job?
If a keyboard needs drivers other than USB-HID, someone's doing something wrong.
Re: Lavabit Reloaded
#158Earlier quoted context omitted.
Regarding Apple and security, their policy via AppleCare seems to be to ASK (over the phone, for instance) for your cleartext computer administrator password before you send in your laptop for repair, without any warning whatsoever of the implications.
I spilled soda on my mac once, and took it to the repair shop. the receptionist there asked me for my password. I laughed and I said of course not. she was shocked and asked: well, how are we going to test the new keyboard. I don't know maybe try to type random things in the password field?
Then, he straight up asked me for my password, "most customers write their password down so we can test that it works."
I feel a little bad because the look I must have given him was pretty absurd. I told him no, I'll just take the risk and test it myself.
Re: Lavabit Reloaded
#159Earlier quoted context omitted.
> If you want encryption, don't use email. That's total nonsense. > Search isn't possible It absolutely is, in both theory and practice. The server stores an encrypted index, and the client walks it (requesting parts as needed). It's going to little slower, and a lot more complex but it's doable. > If you lose your private key, we can't recover your email This is a damn feature. I had my icloud account social enginee…
> > Spam checking on content isn't possible > This is probably your best point. It's definitely harder to do well I think it's possible, just slower and more complex (like search) - and would have to occur upon unlocking your inbox.
Re: Lavabit Reloaded
#160Earlier quoted context omitted.
I have experience at Apple with Account Security and that's a clear violation of SOP. That's a coaching opportunity for the advisor.
> I have experience at Apple with Account Security and that's a clear violation of SOP It should be technically impossible. If it's a matter of choice for tech support reps, it's not secure for many reasons.