Live data from Hacker News

Lavabit Reloaded

lavabit.com

211–220 of 240 posts

Re: Lavabit Reloaded

#211
post #163

If you really want secure email, having it hosted and owned by a U.S. company is a recipe for disaster. Since we know that the U.S. gov't will gladly issue gag orders and blackmail, why even bother? It's great that Lavabit is innovating but Protonmail is already ahead by simply not being in the U.S..

Protonmail is a walled garden of its own because it has no IMAP or POP (hasn't had it for more than two years since it was requested). So you're stuck with using the Protonmail apps on iOS or Android or using the web version. None of them are good choices to have one's own copy of all mails in an easily portable form. The only option Protonmail provides is to individually save or print emails. So there's no easy way…

This used to be true. Their IMAP support is currently in beta.

Re: Lavabit Reloaded

#212
post #182

Earlier quoted context omitted.

The search doesn't happen on the server. The client (e.g. desktop client) indexes the messages and encrypts the index. Then, when another client (e.g. mobile client) wants to search for a message, it downloads the index, searches it, and then pulls down the appropriate message(s).

If an attacker can tell which part of the index was modified, that gives them enough information to decrypt the index and e-mails. Clients would always have to download+upload the full index (which needs to be re-encrypted with a new IV). This is a huge problem - the index can easily be hundreds of MB for a large mailbox.

I'm not quite sure what you're getting at. It sounds like you're describing a known-plaintext attack, which modern ciphers are not vulnerable to. And what you are describing makes it seem like full disk encryption would be totally useless, but we know that's not the case.

Re: Lavabit Reloaded

#213
post #211

Earlier quoted context omitted.

Protonmail is a walled garden of its own because it has no IMAP or POP (hasn't had it for more than two years since it was requested). So you're stuck with using the Protonmail apps on iOS or Android or using the web version. None of them are good choices to have one's own copy of all mails in an easily portable form. The only option Protonmail provides is to individually save or print emails. So there's no easy way…

This used to be true. Their IMAP support is currently in beta.

If it's really a beta in the true sense of the word, it's not reliable enough to export one's mails. It would be better to wait till it's out of beta for those who need flexibility to move out.

Re: Lavabit Reloaded

#214
post #210

Earlier quoted context omitted.

Any source for this? Reading everyone's emails requires them backdooring their server so that it saves plaintext password or symmetric key on login. Were they doing this?

'backdooring their server to themselves' is not 'backdooring' it's just misdesigning. The alternative is believing Lavabit always scrupulously 'looked away'. https://moxie.org/blog/lavabit-critique/

We already know that Lavabit design was bad and that is why everyone is moving to E2E.

Still I found no evidence that Lavabit handed over anything but encrypted data and access logs. The only thing I found is [1]: "He says he's received "two dozen" requests over the last ten years, and in cases where he had information, he would turn over what he had. Sometimes he had nothing; messages deleted from his service are deleted permanently."

He has complied with warrants because he had nothing to transfer. Nothing was stored and there is no legal obligation to modify your service to store passwords. When he was asked for TLS keys, he had to shutdown the service to prevent leaking all the passwords and redesigned the server.

The difference between not looking away and Lavabit design is that nothing is exposed if the server is seized.

The design of old Lavabit was not sufficiently secure and there was no way to check if it is more secure from the users' perspective, but still no reason to call it snake oil [2]. Snake oil is a product that is advertised as secure when maker knows it is insecure. Lavabit design was correctly described on its website and source code was promptly published after the shutdown so it is possible to verify that described features existed.

[1] http://www.forbes.com/sites/kashmirhill/2013/08/09/lavabits-...

[2] https://news.ycombinator.com/item?id=13447919

Re: Lavabit Reloaded

#215
post #204
post #202

Earlier quoted context omitted.

Phil Zimmermann He went to prison over pgp. But then the mail service he was involved in (silent circle mail) shut down at the same time as lavabit.

He never spent time in prison, but he was investigated intensely by the US gov't.

You seem to be correct. He never went to prison for pgp.

But apparently he thought up pgp while in prison for nuclear protests.

Re: Lavabit Reloaded

#216
post #95

Earlier quoted context omitted.

> > To access mail on multiple devices, the private key needs to be shared securely between them > This is a non-issue. It can easily be derived from a password How does that change the equation? You're still exposing the thing-that-decrypts to multiple devices, thus (many!) more threat vectors. Lose one, and you lose them all, which is the point of the claim.

...so use unencrypted email? The point is, some is better than none. More is better than some. So many people here pointing out holes that make it worse than a theoretically perfect system even though it's leagues ahead of where we are now.

No, the (implicit) point in the start of the thread is that multiple other encrypted mediums don't leak as much. Use them instead.

If you care enough to use encrypted email, you should probably seriously consider abandoning email. (signing is different - that's proof of identity and non-modification, useful in many non-private scenarios)

Re: Lavabit Reloaded

#217
post #76

Earlier quoted context omitted.

> > Search isn't possible > It absolutely is, in both theory and practice. The server stores an encrypted index, and the client walks it (requesting parts as needed). It's going to little slower, and a lot more complex but it's doable. Are you suggesting that to search your mailbox, the client should download every single encrypted message in the entire mailbox and decrypt them all locally to search them? If not, how…

> > Encrypted Index This is not the same as the content.

It's still likely too large to really consider for mobile use, but yes - far better than downloading everything.

Re: Lavabit Reloaded

#218
post #210

Earlier quoted context omitted.

'backdooring their server to themselves' is not 'backdooring' it's just misdesigning. The alternative is believing Lavabit always scrupulously 'looked away'. https://moxie.org/blog/lavabit-critique/

We already know that Lavabit design was bad and that is why everyone is moving to E2E. Still I found no evidence that Lavabit handed over anything but encrypted data and access logs. The only thing I found is [1]: "He says he's received "two dozen" requests over the last ten years, and in cases where he had information, he would turn over what he had. Sometimes he had nothing; messages deleted from his service are de…

Still I found no evidence that Lavabit handed over anything but encrypted data and access logs

There isn't any evidence of that or the contrary. He had all the data. We don't know what he did or did not turn over.

Snake oil is a product that is advertised as secure when maker knows it is insecure.

Take another look at this (and Moxie Marlinspike is being generous and sympathetic). It meets your own criteria precisely.

https://moxie.org/blog/lavabit-critique/

Re: Lavabit Reloaded

#219

Earlier quoted context omitted.

> > Spam checking on content isn't possible > This is probably your best point. It's definitely harder to do well I think it's possible, just slower and more complex (like search) - and would have to occur upon unlocking your inbox.

You can mostly get rid of spam by requiring the sender to perform a proof of work if they aren't in your contacts list. I.e. whitelist of senders + proof of work or some kind of configurable per domain quota/proof of work.

Does anyone actually use e.g. hashcash though? I love the concept, but it's useless if nobody can use it.

Re: Lavabit Reloaded

#220

Earlier quoted context omitted.

If a keyboard needs drivers other than USB-HID, someone's doing something wrong.

I thought that too, until i bought a cheap netbook that came with windows (7? Student edition? I cannot remember). I plugged in a mouse and windows said it needed to connect to the internet to download the driver for my MS optical mouse. I practically fell out of my chair laughing.

The "driver" is for adding a gui for doing things like customizing buttons and sensitivity and stuff, not to make the basic mouse work.
Post reply on HN