Live data from Hacker News

Lavabit Reloaded

lavabit.com

231–240 of 240 posts

Re: Lavabit Reloaded

#231
post #184

Earlier quoted context omitted.

Technically if a client has a full index version X (in plaintext), it could modify X to get X+1, compute a binary diff between X and (X+1) - encrypt and upload the diff. Another client on index version X could download the diff, and get index (X+1). Some desktop client should probably do compaction from time to time.

I'd you are using a new IV when encrypting the new index then this won't work, since the old and new indexes will be completely different.

You would have to re-download the index after compaction. But the index and patches would be independent - you apply the decrypted patches to the decrypted index.

Re: Lavabit Reloaded

#232

Earlier quoted context omitted.

So the employees of their "support centers in [California]"[0] can't be blackmailed and gagged? Or do they not have access to the systems? [0] https://protonmail.com/about

They can be blackmailed but can't be gagged as any request for a person's data (including access to it) from a Swiss company MUST go through Swiss court. And even gag orders can't compel someone to break the law. Same situation as three letter agencies requesting EU data from Microsofts' datacenter in Ireland, which whilst it is an American company (and thus they are obliged to deliver by law) is illegal under EU and…

>They can be blackmailed but can't be gagged as any request for a person's data (including access to it) from a Swiss company MUST go through Swiss court.

LOL.

Re: Lavabit Reloaded

#233

Earlier quoted context omitted.

You seem to have a lot of faith in the law and legal process, and assume everyone else does. Laws are a high latency side-chain of authority; a guide perhaps; and for some a business opportunity. And then we have Organised Crime, moles, plants; informants, sympathesiers, casual snitches, quadruple agents, the desperate, and machine learning eating meta-data for breakfast. If you've got something to hide "it's not leg…

It has kept Microsoft from sharing its EU data with American agencies so far.. and considering Microsoft has been under the microscope (haha) since it's EU antitrust suit I don't think they could pass the data without some serious ramifications. As far as ProtonMail goes.. well they certainly could force the support employees somehow, but if that ever gets out there would again be serious ramifications. Plus, why do…

>It has kept Microsoft from sharing its EU data with American agencies so far..

At least publicly. Behind the scenes there could be a sharing bonanza for all we know.

Re: Lavabit Reloaded

#234
post #179

Earlier quoted context omitted.

You seem to have a lot of faith in the law and legal process, and assume everyone else does. Laws are a high latency side-chain of authority; a guide perhaps; and for some a business opportunity. And then we have Organised Crime, moles, plants; informants, sympathesiers, casual snitches, quadruple agents, the desperate, and machine learning eating meta-data for breakfast. If you've got something to hide "it's not leg…

And you seem to be painting Swiss legal system with the exact same brush as the USA governmental and legally sanctioned framework for spying on people.

The Swiss legal system doesn't have to be involved at all if they can get the data directly from the US datacenters, no matter what the Swiss law and/or international treaties say is the "formal" process.

Re: Lavabit Reloaded

#235
post #163

If you really want secure email, having it hosted and owned by a U.S. company is a recipe for disaster. Since we know that the U.S. gov't will gladly issue gag orders and blackmail, why even bother? It's great that Lavabit is innovating but Protonmail is already ahead by simply not being in the U.S..

The good thing is Protonmail and Lavabit can profit from each other.

The more services there are, the better.

Re: Lavabit Reloaded

#236
post #211

Earlier quoted context omitted.

Protonmail is a walled garden of its own because it has no IMAP or POP (hasn't had it for more than two years since it was requested). So you're stuck with using the Protonmail apps on iOS or Android or using the web version. None of them are good choices to have one's own copy of all mails in an easily portable form. The only option Protonmail provides is to individually save or print emails. So there's no easy way…

This used to be true. Their IMAP support is currently in beta.

how do you get it? I've had an account there a long time and see nothing allowing IMAP config.

Re: Lavabit Reloaded

#237

Naming it the "Dark Internet Mail Environment" is not going to get the average person's sympathy or interest, and will be an easy target for politicians.

This.

Folks: encryption is not mainly for doing dark, bad things. It is normal and reasonable to want to control who comes into your house, who reads your email, and who can track your every move.

Stop naming your tools as if they were for bad guys.

Lavabit Guy, of all people, should realize that encryption isn't worth beans to anyone if the rest of society thinks it's Bad and Should Be Punished.

So stop making it sound like that. That's Step 0.

Re: Lavabit Reloaded

#238
post #211

Earlier quoted context omitted.

This used to be true. Their IMAP support is currently in beta.

how do you get it? I've had an account there a long time and see nothing allowing IMAP config.

Beta features are reserved for paying customers (and in this case you also have to apply to get the IMAP functionality). Free accounts don't get it until it becomes stable.

> The best way is to upgrade your account to a paid account and take advantage of the numerous extra features we provide with paid accounts. [0]

[0] https://protonmail.com/pricing

Re: Lavabit Reloaded

#239
post #179

Earlier quoted context omitted.

And you seem to be painting Swiss legal system with the exact same brush as the USA governmental and legally sanctioned framework for spying on people.

The Swiss legal system doesn't have to be involved at all if they can get the data directly from the US datacenters, no matter what the Swiss law and/or international treaties say is the "formal" process.

I believe the point is that there are no US data centers. And protonmail states all the data is encrypted anyway and never decrypted on their servers (obviously except the initial receive/send of the mail).

Re: Lavabit Reloaded

#240
post #67

Earlier quoted context omitted.

> Most email providers don't have retail stores Lots do, though, and the ones that don't often offer customer support over the phone. And anyway, social engineering doesn't only happen in stores or when talking to CS.

Really? Name any of the top 10 email providers that have stores, or a responsive 800 number for email support. I'll give you Apple, but they are the clear outlier. MS, Google, have stores, but not with email support, and questionable phone support at best for any non enterprise product.

AT&T? I don't have a list of top 10 email providers, but them and Verizon and Yahoo have all had people report social engineering attacks against them to gain access to accounts.
Post reply on HN