Live data from Hacker News

Lavabit abruptly shuts down

lavabit.com

51–60 of 671 posts

Re: Lavabit abruptly shuts down

#51
If Congress has passed laws abridging the freedom of speech, then those laws are illegitimate. Unfortunately, it feels as if speaking favorably of the Constitution is enough to get put on a watch list anymore.

Re: Lavabit abruptly shuts down

#52
They should open source the whole thing. We can bring it to Germany. I believe we are legally allowed to tell the NSA to GFYS.

Any people who have businesses in the US need to take a serious look at the risk now posed by their own government on the success of their business.

One rogue customer and business could go down the toilet, or you'll be forced to bend your morals to suit a rogue secret fiefdom.

Re: Lavabit abruptly shuts down

#53
post #3

Crap, I had just recently migrated all of my accounts to my new Lavabit address, paid for a year of service, etc. Although I've seen some mentioned, what recommendations does HN have for a new e-mail service? Preferably something stable and also respecting of a user's privacy. Or perhaps you can only have 1 of the aforementioned attributes.

Run your own server, on your own hardware?

Re: Lavabit abruptly shuts down

#54
post #40

Earlier quoted context omitted.

I don't think canaries are effective. You can't get around a court order just by mental gymnastics, they'll hold you in contempt. I'd be happy to be proven wrong, but I suspect that they'd simply order you to keep updating the canary.

I'm also unsure of their proven effectiveness, but how could they hold you in contempt for _not_ taking an action?

I don't think it would be any different from holding you in contempt for doing something. The court notices that your inaction caused you to contravene a court order, and the court then holds you in contempt.

Re: Lavabit abruptly shuts down

#55
post #40

Earlier quoted context omitted.

I don't think canaries are effective. You can't get around a court order just by mental gymnastics, they'll hold you in contempt. I'd be happy to be proven wrong, but I suspect that they'd simply order you to keep updating the canary.

I'm also unsure of their proven effectiveness, but how could they hold you in contempt for _not_ taking an action?

I have the same question. It's very odd for a court to compel positive action.

Re: Lavabit abruptly shuts down

#56
post #11

Earlier quoted context omitted.

I just lost access to my primary email account.

Do what I do! I have my own domain name, currently hosting with Google Apps. If I get the motivation to move to another host like myself, I can do it without changing contact information.

Oh good, because Google will never be subject to an NSL.

Re: Lavabit abruptly shuts down

#57
post #15

For the unfamiliar: Lavabit was a webmail service, that (claimed to) encrypt emails in such a way that they literally did not have access to the content stored on their own servers. The linked email would lend some credence to those claims. It was originally designed in contrast to gmail scanning your email for targeted advertising, but my imperfect memory says that their system should also have been resilient to "we…

It wouldn't be resilient to interception of mail going to and coming from lavabit however, since email is essentially a plaintext public protocol.

This is somewhat true. RFC3207[1] describes opportunistic TLS encryption for SMTP communications. Our postfix deployment uses this and a fair amount of our email is sent over TLS-encrypted SMTP.

Of course, an MITM attack could hide the STARTTLS option and there are questions around the strength of the CA cert infrastructure, but SMTP is not just plaintext.

[1] https://tools.ietf.org/html/rfc3207

Re: Lavabit abruptly shuts down

#58
post #24

I'm in the process of moving any Saas offerings I use off USA-affiliated companies, but it's actually more difficult than I first thought. I believe there might even be a very profitable market in simply duplicating the functionality of Saas offerings at a higher price with security/privacy guarantees in Germany/HK/etc. Might be the next hot business to be in? You'd be surprised as to the number of people seeking alt…

I'd love to believe that the authorities in Germany are not also tapping lines like France or the UK. Do we have any proof that is the case? I agree this has made me think twice about hosting in the us, but also about crossing national boundaries full stop without encrypting traffic.

If you're German, would you prefer to be surveilled by the German government or by both the US and German governments?

If you're in the US it seems kinda pointless to try to move to overseas hosting; the NSA will probably just focus on the client side.

Re: Lavabit abruptly shuts down

#60
post #11

Earlier quoted context omitted.

I just lost access to my primary email account.

Do what I do! I have my own domain name, currently hosting with Google Apps. If I get the motivation to move to another host like myself, I can do it without changing contact information.

Yes, absolutely. Everyone here should do this.

Never have your identity tied to a mere provider.

Post reply on HN