Live data from Hacker News

Lavabit abruptly shuts down

lavabit.com

91–100 of 671 posts

Re: Lavabit abruptly shuts down

#91
Some questions given the reasons why they had to shutdown:

1. Can Lavabit now set up shop overseas (with a different TLD)?

2. If not 1, can Lavabit license their software infrastructure in such a way such that someone overseas can set up shop for them?

3. If not 2, can Lavabit open source their software such that someone anywhere else in world can start their own Lavabit?

The point that I am trying to get across is that if Lavabit has been forced to shutdown through no wrongdoing of their own by the US government, a case can be made that certain American government actions are making American companies uncompetitive/non-viable in an increasingly competitive global marketplace.

TL;DR jobs are leaving the United States.

Re: Lavabit abruptly shuts down

#92
post #64

Earlier quoted context omitted.

I'd love to believe that the authorities in Germany are not also tapping lines like France or the UK. Do we have any proof that is the case? I agree this has made me think twice about hosting in the us, but also about crossing national boundaries full stop without encrypting traffic.

Encrypting is a given - obviously you'd want to only be using Saas services in Germany etc that are fully encrypted. The problem in using USA services is that even if everything is fully encrypted, the USA can and will send goons around to take your data. Encryption is simply useless when dealing with a company in the USA who is forced to hand over the keys and whose data-centers can be legally entered and modified b…

EU is a very generic term here. There is very little consistency across member states on this topic; UK laws, for example, are probably worse than US ones in most cases. I'm not 100% sure, but I believe Italian ones aren't much better atm.

The short-term answer is to encrypt everything users have to store, and don't handle their keys, but it's a stop-gap: the only real answer is political and that's where things have to be fixed for good.

Re: Lavabit abruptly shuts down

#93
post #3

Crap, I had just recently migrated all of my accounts to my new Lavabit address, paid for a year of service, etc. Although I've seen some mentioned, what recommendations does HN have for a new e-mail service? Preferably something stable and also respecting of a user's privacy. Or perhaps you can only have 1 of the aforementioned attributes.

This is why I contributed to Mailpile( http://www.mailpile.is/)'s fundraiser and hang out in their IRC channel. We need more, better, easy-to-use distributed, crypto-friendly mail software, and we need them yesterday. :/

bitmessage may be our only hope.

Re: Lavabit abruptly shuts down

#94
post #15

For the unfamiliar: Lavabit was a webmail service, that (claimed to) encrypt emails in such a way that they literally did not have access to the content stored on their own servers. The linked email would lend some credence to those claims. It was originally designed in contrast to gmail scanning your email for targeted advertising, but my imperfect memory says that their system should also have been resilient to "we…

Well, he may not have been able to hand over the old data, but he may have been asked to include an exploit for all mail going forward. That could have been as simple as the authorities inserting some middleware.

This actually did happen with hushmail. It's hosted in Canada, but the US leaned on them hard enough that they ended up backdooring the client to let the feds snoop on the targeted user.

Re: Lavabit abruptly shuts down

#96
post #50

Earlier quoted context omitted.

[deleted]

Actually, I don't think so, if he was a paying user. Everything on-disk was encrypted for paying users, and since lavabit had to shut down completely to not "be complicit in a crime against the American public", I assume that the NSL wanted them to make a change like Hushmail did in the past, to send the user's password to the server on the next login so that they can decrypt all emails.

[deleted]

Re: Lavabit abruptly shuts down

#97
post #43

Earlier quoted context omitted.

I'd love to believe that the authorities in Germany are not also tapping lines like France or the UK. Do we have any proof that is the case? I agree this has made me think twice about hosting in the us, but also about crossing national boundaries full stop without encrypting traffic.

The difference is that the authorities in Germany don't have the legal framework to force someone to do this and threaten them to stay silent.

Ostensibly the US doesn't have that framework either, the Constitution would seem to preclude it (I realize we are talking about a myriad of offenses at this point so it may get hazy). But as you can see, shit gets ignored. Secret government agencies in Germany could ignore laws there just as easily as the NSA does in the US.

Re: Lavabit abruptly shuts down

#98
post #21

Earlier quoted context omitted.

The head of the NSA branded them as "the next terrorists". http://www.salon.com/2013/08/06/cyberscare_ex_nsa_chief_call...

> “nihilists, anarchists, activists, Lulzsec, Anonymous, twentysomethings who haven’t talked to the opposite sex in five or six years” Now that's a generalization if I ever heard one.

The following is a bit of a stretch, but the quoted abusive language from Hayden brings it to mind, as the movie "Eastern Promises" just came up in conversation the other day.

There is a scene in "Eastern Promises" where the protagonist, a "deep cover" police officer infiltrating the Russian / Eastern European mob in London, is compelled to have sex with an enslaved woman in order to prove that he isn't gay. (Because, up to this point, he has not shown interest in these "usual" activities.)

The quote from Hayden, after raising my ire, quickly made me think of this. So, Hayden is more or less saying that, um... "lack of demonstrated sexual prowess" is tantamount to being a misanthrope -- and worse, from the criminal justice perspective, a "criminal" (I'll refrain from using the t-word, including because it probably bumps the ranking of a post in today's data collection systems).

Of course, one might presume to take it as implied also, that if you're gay, you belong to this group.

That such a figure of authority can and does so loosely -- or perhaps purposefully -- bandy about such prejudiced language...

These are not consummate professionals. They are... apparatchiks.

Re: Lavabit abruptly shuts down

#99
post #15

For the unfamiliar: Lavabit was a webmail service, that (claimed to) encrypt emails in such a way that they literally did not have access to the content stored on their own servers. The linked email would lend some credence to those claims. It was originally designed in contrast to gmail scanning your email for targeted advertising, but my imperfect memory says that their system should also have been resilient to "we…

Hushmail is a similar service. There's been some speculation that authorities could compel the owners to perform a sort of internal phishing scam to get the passwords.

Re: Lavabit abruptly shuts down

#100
post #69

Earlier quoted context omitted.

I don't think canaries are effective. You can't get around a court order just by mental gymnastics, they'll hold you in contempt. I'd be happy to be proven wrong, but I suspect that they'd simply order you to keep updating the canary.

This would imply that the court can order you to lie to your customers. I think this is not the case. If there is any precedence for any US court requiring public citizen to lie I definitely want to know about it. If the courts are acting like they have this power then it will greatly change my perception of how the courts, NSA, and congress are currently acting.

They have in the past - there are definitely situations where you are required to lie, for example, when working on classified materials or covert operations.
Post reply on HN