Live data from Hacker News

Lavabit abruptly shuts down

lavabit.com

111–120 of 671 posts

Re: Lavabit abruptly shuts down

#111

Earlier quoted context omitted.

It wouldn't be resilient to interception of mail going to and coming from lavabit however, since email is essentially a plaintext public protocol.

What? I don't think this is true at all. Plaintext data, email or not, can be protected with robust encryption. Your end security is the main consideration, but that has nothing to do with the protocol or content, really.

The difficulty is that most recipients of your message will not be willing to use whatever crypto technology you've chosen. PGP is probably the most popular email encryption system, but good luck finding people who use it. I work in the software industry, and I don't regularly correspond with a single person whom I know to use PGP.

Re: Lavabit abruptly shuts down

#112
post #15

For the unfamiliar: Lavabit was a webmail service, that (claimed to) encrypt emails in such a way that they literally did not have access to the content stored on their own servers. The linked email would lend some credence to those claims. It was originally designed in contrast to gmail scanning your email for targeted advertising, but my imperfect memory says that their system should also have been resilient to "we…

Hushmail is a similar service. There's been some speculation that authorities could compel the owners to perform a sort of internal phishing scam to get the passwords.

It's not speculation:

http://www.wired.com/threatlevel/2007/11/encrypted-e-mai/

> a federal prosecution of alleged steroid dealers reveals the Canadian company turned over 12 CDs worth of e-mails from three Hushmail accounts, following a court order obtained through a mutual assistance treaty between the U.S. and Canada.

Re: Lavabit abruptly shuts down

#113

I've had a lavabit email as one of my main emails for years (close to when they first started) and this is a major inconvenience. I'm not sure I'll be able to change the email address associated with a lot of my various accounts now that they're offline.

I'm in the same boat. Anyone know of other services similar to Lavabit?

Re: Lavabit abruptly shuts down

#114
post #64

Earlier quoted context omitted.

I'd love to believe that the authorities in Germany are not also tapping lines like France or the UK. Do we have any proof that is the case? I agree this has made me think twice about hosting in the us, but also about crossing national boundaries full stop without encrypting traffic.

Encrypting is a given - obviously you'd want to only be using Saas services in Germany etc that are fully encrypted. The problem in using USA services is that even if everything is fully encrypted, the USA can and will send goons around to take your data. Encryption is simply useless when dealing with a company in the USA who is forced to hand over the keys and whose data-centers can be legally entered and modified b…

The EU has minimum standards for surveillance and most EU member states are clearly American vassals. Even France proved to a vasall in forcing the Bolivian president's aircraft to make an unplanned stopover in Vienna … and even the neutral countries are full in favor of surveillance – Switzerland for example is just revising its surveillance laws and many other legal areas, for example copyright, see an increased level of surveilance too.

Re: Lavabit abruptly shuts down

#115
You know, all these counter measures we come up with are just 'patches' to a set of bugs in our society. We need to rewrite the damn thing. This will just become a cat and mouse game against our own gov't and indirect defensive movements are meaningless without some sort of offensive to change policy. This is becoming a full blown arms race over people's private information. The funding, the computational power, the human capital used to create these things... if the gov't can't or won't listen to the people's will and the situation is bad enough, then something will rise to replace the broken system. Someone's got to spearhead a defense of the individual.

Re: Lavabit abruptly shuts down

#116
post #105

Earlier quoted context omitted.

Former head, and he was talking about the extremists who might attack Google or Microsoft, not lobbying groups like the EFF.

He's using the same logic that's used against extremists: if they're disenfranchised then they're a threat, and if we're disenfranchising them then they're a threat to us. Why does the military have indefinite detention? It's simple: as a matter of policy they torture suspects, but since they were tortured then it stands to reason that they will become radicalized upon release, so they're held indefinitely. Let me sp…

No, he's saying that there are groups on the Internet known for lashing out at companies for various politically motivated reasons, and this Snowden story is going to be one such reason.

His choice to call them terrorists isn't something I'm going to really defend, but if it makes you feel any better, he hasn't been in charge of anything for 4 years.

Re: Lavabit abruptly shuts down

#117

I've had a lavabit email as one of my main emails for years (close to when they first started) and this is a major inconvenience. I'm not sure I'll be able to change the email address associated with a lot of my various accounts now that they're offline.

Assuming you're using (and lavabit supported) custom domains, all you'd need to do is sign up for a dummy email address for now and go to your domain settings and reenter the MX records. But if it was an username@lavabit.com or something like that, then I'm afraid you're out of luck.

Re: Lavabit abruptly shuts down

#118
post #39

Takeaway: > "This experience has taught me one very important lesson: without congressional action or a strong judicial precedent, I would _strongly_ recommend against anyone trusting their private data to a company with physical ties to the United States." It's kind of fitting. The nation that spawned the internet is the nation that's killing the internet biz on its own turf.

I wonder if there is some historical regularity here. After all, my own country, "Das Land der Dichter und Denker" turned on its "Dichter und Denker" when it was at (or close to) the apex of intellectual achievement.

Re: Lavabit abruptly shuts down

#119

Are there any countries, anywhere, where a person can store data outside the reach of the US government's illegal overreach? Any countries friendly to the US are right out. They can tap the lines, but there are ways around that. I just want to be able to park data where some twit with a piece of paper that says "NSA" on it can't get it retrieved or deleted. Any suggestions?

But you have to get the data there. It most certainly isn't protected in transit.

Anything that I really care about will be. And if this is just bulk data, there's tar -czf | gpg -e | ssh

Re: Lavabit abruptly shuts down

#120
post #43

Earlier quoted context omitted.

I'd love to believe that the authorities in Germany are not also tapping lines like France or the UK. Do we have any proof that is the case? I agree this has made me think twice about hosting in the us, but also about crossing national boundaries full stop without encrypting traffic.

The difference is that the authorities in Germany don't have the legal framework to force someone to do this and threaten them to stay silent.

There are no countries where you are allowed to go public on surveillance measures applied to your customers, user etc. – at least not before the surveillance has been completed. And while traditional surveillance measures have an end, today's +/- total surveillance is continous.
Post reply on HN