Live data from Hacker News

Lavabit abruptly shuts down

lavabit.com

121–130 of 671 posts

Re: Lavabit abruptly shuts down

#121
post #64

Earlier quoted context omitted.

I'd love to believe that the authorities in Germany are not also tapping lines like France or the UK. Do we have any proof that is the case? I agree this has made me think twice about hosting in the us, but also about crossing national boundaries full stop without encrypting traffic.

Encrypting is a given - obviously you'd want to only be using Saas services in Germany etc that are fully encrypted. The problem in using USA services is that even if everything is fully encrypted, the USA can and will send goons around to take your data. Encryption is simply useless when dealing with a company in the USA who is forced to hand over the keys and whose data-centers can be legally entered and modified b…

Don't choose Germany. We may have strict privacy laws here, but we also have the BND cooperating with the NSA, tapping directly into the main internet nodes (Frankfurt). And don't forget that part of the method of the NSA is to use a mule inside the target company, which would be very easy in Germany given its status of being a wannabe ally of the USA and the longstanding sympathy of the german public for the USA.

And Germany has also laws which force every mail provider to install an access point to the German authorities and intelligence agencies. I am not sure if also a generic saas platform would have to do it, but it is quite possible.

Better pick Switzerland or Island.

Re: Lavabit abruptly shuts down

#122
post #105

Earlier quoted context omitted.

He's using the same logic that's used against extremists: if they're disenfranchised then they're a threat, and if we're disenfranchising them then they're a threat to us. Why does the military have indefinite detention? It's simple: as a matter of policy they torture suspects, but since they were tortured then it stands to reason that they will become radicalized upon release, so they're held indefinitely. Let me sp…

No, he's saying that there are groups on the Internet known for lashing out at companies for various politically motivated reasons, and this Snowden story is going to be one such reason. His choice to call them terrorists isn't something I'm going to really defend, but if it makes you feel any better, he hasn't been in charge of anything for 4 years.

He may not have been in charge of anything for four years, but it would be nice to see General Alexander condemning such specious reasoning and fear-mongering.

Re: Lavabit abruptly shuts down

#124
post #108
post #24

I'm in the process of moving any Saas offerings I use off USA-affiliated companies, but it's actually more difficult than I first thought. I believe there might even be a very profitable market in simply duplicating the functionality of Saas offerings at a higher price with security/privacy guarantees in Germany/HK/etc. Might be the next hot business to be in? You'd be surprised as to the number of people seeking alt…

Moving services off USA-based companies is like using two bicycle locks instead of one. A determined government is still going to get your data, they just need to spend a bit more time. Focus instead on encryption.

It is just as bad or worse. You have to move the data in/out of the country. It definitely isn't protected when it leaves the country. The only advantage I see is that it punishes US businesses for failing to protest.

Re: Lavabit abruptly shuts down

#125
post #92
post #64

Earlier quoted context omitted.

Encrypting is a given - obviously you'd want to only be using Saas services in Germany etc that are fully encrypted. The problem in using USA services is that even if everything is fully encrypted, the USA can and will send goons around to take your data. Encryption is simply useless when dealing with a company in the USA who is forced to hand over the keys and whose data-centers can be legally entered and modified b…

EU is a very generic term here. There is very little consistency across member states on this topic; UK laws, for example, are probably worse than US ones in most cases. I'm not 100% sure, but I believe Italian ones aren't much better atm. The short-term answer is to encrypt everything users have to store, and don't handle their keys, but it's a stop-gap: the only real answer is political and that's where things have…

Then the most obvious answer to me seems to use technology to affect the political landscape.

How that actually manifests itself, depends on how desperate people become to retain some sovereignty over their livelihoods… which begs the question, where are we now and who could provide the resources/environment to foster the type of change that is needed?

Re: Lavabit abruptly shuts down

#126
post #24

I'm in the process of moving any Saas offerings I use off USA-affiliated companies, but it's actually more difficult than I first thought. I believe there might even be a very profitable market in simply duplicating the functionality of Saas offerings at a higher price with security/privacy guarantees in Germany/HK/etc. Might be the next hot business to be in? You'd be surprised as to the number of people seeking alt…

How about a local cloud? I understand that this may seem pointless, as you're owning and paying for all the hardware, but it would really help in deployment, scaling and maintenance just like a "classic" cloud service can.

Re: Lavabit abruptly shuts down

#127
post #24

I'm in the process of moving any Saas offerings I use off USA-affiliated companies, but it's actually more difficult than I first thought. I believe there might even be a very profitable market in simply duplicating the functionality of Saas offerings at a higher price with security/privacy guarantees in Germany/HK/etc. Might be the next hot business to be in? You'd be surprised as to the number of people seeking alt…

> I'm in the process of moving any Saas offerings I use off USA-affiliated companies, but it's actually more difficult than I first thought. You should try finding a SSL cert retailer that's outside of the US. The only ones I could find that would actually sell me certs without a phone call charged at least $200 for a basic certificate. https://swisssign.com/en were the most sensible looking ones I could find.

[deleted]

Re: Lavabit abruptly shuts down

#128
post #108
post #24

I'm in the process of moving any Saas offerings I use off USA-affiliated companies, but it's actually more difficult than I first thought. I believe there might even be a very profitable market in simply duplicating the functionality of Saas offerings at a higher price with security/privacy guarantees in Germany/HK/etc. Might be the next hot business to be in? You'd be surprised as to the number of people seeking alt…

Moving services off USA-based companies is like using two bicycle locks instead of one. A determined government is still going to get your data, they just need to spend a bit more time. Focus instead on encryption.

The goal is not necessarily security (I have nothing to hide (I still do hide as much as possible))-- the goal is political change. That's the only real way out of this mess. By not using US companies, you incentivize those to lobby for better laws.

Re: Lavabit abruptly shuts down

#129
post #63

I really would want to donate to them. But you know I kind of feel weary now connecting my PayPal Account with them. I hope some kind of organisation is standing up for them. Like EFF or something. Not because I don't trust them. But because I don't trust the NSA. They might flag me as a terrorist or something. Then again I'm probably already on this list for having some technical involvment with something the US gov…

If you're so easily intimidated why do you still post comments about the NSA on the internet?

Re: Lavabit abruptly shuts down

#130
post #108
post #24

I'm in the process of moving any Saas offerings I use off USA-affiliated companies, but it's actually more difficult than I first thought. I believe there might even be a very profitable market in simply duplicating the functionality of Saas offerings at a higher price with security/privacy guarantees in Germany/HK/etc. Might be the next hot business to be in? You'd be surprised as to the number of people seeking alt…

Moving services off USA-based companies is like using two bicycle locks instead of one. A determined government is still going to get your data, they just need to spend a bit more time. Focus instead on encryption.

There's not even the time factor. Western countries at least might theoretically not spy on their own citizens but the exchange data with partners intelligence services. And the US is by far not the only country that mandates surveillance cooperation for providers etc.

Encryption is OK but doesn't solve the problem. There's always metadata and whom can your trust with your encryption? You have to assume that hardware and software you use has backdoors. Mobile phones for example has even official backdoors, your SIM card can be remotely changed and so on …

Post reply on HN