Live data from Hacker News

Lavabit abruptly shuts down

lavabit.com

141–150 of 671 posts

Re: Lavabit abruptly shuts down

#141
post #122

Earlier quoted context omitted.

No, he's saying that there are groups on the Internet known for lashing out at companies for various politically motivated reasons, and this Snowden story is going to be one such reason. His choice to call them terrorists isn't something I'm going to really defend, but if it makes you feel any better, he hasn't been in charge of anything for 4 years.

He may not have been in charge of anything for four years, but it would be nice to see General Alexander condemning such specious reasoning and fear-mongering.

It'd be nice to see Obama pardon Snowden, too.

Re: Lavabit abruptly shuts down

#142
post #32

I like the part where he can't tell you why he's shutting down. As if we won't engage in rampant irresponsible speculation that they have told him to decrypt and forward everything to them in real time.

what would you have him do? He's clearly under NSL, so he can't tell you what he was asked for. This is the strongest statement he can legally make (in fact, i'm sure some US lawyers would argue that it's actually beyond that). I guess we now know how it must have felt to watch republican institutions spiral into tyranny in ancient Rome.

Yes, unfortunately; I'm a student of that period of history and it's getting pretty bad by its standards. No proscriptions yet, though ... perhaps because that doesn't work so well with a well armed populace.

Re: Lavabit abruptly shuts down

#143
So we've hear stories of the big companies being targeted. Now a smaller company has been included. How small will this go for monitoring?

Should we assume that any browser plugins are potential trojan horses for desktop targeting?

Re: Lavabit abruptly shuts down

#144

Earlier quoted context omitted.

What? I don't think this is true at all. Plaintext data, email or not, can be protected with robust encryption. Your end security is the main consideration, but that has nothing to do with the protocol or content, really.

The difficulty is that most recipients of your message will not be willing to use whatever crypto technology you've chosen. PGP is probably the most popular email encryption system, but good luck finding people who use it. I work in the software industry, and I don't regularly correspond with a single person whom I know to use PGP.

It'll be interesting to see whether companies start to shift to using encrypted email over the next few decades - it's not that hard to set up if you know the counterparty will be using encryption of the same kind, and if it's not a service bought in from an external company you can fairly sure it is secure.

Companies could at least insist that intra-company email is encrypted, which would be a huge amount of their normal communications, and then extend that outside their boundaries with partners who also accept (say) S/MIME.

At present I sign my mails but like you have no clients who use encryption.

Re: Lavabit abruptly shuts down

#145
post #108
post #24

I'm in the process of moving any Saas offerings I use off USA-affiliated companies, but it's actually more difficult than I first thought. I believe there might even be a very profitable market in simply duplicating the functionality of Saas offerings at a higher price with security/privacy guarantees in Germany/HK/etc. Might be the next hot business to be in? You'd be surprised as to the number of people seeking alt…

Moving services off USA-based companies is like using two bicycle locks instead of one. A determined government is still going to get your data, they just need to spend a bit more time. Focus instead on encryption.

It would be really unfortunate if people started getting polarized into encryption / social / legal camps. All these things are necessary.

Re: Lavabit abruptly shuts down

#146
post #39

Takeaway: > "This experience has taught me one very important lesson: without congressional action or a strong judicial precedent, I would _strongly_ recommend against anyone trusting their private data to a company with physical ties to the United States." It's kind of fitting. The nation that spawned the internet is the nation that's killing the internet biz on its own turf.

The internet is serious business.

Re: Lavabit abruptly shuts down

#147

Are there any countries, anywhere, where a person can store data outside the reach of the US government's illegal overreach? Any countries friendly to the US are right out. They can tap the lines, but there are ways around that. I just want to be able to park data where some twit with a piece of paper that says "NSA" on it can't get it retrieved or deleted. Any suggestions?

China, Russia, or North Korea, pretty sure. You have your pick of which governmental spy agency gets to snoop through your data!

Re: Lavabit abruptly shuts down

#148
post #40

Earlier quoted context omitted.

I'm also unsure of their proven effectiveness, but how could they hold you in contempt for _not_ taking an action?

I have the same question. It's very odd for a court to compel positive action.

An order to appear is a positive action where you can be punished for not doing something.

Re: Lavabit abruptly shuts down

#149
One big question I have for the legal beagles: It's understood (if not well-liked) that Fourth Amendment protections don't apply to data given to a third-party...

What if, instead, you host server space within the U.S. and run your own software (email, listserv, whatever) and data on the leased hardware? I would think there's a good argument that Fourth Amendment protections then resume, and the domestic-ness of the server would also mean the NSA is not legally allowed to look at it, at least without a real Article III warrant.

Do similar rights apply IRL, e.g. if you rent a storage closet, can law enforcement just open the door when they wish or do they need to get a warrant?

Re: Lavabit abruptly shuts down

#150
post #121
post #64

Earlier quoted context omitted.

Encrypting is a given - obviously you'd want to only be using Saas services in Germany etc that are fully encrypted. The problem in using USA services is that even if everything is fully encrypted, the USA can and will send goons around to take your data. Encryption is simply useless when dealing with a company in the USA who is forced to hand over the keys and whose data-centers can be legally entered and modified b…

Don't choose Germany. We may have strict privacy laws here, but we also have the BND cooperating with the NSA, tapping directly into the main internet nodes (Frankfurt). And don't forget that part of the method of the NSA is to use a mule inside the target company, which would be very easy in Germany given its status of being a wannabe ally of the USA and the longstanding sympathy of the german public for the USA. An…

"And Germany has also laws which force every mail provider to install an access point to the German authorities and intelligence agencies. I am not sure if also a generic saas platform would have to do it, but it is quite possible."

Thanks for the heads up - as I said in the OP, it really is a difficult task. Those kind of laws are exactly what need to be avoided when choosing a country to host in. I don't believe that this kind of thing can be carried out in absolute silence though, so if a country is actively modifying and silencing hosts it's fairly likely that word of it will leak somewhere.

If I get a chance, I might try to put together a red/orange/green overview of known laws and practices in different countries that would affect hosting services there. Unless someone is already working on that and needs a hand?

Post reply on HN