Live data from Hacker News

Lavabit abruptly shuts down

lavabit.com

161–170 of 671 posts

Re: Lavabit abruptly shuts down

#161

Please donate to their defense fund. It's not often you get a chance to directly support a cause like this. The link is at the bottom of http://lavabit.com/ , but I'll repost it here: https://www.paypal.com/cgi-bin/webscr?cmd=_s-xclick&hosted_b...

I already donated when I paid for a service that I now can't use. How do I go about getting a reverse donation -- i.e., a refund?

Re: Lavabit abruptly shuts down

#162

Earlier quoted context omitted.

I'm sure they would argue that you weren't supposed to reveal that you were under an NSL, and that your inaction did reveal it, so you violated the terms. As the grandparent says, it probably just a cute legal trick that wouldn't impress a judge.

If it gets to the point that a judge is not impressed, at least the public has been warned.

The "judge is not impressed" means they would probably view it as the same as just warning the public directly, with equivalent penalties.

And thus the canary is legally useless--if you're going to have the penalties of violating a national security order, might as well just do it in a straightforward manner.

Re: Lavabit abruptly shuts down

#163
Refunds for anyone? I can't believe this guy asks for a donation to his legal defense fund. I already donated when I paid for a service that I now can't use. How do I go about getting a reverse donation -- i.e., a refund?

Re: Lavabit abruptly shuts down

#164
post #121

Earlier quoted context omitted.

Don't choose Germany. We may have strict privacy laws here, but we also have the BND cooperating with the NSA, tapping directly into the main internet nodes (Frankfurt). And don't forget that part of the method of the NSA is to use a mule inside the target company, which would be very easy in Germany given its status of being a wannabe ally of the USA and the longstanding sympathy of the german public for the USA. An…

"And Germany has also laws which force every mail provider to install an access point to the German authorities and intelligence agencies. I am not sure if also a generic saas platform would have to do it, but it is quite possible." Thanks for the heads up - as I said in the OP, it really is a difficult task. Those kind of laws are exactly what need to be avoided when choosing a country to host in. I don't believe th…

If you do that, could you send me a mail? I'd be interested.

Re: Lavabit abruptly shuts down

#165
post #108
post #24

I'm in the process of moving any Saas offerings I use off USA-affiliated companies, but it's actually more difficult than I first thought. I believe there might even be a very profitable market in simply duplicating the functionality of Saas offerings at a higher price with security/privacy guarantees in Germany/HK/etc. Might be the next hot business to be in? You'd be surprised as to the number of people seeking alt…

Moving services off USA-based companies is like using two bicycle locks instead of one. A determined government is still going to get your data, they just need to spend a bit more time. Focus instead on encryption.

I had the impression that government does not need to decrypt anything. They just request it from a company, and the company has to comply.

Re: Lavabit abruptly shuts down

#166
> I wish that I could legally share with you the events that led to my decision. I cannot. I feel you deserve to know what’s going on--the first amendment is supposed to guarantee me the freedom to speak out in situations like this.

Anyone know what happens if he just says "F it" and writes a massive blog post on what exactly happened or what exactly they said to him?

Re: Lavabit abruptly shuts down

#167

Earlier quoted context omitted.

If it gets to the point that a judge is not impressed, at least the public has been warned.

The "judge is not impressed" means they would probably view it as the same as just warning the public directly, with equivalent penalties. And thus the canary is legally useless--if you're going to have the penalties of violating a national security order, might as well just do it in a straightforward manner.

At this point, it is speculation that the judge would not be impressed. If anyone decided to test the theory, the public would be informed regardless.

Re: Lavabit abruptly shuts down

#168

Earlier quoted context omitted.

Do what I do! I have my own domain name, currently hosting with Google Apps. If I get the motivation to move to another host like myself, I can do it without changing contact information.

Oh good, because Google will never be subject to an NSL.

At the moment, I accept the danger and resent myself for it. Moving to a custom domain is one step in the process, though.

And really, since all your email hops through relays constantly, the only truly effective anti-spy technology is message encryption, which wouldn't depend on where the messages end up.

Re: Lavabit abruptly shuts down

#169
post #92
post #64

Earlier quoted context omitted.

Encrypting is a given - obviously you'd want to only be using Saas services in Germany etc that are fully encrypted. The problem in using USA services is that even if everything is fully encrypted, the USA can and will send goons around to take your data. Encryption is simply useless when dealing with a company in the USA who is forced to hand over the keys and whose data-centers can be legally entered and modified b…

EU is a very generic term here. There is very little consistency across member states on this topic; UK laws, for example, are probably worse than US ones in most cases. I'm not 100% sure, but I believe Italian ones aren't much better atm. The short-term answer is to encrypt everything users have to store, and don't handle their keys, but it's a stop-gap: the only real answer is political and that's where things have…

Where exactly are these keys going to be stored?

Users can not and will not securely manage key material.

Re: Lavabit abruptly shuts down

#170
post #121

Earlier quoted context omitted.

Don't choose Germany. We may have strict privacy laws here, but we also have the BND cooperating with the NSA, tapping directly into the main internet nodes (Frankfurt). And don't forget that part of the method of the NSA is to use a mule inside the target company, which would be very easy in Germany given its status of being a wannabe ally of the USA and the longstanding sympathy of the german public for the USA. An…

"And Germany has also laws which force every mail provider to install an access point to the German authorities and intelligence agencies. I am not sure if also a generic saas platform would have to do it, but it is quite possible." Thanks for the heads up - as I said in the OP, it really is a difficult task. Those kind of laws are exactly what need to be avoided when choosing a country to host in. I don't believe th…

Please do this! This would actually be very useful..
Post reply on HN