Please donate to their defense fund. It's not often you get a chance to directly support a cause like this. The link is at the bottom of http://lavabit.com/ , but I'll repost it here: https://www.paypal.com/cgi-bin/webscr?cmd=_s-xclick&hosted_b...
Lavabit abruptly shuts down
161–170 of 671 posts
Re: Lavabit abruptly shuts down
#162Earlier quoted context omitted.
I'm sure they would argue that you weren't supposed to reveal that you were under an NSL, and that your inaction did reveal it, so you violated the terms. As the grandparent says, it probably just a cute legal trick that wouldn't impress a judge.
If it gets to the point that a judge is not impressed, at least the public has been warned.
And thus the canary is legally useless--if you're going to have the penalties of violating a national security order, might as well just do it in a straightforward manner.
Re: Lavabit abruptly shuts down
#163Re: Lavabit abruptly shuts down
#164Earlier quoted context omitted.
Don't choose Germany. We may have strict privacy laws here, but we also have the BND cooperating with the NSA, tapping directly into the main internet nodes (Frankfurt). And don't forget that part of the method of the NSA is to use a mule inside the target company, which would be very easy in Germany given its status of being a wannabe ally of the USA and the longstanding sympathy of the german public for the USA. An…
"And Germany has also laws which force every mail provider to install an access point to the German authorities and intelligence agencies. I am not sure if also a generic saas platform would have to do it, but it is quite possible." Thanks for the heads up - as I said in the OP, it really is a difficult task. Those kind of laws are exactly what need to be avoided when choosing a country to host in. I don't believe th…
Re: Lavabit abruptly shuts down
#165I'm in the process of moving any Saas offerings I use off USA-affiliated companies, but it's actually more difficult than I first thought. I believe there might even be a very profitable market in simply duplicating the functionality of Saas offerings at a higher price with security/privacy guarantees in Germany/HK/etc. Might be the next hot business to be in? You'd be surprised as to the number of people seeking alt…
Moving services off USA-based companies is like using two bicycle locks instead of one. A determined government is still going to get your data, they just need to spend a bit more time. Focus instead on encryption.
Re: Lavabit abruptly shuts down
#166Anyone know what happens if he just says "F it" and writes a massive blog post on what exactly happened or what exactly they said to him?
Re: Lavabit abruptly shuts down
#167Earlier quoted context omitted.
If it gets to the point that a judge is not impressed, at least the public has been warned.
The "judge is not impressed" means they would probably view it as the same as just warning the public directly, with equivalent penalties. And thus the canary is legally useless--if you're going to have the penalties of violating a national security order, might as well just do it in a straightforward manner.
Re: Lavabit abruptly shuts down
#168Earlier quoted context omitted.
Do what I do! I have my own domain name, currently hosting with Google Apps. If I get the motivation to move to another host like myself, I can do it without changing contact information.
Oh good, because Google will never be subject to an NSL.
And really, since all your email hops through relays constantly, the only truly effective anti-spy technology is message encryption, which wouldn't depend on where the messages end up.
Re: Lavabit abruptly shuts down
#169Earlier quoted context omitted.
Encrypting is a given - obviously you'd want to only be using Saas services in Germany etc that are fully encrypted. The problem in using USA services is that even if everything is fully encrypted, the USA can and will send goons around to take your data. Encryption is simply useless when dealing with a company in the USA who is forced to hand over the keys and whose data-centers can be legally entered and modified b…
EU is a very generic term here. There is very little consistency across member states on this topic; UK laws, for example, are probably worse than US ones in most cases. I'm not 100% sure, but I believe Italian ones aren't much better atm. The short-term answer is to encrypt everything users have to store, and don't handle their keys, but it's a stop-gap: the only real answer is political and that's where things have…
Users can not and will not securely manage key material.
Re: Lavabit abruptly shuts down
#170Earlier quoted context omitted.
Don't choose Germany. We may have strict privacy laws here, but we also have the BND cooperating with the NSA, tapping directly into the main internet nodes (Frankfurt). And don't forget that part of the method of the NSA is to use a mule inside the target company, which would be very easy in Germany given its status of being a wannabe ally of the USA and the longstanding sympathy of the german public for the USA. An…
"And Germany has also laws which force every mail provider to install an access point to the German authorities and intelligence agencies. I am not sure if also a generic saas platform would have to do it, but it is quite possible." Thanks for the heads up - as I said in the OP, it really is a difficult task. Those kind of laws are exactly what need to be avoided when choosing a country to host in. I don't believe th…