Live data from Hacker News

Lavabit abruptly shuts down

lavabit.com

171–180 of 671 posts

Re: Lavabit abruptly shuts down

#171
post #69

Earlier quoted context omitted.

This would imply that the court can order you to lie to your customers. I think this is not the case. If there is any precedence for any US court requiring public citizen to lie I definitely want to know about it. If the courts are acting like they have this power then it will greatly change my perception of how the courts, NSA, and congress are currently acting.

They have in the past - there are definitely situations where you are required to lie, for example, when working on classified materials or covert operations.

Slightly different, that is an operative agreeing to be an operative with up front knowledge of what it entails. So the person lying has agreed to lie before being given the information or a mission. If you know a case where a person has been prosecuted for not lying rather then breaking an agreement I would still be interested.

I am not sure what I think about your scenario off the top of my head but I do consider it different.

Re: Lavabit abruptly shuts down

#172

I watched Casablanca the other night. SPOILERS I thought about how the Gestapo had Lazlow in their midst, at the same TABLE as them, and yet didn't do anything immediately other than deny him further travel. Of course, it's a movie, but it was an interesting thought. Nowadays, if Snowden were known to be hiding in a foreigner's Moroccan cafe, we'ds drone half the building. Also, I noticed the pride and the wonder tha…

Old European elites shared a common culture that went beyond borders, at times perversely so (e.g. the whole Geneva Convention mindset where war is all a big game in need of more gentlemanly rules). They respected each other more than they did their fellow countrymen from lower classes. It's the same today: you'd never see a Saudi billionaire droned, even if we knew he'd been "the real Osama" all along.

Snowden is a little fish and as such he's being treated, as an example to his uppity peers. His friends are little fish, and as such are being burnt down without a second thought.

Re: Lavabit abruptly shuts down

#173
post #24

I'm in the process of moving any Saas offerings I use off USA-affiliated companies, but it's actually more difficult than I first thought. I believe there might even be a very profitable market in simply duplicating the functionality of Saas offerings at a higher price with security/privacy guarantees in Germany/HK/etc. Might be the next hot business to be in? You'd be surprised as to the number of people seeking alt…

> I'm in the process of moving any Saas offerings I use off USA-affiliated companies, but it's actually more difficult than I first thought. You should try finding a SSL cert retailer that's outside of the US. The only ones I could find that would actually sell me certs without a phone call charged at least $200 for a basic certificate. https://swisssign.com/en were the most sensible looking ones I could find.

This part doesn't matter. Where your cert comes from is irrelevant.

Re: Lavabit abruptly shuts down

#174
I've posted this link on HN before, but it's potentially relevant - we might find out more, but it sounds like this might be the result of a National Security Letter preventing Ladar from talking about the reason behind the shutdown.

I would suspect he has tried to protect his users from a request for information (NSLs are allegedly limited to metadata), but would prefer to discontinue the service than take the other possible legal action (silently disclosing information). Perhaps it is possible he will/has been forced to disclose information anyway.

This link is a video featuring Nicholas Merrill who (if this is in fact NSL-related) went through a similar situation with his ISP Calyx, and gave as much information as legally possible about the frustrating process as a talk at the yearly Chaos Communication Congress in 2010.

https://events.ccc.de/congress/2010/Fahrplan/events/4263.en....

Re: Lavabit abruptly shuts down

#175
post #155

Earlier quoted context omitted.

It is just as bad or worse. You have to move the data in/out of the country. It definitely isn't protected when it leaves the country. The only advantage I see is that it punishes US businesses for failing to protest.

I don't blame the companies; they're about as much a victim of USgov as we are IMHO. That being said, if all the online-storage/cloud-server/email-providers/social-whatever companies in US start going out of business because nobody trusts them I strongly suspect something will have to change. It's just too bad we have to do a "scorched earth"[1] to bring about change. 1. http://en.wikipedia.org/wiki/Scorched_earth

> I don't blame the companies; they're as much a victim of USgov as we are IMHO.

While it's true that they are victims, they are in a far better place to demand change or to defend themselves. Money buys the ears of lawyers that the average person couldn't even afford to speak to.

Re: Lavabit abruptly shuts down

#176
post #64

Earlier quoted context omitted.

I'd love to believe that the authorities in Germany are not also tapping lines like France or the UK. Do we have any proof that is the case? I agree this has made me think twice about hosting in the us, but also about crossing national boundaries full stop without encrypting traffic.

Encrypting is a given - obviously you'd want to only be using Saas services in Germany etc that are fully encrypted. The problem in using USA services is that even if everything is fully encrypted, the USA can and will send goons around to take your data. Encryption is simply useless when dealing with a company in the USA who is forced to hand over the keys and whose data-centers can be legally entered and modified b…

Germany sends goons to take data as well, as does every country in Europe.

http://arstechnica.com/tech-policy/2011/05/german-police-sei...

Re: Lavabit abruptly shuts down

#177

This is infuriating, and the worst part is that a clear solution isn't in sight. Sure, we can fight this in the courts, and a few secret programs might get shut down, but operations will just continue under a different name. We can encrypt our data, move our services and data offshore, but that just paints a big target on our heads - doesn't actually address the fundamental issue. This is supposed to be a democracy,…

If the mere capability of surveillance is what upsets you, then I'd recommend yoga and encryption. Investigatory powers have been used in pretty much all nations for hundreds of years and so if your big plan is to remove the very ability for governments to do that, you're going to be in for a long and arduous slog.

If instead your concern is with unchecked and expansive untargeted surveillance, we need to push hard for transparency and oversight, which is something that is politically viable and gets 99.9% of the benefit to the average person of surveillance not being possible at all.

Re: Lavabit abruptly shuts down

#178

This is infuriating, and the worst part is that a clear solution isn't in sight. Sure, we can fight this in the courts, and a few secret programs might get shut down, but operations will just continue under a different name. We can encrypt our data, move our services and data offshore, but that just paints a big target on our heads - doesn't actually address the fundamental issue. This is supposed to be a democracy,…

Make the bastards work for it.

Enough people using strong encryption (both for data over the wire and data at rest) makes big-data collection (can't dedupe random noise) and processing/datamining prohibitively expensive if not impossible.

Nobody is getting in trouble for moving their data and services offshore.

Aside from that? I'd suggest finding a few friendly people in various countries and establish a constant /dev/urandom | ssh | > /dev/null stream when your internet connection is idle.

Re: Lavabit abruptly shuts down

#179
post #11

Earlier quoted context omitted.

I just lost access to my primary email account.

Do what I do! I have my own domain name, currently hosting with Google Apps. If I get the motivation to move to another host like myself, I can do it without changing contact information.

Yeah, I thank my stars that I had the sense to do this almost 2 years ago. It really is much better. Another neat hack of using your custom domain is when people ask for your email address you can make one up without you appearing in their chat list. So for instance on Google Talk you're registered as iam@firstlastname.com, you could simply give them i@firstlastname.com so they can still converse with you (catch-alls ftw) yet they don't annoyingly appear on your Talk list.

And yeah, changing providers is just a matter of altering a field or two in the host records page.

Re: Lavabit abruptly shuts down

#180
post #108
post #24

I'm in the process of moving any Saas offerings I use off USA-affiliated companies, but it's actually more difficult than I first thought. I believe there might even be a very profitable market in simply duplicating the functionality of Saas offerings at a higher price with security/privacy guarantees in Germany/HK/etc. Might be the next hot business to be in? You'd be surprised as to the number of people seeking alt…

Moving services off USA-based companies is like using two bicycle locks instead of one. A determined government is still going to get your data, they just need to spend a bit more time. Focus instead on encryption.

I will take mine government over yours. I can atleast try to deal with mine.
Post reply on HN