Live data from Hacker News

Lavabit abruptly shuts down

lavabit.com

181–190 of 671 posts

Re: Lavabit abruptly shuts down

#181
post #28

Earlier quoted context omitted.

And this reads as if someone was trying to force him to install means to spy on his users, and it wouldn't be surprising if the aim was to spy on Snowden directly (if he really used this service).

It may be simpler than that. Even if Snowden has walked away from this service, the publicity may have attracted a lot of people the authorities find interesting, including legitimate (whatever that means) persons of interest.

The political backlash attached to slapping an NSL on "Snowden's email provider" would have looked obvious to a 5-year-old, and any real player worth its salt would have run from Lavabit as soon as it hit the news.

No, this has nothing to do with common criminals and everything to do with Snowden.

Re: Lavabit abruptly shuts down

#182
post #108
post #24

I'm in the process of moving any Saas offerings I use off USA-affiliated companies, but it's actually more difficult than I first thought. I believe there might even be a very profitable market in simply duplicating the functionality of Saas offerings at a higher price with security/privacy guarantees in Germany/HK/etc. Might be the next hot business to be in? You'd be surprised as to the number of people seeking alt…

Moving services off USA-based companies is like using two bicycle locks instead of one. A determined government is still going to get your data, they just need to spend a bit more time. Focus instead on encryption.

Not quite. Storing ciphertext and keys in legal jurisdictions (like the US) that can be forced to turn over both is a bad idea.

Also, practical key management is still an unsolved problem. The web of trust never took off and the PKI is fucked. Encryption is only as useful as the keys being used to encrypt.

Re: Lavabit abruptly shuts down

#183
The US government is destroying one of the few bright spots in the American economy with its out of control military. It is unconscionable. And the sad thing is it has been enabled by the betrayal by many of the web 2.0 giants, Facebook, Google etc. Google especially is sad to see since they were willing to forgo the Chinese market on principle, but then decided that taking on the authoritarian US government was too lucrative for principle to be involved. If Google had done what Lavabit just did we would be living in a freer country today.

Re: Lavabit abruptly shuts down

#184
post #12

From 2011: > Lavabit processes 70 gigabytes of data per day, is made up of 26 servers, hosts 260,000 email addresses, and processes 600,000 emails a day. That’s a lot of email. http://www.dbasoul.com/2011/1008.html Update: According to their stats page, they had 410k email accounts hosted before shutdown https://twitter.com/georgemaschke/status/365553445538775040

70 GB / 600K emails = 122KB per email. That's a large average even with headers. To put things in perspective, Costco's massive marketing email sent to me this morning is 138K including headers.

So the question is, what were people sending though Lavabit that averaged 122K and would have attracted attention? Therein probably lies the reason for all of this.

Re: Lavabit abruptly shuts down

#186
Is there a way to verify that the service has been shut down for the reasons stated/(not-stated)? I want to call my political representatives and let them know that these secret court filings that prevent people from speaking about their case hurts businesses & individuals alike. Before I do that though I'd like be sure that the reason Lavabit shut down is due to the government's interference. Is there any way of finding out?

Also, can someone recommend a trusted alternative?

Re: Lavabit abruptly shuts down

#187

This is infuriating, and the worst part is that a clear solution isn't in sight. Sure, we can fight this in the courts, and a few secret programs might get shut down, but operations will just continue under a different name. We can encrypt our data, move our services and data offshore, but that just paints a big target on our heads - doesn't actually address the fundamental issue. This is supposed to be a democracy,…

The only nonviolent solution I've found is to move away and stop paying taxes to the US war machine. Don't use or support services that pay US taxes, either.

It's what I did.

PS: It is very, very, very difficult, because most of the people you care about will not move with you.

Re: Lavabit abruptly shuts down

#188
post #9

Time to donate to the EFF. They haven't been branded as a terrorist charity yet, AFAIK...

Don't give ideas. Too bad that he does not have donations page. I would gladly donate. Also - respect for the decision he made. If he kickstarts a campaign for restoring the service I will be there too.

[deleted]

Re: Lavabit abruptly shuts down

#189

This is infuriating, and the worst part is that a clear solution isn't in sight. Sure, we can fight this in the courts, and a few secret programs might get shut down, but operations will just continue under a different name. We can encrypt our data, move our services and data offshore, but that just paints a big target on our heads - doesn't actually address the fundamental issue. This is supposed to be a democracy,…

Make the bastards work for it. Enough people using strong encryption (both for data over the wire and data at rest) makes big-data collection (can't dedupe random noise) and processing/datamining prohibitively expensive if not impossible. Nobody is getting in trouble for moving their data and services offshore. Aside from that? I'd suggest finding a few friendly people in various countries and establish a constant /d…

I wonder if, more than crypto, false positives would make them work harder. They know who you are emailing too, and so likely are not going to target you in any case, since you are not part of an interesting network.

But if you start talking about a movie, where they plan to detonate a dirty bomb in Times Square or something...

Emacs automates this with M-x spook:

morse War on Terrorism encryption Forte Blowpipe LLNL John Kerry Albright Kh-11 22nd SAS ANC Semtex SEAL Team 6 smuggle CIA

Also, everyone here from the US has placed a phone call to their representatives to politely, succinctly, and clearly state their opposition to this stuff, right? Ultimately, a political solution is best. False positives make them waste their time, and there are a lot of them who probably really do care about catching genuinely bad people who want to do bad stuff. Just that they need less secrecy, more focus, and much more oversight.

Re: Lavabit abruptly shuts down

#190
Where's the "I wish you hadn't done that, lavabit, I'm a customer and I feel very screwed over by this action" comments?

Or is this appropriate for any SaaS vendor? You're OK with this? Should all customers, even those who really don't care if the NSA could be watching, be put out because some feel that this cause trumps actually doing business and having customer-vendor relationships?

I could see someone suing an SaaS vendor for an action like this, actually. "You cost me $XX in actual costs and $YYY in lost business. Your TOS says nothing about your shutting down because the government asked you to do something you didn't agree with."

Post reply on HN