Live data from Hacker News

Lavabit abruptly shuts down

lavabit.com

191–200 of 671 posts

Re: Lavabit abruptly shuts down

#191
post #149

One big question I have for the legal beagles: It's understood (if not well-liked) that Fourth Amendment protections don't apply to data given to a third-party... What if, instead, you host server space within the U.S. and run your own software (email, listserv, whatever) and data on the leased hardware? I would think there's a good argument that Fourth Amendment protections then resume, and the domestic-ness of the…

You need a warrant, but honestly we don't know if that isn't the case here. It's come up before that the NSA, FBI et al, serve warrants for encrypted data and can demand it be decrypted. Otherwise, services like lavabit are equivalent to Swiss bank accounts that are unreachable by any means, legitimate or otherwise. Realistically, this service was almost certainly hosting a ton a illegal activities.

Re: Lavabit abruptly shuts down

#192

You know, all these counter measures we come up with are just 'patches' to a set of bugs in our society. We need to rewrite the damn thing. This will just become a cat and mouse game against our own gov't and indirect defensive movements are meaningless without some sort of offensive to change policy. This is becoming a full blown arms race over people's private information. The funding, the computational power, the…

You're talking about Assange. He's currently running for australian senate spot. Read his book, spread the word.

Re: Lavabit abruptly shuts down

#193
post #58

Earlier quoted context omitted.

If you're German, would you prefer to be surveilled by the German government or by both the US and German governments? If you're in the US it seems kinda pointless to try to move to overseas hosting; the NSA will probably just focus on the client side.

Accountability and culture. German intelligence services are "weaker" in the sense that they (seemlingly) still are under the control of the legislative body (secret contracts with the Western Allies sadly nonwithstanding). They are also regarded with deep distrust by large parts of the populace and by a significant segment of the legislature. It is quite possbible that, come September, some of the government parties…

>Accountability and culture

The culture that brought us the SS and the Stasi.

Re: Lavabit abruptly shuts down

#194
post #181

Earlier quoted context omitted.

It may be simpler than that. Even if Snowden has walked away from this service, the publicity may have attracted a lot of people the authorities find interesting, including legitimate (whatever that means) persons of interest.

The political backlash attached to slapping an NSL on "Snowden's email provider" would have looked obvious to a 5-year-old, and any real player worth its salt would have run from Lavabit as soon as it hit the news. No, this has nothing to do with common criminals and everything to do with Snowden.

Didn't Italy nail a mob boss a few years ago because they were using a common substitution cipher?

Re: Lavabit abruptly shuts down

#195
does anybody know any alternatives to the lavabit free accounts?

man, i am so fed up with those mf'ing feds in the us. now i have to migrate all my website registrations to a new provider without being able to receive cancellations on the lavabit addresses.

F*CK!

Re: Lavabit abruptly shuts down

#196
post #57

Earlier quoted context omitted.

It wouldn't be resilient to interception of mail going to and coming from lavabit however, since email is essentially a plaintext public protocol.

This is somewhat true. RFC3207[1] describes opportunistic TLS encryption for SMTP communications. Our postfix deployment uses this and a fair amount of our email is sent over TLS-encrypted SMTP. Of course, an MITM attack could hide the STARTTLS option and there are questions around the strength of the CA cert infrastructure, but SMTP is not just plaintext. [1] https://tools.ietf.org/html/rfc3207

The problem is that you don't sent to the destination SMTP server. You send to your SMTP server. That goes at least one hop via SMTP and eventually ends up on the destination's domain server.

So even if I setup and host my own SMTP server, and even if I verify the TLS certs on my side, I have no way to verify that I'll get (1) A TLS connection (2) with an authenticated cert all the way to the ultimate destination.

It's beyond my control to ensure that I'm secured when emailing to an arbitrary domain with arbitrary configuration.

Re: Lavabit abruptly shuts down

#197
post #132

Interesting thread from Email Discussions: http://www.emaildiscussions.com/showthread.php?t=66968 If you're a SAAS provider, be aware if you need to shutdown that many users are not prepared for this. Several posters in the linked thread rely on a recover password feature sent to e-mail for access to other accounts. Not a prudent practice but this is common for many.

This is not an orderly shutdown, this is basically a civil disobedience act. As such, the more people are pissed off, the better (as long as their rage is channeled to the real culprits, i.e. the feds).

Re: Lavabit abruptly shuts down

#198

Are there any countries, anywhere, where a person can store data outside the reach of the US government's illegal overreach? Any countries friendly to the US are right out. They can tap the lines, but there are ways around that. I just want to be able to park data where some twit with a piece of paper that says "NSA" on it can't get it retrieved or deleted. Any suggestions?

http://cdn2.sbnation.com/entry_photo_images/3526356/sealand-...

Re: Lavabit abruptly shuts down

#200

I like the part where he can't tell you why he's shutting down. As if we won't engage in rampant irresponsible speculation that they have told him to decrypt and forward everything to them in real time.

He's most likely under a gag order. I thought that was pretty obvious.
Post reply on HN