Live data from Hacker News

Lavabit abruptly shuts down

lavabit.com

201–210 of 671 posts

Re: Lavabit abruptly shuts down

#201
post #189

Earlier quoted context omitted.

Make the bastards work for it. Enough people using strong encryption (both for data over the wire and data at rest) makes big-data collection (can't dedupe random noise) and processing/datamining prohibitively expensive if not impossible. Nobody is getting in trouble for moving their data and services offshore. Aside from that? I'd suggest finding a few friendly people in various countries and establish a constant /d…

I wonder if, more than crypto, false positives would make them work harder. They know who you are emailing too, and so likely are not going to target you in any case, since you are not part of an interesting network. But if you start talking about a movie, where they plan to detonate a dirty bomb in Times Square or something... Emacs automates this with M-x spook: morse War on Terrorism encryption Forte Blowpipe LLNL…

6 degrees, though. The network of connecting one person to any other person on the earth is usually quite small.

Hmm.. here's a silly idea.

A peer to peer network, let's go with a cool web-2.0-ey name like Chaffr, that assigns you a GUID and establishes a stream of truly random (or pseudorandom) data which is propagated out via a P2P system kinda the same way Tor nodes communicate with each other.

This stream of noise is generated and runs 24x7. Might require a hardware dongle of some kind to keep the entropy pool full enough.

This data is random for the most part, but if you have the GUID of another user, you can send them messages which will be encoded into the stream and received by the other person either immediately, at a set time, or at a random time inside a given window.

Garbage, uncompressable, unusable data for the snoops (and the nature of the system as explained in the Snowden leaks will require them to store every useless byte), an anonymous, decentralized communication network for everyone else.

Re: Lavabit abruptly shuts down

#202
post #108
post #24

I'm in the process of moving any Saas offerings I use off USA-affiliated companies, but it's actually more difficult than I first thought. I believe there might even be a very profitable market in simply duplicating the functionality of Saas offerings at a higher price with security/privacy guarantees in Germany/HK/etc. Might be the next hot business to be in? You'd be surprised as to the number of people seeking alt…

Moving services off USA-based companies is like using two bicycle locks instead of one. A determined government is still going to get your data, they just need to spend a bit more time. Focus instead on encryption.

No, do both.

Focus on encryption, to keep ahead and protect the data.

Move out of the US, because it sucks, is far from 'the land of the free' anymore and needs to learn that its place in the digital world is not at the top, but more around the center. Between lots of other states that fail and fail again, in terms of surveillance..

Re: Lavabit abruptly shuts down

#203
post #108
post #24

I'm in the process of moving any Saas offerings I use off USA-affiliated companies, but it's actually more difficult than I first thought. I believe there might even be a very profitable market in simply duplicating the functionality of Saas offerings at a higher price with security/privacy guarantees in Germany/HK/etc. Might be the next hot business to be in? You'd be surprised as to the number of people seeking alt…

Moving services off USA-based companies is like using two bicycle locks instead of one. A determined government is still going to get your data, they just need to spend a bit more time. Focus instead on encryption.

I saw a frustrating article the other day on a mainstream news site that was saying that the economic damage to the US for the Snoden leaks was in the tens of billions of dollars because of all the non US business that will be leaving US based cloud providers.

That's infuriating. It's the same as having an insecure system and then charging a hacker millions of dollars in restitution to re-architect the system to do it right.

Those firms wouldn't have to leave the US cloud providers if they had assurances that the US wasn't spying on them for no good reason.

Re: Lavabit abruptly shuts down

#204
post #191
post #149

One big question I have for the legal beagles: It's understood (if not well-liked) that Fourth Amendment protections don't apply to data given to a third-party... What if, instead, you host server space within the U.S. and run your own software (email, listserv, whatever) and data on the leased hardware? I would think there's a good argument that Fourth Amendment protections then resume, and the domestic-ness of the…

You need a warrant, but honestly we don't know if that isn't the case here. It's come up before that the NSA, FBI et al, serve warrants for encrypted data and can demand it be decrypted. Otherwise, services like lavabit are equivalent to Swiss bank accounts that are unreachable by any means, legitimate or otherwise. Realistically, this service was almost certainly hosting a ton a illegal activities.

Well there we go then, Constitutional Fourth Amendment protections restored.

But why do I get the impression that's not actually what we all were really asking for here?

Re: Lavabit abruptly shuts down

#205
I had just signed up for 2 years pro service, and had been wondering why thunderbird couldn't log in all day (and I've been waiting to send an email all day!)

I also recently had a chat with their support about this (before purchasing,) and they told me something like "don't worry, we're not big enough to get hit by this stuff, and if we are we'll tell them where to shove it!" -- it looks like they were telling the truth.

Re: Lavabit abruptly shuts down

#206

I like the part where he can't tell you why he's shutting down. As if we won't engage in rampant irresponsible speculation that they have told him to decrypt and forward everything to them in real time.

I'd say it's more than rampant speculation. Shutting down his company was probably his only legal way of informing us.

Re: Lavabit abruptly shuts down

#207
post #91

Some questions given the reasons why they had to shutdown: 1. Can Lavabit now set up shop overseas (with a different TLD)? 2. If not 1, can Lavabit license their software infrastructure in such a way such that someone overseas can set up shop for them? 3. If not 2, can Lavabit open source their software such that someone anywhere else in world can start their own Lavabit? The point that I am trying to get across is t…

https://www.hnsearch.com/search#request/all&q=sneak+obama+fo...

http://news.ycombinator.com/item?id=6090048

http://news.ycombinator.com/item?id=5985100

http://news.ycombinator.com/item?id=5978036

Re: Lavabit abruptly shuts down

#208
post #108

Earlier quoted context omitted.

Moving services off USA-based companies is like using two bicycle locks instead of one. A determined government is still going to get your data, they just need to spend a bit more time. Focus instead on encryption.

The goal is not necessarily security (I have nothing to hide (I still do hide as much as possible))-- the goal is political change. That's the only real way out of this mess. By not using US companies, you incentivize those to lobby for better laws.

Much of the data traveling over the internet passes through NAPs controlled and owned by the USA.

Re: Lavabit abruptly shuts down

#209
post #135
post #91

Some questions given the reasons why they had to shutdown: 1. Can Lavabit now set up shop overseas (with a different TLD)? 2. If not 1, can Lavabit license their software infrastructure in such a way such that someone overseas can set up shop for them? 3. If not 2, can Lavabit open source their software such that someone anywhere else in world can start their own Lavabit? The point that I am trying to get across is t…

Not knowing the actual crime, you cannot answer any of those questions. See, this is why "secret laws" are so bad: you cannot legally counteract because you don't know what's legal anymore .

I am speculating because I am genuinely interested.

Assuming this event is the result of an NSL, what can the owners do next? An NSL would have to have been served against an organization. If said organization no longer exists, there should be no reason why another organization that performs exactly the same activity as the first could not be formed.

If the answer is no, then it's as if a coffee shop was destroyed by a hurricane, but now the government says you aren't allowed own/operate/license coffee shops anymore except the hurricane is actually an arm of the government.

This event really gives a new meaning to "invisible hand", except this time, it's in the shape of a fist[1].

[1] https://en.wikipedia.org/wiki/Invisible_hand

Re: Lavabit abruptly shuts down

#210
post #40

Earlier quoted context omitted.

I'm also unsure of their proven effectiveness, but how could they hold you in contempt for _not_ taking an action?

I'm sure they would argue that you weren't supposed to reveal that you were under an NSL, and that your inaction did reveal it, so you violated the terms. As the grandparent says, it probably just a cute legal trick that wouldn't impress a judge.

Maybe, but expecting a false oath makes a mockery of the entire testimonial system.
Post reply on HN