Live data from Hacker News

Lavabit abruptly shuts down

lavabit.com

251–260 of 671 posts

Re: Lavabit abruptly shuts down

#251

Earlier quoted context omitted.

Do what I do! I have my own domain name, currently hosting with Google Apps. If I get the motivation to move to another host like myself, I can do it without changing contact information.

Oh good, because Google will never be subject to an NSL.

Everyone you converse with uses gmail.

Re: Lavabit abruptly shuts down

#252

So he pretty much does say why he's shutting down, the US gov. has demanded access and he said no. Kudos for standing up for his users, and he does raise an interesting point at the end: This experience has taught me one very important lesson: without congressional action or a strong judicial precedent, I would _strongly_ recommend against anyone trusting their private data to a company with physical ties to the Unit…

> Kudos for standing up for his users,

Where did you get this one from? I think its a bit of a stretch to say he is "standing up to his users". I would rather say he is standing up against the GOV, and that's nice for a change, but we have no idea what has happened with all the emails residing on their servers.

Knowing just a bit that I know how the us gov operates, I am pretty sure he was given two options at exact the same time: either you accept our black box, OR you will not. If you not, then you are not allowed to delete or alter any messages on your servers. Given the business lavabit was in, I am sure Feds will punish him to the extends of the law (or more) if he decides to "stand up to his users" and delete content of their mailboxes.

Re: Lavabit abruptly shuts down

#253
post #26

Seems like it would make sense for users to demand that any US based service includes a warrant canary, just like rsync.net's implementation. A global canary + separate canaries for individual accounts would also make sense. https://en.wikipedia.org/wiki/Warrant_canary http://rsync.net/resources/notices/canary.txt

This presumes that the host has an actual warrant filed against them. I assume that if the feds want data from a service which is ultimately hosted on Amazon they'll just go straight to Amazon.

Re: Lavabit abruptly shuts down

#254
post #173

Earlier quoted context omitted.

> I'm in the process of moving any Saas offerings I use off USA-affiliated companies, but it's actually more difficult than I first thought. You should try finding a SSL cert retailer that's outside of the US. The only ones I could find that would actually sell me certs without a phone call charged at least $200 for a basic certificate. https://swisssign.com/en were the most sensible looking ones I could find.

This part doesn't matter. Where your cert comes from is irrelevant.

It has implications for certificate pinning (like that used in Chrome) if you can only pin to CAs that operate in a single regulatory domain.

Re: Lavabit abruptly shuts down

#256
post #184
post #12

From 2011: > Lavabit processes 70 gigabytes of data per day, is made up of 26 servers, hosts 260,000 email addresses, and processes 600,000 emails a day. That’s a lot of email. http://www.dbasoul.com/2011/1008.html Update: According to their stats page, they had 410k email accounts hosted before shutdown https://twitter.com/georgemaschke/status/365553445538775040

70 GB / 600K emails = 122KB per email. That's a large average even with headers. To put things in perspective, Costco's massive marketing email sent to me this morning is 138K including headers. So the question is, what were people sending though Lavabit that averaged 122K and would have attracted attention? Therein probably lies the reason for all of this.

Average, not median. A thousand 50KB email are easily offset by a few 30MB email with max size attachments. 122KB average isn't unusual.

Re: Lavabit abruptly shuts down

#257
post #212

> I wish that I could legally share with you the events that led to my decision. I cannot. I feel you deserve to know what’s going on--the first amendment is supposed to guarantee me the freedom to speak out in situations like this. Anyone know what happens if he just says "F it" and writes a massive blog post on what exactly happened or what exactly they said to him?

He'd probably go to jail immediately and then spend years working the case through the courts in the hopes of getting a Supreme Court decision striking the law down as unconstitutional.

They'd probably put him next to a child molester who is server less time just to complete the circle of irony.

Re: Lavabit abruptly shuts down

#258

Host in Russia. You all saw how the Snowden issue was handled. Just don't do anything that would attract FSB's attention.

Snowden isn't a general purpose tool. As far as Russia is concerned, he presents no threat to them; it's not like they are going to let him pursue a career in the FSB.

This service however is a general purpose tool. It would attract the attention of the FSB immediately.

Re: Lavabit abruptly shuts down

#259

Earlier quoted context omitted.

The goal is not necessarily security (I have nothing to hide (I still do hide as much as possible))-- the goal is political change. That's the only real way out of this mess. By not using US companies, you incentivize those to lobby for better laws.

Much of the data traveling over the internet passes through NAPs controlled and owned by the USA.

Did you respond to the right comment? He said the goal was not security, it was political change.

Re: Lavabit abruptly shuts down

#260
post #24

I'm in the process of moving any Saas offerings I use off USA-affiliated companies, but it's actually more difficult than I first thought. I believe there might even be a very profitable market in simply duplicating the functionality of Saas offerings at a higher price with security/privacy guarantees in Germany/HK/etc. Might be the next hot business to be in? You'd be surprised as to the number of people seeking alt…

> I'm in the process of moving any Saas offerings I use off USA-affiliated companies, but it's actually more difficult than I first thought. You should try finding a SSL cert retailer that's outside of the US. The only ones I could find that would actually sell me certs without a phone call charged at least $200 for a basic certificate. https://swisssign.com/en were the most sensible looking ones I could find.

from what I know you never give your private key away, they just sign your public one. so that would be irrelevant.
Post reply on HN