For the unfamiliar: Lavabit was a webmail service, that (claimed to) encrypt emails in such a way that they literally did not have access to the content stored on their own servers. The linked email would lend some credence to those claims. It was originally designed in contrast to gmail scanning your email for targeted advertising, but my imperfect memory says that their system should also have been resilient to "we…
It seems like the most secure way to send a message these days might be snail mail. While I know the feds to open it from time to time in specific cases, they definitely don't open all.
Lavabit abruptly shuts down
271–280 of 671 posts
Re: Lavabit abruptly shuts down
#272Earlier quoted context omitted.
Accountability and culture. German intelligence services are "weaker" in the sense that they (seemlingly) still are under the control of the legislative body (secret contracts with the Western Allies sadly nonwithstanding). They are also regarded with deep distrust by large parts of the populace and by a significant segment of the legislature. It is quite possbible that, come September, some of the government parties…
>Accountability and culture The culture that brought us the SS and the Stasi.
There are very strong open source, transparency and anti surveillance movements in Germany. Stasi is the entire reason WHY we have strong privacy laws here.
Re: Lavabit abruptly shuts down
#273One big question I have for the legal beagles: It's understood (if not well-liked) that Fourth Amendment protections don't apply to data given to a third-party... What if, instead, you host server space within the U.S. and run your own software (email, listserv, whatever) and data on the leased hardware? I would think there's a good argument that Fourth Amendment protections then resume, and the domestic-ness of the…
You put your data into a server owned by someone else. Game over. The real solution, I think, eventually incorporates HSMs. There have been reports of EU authorities seizing racks if servers while keeping them powered up for forensic analysis (presumably key recovery out of running RAM).
That's admittedly a good point, and is the same reason I don't personally use SaaS (even in the user-brings-the-software mode) where I don't encrypt the data for myself.
But most people don't seem to care about that and are perfectly willing to use SaaS, as long as they can be assured government isn't able to indiscriminately peek at all their data (just the hardware host). If you're that kind of person, this might be the thing.
I am looking forward to a real solution to that problem though, as it would be useful in situations where you simply can't rely on trusting the hardware host (e.g. handling sensitive PII).
Re: Lavabit abruptly shuts down
#274So he pretty much does say why he's shutting down, the US gov. has demanded access and he said no. Kudos for standing up for his users, and he does raise an interesting point at the end: This experience has taught me one very important lesson: without congressional action or a strong judicial precedent, I would _strongly_ recommend against anyone trusting their private data to a company with physical ties to the Unit…
> Kudos for standing up for his users, Where did you get this one from? I think its a bit of a stretch to say he is "standing up to his users". I would rather say he is standing up against the GOV, and that's nice for a change, but we have no idea what has happened with all the emails residing on their servers. Knowing just a bit that I know how the us gov operates, I am pretty sure he was given two options at exact…
Re: Lavabit abruptly shuts down
#275I'm in the process of moving any Saas offerings I use off USA-affiliated companies, but it's actually more difficult than I first thought. I believe there might even be a very profitable market in simply duplicating the functionality of Saas offerings at a higher price with security/privacy guarantees in Germany/HK/etc. Might be the next hot business to be in? You'd be surprised as to the number of people seeking alt…
Moving services off USA-based companies is like using two bicycle locks instead of one. A determined government is still going to get your data, they just need to spend a bit more time. Focus instead on encryption.
If they were outside of US-and-friends jurisdiction, they wouldn't be shut down and there wouldn't be a gag order.
Re: Lavabit abruptly shuts down
#276Source: https://lavabit.com/?repost=true This is very unfortunate and sad. I hope he wins in Court. The NSA/administration are really trying to destroy the last bit of privacy in the world, and they will fight relentlessly until they do (especially if the People aren't fighting back).
Most likely, this is all so secret with secret courts foreseeing secret rulings that unless he has solid capital to burn on legal defense, he won't get far. He won't get far probably either if he has the money. I am sure courts would stretched it in infinity. And I am sure the owner is businessman more than a libertarian.
Re: Lavabit abruptly shuts down
#277Earlier quoted context omitted.
You need a warrant, but honestly we don't know if that isn't the case here. It's come up before that the NSA, FBI et al, serve warrants for encrypted data and can demand it be decrypted. Otherwise, services like lavabit are equivalent to Swiss bank accounts that are unreachable by any means, legitimate or otherwise. Realistically, this service was almost certainly hosting a ton a illegal activities.
Well there we go then, Constitutional Fourth Amendment protections restored. But why do I get the impression that's not actually what we all were really asking for here?
Re: Lavabit abruptly shuts down
#278Earlier quoted context omitted.
I don't blame the companies; they're about as much a victim of USgov as we are IMHO. That being said, if all the online-storage/cloud-server/email-providers/social-whatever companies in US start going out of business because nobody trusts them I strongly suspect something will have to change. It's just too bad we have to do a "scorched earth"[1] to bring about change. 1. http://en.wikipedia.org/wiki/Scorched_earth
> I don't blame the companies; they're as much a victim of USgov as we are IMHO. While it's true that they are victims, they are in a far better place to demand change or to defend themselves. Money buys the ears of lawyers that the average person couldn't even afford to speak to.
Re: Lavabit abruptly shuts down
#279Earlier quoted context omitted.
Well there we go then, Constitutional Fourth Amendment protections restored. But why do I get the impression that's not actually what we all were really asking for here?
There are multiple overreaches. In this case the government is probably trying to pull a hushmail: getting the service provider to install spying equipment targeted at their users, and then sharing the spy data with the government. 1. The government should not be able to force this kind of spy equipment to be installed. 2. If we had good privacy laws it would be illegal for the company to even willingly share this da…
I wonder though, whether this presumed requirement to install spying software is being done by only an executive-level NSL or by a court order/warrant.
Re: Lavabit abruptly shuts down
#280For the unfamiliar: Lavabit was a webmail service, that (claimed to) encrypt emails in such a way that they literally did not have access to the content stored on their own servers. The linked email would lend some credence to those claims. It was originally designed in contrast to gmail scanning your email for targeted advertising, but my imperfect memory says that their system should also have been resilient to "we…
And this reads as if someone was trying to force him to install means to spy on his users, and it wouldn't be surprising if the aim was to spy on Snowden directly (if he really used this service).
The Government has been trying to get into Lavabit longer than that.
Although, perhaps they already knew that Snowden was using Lavabit and started the process immediately after his flight to HK.