Live data from Hacker News

Lavabit abruptly shuts down

lavabit.com

321–330 of 671 posts

Re: Lavabit abruptly shuts down

#321
post #108

Earlier quoted context omitted.

Moving services off USA-based companies is like using two bicycle locks instead of one. A determined government is still going to get your data, they just need to spend a bit more time. Focus instead on encryption.

It is just as bad or worse. You have to move the data in/out of the country. It definitely isn't protected when it leaves the country. The only advantage I see is that it punishes US businesses for failing to protest.

You say that as an American obviously. It makes a lot of sense for everyone else.

Re: Lavabit abruptly shuts down

#322
post #43

Earlier quoted context omitted.

I'd love to believe that the authorities in Germany are not also tapping lines like France or the UK. Do we have any proof that is the case? I agree this has made me think twice about hosting in the us, but also about crossing national boundaries full stop without encrypting traffic.

The difference is that the authorities in Germany don't have the legal framework to force someone to do this and threaten them to stay silent.

At some point, maybe the citizens of the world will understand that laws don't apply to the people who make them. They never have, and they never will.

Re: Lavabit abruptly shuts down

#323
post #63

I really would want to donate to them. But you know I kind of feel weary now connecting my PayPal Account with them. I hope some kind of organisation is standing up for them. Like EFF or something. Not because I don't trust them. But because I don't trust the NSA. They might flag me as a terrorist or something. Then again I'm probably already on this list for having some technical involvment with something the US gov…

I had the exact same thought. The chilling effects here are tangible - I am avoiding exercising what are ostensibly my freedoms because I fear reprisal by my government.

Re: Lavabit abruptly shuts down

#324
post #310

Does anybody know of a good European VPS provider for self-hosted email? That seems to be the only way to go moving forward.

If you want security, avoid VPSes. Your VPS is at the mercy of the hypervisor. You need to own a physical machine under lock and key if you want to be assured of its security.

Re: Lavabit abruptly shuts down

#326

Earlier quoted context omitted.

>Accountability and culture The culture that brought us the SS and the Stasi.

No, it's the reverse. The nazi era and the Stasi have resulted in a modern Germany that is fiercely oppositional to anything that leads in this direction. There are very strong open source, transparency and anti surveillance movements in Germany. Stasi is the entire reason WHY we have strong privacy laws here.

As Goebbels pointed out, all it takes is the right kind of threat, either real or manufactured ("Think of the children!"), and those "transparency movements" you speak of will fade out more rapidly than the grandparent post.

Re: Lavabit abruptly shuts down

#327

Where's the "I wish you hadn't done that, lavabit, I'm a customer and I feel very screwed over by this action" comments? Or is this appropriate for any SaaS vendor? You're OK with this? Should all customers, even those who really don't care if the NSA could be watching, be put out because some feel that this cause trumps actually doing business and having customer-vendor relationships? I could see someone suing an Sa…

>Your TOS says nothing about your shutting down because the government asked you to do something you didn't agree with.

Technically, you can't say that this happened, because they can't confirm that they shut down for this reason. In light of recent events this seems obvious, but in an actual court, you would not be allowed to use this as a sole defense.

Re: Lavabit abruptly shuts down

#328

Earlier quoted context omitted.

The "judge is not impressed" means they would probably view it as the same as just warning the public directly, with equivalent penalties. And thus the canary is legally useless--if you're going to have the penalties of violating a national security order, might as well just do it in a straightforward manner.

At this point, it is speculation that the judge would not be impressed. If anyone decided to test the theory, the public would be informed regardless.

I agree, but your analysis is missing something: the canary-threatener may be secretly, without a public ruling, within the refresh interval, be convinced that if he doesn't keep updating (falsely) the canary, he'll go to jail. In other words, the precommitment to stop producing the canary signal isn't fully credible (though it seems much more likely to get the message out than a promise to actively say if something happens).

Re: Lavabit abruptly shuts down

#329
post #245

This is infuriating, and the worst part is that a clear solution isn't in sight. Sure, we can fight this in the courts, and a few secret programs might get shut down, but operations will just continue under a different name. We can encrypt our data, move our services and data offshore, but that just paints a big target on our heads - doesn't actually address the fundamental issue. This is supposed to be a democracy,…

As developers perhaps the most effective thing we can do from a long-term perspective is baking strong cryptography in to all of the products we create, and opting for open source whenever possible. (After all, open source is the only way we can guarantee that the software we're using really doesn't snoop on us.) If crypto were easier to use and presented as a default, more regular people would wind up using it and w…

To make crypto truly secure, the end user has to take on management of their key and that key can never reside on your servers. Users can barely manage their password; expecting them to manage something that, if they lose, takes all their data with them, is asking a lot.

I tried to get a startup off the ground for 2 years that would secure gmail, and we went round and round on this. We wanted to not be able to read the user's mail, but the impact on usability was so large, users wouldn't touch it.

How do we train users to manage keys? What would be really nice is true homomorphic encryption.

Re: Lavabit abruptly shuts down

#330
post #234

Earlier quoted context omitted.

I wonder if there is some historical regularity here. After all, my own country, "Das Land der Dichter und Denker" turned on its "Dichter und Denker" when it was at (or close to) the apex of intellectual achievement.

Yes, there is a strong parallel between pre-Nazi Germany and current USA. Of course, Americans will not literally follow Nazi ideology. What we see in America is an increasing merger between industry and government. Finance is the most regulated sector; hence "too big to fail" and all the exploits pulled by big banks. Telecom is almost completely government controlled (through the graning of regulatory monopolies). T…

> we're taking anti-corrective action instead of corrective action at every step

That's not true. The Congress almost defunded the NSA recently. It was a far closer thing than anyone in the establishment suspects. In the end, we are a country that values it's privacy, values small government, and we'll assert that sooner or later. It may be later. But hey, it took a long time for us to figure out slavery, women's rights, civil rights, gay rights, and drug rights. But in the end we did the right thing, and we'll do the right thing on this.

Patience.

Post reply on HN