Live data from Hacker News

Lavabit abruptly shuts down

lavabit.com

331–340 of 671 posts

Re: Lavabit abruptly shuts down

#331
post #183

The US government is destroying one of the few bright spots in the American economy with its out of control military. It is unconscionable. And the sad thing is it has been enabled by the betrayal by many of the web 2.0 giants, Facebook, Google etc. Google especially is sad to see since they were willing to forgo the Chinese market on principle, but then decided that taking on the authoritarian US government was too…

If you are seriously suggesting that abandoning the US market is a realistic option, especially for a multibillion dollar corporation, then you are (and I'm not using this word lightly) an idiot.

Not to mention that there is no US equivalent to the rampant human rights violations and censorship in China.

Re: Lavabit abruptly shuts down

#333

Earlier quoted context omitted.

Hello, I didn't say stand up to, but for (i.e. on behalf of) . The most he can do is stand up to the government, for his users, in court, deleting servers would not be a wise move, and I wouldn't expect it of him, would you? Just standing up and saying no in a climate like this takes some courage, for which I admire him.

by the time he is done wish courts defending their users, Feds will be given chances to copy all users data over and over again about 250 times. So it doesn't matter whether he loses or wins. Not a bit.

I thought it was encrypted. If they are, they can copy user data as much as they want, they will get nothing. However if it was still running, they could ask him to intercept password, network traffic, etc...

Re: Lavabit abruptly shuts down

#334
post #50

Earlier quoted context omitted.

[deleted]

Actually, I don't think so, if he was a paying user. Everything on-disk was encrypted for paying users, and since lavabit had to shut down completely to not "be complicit in a crime against the American public", I assume that the NSL wanted them to make a change like Hushmail did in the past, to send the user's password to the server on the next login so that they can decrypt all emails.

I would assume that the NSA had already forcibly installed something that would compromise all further access to lavabit mail. Therefore the only option that doesn't reveal data is immediate shutdown.

Re: Lavabit abruptly shuts down

#335

Earlier quoted context omitted.

The difficulty is that most recipients of your message will not be willing to use whatever crypto technology you've chosen. PGP is probably the most popular email encryption system, but good luck finding people who use it. I work in the software industry, and I don't regularly correspond with a single person whom I know to use PGP.

It'll be interesting to see whether companies start to shift to using encrypted email over the next few decades - it's not that hard to set up if you know the counterparty will be using encryption of the same kind, and if it's not a service bought in from an external company you can fairly sure it is secure. Companies could at least insist that intra-company email is encrypted, which would be a huge amount of their n…

Exchange/Outlook already does intra- and extra-company encryption.

Re: Lavabit abruptly shuts down

#336

Earlier quoted context omitted.

My family and I have started this process already and expect to be in Central America within the year.

Because the Central American governments so wonderfully respect human rights.

Not to put words in the OP's mouth, but I think it's not so much about the USA's not respecting human rights as about that _and_ its having too much power for everybody's good.

By not having to pay taxes to USGov, they probably hope to make that power diminish.

EDIT: Good God, I've always been the guy arguing with your average America hater that we should count ourselves lucky that in the monopolar world we live in, the US is that only superpower that remains (as other candidates, such as Russia and China, would be a lot worse for everybody). I still think this is the case, but it's getting harder and harder to justify the position, with USGov seemingly hell bent on tranforming the country into a surveillance state.

Re: Lavabit abruptly shuts down

#337
post #181

Earlier quoted context omitted.

It may be simpler than that. Even if Snowden has walked away from this service, the publicity may have attracted a lot of people the authorities find interesting, including legitimate (whatever that means) persons of interest.

The political backlash attached to slapping an NSL on "Snowden's email provider" would have looked obvious to a 5-year-old, and any real player worth its salt would have run from Lavabit as soon as it hit the news. No, this has nothing to do with common criminals and everything to do with Snowden.

NSL's come with a gag order. There wouldn't have been any backlash as no one would have known about it.

He shut it down because that was the only way to legally prevent the government from spying on his users.

Re: Lavabit abruptly shuts down

#338
post #216
post #57

Earlier quoted context omitted.

This is somewhat true. RFC3207[1] describes opportunistic TLS encryption for SMTP communications. Our postfix deployment uses this and a fair amount of our email is sent over TLS-encrypted SMTP. Of course, an MITM attack could hide the STARTTLS option and there are questions around the strength of the CA cert infrastructure, but SMTP is not just plaintext. [1] https://tools.ietf.org/html/rfc3207

The problem is that all of the people you correspond with use gmail, which participates in PRISM. No amount of transport encryption or storage encryption on your own end will stop Google from sharing that data with US authorities.

"Participates" is the wrong characterisation, they are under the jurisdiction of FISA orders, if the NSA wants to call that PRISM, it's their business. Also worth mentioning is that providers in non-US countries are subject to their respective country's surveillance efforts, so either way it's a red herring argument.

Re: Lavabit abruptly shuts down

#339
post #15

For the unfamiliar: Lavabit was a webmail service, that (claimed to) encrypt emails in such a way that they literally did not have access to the content stored on their own servers. The linked email would lend some credence to those claims. It was originally designed in contrast to gmail scanning your email for targeted advertising, but my imperfect memory says that their system should also have been resilient to "we…

It seems like the most secure way to send a message these days might be snail mail. While I know the feds to open it from time to time in specific cases, they definitely don't open all.

They take a photo of the front and back of every piece of mail that is sent. Your content is safe, but they still get the metadata.

Re: Lavabit abruptly shuts down

#340
post #321

Earlier quoted context omitted.

It is just as bad or worse. You have to move the data in/out of the country. It definitely isn't protected when it leaves the country. The only advantage I see is that it punishes US businesses for failing to protest.

You say that as an American obviously. It makes a lot of sense for everyone else.

>It makes a lot of sense for everyone else.

Absolutely!

Post reply on HN