Live data from Hacker News

Lavabit abruptly shuts down

lavabit.com

371–380 of 671 posts

Re: Lavabit abruptly shuts down

#371
post #181

Earlier quoted context omitted.

The political backlash attached to slapping an NSL on "Snowden's email provider" would have looked obvious to a 5-year-old, and any real player worth its salt would have run from Lavabit as soon as it hit the news. No, this has nothing to do with common criminals and everything to do with Snowden.

NSL's come with a gag order. There wouldn't have been any backlash as no one would have known about it. He shut it down because that was the only way to legally prevent the government from spying on his users.

Good point. While controversial, this is exactly why, too. (Fed's don't want to tip their hand).

Re: Lavabit abruptly shuts down

#372
post #183

The US government is destroying one of the few bright spots in the American economy with its out of control military. It is unconscionable. And the sad thing is it has been enabled by the betrayal by many of the web 2.0 giants, Facebook, Google etc. Google especially is sad to see since they were willing to forgo the Chinese market on principle, but then decided that taking on the authoritarian US government was too…

Agreed, these US Gov contractors and agencies systematically destroying our industry and our prospects.

As a community, let's shun and shame all those who continue work for those agencies (NSA/CIA/FBI/DIA/DEA) both directly and as contractors from this date forward. If you didn't quite in August 2013, we don't want to hire you. If you quite now in disgust, we should view that in a positive light. If you or your company stand up to the US Gov, that should view that in a VERY positive light and we should be looking to hire them.

Let's shun and shame FB, Google, et all as collaborators. Let's make it a point to avoid google app engine and other Google services.

Re: Lavabit abruptly shuts down

#373
post #297

Earlier quoted context omitted.

This actually did happen with hushmail. It's hosted in Canada, but the US leaned on them hard enough that they ended up backdooring the client to let the feds snoop on the targeted user.

That is not quite what happened. As the link below says, it was not an exploit. Users were warned that using pure IMAP access and/or webmail, which was a convenience feature and continues to be with them, would require your private key. It was recommended you do not do that, and use the provided Java applet or mobile app. The person in question in those criminal proceedings used one of those convenience functions, if…

"It was recommended you do not do that, and use the provided Java applet"

Which is equally insecure, as the company could easily insert a back door the next time you load the applet. Hushmail was and is snake oil.

Re: Lavabit abruptly shuts down

#374
post #292
post #269

Earlier quoted context omitted.

I think the trick here is that lavabit can't share data even with a warrant. Their inability to do so is pretty much their entire business model. That protects people from unwarranted intrusions, but it also insulates people from legitimate investigation. If they build a backdoor for only duly authorized warrants, they are no more or less obligated to comply with an NSL.

I would hope that if they've received an NSL ordering them to wiretap their own email, that the NSL is at least limited to specific targets of an investigation. But some people do strongly believe in throwing out the whole bathtub if that's what it takes to keep the data safe, and to those people I will certainly tip my hat, even if I disagree myself.

I can accept a company complying with a warrant and divulging data for some customers.

I will not accept a company that promises complete security and then sends a trojan to customer computers. Anyone that betrays the security promises made to the entire user base (eg. hushmail) should be ostracized.

Re: Lavabit abruptly shuts down

#375
post #15

For the unfamiliar: Lavabit was a webmail service, that (claimed to) encrypt emails in such a way that they literally did not have access to the content stored on their own servers. The linked email would lend some credence to those claims. It was originally designed in contrast to gmail scanning your email for targeted advertising, but my imperfect memory says that their system should also have been resilient to "we…

The data may have been protected, but the senders and recipients probably were not. Similarly to SSL, it encrypts the traffic, but does not hide which websites you use.

I bet that data are still valuable to the government.

I have been thinking of starting a business in the privacy space. This has shown me that that all customer data needs to be periodically obliterated in safe way and that a kill switch or nuke button is needed as well to destroy everything on a moment's notice.

Where and how to host is a major concern. Cloud, etc., is obviously out of the question.

Re: Lavabit abruptly shuts down

#376
post #297

Earlier quoted context omitted.

That is not quite what happened. As the link below says, it was not an exploit. Users were warned that using pure IMAP access and/or webmail, which was a convenience feature and continues to be with them, would require your private key. It was recommended you do not do that, and use the provided Java applet or mobile app. The person in question in those criminal proceedings used one of those convenience functions, if…

"It was recommended you do not do that, and use the provided Java applet" Which is equally insecure, as the company could easily insert a back door the next time you load the applet. Hushmail was and is snake oil.

For sure, but can I fault idiots for inability to read the documentation and caveats? Maybe, but not really lest most on this site could not "do computers" professionally.

Unfortunately, the trust problem you mention is pervasive. It was a signed applet IIRC, but we both requires you trust the original and modified applets from the developer. I am wishing someone released an auto-encrypting PGP service and client, open-sourced on purpose.

We all know only four people would read the source of that, and two of those would verify the dev key given with the release. :-)

Re: Lavabit abruptly shuts down

#377

Earlier quoted context omitted.

No, it's the reverse. The nazi era and the Stasi have resulted in a modern Germany that is fiercely oppositional to anything that leads in this direction. There are very strong open source, transparency and anti surveillance movements in Germany. Stasi is the entire reason WHY we have strong privacy laws here.

As Goebbels pointed out, all it takes is the right kind of threat, either real or manufactured ("Think of the children!"), and those "transparency movements" you speak of will fade out more rapidly than the grandparent post.

That doesn't work as well if the culture has been inocculated.

How does one do that?

Well, I don't know if this is still done today, but when I was in 7th or 8th grade, they (school) drove us, by the busload, to visit a concentration camp.

We were shown the lampshades and wallets made of human skin. The place to stand where inmates would be executed during what they thought were medical examinations. And so on and so on.

It is quite possible that the next "Western" genocide will happen somewhere in Europe. But as somebody who has grown up here, I can assure you it won't be in Germany.

I just wish that history was thaught like this everywhere.

Re: Lavabit abruptly shuts down

#378

Host in Russia. You all saw how the Snowden issue was handled. Just don't do anything that would attract FSB's attention.

Host in Brazil, we're never at war so spying, national security and etc budgets are always low, besides, we can barely handle basic stuff like education, security, public transport, so if there's a BRPrism, part of the money probably goes to some corrupt, and then it must be shitty!

Re: Lavabit abruptly shuts down

#379
post #365

Earlier quoted context omitted.

Exchange/Outlook already does intra- and extra-company encryption.

This comment implies you actually trust Microsoft's crypto implementation.

Nope, only that companies trust Microsoft's crypto implementation.

But as it happens, yes, I trust our crypto developers. They're much better at it than most of HN.

Re: Lavabit abruptly shuts down

#380
post #350
post #15

For the unfamiliar: Lavabit was a webmail service, that (claimed to) encrypt emails in such a way that they literally did not have access to the content stored on their own servers. The linked email would lend some credence to those claims. It was originally designed in contrast to gmail scanning your email for targeted advertising, but my imperfect memory says that their system should also have been resilient to "we…

Edit: I was a PM on Exchange and Exchange Hosted Encryption for some time, so it looks like Lavabit tried to fight the government on whether they are required to release private keys. I've seen one other customer try to fight, and it was not pretty either. The US government in these cases are serious. Takeaway for fellow hackers: If you are building a system that stores user-generated data, prepare for the eventualit…

The worst case (that I can talk about) I saw involved requiring a specific employee be demoted due to improper care of a company's systems.

Would you expand on this? Are you saying that a court was meddling directly with an individual company's hierarchy?

Post reply on HN