Live data from Hacker News

Lavabit abruptly shuts down

lavabit.com

381–390 of 671 posts

Re: Lavabit abruptly shuts down

#382
post #297

Earlier quoted context omitted.

This actually did happen with hushmail. It's hosted in Canada, but the US leaned on them hard enough that they ended up backdooring the client to let the feds snoop on the targeted user.

That is not quite what happened. As the link below says, it was not an exploit. Users were warned that using pure IMAP access and/or webmail, which was a convenience feature and continues to be with them, would require your private key. It was recommended you do not do that, and use the provided Java applet or mobile app. The person in question in those criminal proceedings used one of those convenience functions, if…

In my eyes a backdoor is a subcategory of exploit. But the term used doesn't matter. The point is that they altered the software used by their clients to not only encrypt emails with the key, but to forward copies to be given to the government.

The warning they gave out was to point out lower security, it does not absolve them of the obligation to try to keep their severs secure.

Re: Lavabit abruptly shuts down

#383
Doesn't the fact that Snowden was using Lavabit lend credence to the allegation that he has been leaking information?

If you're just a regular joe who, one day, realizes that what he's working on is bad for the public and decides to release it to the public, surely you have had no reason to use an encrypted email service before this realization dawned on you.

Re: Lavabit abruptly shuts down

#384
post #350
post #15

For the unfamiliar: Lavabit was a webmail service, that (claimed to) encrypt emails in such a way that they literally did not have access to the content stored on their own servers. The linked email would lend some credence to those claims. It was originally designed in contrast to gmail scanning your email for targeted advertising, but my imperfect memory says that their system should also have been resilient to "we…

Edit: I was a PM on Exchange and Exchange Hosted Encryption for some time, so it looks like Lavabit tried to fight the government on whether they are required to release private keys. I've seen one other customer try to fight, and it was not pretty either. The US government in these cases are serious. Takeaway for fellow hackers: If you are building a system that stores user-generated data, prepare for the eventualit…

ziplip shut down in 2005 citing an inability to maintain user privacy in light of new legislation. Their servers were in Ireland, I think.

Re: Lavabit abruptly shuts down

#385

Earlier quoted context omitted.

Make the bastards work for it. Enough people using strong encryption (both for data over the wire and data at rest) makes big-data collection (can't dedupe random noise) and processing/datamining prohibitively expensive if not impossible. Nobody is getting in trouble for moving their data and services offshore. Aside from that? I'd suggest finding a few friendly people in various countries and establish a constant /d…

This is a brilliant suggestion actually. If I ever make a crypto messaging system I'll surely bake in a module that sends bogus messages to random nodes in the system. Then any sorts of metadata are useless to evil people.

Filtering out the random noise wouldn't be very hard.

Re: Lavabit abruptly shuts down

#386

Doesn't the fact that Snowden was using Lavabit lend credence to the allegation that he has been leaking information? If you're just a regular joe who, one day, realizes that what he's working on is bad for the public and decides to release it to the public, surely you have had no reason to use an encrypted email service before this realization dawned on you.

No.

Some people are aware of the long history of government surveillance, or of the lack of privacy in regular email. Some of those people will have encrypted their email in an attempt to reduce the amount of casual snooping they leave themselves open to.

Re: Lavabit abruptly shuts down

#387
post #216

Earlier quoted context omitted.

The problem is that all of the people you correspond with use gmail, which participates in PRISM. No amount of transport encryption or storage encryption on your own end will stop Google from sharing that data with US authorities.

"Participates" is the wrong characterisation, they are under the jurisdiction of FISA orders, if the NSA wants to call that PRISM, it's their business. Also worth mentioning is that providers in non-US countries are subject to their respective country's surveillance efforts, so either way it's a red herring argument.

"Participates" is a perfectly acceptable word for silently complying with a law. Especially for an international company that could have changed jurisdiction of the relevant servers.

Re: Lavabit abruptly shuts down

#389

Earlier quoted context omitted.

Canaries always stunk of that juvenile "technically correct" stuff many tech people seem to grow out of later than others. If the judge says "don't paint your wall red" that means "or anything close by any means". It doesn't matter you tried to hack your way out with an automatic vermillion paint flinger setup before the order. You still are supposed to "make the wall not get painted red".

The government can compel you to paint a wall green. They can't compel you to say you liked it. They especially can't compel you to break the law (assuming you set up some kind of situation where it's fraud/perjury/whatever to lie). And look at how email retention works.

>They especially can't compel you to break the law (assuming you set up some kind of situation where it's fraud/perjury/whatever to lie).

They can most certainly hold you in contempt because you got your self in that mess.

>look at how email retention works.

Document retention policies are allowed because otherwise the civil court system would be prohibitively expensive (lawyers have to read all your email once you get sued basically). Once you get a court order that says to, you have to stop destroying email, etc, disabling your automated destruction systems.

The only reason to have canaries is to violate the terms of gag orders. Judges aren't sympathetic to that.

Re: Lavabit abruptly shuts down

#390
post #238

How in the hell are national security letters constitutional? It's mindboggling to me that they haven't reached the Supreme Court. I don't mean to sound like a hippie or patriotic douche, but it seem rather tyrannical that you aren't even allowed to talk about something that happened to you.

Not a national security letter: https://plus.google.com/112961607570158342254/posts/EujgUYbr...
Post reply on HN