Live data from Hacker News

Lavabit abruptly shuts down

lavabit.com

391–400 of 671 posts

Re: Lavabit abruptly shuts down

#391
post #216
post #57

Earlier quoted context omitted.

This is somewhat true. RFC3207[1] describes opportunistic TLS encryption for SMTP communications. Our postfix deployment uses this and a fair amount of our email is sent over TLS-encrypted SMTP. Of course, an MITM attack could hide the STARTTLS option and there are questions around the strength of the CA cert infrastructure, but SMTP is not just plaintext. [1] https://tools.ietf.org/html/rfc3207

The problem is that all of the people you correspond with use gmail, which participates in PRISM. No amount of transport encryption or storage encryption on your own end will stop Google from sharing that data with US authorities.

Well anything that hits an MTA or MDA and sits in a queue somewhere on rust is liable to be snagged. That's usually every host between you and the destination MUA.

The whole protocol and mail delivery system is fucking hopeless.

As an ex-ISP mail architect and ex-operations guy, I hope the whole existing email protocol suite and architecture dies in a fire.

Re: Lavabit abruptly shuts down

#392
post #350

Earlier quoted context omitted.

Edit: I was a PM on Exchange and Exchange Hosted Encryption for some time, so it looks like Lavabit tried to fight the government on whether they are required to release private keys. I've seen one other customer try to fight, and it was not pretty either. The US government in these cases are serious. Takeaway for fellow hackers: If you are building a system that stores user-generated data, prepare for the eventualit…

The worst case (that I can talk about) I saw involved requiring a specific employee be demoted due to improper care of a company's systems. Would you expand on this? Are you saying that a court was meddling directly with an individual company's hierarchy?

(Forgive a 5-year-old memory of one of many cases -- I probably have the numbers wrong) It went something like this: The director of engineering approved a log retention plan that kept access logs for 7 days or something. They wanted to reduce costs and issues with log files were the top reasons for getting called to support the service. The government needed to demonstrate that someone had accessed the service 14 days ago, and the government could not understand why the 'minimum' of 30-day access logs were not present. I think something else was missing, too. There was a back-and-forth, and since the company couldn't produce the logs as requested the government got a contempt of court with the understanding that the director would be demoted to an IC and not be anywhere near the production service. I think the company lawyers agreed to the conditions to make a worse outcome go away.

If it's not clear, there were strong personalities involved. One way to tell the story is the director went out of his way to poke a bear and got mauled. Another way to tell the story is that a bear went walking down main street looking for trouble ("How do we know you didn't change the retention policy to protect the individual?"). In both cases the guy lost his hand and the bear is still loose.

Re: Lavabit abruptly shuts down

#393

Earlier quoted context omitted.

It seems like the most secure way to send a message these days might be snail mail. While I know the feds to open it from time to time in specific cases, they definitely don't open all.

They take a photo of the front and back of every piece of mail that is sent. Your content is safe, but they still get the metadata.

Couldn't you just leave off the return address? In this case there's not much metadata to collect except for the recipient address.

Re: Lavabit abruptly shuts down

#394
post #365

Earlier quoted context omitted.

This comment implies you actually trust Microsoft's crypto implementation.

Nope, only that companies trust Microsoft's crypto implementation. But as it happens, yes, I trust our crypto developers. They're much better at it than most of HN.

I don't. I've seen the source (via shared source) and there is a big fucking hole where the CSPs should be.

And the rest of the code is pretty shitty in places.

Re: Lavabit abruptly shuts down

#397

Maybe we should all just start writing letters again. Snoop that mutha fucka!

The USPS reportedly has some very expensive machines that can read letters without opening them now. I believe it was Russell Tice that said that, though I can't find the specific source at the moment.

But it's technical feasible and a desirable tool to get around being unable to legally open letters.

Re: Lavabit abruptly shuts down

#398
post #21

Earlier quoted context omitted.

The head of the NSA branded them as "the next terrorists". http://www.salon.com/2013/08/06/cyberscare_ex_nsa_chief_call...

> “nihilists, anarchists, activists, Lulzsec, Anonymous, twentysomethings who haven’t talked to the opposite sex in five or six years” Now that's a generalization if I ever heard one.

>"twentysomethings who haven’t talked to the opposite sex in five or six years"

guess one of the patterns coded into their dragnet.

Note to geeks - get out and talk to girls or your file will be moved into "next terrorists" folder :)

Re: Lavabit abruptly shuts down

#399
post #184
post #12

From 2011: > Lavabit processes 70 gigabytes of data per day, is made up of 26 servers, hosts 260,000 email addresses, and processes 600,000 emails a day. That’s a lot of email. http://www.dbasoul.com/2011/1008.html Update: According to their stats page, they had 410k email accounts hosted before shutdown https://twitter.com/georgemaschke/status/365553445538775040

70 GB / 600K emails = 122KB per email. That's a large average even with headers. To put things in perspective, Costco's massive marketing email sent to me this morning is 138K including headers. So the question is, what were people sending though Lavabit that averaged 122K and would have attracted attention? Therein probably lies the reason for all of this.

Most of the companies I receive email from these days have 122Kb of crap attached to the bottom by their outgoing MTA. You know: awards, disclaimers, twitter icons, facebook icons.

Makes me want to fuck off back to plain text.

Re: Lavabit abruptly shuts down

#400

This is infuriating, and the worst part is that a clear solution isn't in sight. Sure, we can fight this in the courts, and a few secret programs might get shut down, but operations will just continue under a different name. We can encrypt our data, move our services and data offshore, but that just paints a big target on our heads - doesn't actually address the fundamental issue. This is supposed to be a democracy,…

The democratic solution is to get people to care about your issue. If the anti-abortionists can do it, so can privacy advocates. Also, we have no idea whether Lavabit's operator's real situation is (though I certainly fault the government for the ridiculous NSL scheme that prevents him from spilling the beans). Is he objecting to installing a PRISM-style scheme, or to legitimate wiretaps?

This is why the "first amendment" issue might be the most important part of this - he might want to stand up and say "the Govenment wants to force me to backdoor my system, and I think Congress should change the law so this can't happen", but he's not allowed to do so. Restricting this kind of clearly political speech is not right, is not just and is not democratic.
Post reply on HN