Live data from Hacker News

Lavabit abruptly shuts down

lavabit.com

401–410 of 671 posts

Re: Lavabit abruptly shuts down

#401
post #187

This is infuriating, and the worst part is that a clear solution isn't in sight. Sure, we can fight this in the courts, and a few secret programs might get shut down, but operations will just continue under a different name. We can encrypt our data, move our services and data offshore, but that just paints a big target on our heads - doesn't actually address the fundamental issue. This is supposed to be a democracy,…

The only nonviolent solution I've found is to move away and stop paying taxes to the US war machine. Don't use or support services that pay US taxes, either. It's what I did. PS: It is very, very, very difficult, because most of the people you care about will not move with you.

Don't be delusional. Unless you have business intentions, that rely on government not knowing what your business is, it is NOT, by any stretch of imagination" a reason to leave a country like USA, the more so for a Central American country. This issue is so minor to most people that many don't even give it much thought. I am sure you can live with the government watching you and still make some kind of contribution towards solving the problem. Besides NSA spies on the whole world if you use USA services. I live in a God's forgotten land of country you probably haven't even heard, yet I too am spied while using popular services. So my advice would be to avoid using USA based internet services when possible to minimize any potential damage your leaked private information might do to you and, together with thousands of others, help find the solution and make it happen.

Re: Lavabit abruptly shuts down

#402
post #292

Earlier quoted context omitted.

I would hope that if they've received an NSL ordering them to wiretap their own email, that the NSL is at least limited to specific targets of an investigation. But some people do strongly believe in throwing out the whole bathtub if that's what it takes to keep the data safe, and to those people I will certainly tip my hat, even if I disagree myself.

I can accept a company complying with a warrant and divulging data for some customers. I will not accept a company that promises complete security and then sends a trojan to customer computers. Anyone that betrays the security promises made to the entire user base (eg. hushmail) should be ostracized.

Agreed.

Re: Lavabit abruptly shuts down

#403
post #15

For the unfamiliar: Lavabit was a webmail service, that (claimed to) encrypt emails in such a way that they literally did not have access to the content stored on their own servers. The linked email would lend some credence to those claims. It was originally designed in contrast to gmail scanning your email for targeted advertising, but my imperfect memory says that their system should also have been resilient to "we…

So... there would be market for a secure email service that ran on a ship/vessel that was permanently in the middle of international waters?

(might have to have multiple vessel's for redundancy purposes)

Re: Lavabit abruptly shuts down

#404

Earlier quoted context omitted.

It wouldn't be resilient to interception of mail going to and coming from lavabit however, since email is essentially a plaintext public protocol.

...which is why you encrypt the contents before you send it, yes?

This is why the speculation that even with encrypted emails, to and from address is in the clear and that could be valuable info to government. So we're back to meta data in plain text both in transit and storage.

Re: Lavabit abruptly shuts down

#405

Earlier quoted context omitted.

Make the bastards work for it. Enough people using strong encryption (both for data over the wire and data at rest) makes big-data collection (can't dedupe random noise) and processing/datamining prohibitively expensive if not impossible. Nobody is getting in trouble for moving their data and services offshore. Aside from that? I'd suggest finding a few friendly people in various countries and establish a constant /d…

This is a brilliant suggestion actually. If I ever make a crypto messaging system I'll surely bake in a module that sends bogus messages to random nodes in the system. Then any sorts of metadata are useless to evil people.

Pond does something along those lines:

> Pond doesn't transmit messages as needed because that would disclose when messages were being sent. Instead it transmits messages at random, whether there's anything to be sent or not. When there's a real message pending, it has to wait until the next randomly timed slot, which could be many minutes.

https://pond.imperialviolet.org/

Re: Lavabit abruptly shuts down

#406

Earlier quoted context omitted.

Nope, only that companies trust Microsoft's crypto implementation. But as it happens, yes, I trust our crypto developers. They're much better at it than most of HN.

I don't. I've seen the source (via shared source) and there is a big fucking hole where the CSPs should be. And the rest of the code is pretty shitty in places.

[deleted]

Re: Lavabit abruptly shuts down

#407
post #392

Earlier quoted context omitted.

The worst case (that I can talk about) I saw involved requiring a specific employee be demoted due to improper care of a company's systems. Would you expand on this? Are you saying that a court was meddling directly with an individual company's hierarchy?

(Forgive a 5-year-old memory of one of many cases -- I probably have the numbers wrong) It went something like this: The director of engineering approved a log retention plan that kept access logs for 7 days or something. They wanted to reduce costs and issues with log files were the top reasons for getting called to support the service. The government needed to demonstrate that someone had accessed the service 14 da…

Software/technology is quickly becoming a place full of dangerous legal landmines.

Re: Lavabit abruptly shuts down

#408
post #385

Earlier quoted context omitted.

This is a brilliant suggestion actually. If I ever make a crypto messaging system I'll surely bake in a module that sends bogus messages to random nodes in the system. Then any sorts of metadata are useless to evil people.

Filtering out the random noise wouldn't be very hard.

How are you going to figure out whether it's random encrypted noise or an unrandom encrypted message?

Re: Lavabit abruptly shuts down

#409
post #336

Earlier quoted context omitted.

Not to put words in the OP's mouth, but I think it's not so much about the USA's not respecting human rights as about that _and_ its having too much power for everybody's good. By not having to pay taxes to USGov, they probably hope to make that power diminish. EDIT: Good God, I've always been the guy arguing with your average America hater that we should count ourselves lucky that in the monopolar world we live in,…

What big liberal democracy isn't becoming a surveillance state? The U.K. seems 10-15 years ahead of us on that front, and people seem to like it just fine over there. Maybe the answer is just that pervasive surveillance isn't something that upsets people?

Maybe that's because the US exports the surveillance state, not because the locals like it so much. It will be interesting to see if any US allies go their own way on this issue.
Post reply on HN