Live data from Hacker News

Lavabit abruptly shuts down

lavabit.com

421–430 of 671 posts

Re: Lavabit abruptly shuts down

#421
post #183

The US government is destroying one of the few bright spots in the American economy with its out of control military. It is unconscionable. And the sad thing is it has been enabled by the betrayal by many of the web 2.0 giants, Facebook, Google etc. Google especially is sad to see since they were willing to forgo the Chinese market on principle, but then decided that taking on the authoritarian US government was too…

If you are seriously suggesting that abandoning the US market is a realistic option, especially for a multibillion dollar corporation, then you are (and I'm not using this word lightly) an idiot . Not to mention that there is no US equivalent to the rampant human rights violations and censorship in China.

>Not to mention that there is no US equivalent to the rampant human rights violations and censorship in China.

So that makes it okay for them to systematically spy on their own citizens and violate their own constitution?

Saying "this country is worse" doesn't make it okay in the US.

Bad logic.

Re: Lavabit abruptly shuts down

#422
post #403
post #15

For the unfamiliar: Lavabit was a webmail service, that (claimed to) encrypt emails in such a way that they literally did not have access to the content stored on their own servers. The linked email would lend some credence to those claims. It was originally designed in contrast to gmail scanning your email for targeted advertising, but my imperfect memory says that their system should also have been resilient to "we…

So... there would be market for a secure email service that ran on a ship/vessel that was permanently in the middle of international waters? (might have to have multiple vessel's for redundancy purposes)

So guarantee you will be regarded as a "terrorist" and then put yourself somewhere in the middle of international waters?

At least when the ship disappeared off the face of the earth it would be easy to figure out what happened.

Re: Lavabit abruptly shuts down

#423
post #350

Earlier quoted context omitted.

Edit: I was a PM on Exchange and Exchange Hosted Encryption for some time, so it looks like Lavabit tried to fight the government on whether they are required to release private keys. I've seen one other customer try to fight, and it was not pretty either. The US government in these cases are serious. Takeaway for fellow hackers: If you are building a system that stores user-generated data, prepare for the eventualit…

ziplip shut down in 2005 citing an inability to maintain user privacy in light of new legislation. Their servers were in Ireland, I think.

[deleted]

Re: Lavabit abruptly shuts down

#424
post #403
post #15

For the unfamiliar: Lavabit was a webmail service, that (claimed to) encrypt emails in such a way that they literally did not have access to the content stored on their own servers. The linked email would lend some credence to those claims. It was originally designed in contrast to gmail scanning your email for targeted advertising, but my imperfect memory says that their system should also have been resilient to "we…

So... there would be market for a secure email service that ran on a ship/vessel that was permanently in the middle of international waters? (might have to have multiple vessel's for redundancy purposes)

The Pirate Bay team are implementing something like that, i believe.

http://www.tomshardware.com/news/Pirate-Bay-Orbit-Serves-Spa...

Re: Lavabit abruptly shuts down

#425
post #368

Earlier quoted context omitted.

The goal is not necessarily security (I have nothing to hide (I still do hide as much as possible))-- the goal is political change. That's the only real way out of this mess. By not using US companies, you incentivize those to lobby for better laws.

Political change on it's own won't work. They will still keep the infrastructure in case they need to spy on someone(with a court order). But if they have the infrastructure , conceptually it's just a press of button again to full blown illegal surveillance.

there has been infrastructure to read snail mail contents for 200 years. Doesn't matter, the US Gov isn't routinely reading snail mail because of politics. I think he's right, make it a political issues. Actually, more: make it political issue, encryption issue, hosting issue, social issue (denied nsa contracting recently based on Snowden), I mean total war - make their life as difficult as possible using all means possible. As long as it's legal of course.

Re: Lavabit abruptly shuts down

#426
post #155

Earlier quoted context omitted.

I don't blame the companies; they're about as much a victim of USgov as we are IMHO. That being said, if all the online-storage/cloud-server/email-providers/social-whatever companies in US start going out of business because nobody trusts them I strongly suspect something will have to change. It's just too bad we have to do a "scorched earth"[1] to bring about change. 1. http://en.wikipedia.org/wiki/Scorched_earth

This is where I disagree. I do blame companies like Google for not fighting this more. At the very least they make users aware that these laws exist, even if they cannot detail specifics related to their surveillance involvement.

See this comment : https://news.ycombinator.com/item?id=6182179

Fighting the USgov isn't a decision to take lightly regardless of how much money & resources you have. I cannot condemn a company that backs down from that battle. It could hurt an employee(s) significantly, or the whole company. While I agree they have the most resources to fight it, they're not immune to harm from USgov.

Re: Lavabit abruptly shuts down

#427
post #403
post #15

For the unfamiliar: Lavabit was a webmail service, that (claimed to) encrypt emails in such a way that they literally did not have access to the content stored on their own servers. The linked email would lend some credence to those claims. It was originally designed in contrast to gmail scanning your email for targeted advertising, but my imperfect memory says that their system should also have been resilient to "we…

So... there would be market for a secure email service that ran on a ship/vessel that was permanently in the middle of international waters? (might have to have multiple vessel's for redundancy purposes)

IANAAL, but I'm guessing the U.S. would just pressure your flag state to revoke your license. Then they'll arrest you for piracy or something. Or even better issue a letter of marque and reprisal so private citizens can hunt you down and take your stuff.

Re: Lavabit abruptly shuts down

#428
post #392

Earlier quoted context omitted.

The worst case (that I can talk about) I saw involved requiring a specific employee be demoted due to improper care of a company's systems. Would you expand on this? Are you saying that a court was meddling directly with an individual company's hierarchy?

(Forgive a 5-year-old memory of one of many cases -- I probably have the numbers wrong) It went something like this: The director of engineering approved a log retention plan that kept access logs for 7 days or something. They wanted to reduce costs and issues with log files were the top reasons for getting called to support the service. The government needed to demonstrate that someone had accessed the service 14 da…

Is there a legal precedent for minimum time that logs must be kept, say for an email service or messaging service? I'm talking about US policy, if that makes it more clear.

Re: Lavabit abruptly shuts down

#429
post #245

Earlier quoted context omitted.

As developers perhaps the most effective thing we can do from a long-term perspective is baking strong cryptography in to all of the products we create, and opting for open source whenever possible. (After all, open source is the only way we can guarantee that the software we're using really doesn't snoop on us.) If crypto were easier to use and presented as a default, more regular people would wind up using it and w…

To make crypto truly secure, the end user has to take on management of their key and that key can never reside on your servers. Users can barely manage their password; expecting them to manage something that, if they lose, takes all their data with them, is asking a lot. I tried to get a startup off the ground for 2 years that would secure gmail, and we went round and round on this. We wanted to not be able to read t…

Give us a try? It seems this is the default line and that the users never get to piss off the support people because they're never given the chance.

Let us burn ourselves and then we can learn to use the stove. If we never understand the importance of that key we'll never get used to maintaining it properly.

Quite clearly - is there any messaging service that allows users to end-to-end encrypt? That is not PGP? There is such a conspicuous void in the market here...

Re: Lavabit abruptly shuts down

#430
post #108

Earlier quoted context omitted.

Moving services off USA-based companies is like using two bicycle locks instead of one. A determined government is still going to get your data, they just need to spend a bit more time. Focus instead on encryption.

It is just as bad or worse. You have to move the data in/out of the country. It definitely isn't protected when it leaves the country. The only advantage I see is that it punishes US businesses for failing to protest.

Dual US/Polish citizen here. Just wanted to say that in many cases abroad (i.e. Poland) the case isn't about the laws protecting your privacy but rather about the Government having no means (technical, resources, know-how, etc) to enforce ridicolous things like reading and storing email contents of all the people. Even with court order just to read stuff in your inbox, I would imagine that the Polish police would have big time difficulties doing anything. These are guys making 700usd a month and the Government doesn't have money and/or the need/desire to hire folks who could execute these things. And I can just imagine that in places like Ukraine the law may say whatever but what happens is this what the highest bidder asked for ;-) Remember, not the whole world works the way the first world or the USA does.

Unless of course, what you referred to is that most of the traffic goes via the US soil anyway. But then again, why to stay in the US? Move whole business and yourself abroad :-)) Ironically, I found much, much, much more freedom in post communistic Poland than - oh irony! - Land of the Free.

Post reply on HN