Live data from Hacker News

Lavabit abruptly shuts down

lavabit.com

441–450 of 671 posts

Re: Lavabit abruptly shuts down

#441
post #15

For the unfamiliar: Lavabit was a webmail service, that (claimed to) encrypt emails in such a way that they literally did not have access to the content stored on their own servers. The linked email would lend some credence to those claims. It was originally designed in contrast to gmail scanning your email for targeted advertising, but my imperfect memory says that their system should also have been resilient to "we…

"encrypt emails in such a way that they literally did not have access to the content stored on their own servers" how is that possible? I'm curious to know as to how they achieved that technically. I mean if the user is reading an email in their browser, then it would've had to have been created on the server first.

Lavabit's explanation of their security, via the Wayback Machine: http://web.archive.org/web/20130530023856/http://lavabit.com...

Re: Lavabit abruptly shuts down

#442
post #393

Earlier quoted context omitted.

They take a photo of the front and back of every piece of mail that is sent. Your content is safe, but they still get the metadata.

Couldn't you just leave off the return address? In this case there's not much metadata to collect except for the recipient address.

You can also fake the "from" address in an e-mail, and send it from somewhere in the world via vpn

Re: Lavabit abruptly shuts down

#443
post #392

Earlier quoted context omitted.

(Forgive a 5-year-old memory of one of many cases -- I probably have the numbers wrong) It went something like this: The director of engineering approved a log retention plan that kept access logs for 7 days or something. They wanted to reduce costs and issues with log files were the top reasons for getting called to support the service. The government needed to demonstrate that someone had accessed the service 14 da…

Software/technology is quickly becoming a place full of dangerous legal landmines.

so no matter how good encryption gets, government will simply ratchet up the penalties; financial and/or prison time; to keep pace.

we simply can be guilty hiding the nothing we have to hide

Re: Lavabit abruptly shuts down

#445
post #24

I'm in the process of moving any Saas offerings I use off USA-affiliated companies, but it's actually more difficult than I first thought. I believe there might even be a very profitable market in simply duplicating the functionality of Saas offerings at a higher price with security/privacy guarantees in Germany/HK/etc. Might be the next hot business to be in? You'd be surprised as to the number of people seeking alt…

It's not just going to be hosting providers that are affected by this. It's going to lawyers, software engineers, sys admins, writers and graphic designers who are going to lose work/business from SAAS companies. Software is one of the few areas where the US economy is growing somewhat sustainably (as opposed to banking/gambling/housing speculation/medical expenses for elderly). The NSA and all those NSA contractors…

The nails are already in the coffin for US internet behemoths. Any non-NSA cooperating country has strong interests in keeping their search engines, social networks, and cloud software internal to their country.

Google, Microsoft, and Facebook basically have had billions of dollars shaved off of their future market capitalization -- though I have not seen anyone say this yet.

For everyone abroad who is technically adept and talented, the vaults of wealth have been unlocked for you; just copy the successful offerings of American companies. Don't worry about software patents or trademarks unless your country is complicit, you'll have the autonomy of a oligarch (said with some sarcasm.)

There is one solution here: open source, distributed software. If you want to build a company to promote real security this is your only option.

Re: Lavabit abruptly shuts down

#446
post #428
post #392

Earlier quoted context omitted.

(Forgive a 5-year-old memory of one of many cases -- I probably have the numbers wrong) It went something like this: The director of engineering approved a log retention plan that kept access logs for 7 days or something. They wanted to reduce costs and issues with log files were the top reasons for getting called to support the service. The government needed to demonstrate that someone had accessed the service 14 da…

Is there a legal precedent for minimum time that logs must be kept, say for an email service or messaging service? I'm talking about US policy, if that makes it more clear.

Generally speaking unless you are specifically required to keep records for a regulatory purpose (i.e. tax), you don't have to keep logs at all. Lavabit used to keep logs for a limited time (I think a week?).

More concerning are key disclosure laws [1] and their crazy penalties that seem to be creeping in all over the world.

[1] https://en.wikipedia.org/wiki/Key_disclosure_law

Re: Lavabit abruptly shuts down

#448
Apparently they just cut off all email access. From Facebook: "Could you please at least forward the messages for a couple of days to some other e-mail accounts? I can't reset/change the e-mails I used on other websites because they require validation PER EMAIL." "While I approve of what you've chosen to do, I just purchased a decade of advance service from you, and you've left no contact addresses or information. Who are your customers supposed to speak to at this time?" "i do respect your decision. But as a long time lavabit customer(8 or so years) I am very upset. I have paid money every year to upgrade and have spam protection and now lost all my emails. I would have liked some notice and a forwarding option for us." https://www.facebook.com/KingLadar?fref=ts

Re: Lavabit abruptly shuts down

#449

This is infuriating, and the worst part is that a clear solution isn't in sight. Sure, we can fight this in the courts, and a few secret programs might get shut down, but operations will just continue under a different name. We can encrypt our data, move our services and data offshore, but that just paints a big target on our heads - doesn't actually address the fundamental issue. This is supposed to be a democracy,…

The democratic solution is to get people to care about your issue. If the anti-abortionists can do it, so can privacy advocates. Also, we have no idea whether Lavabit's operator's real situation is (though I certainly fault the government for the ridiculous NSL scheme that prevents him from spilling the beans). Is he objecting to installing a PRISM-style scheme, or to legitimate wiretaps?

>>The democratic solution is to get people to care about your issue. If the anti-abortionists can do it, so can privacy advocates.

Not quite the same thing. Abortion is an inherently sensitive topic that is susceptible to emotion. Saying something as simple as "they are killing helpless babies!" is enough to get a ton of people on the anti-abortion side.

What's the equivalent of privacy? How do we make the 4th amendment an emotional issue? Because there lies our victory.

Re: Lavabit abruptly shuts down

#450
post #348

Earlier quoted context omitted.

Maybe there will be a turnaround, but given that the education system has long been (and continues to be) controlled by Progressives, it doesn't seem that likely to me. But yes, the USA is the only nation founded on the principles of individual freedom, and many people remember that, so there is a chance.

Education is controlled by corporate interest and always will be. In fact the education system was founded by wealthy industrialists so they could churn out great factory workers. To learn more about this read Seth Godin's Linchpin. It's not profitable to have a smart populous. George Carlin sums it up here: http://www.youtube.com/watch?v=AMqJvhmD5Yg

I don't believe there's any evidence at all for what you're claiming regarding "corporate interests." In fact, I think it's obvious that it's wrong.

As far as I know, Otto von Bismarck started modern education so that he could indoctrinate the German youth, but I'm less certain on the details of that.

Post reply on HN