Live data from Hacker News

Lavabit abruptly shuts down

lavabit.com

451–460 of 671 posts

Re: Lavabit abruptly shuts down

#451
post #183

The US government is destroying one of the few bright spots in the American economy with its out of control military. It is unconscionable. And the sad thing is it has been enabled by the betrayal by many of the web 2.0 giants, Facebook, Google etc. Google especially is sad to see since they were willing to forgo the Chinese market on principle, but then decided that taking on the authoritarian US government was too…

Agreed, these US Gov contractors and agencies systematically destroying our industry and our prospects. As a community, let's shun and shame all those who continue work for those agencies (NSA/CIA/FBI/DIA/DEA) both directly and as contractors from this date forward. If you didn't quite in August 2013, we don't want to hire you. If you quite now in disgust, we should view that in a positive light. If you or your compa…

Should I still use Golang? Would making crypto-software in Golang make it less secure? Would the irony be worth it? Is it a worthy language?

Re: Lavabit abruptly shuts down

#452
post #324
post #310

Does anybody know of a good European VPS provider for self-hosted email? That seems to be the only way to go moving forward.

If you want security, avoid VPSes. Your VPS is at the mercy of the hypervisor. You need to own a physical machine under lock and key if you want to be assured of its security.

And your own army to defend it when whatever government has jurisdiction in the location of your servers demands access to it.

Re: Lavabit abruptly shuts down

#453

Apparently they just cut off all email access. From Facebook: "Could you please at least forward the messages for a couple of days to some other e-mail accounts? I can't reset/change the e-mails I used on other websites because they require validation PER EMAIL." "While I approve of what you've chosen to do, I just purchased a decade of advance service from you, and you've left no contact addresses or information. Wh…

I doubt they truly have much choice in the matter. It sounds more like a pull-the-plug-and-run sort of situation than one that leaves any actual planning. As their servers now just flat out don't have an SMTP service running, it seems like a fairly reasonable guess.

Re: Lavabit abruptly shuts down

#454
post #429

Earlier quoted context omitted.

To make crypto truly secure, the end user has to take on management of their key and that key can never reside on your servers. Users can barely manage their password; expecting them to manage something that, if they lose, takes all their data with them, is asking a lot. I tried to get a startup off the ground for 2 years that would secure gmail, and we went round and round on this. We wanted to not be able to read t…

Give us a try? It seems this is the default line and that the users never get to piss off the support people because they're never given the chance. Let us burn ourselves and then we can learn to use the stove. If we never understand the importance of that key we'll never get used to maintaining it properly. Quite clearly - is there any messaging service that allows users to end-to-end encrypt? That is not PGP? There…

Adium and Jabber both support OTR for IM, which is end-to-end encryption.

Re: Lavabit abruptly shuts down

#455

Earlier quoted context omitted.

This is why I contributed to Mailpile( http://www.mailpile.is/)'s fundraiser and hang out in their IRC channel. We need more, better, easy-to-use distributed, crypto-friendly mail software, and we need them yesterday. :/

bitmessage may be our only hope.

Bitmessage is fairly atrocious to use in practise. It's slow (by design) and extremely difficult to use properly. Moreover, I'd bet my hat that it's not secure.

Re: Lavabit abruptly shuts down

#456
post #413
post #140

Earlier quoted context omitted.

Is it fear-mongering? Sites actually do get hacked and defaced all the time for political advocacy (e.g. LulzSec). I've long been more afraid, in general, of computer hackers than government.

> " I've long been more afraid, in general, of computer hackers than government." Seriously?

Yes, seriously. People like to think that computer hackers have some perfect sense of morality, I have real-life experience that they don't.

The government, though occasionally surreal, has not once been a serious impediment to anything I've wanted to do, and in fact has occasionally been an exceptional aid in what I've wanted to do.

Re: Lavabit abruptly shuts down

#457
post #324
post #310

Does anybody know of a good European VPS provider for self-hosted email? That seems to be the only way to go moving forward.

If you want security, avoid VPSes. Your VPS is at the mercy of the hypervisor. You need to own a physical machine under lock and key if you want to be assured of its security.

Thanks. I'm aware of the security implications. Please answer the question or don't reply.

Re: Lavabit abruptly shuts down

#458
post #445

Earlier quoted context omitted.

It's not just going to be hosting providers that are affected by this. It's going to lawyers, software engineers, sys admins, writers and graphic designers who are going to lose work/business from SAAS companies. Software is one of the few areas where the US economy is growing somewhat sustainably (as opposed to banking/gambling/housing speculation/medical expenses for elderly). The NSA and all those NSA contractors…

The nails are already in the coffin for US internet behemoths. Any non-NSA cooperating country has strong interests in keeping their search engines, social networks, and cloud software internal to their country. Google, Microsoft, and Facebook basically have had billions of dollars shaved off of their future market capitalization -- though I have not seen anyone say this yet. For everyone abroad who is technically ad…

Agreed. The nails are in for the current system, but that is not The System, just one of many potential ones.

If you are non-US citizen and your customers request a product similar to US product please do exactly as AJ007 says. It will help you, the world, and the US long term. I say this as US citizen and SW dev. Please take our jobs and customers! We don't deserve those customers if we can't protect them and their data.

However, you should only build it if customers are requesting SAAS (or other offerings). Be very careful about blindly copying US business b/c many are successful simply b/c they are almost "Apparatchik" entities, supplying and protected by the US Gov. For example, if you copy Palantir or even Google/Facebook you may not succeed b/c you won't have customers in the same way the US does. But overall, this is a great opportunity for devs from Switzerland (and the like) to get some new customers.

Re: Lavabit abruptly shuts down

#459
post #281

Earlier quoted context omitted.

no, they don't open the mail, but they scan all the addresses as part of their routing process. We should assume that all postal "metadata" is stored forever.

As a veteran of the USPS software industry, I wouldn't worry too much.

hilarious!! since we on the subject, are there any veterans of NSA software industry who can share some insight?

Re: Lavabit abruptly shuts down

#460
post #292
post #269

Earlier quoted context omitted.

I think the trick here is that lavabit can't share data even with a warrant. Their inability to do so is pretty much their entire business model. That protects people from unwarranted intrusions, but it also insulates people from legitimate investigation. If they build a backdoor for only duly authorized warrants, they are no more or less obligated to comply with an NSL.

I would hope that if they've received an NSL ordering them to wiretap their own email, that the NSL is at least limited to specific targets of an investigation. But some people do strongly believe in throwing out the whole bathtub if that's what it takes to keep the data safe, and to those people I will certainly tip my hat, even if I disagree myself.

I'm thinking now that if he had just been ordered to turn over some data, shutting down his service wouldn't let him off the hook. They must have asked for a back door or some other ongoing intrusion.
Post reply on HN