Live data from Hacker News

Lavabit abruptly shuts down

lavabit.com

471–480 of 671 posts

Re: Lavabit abruptly shuts down

#471
post #32

I like the part where he can't tell you why he's shutting down. As if we won't engage in rampant irresponsible speculation that they have told him to decrypt and forward everything to them in real time.

what would you have him do? He's clearly under NSL, so he can't tell you what he was asked for. This is the strongest statement he can legally make (in fact, i'm sure some US lawyers would argue that it's actually beyond that). I guess we now know how it must have felt to watch republican institutions spiral into tyranny in ancient Rome.

Hopefully he would become a whistleblower, but with such a bleak outcome for Snowden I can sympathize with his not wanting to.

Re: Lavabit abruptly shuts down

#472
post #26

Seems like it would make sense for users to demand that any US based service includes a warrant canary, just like rsync.net's implementation. A global canary + separate canaries for individual accounts would also make sense. https://en.wikipedia.org/wiki/Warrant_canary http://rsync.net/resources/notices/canary.txt

The canary trick is roughly on par with "I was NOT served a letter on July 20, 2013, which did NOT say the following..."

To be honest, I'm even a little nervous that something as innocuous as "I wish I could tell you more about the circumstances leading to the decision" could be seen as communicating the presence of an NSL indirectly, and lead to contempt of court.

Re: Lavabit abruptly shuts down

#473
Here's my speculation, to be buried 450 comments deep:

The government said, "you must update your software to compromise your encryption, and deliver us this information we have a warrant for." Lavabit said, "well, no, that defeats the purpose of our business". The gov't said "we don't care, we have a valid warrant" and now Lavabit is out of business.

If I'm right, nobody's files were compromised because Lavabit refused, but I imagine that doesn't bode well for returning user data because there could be huge legal consequences if one of the confirmed users is strongly suspected of XYZ.

If I'm right, it shouldn't prevent the owner from starting a new secure email service outside of the US. I suggest Iceland.

Re: Lavabit abruptly shuts down

#474

Where's the "I wish you hadn't done that, lavabit, I'm a customer and I feel very screwed over by this action" comments? Or is this appropriate for any SaaS vendor? You're OK with this? Should all customers, even those who really don't care if the NSA could be watching, be put out because some feel that this cause trumps actually doing business and having customer-vendor relationships? I could see someone suing an Sa…

If you're buying a secure email service, the compromise of that security would be a bigger screw-job. Lavabit must have shut down in the interest of its customers, otherwise why would they have shut down?

Re: Lavabit abruptly shuts down

#475
post #469

Earlier quoted context omitted.

"encrypt emails in such a way that they literally did not have access to the content stored on their own servers" how is that possible? I'm curious to know as to how they achieved that technically. I mean if the user is reading an email in their browser, then it would've had to have been created on the server first.

It all happens on the client side. Servers only store the encrypted emails and have no idea what the contents or the keys are.

right, but incoming and outgoing emails from lavabit servers won't necessarily be encrypted, unless the other party is using GPG or whatever - it's just the way they're stored.

Re: Lavabit abruptly shuts down

#476

Earlier quoted context omitted.

Agreed, these US Gov contractors and agencies systematically destroying our industry and our prospects. As a community, let's shun and shame all those who continue work for those agencies (NSA/CIA/FBI/DIA/DEA) both directly and as contractors from this date forward. If you didn't quite in August 2013, we don't want to hire you. If you quite now in disgust, we should view that in a positive light. If you or your compa…

Should I still use Golang? Would making crypto-software in Golang make it less secure? Would the irony be worth it? Is it a worthy language?

Obviously you're being somewhat facetious. If you're good/confident enough to write your own crypto, go seems fine as it's open source so you can inspect it. I don't trust myself to write my own crypt for important things, so obviously I would not use Golang for that and I would pause before using the Golang crypto module, but that's probably a bit paranoid. In general, I would probably use Golang on projects. I use Angular.s and Python and those have been funded in ways by Google.

Things like Google App Engine/Data store are an issue b/c your backend is Google's backend...fundamentally the same issue Gmail faces. If the NSA/FBI/DEA/TSA mistakenly fingers one of my customers as a drug dealer or "terrorist" or thinks they are associated with a drug dealer/whistleblower/"terrorist", google will hand over all my apps data.

Re: Lavabit abruptly shuts down

#477
post #189

Earlier quoted context omitted.

Make the bastards work for it. Enough people using strong encryption (both for data over the wire and data at rest) makes big-data collection (can't dedupe random noise) and processing/datamining prohibitively expensive if not impossible. Nobody is getting in trouble for moving their data and services offshore. Aside from that? I'd suggest finding a few friendly people in various countries and establish a constant /d…

I wonder if, more than crypto, false positives would make them work harder. They know who you are emailing too, and so likely are not going to target you in any case, since you are not part of an interesting network. But if you start talking about a movie, where they plan to detonate a dirty bomb in Times Square or something... Emacs automates this with M-x spook: morse War on Terrorism encryption Forte Blowpipe LLNL…

http://www.youtube.com/watch?v=v4z09el30f8 Trevor Moore's take on this idea.

Re: Lavabit abruptly shuts down

#479
post #456
post #413

Earlier quoted context omitted.

> " I've long been more afraid, in general, of computer hackers than government." Seriously?

Yes, seriously. People like to think that computer hackers have some perfect sense of morality, I have real-life experience that they don't. The government, though occasionally surreal, has not once been a serious impediment to anything I've wanted to do, and in fact has occasionally been an exceptional aid in what I've wanted to do.

I find it amazing that anyone can still justify what the government is doing. Every line has been crossed. To the DEA, to the IRS. And, still, you are okie dokie. I am amazed.

Re: Lavabit abruptly shuts down

#480

Earlier quoted context omitted.

Software/technology is quickly becoming a place full of dangerous legal landmines.

so no matter how good encryption gets, government will simply ratchet up the penalties; financial and/or prison time; to keep pace. we simply can be guilty hiding the nothing we have to hide

Don't be so bleak. If you're going to do something that will get the attention of any government, here's a simple rule to follow. Don't use 3rd parties. And if you must, do it in a way that can never be traced back to you in the "real world". It isn't hard and it isn't even illegal.

http://www.amazon.com/How-Be-Invisible-Protect-Children/dp/1...

Post reply on HN