Live data from Hacker News

Lavabit abruptly shuts down

lavabit.com

541–550 of 671 posts

Re: Lavabit abruptly shuts down

#541
post #183

The US government is destroying one of the few bright spots in the American economy with its out of control military. It is unconscionable. And the sad thing is it has been enabled by the betrayal by many of the web 2.0 giants, Facebook, Google etc. Google especially is sad to see since they were willing to forgo the Chinese market on principle, but then decided that taking on the authoritarian US government was too…

If you are seriously suggesting that abandoning the US market is a realistic option, especially for a multibillion dollar corporation, then you are (and I'm not using this word lightly) an idiot . Not to mention that there is no US equivalent to the rampant human rights violations and censorship in China.

Yup. Tax benefits of being in the us are huge. Easy to bribe politicians, no corporate income tax, huge rebates.

As to the US market - meh. The US is third world in terms of purchasing power. Only reason to base there is the pro-corporate corruption.

Re: Lavabit abruptly shuts down

#542
post #480

Earlier quoted context omitted.

so no matter how good encryption gets, government will simply ratchet up the penalties; financial and/or prison time; to keep pace. we simply can be guilty hiding the nothing we have to hide

Don't be so bleak. If you're going to do something that will get the attention of any government, here's a simple rule to follow. Don't use 3rd parties. And if you must, do it in a way that can never be traced back to you in the "real world". It isn't hard and it isn't even illegal. http://www.amazon.com/How-Be-Invisible-Protect-Children/dp/1...

Step 1: Don't buy a book called "How to be Invisible" from Amazon.

Re: Lavabit abruptly shuts down

#543
post #15

For the unfamiliar: Lavabit was a webmail service, that (claimed to) encrypt emails in such a way that they literally did not have access to the content stored on their own servers. The linked email would lend some credence to those claims. It was originally designed in contrast to gmail scanning your email for targeted advertising, but my imperfect memory says that their system should also have been resilient to "we…

it sounds like they were asked to modify their system to retain data

Re: Lavabit abruptly shuts down

#544
post #200

Earlier quoted context omitted.

He's most likely under a gag order. I thought that was pretty obvious.

Aren't gag orders challengeable? I thought they were found unconstitutional. http://securitywatch.pcmag.com/privacy/309277-judge-says-fbi...

I think they were found unconstitutional when they were forcing people to not even tell their lawyers. You can tell your lawyer now, and you can fight the gag order in Court - but in secret. Until the court tells you can tell everyone about it, you can't.

Re: Lavabit abruptly shuts down

#545
post #431

Earlier quoted context omitted.

> I'm in the process of moving any Saas offerings I use off USA-affiliated companies, but it's actually more difficult than I first thought. You should try finding a SSL cert retailer that's outside of the US. The only ones I could find that would actually sell me certs without a phone call charged at least $200 for a basic certificate. https://swisssign.com/en were the most sensible looking ones I could find.

There's StartCom (StartSSL) from Israel. Have you tried them? They even offer free SSL certs, by the way.

They are from Israel, a good friend of the US, and for free. What part of that does not scream 'run for the hills' exactly?

Re: Lavabit abruptly shuts down

#546

Earlier quoted context omitted.

Which companies would that be? I can imagine what would happen to Google if, through some dark miracle, their leadership decided to do this. Most of their top engineers live in America. So do the leaders, but ignore them, we've already decided they want this. The employees don't, though: There are eleven thousand people, there, who'll need to be relocated to - where? Europe, probably Ireland, where many of them have…

The would do far better to spend a billion on lawyers and lobbyists.

Would you want to be the one who makes that stand against them? You can be guaranteed that you are from that day onwards a marked man. Everything you do, everywhere you go, and every person you talk to will be monitored. They will look for the tiniest chin in your armour, and once shown they will hang you out to dry. This explains why companies like Google and Yahoo had little choice but to comply. It might also explain why Obama so drastically changed hs beliefs.

Re: Lavabit abruptly shuts down

#547
post #531

Earlier quoted context omitted.

Dual US/Polish citizen here. Just wanted to say that in many cases abroad (i.e. Poland) the case isn't about the laws protecting your privacy but rather about the Government having no means (technical, resources, know-how, etc) to enforce ridicolous things like reading and storing email contents of all the people. Even with court order just to read stuff in your inbox, I would imagine that the Polish police would hav…

I second to that. If you want security (at least on a servers/ISP level) choose some 3rd world country which government (preferably not very fond of USA) does not have technical means on surveillance. I live in a small EU country and government’s IT forces are just laughable, so I can just imagine that in less civilised countries it should be close to non-existent. Combined with strong encryption to protect data in b…

The problem is that most 3rd world countries will just come knocking on your doors and take everything away, if the US goverment requests it.

After all, those countries wouldn't be 3rd world countries, if they had the power to resist US threats/requests. Or they are part of the "axis of evil" (or whatever the current propaganda term is), in which case the internet connection to that country could either be cut off, or be heavily censored, if it isn't already happening.

Re: Lavabit abruptly shuts down

#548
post #350
post #15

For the unfamiliar: Lavabit was a webmail service, that (claimed to) encrypt emails in such a way that they literally did not have access to the content stored on their own servers. The linked email would lend some credence to those claims. It was originally designed in contrast to gmail scanning your email for targeted advertising, but my imperfect memory says that their system should also have been resilient to "we…

Edit: I was a PM on Exchange and Exchange Hosted Encryption for some time, so it looks like Lavabit tried to fight the government on whether they are required to release private keys. I've seen one other customer try to fight, and it was not pretty either. The US government in these cases are serious. Takeaway for fellow hackers: If you are building a system that stores user-generated data, prepare for the eventualit…

Could you name some examples from Europe? Cases when police physically takes servers are common. But I never heard of case where police would require encryption keys for 'maybe we will needed it'.

Re: Lavabit abruptly shuts down

#549
post #428
post #392

Earlier quoted context omitted.

(Forgive a 5-year-old memory of one of many cases -- I probably have the numbers wrong) It went something like this: The director of engineering approved a log retention plan that kept access logs for 7 days or something. They wanted to reduce costs and issues with log files were the top reasons for getting called to support the service. The government needed to demonstrate that someone had accessed the service 14 da…

Is there a legal precedent for minimum time that logs must be kept, say for an email service or messaging service? I'm talking about US policy, if that makes it more clear.

It was likely agreed on (possibly via contract) to meet the compliance policy of the government agency. So I could see breach of contract. I don't know about legal precedent for logs per se, but there is precedent for retention of other files. For instance HIPAA involves some well known regulations around keeping and destroying medical data.

Re: Lavabit abruptly shuts down

#550

Earlier quoted context omitted.

Where are you going to go? People playing up third world countries don't know shit. The day-to-day corruption in nearly every such country is so bad that after awhile you'd rather have someone reading your e-mail but otherwise leaving you alone. And let me tell you from first hand experience--it is soul sucking to live in a country like that where you're constantly surrounded by people living on the edge of subsisten…

> That leaves the Scandinavian countries, I suppose, but I have a hard time seeing a lot of libertarian-minded people fleeing the U.S. for that collectivist utopia. As a pragmatic libertarian, I am willing to pay many more dollars in taxes to provide services I don't agree with so long as little to none of my tax dollars go towards bombing brown people and spying on citizens. Some things are worth compromising over.

All Scandinavian countries do implement EU Data Retention Directive just as well.
Post reply on HN