Live data from Hacker News

Lavabit abruptly shuts down

lavabit.com

561–570 of 671 posts

Re: Lavabit abruptly shuts down

#561
post #15

For the unfamiliar: Lavabit was a webmail service, that (claimed to) encrypt emails in such a way that they literally did not have access to the content stored on their own servers. The linked email would lend some credence to those claims. It was originally designed in contrast to gmail scanning your email for targeted advertising, but my imperfect memory says that their system should also have been resilient to "we…

The data may have been protected, but the senders and recipients probably were not. Similarly to SSL, it encrypts the traffic, but does not hide which websites you use. I bet that data are still valuable to the government. I have been thinking of starting a business in the privacy space. This has shown me that that all customer data needs to be periodically obliterated in safe way and that a kill switch or nuke butto…

Apparently a business where some guy is moving paper mail icognito from one point to the ther could be a possible business. I guess lawyers may want this, especially lawyers working to defend issues related to abuse of privacy breach or executive actions. Of course it will be hard to advertise such business.

If you'll be trying to keep this secrect by creating small cells of people not knowing each other and smart mailboxes preventing people exchanging t identify each other, you'll become suspect of supporting spying activity.

So you better work for the minimal number of clients and charge a lot to remain sustainble.

My understanding is that as long as keep the info concentrated in one spot (i.e. Paper mail) it is easy to grab it. If you dilute and spread the info using shared secret and hide it smartly in images or random text, this info would be much harder to catch but could use conventionnal transport means.

Extending this idea further, turn the mail network into one big world wide hologram. The information would then be spreaded, available from everywhere, very hard to censor, and private since you need some specific reference signal to extract the info. It's like shared secret.

Note however that the need to catch evil people using such communication system for evil means is needed. Just considering our own privacy regardless of what can go wrong with such system is in my opinion selfish. We will always need method to protect against abuses.

Re: Lavabit abruptly shuts down

#562
In communism there was no progress exactly because of laws like this. Who wants to operate hosting business in the US now? Why not Asia? HK, Singapore? Or even New Zealand at this point. See how much business is lost. See how much Google, Yahoo, MS, Facebook are hurting now. That's true people will still use them, but not for business critical stuff. No way. In the name of catching a few idiots from a desert who try to blow up themselves they just handled over the whole IT industry to the rest of the world. How stupid you must be to do that?

Re: Lavabit abruptly shuts down

#563
post #546

Earlier quoted context omitted.

The would do far better to spend a billion on lawyers and lobbyists.

Would you want to be the one who makes that stand against them? You can be guaranteed that you are from that day onwards a marked man. Everything you do, everywhere you go, and every person you talk to will be monitored. They will look for the tiniest chin in your armour, and once shown they will hang you out to dry. This explains why companies like Google and Yahoo had little choice but to comply. It might also expl…

If Google et al are facing major potential economic loss due to a widespread lack of confidence in the security of their data, they had better come up with a plan to combat that loss.

Re: Lavabit abruptly shuts down

#564
post #297

Earlier quoted context omitted.

That is not quite what happened. As the link below says, it was not an exploit. Users were warned that using pure IMAP access and/or webmail, which was a convenience feature and continues to be with them, would require your private key. It was recommended you do not do that, and use the provided Java applet or mobile app. The person in question in those criminal proceedings used one of those convenience functions, if…

"It was recommended you do not do that, and use the provided Java applet" Which is equally insecure, as the company could easily insert a back door the next time you load the applet. Hushmail was and is snake oil.

I think Hushmail are pretty up front about being no protection if the person who wants access has a court order. I would not go so far as to say 'snake oil'.

From wikipedia: "The issue originally revolved around the use of the non-Java version of the Hush system. It performed the encrypt and decrypt steps on Hush's servers and then used SSL to transmit the data to the user. The data is available as cleartext during this small window; additionally the passphrase can be captured at this point. This facilitates the decryption of all stored messages and future messages using this passphrase."

"Hushmail has stated that the Java version is also vulnerable in that they may be compelled to deliver a compromised java applet to a user.[5][7]"

In [7] "Brian" working for hushmail responds to a wired journalist agreeing that the applet was an attack vector and Brian even points to a schneier.com article stating the same[2]. He did weasel around a bit about "viewing applet/HTML source" which he admits is no use for determining the validity of the applet as it is compiled.

[1] https://en.wikipedia.org/wiki/Hushmail#Compromises_to_email_...

[2] https://www.schneier.com/essay-191.html

[5] http://blog.wired.com/27bstroke6/2007/11/encrypted-e-mai.htm...

[7] http://web.archive.org/web/20071019225245/http://blog.wired....

Re: Lavabit abruptly shuts down

#565
post #478

I regret giving Lavabit my business and more so paying for several years up front. This is immensely disrespectful.

Jesus! The guy is being leaned on by the Government. This is his only option to maintain customer privacy. "disrespectful"? There aren't polite words to describe the contenpt I have for whiners like you.

Re: Lavabit abruptly shuts down

#566

Earlier quoted context omitted.

there has been infrastructure to read snail mail contents for 200 years. Doesn't matter, the US Gov isn't routinely reading snail mail because of politics. I think he's right, make it a political issues. Actually, more: make it political issue, encryption issue, hosting issue, social issue (denied nsa contracting recently based on Snowden), I mean total war - make their life as difficult as possible using all means p…

Mass reading of snail-mail has traditionally been a question of manpower. You don't just flip the switch on that without anybody noticing.

Doesn't really matter. To read a regular mail you just need so much more in legal terms compared to reading somebody's email that it's just not worth contemplating no matter what. It's not like with emails where after 6 months they automatically are open to the Government sniffing. Because of the political reasons it's not even worth contemplating -- look -- you need regular court order, not some BS whatever rubber-stamp.

Re: Lavabit abruptly shuts down

#567

In communism there was no progress exactly because of laws like this. Who wants to operate hosting business in the US now? Why not Asia? HK, Singapore? Or even New Zealand at this point. See how much business is lost. See how much Google, Yahoo, MS, Facebook are hurting now. That's true people will still use them, but not for business critical stuff. No way. In the name of catching a few idiots from a desert who try…

I'm sure some of the largest of the tech firms are getting something for their troubles.

Re: Lavabit abruptly shuts down

#568
post #155

Earlier quoted context omitted.

I don't blame the companies; they're about as much a victim of USgov as we are IMHO. That being said, if all the online-storage/cloud-server/email-providers/social-whatever companies in US start going out of business because nobody trusts them I strongly suspect something will have to change. It's just too bad we have to do a "scorched earth"[1] to bring about change. 1. http://en.wikipedia.org/wiki/Scorched_earth

This is where I disagree. I do blame companies like Google for not fighting this more. At the very least they make users aware that these laws exist, even if they cannot detail specifics related to their surveillance involvement.

Do you remember google asking for your telephone number? They knew what they were doing.

Re: Lavabit abruptly shuts down

#569

Can we get a list going of non-US alternatives of popular apps most of us use? Let's start with Dropbox. What's the alternative?

I'd suggest Owncloud for that, on a server running in your own home. Encrypted file system (LUKS), the works. Pretty much identical to Dropbox and just as stable, IMHO. Pricewise? You can buy an HP Microserver for about $300 that's capable of 12TB of storage on the top end (more if you get fancy with external arrays), whack it into a APC UPS for another $50, and just run it off your home internet connection. Hang a f…

afraid.org looks nice - thanks for sharing :)

Re: Lavabit abruptly shuts down

#570
post #245

This is infuriating, and the worst part is that a clear solution isn't in sight. Sure, we can fight this in the courts, and a few secret programs might get shut down, but operations will just continue under a different name. We can encrypt our data, move our services and data offshore, but that just paints a big target on our heads - doesn't actually address the fundamental issue. This is supposed to be a democracy,…

As developers perhaps the most effective thing we can do from a long-term perspective is baking strong cryptography in to all of the products we create, and opting for open source whenever possible. (After all, open source is the only way we can guarantee that the software we're using really doesn't snoop on us.) If crypto were easier to use and presented as a default, more regular people would wind up using it and w…

Open source unfortunately gives no such guarantee [1].

[1]. https://www.ece.cmu.edu/~ganger/712.fall02/papers/p761-thomp... (Reflections on trusting trust)

Post reply on HN