Live data from Hacker News

Two Providers of Secure E-Mail Shut Down

bits.blogs.nytimes.com

61–70 of 72 posts

Re: Two Providers of Secure E-Mail Shut Down

#61
post #47

This is officially Iran level of government-busdiness interaction guys. US seems to have state religion now, that is State Security. Sin and get destroyed. Reminds me of USSR in that regard.

"State Security" as defined by a handful of war-mongers living in the past and bent upon visiting its ghosts on the present, and sadly, the future generation.

Related but I just checked the USPTO, and the trademark for "State Secrets" is available.

Re: Two Providers of Secure E-Mail Shut Down

#62
post #58
post #34

> Taken together, the closures signal that e-mails, even if they are encrypted, can be accessed by government authorities and that the only way to prevent turning over the data is to obliterate the servers that the data sits on. Can someone explain to me how this is possible? Or is this inaccurate?

I think it is inaccurate. The concerns of lavabit and silent circle seemed to be about unencrypted email.

Their concerns are not about unencrypted email, they refuse to install eavesdropping equipment in their server rack.

You can encrypt your email all you want but it's not encrypted in the space between your load balancer and your app server.

Re: Two Providers of Secure E-Mail Shut Down

#63

Earlier quoted context omitted.

so the nsa gets a list of IP addresses of mail servers that sent you mail, and sends a subpoena to each of those providers instead.

If they want to get you they're gonna get you. The point is that takes a lot more work than the analyst sitting at his desk typing in friggin Google searches on your Gmail.

And the odds you'll know it has happened is much higher.

Re: Two Providers of Secure E-Mail Shut Down

#64
post #55
post #51

Earlier quoted context omitted.

People 'suggest' the government is going to kill people all the time, it doesn't make it true. That is the world you live in. You do not live in a James Bond film. This guy didn't risk his life. His livelihood perhaps, but not his life.

he risked his life in in the way that he may be placed in jail for a while. I don't think anyone is suggesting that he may be killed over a destroyed server.

I would probably argue that being imprisoned for an undetermined time is fairly comparable to "losing your life" for most people.

Re: Two Providers of Secure E-Mail Shut Down

#65
post #12

How did Silent Circle become a "major secure email service provider?" Lavabit launched in 2004. Silent Circle launched "Silent Mail" four months ago. I don't see how SC's action belongs in the same sentence as what Lavabit was forced to do.

Lavabit was a much more "under the radar" provider. Silent circle has gained huge traction since they started and provide secure Phone, SMS and mail services. They may not be "equal" but silent circle is certainly more of a high profile target.

Re: Two Providers of Secure E-Mail Shut Down

#66
post #58

Earlier quoted context omitted.

I think it is inaccurate. The concerns of lavabit and silent circle seemed to be about unencrypted email.

Their concerns are not about unencrypted email, they refuse to install eavesdropping equipment in their server rack. You can encrypt your email all you want but it's not encrypted in the space between your load balancer and your app server.

I think in general "encrypted email" refers to end-to-end encrypted email which of course does not have that problem.

Re: Two Providers of Secure E-Mail Shut Down

#67

This is officially Iran level of government-busdiness interaction guys. US seems to have state religion now, that is State Security. Sin and get destroyed. Reminds me of USSR in that regard.

So long as they are doing this to target legitimate national security threats, it isn't. There is no filter on free speech nor any hint that one might be coming. Right now it's just overzealous prosecution that is nipping at the 4th amendment. The 1st amendment is secure for now.

Re: Two Providers of Secure E-Mail Shut Down

#68
post #34

> Taken together, the closures signal that e-mails, even if they are encrypted, can be accessed by government authorities and that the only way to prevent turning over the data is to obliterate the servers that the data sits on. Can someone explain to me how this is possible? Or is this inaccurate?

That's probably inaccurate. It is likely that the problem Lavabit faced was being required to transmit malware to their customers.

Re: Two Providers of Secure E-Mail Shut Down

#69
post #25
post #17

It seems like there's an opportunity for a PGP mail forwarder, a service that encrypts all incoming mail and then forwards it without saving anything in the process. I'd pay bitcoins for that.

This sounds totally useless as a 3rd party service due to how obvious a target it would be but a simple encrypting proxy or MTA config would be pretty useful for self hosted setups.

It'd be much less of a target than any encrypted hosted mail since it wouldn't store anything, just be a pass-through filter.

Yeah, ideally we would all have our own encrypted, self hosted setup, but that's just not realistic.

Re: Two Providers of Secure E-Mail Shut Down

#70
post #12

How did Silent Circle become a "major secure email service provider?" Lavabit launched in 2004. Silent Circle launched "Silent Mail" four months ago. I don't see how SC's action belongs in the same sentence as what Lavabit was forced to do.

Lavabit was a much more "under the radar" provider. Silent circle has gained huge traction since they started and provide secure Phone, SMS and mail services. They may not be "equal" but silent circle is certainly more of a high profile target.

What evidence is there of the huge traction? Have they announced actual numbers?
Post reply on HN