Live data from Hacker News

Lavabit abruptly shuts down

lavabit.com

651–660 of 671 posts

Re: Lavabit abruptly shuts down

#651

Earlier quoted context omitted.

Hold you in contempt for something you did years before the case was filed or the investigation even started? God, that's even worse than contempt of court for failing to say passwords under the fifth amendment. I'm pretty sure I have some truecrypt containers I've forgotten the passwords to, sure hope I never get arrested!

I think automatically breaking a gag order by a complicated mechanism is pretty contemptuous of someone trying to not get that information out? I am not saying they're not worthy of that contempt, merely that they don't care if they are, just if you're showing contempt for the process and violating the order

It's contemptuous of the court if I set up the mechanism because I was going to get such a gag letter.

But to say that a canary I set up a decade ago is contemptuous of a court filing made a month ago is ridiculous.

Re: Lavabit abruptly shuts down

#652

Earlier quoted context omitted.

Hold you in contempt for something you did years before the case was filed or the investigation even started? God, that's even worse than contempt of court for failing to say passwords under the fifth amendment. I'm pretty sure I have some truecrypt containers I've forgotten the passwords to, sure hope I never get arrested!

I think automatically breaking a gag order by a complicated mechanism is pretty contemptuous of someone trying to not get that information out? I am not saying they're not worthy of that contempt, merely that they don't care if they are, just if you're showing contempt for the process and violating the order

Laws and ethics are rarely synonymous though.

Re: Lavabit abruptly shuts down

#653
post #642

Earlier quoted context omitted.

That doesn't work as well if the culture has been inocculated. How does one do that? Well, I don't know if this is still done today, but when I was in 7th or 8th grade, they (school) drove us, by the busload, to visit a concentration camp. We were shown the lampshades and wallets made of human skin. The place to stand where inmates would be executed during what they thought were medical examinations. And so on and so…

I have to agree. I spent two days in Berlin this week and went to the Holocaust memorial, etc. I was impressed with the way these things are talked about with such openness - to make sure that this stuff never happens again. Also, I've traveled to several european countries and found Germans to be quite open minded regarding race, religion, etc. since I think the past has a lot to do with that. Happy that the german…

To be fair there are still lots of racist and intolerant people here. And nazis, though the antifa usually kick their asses.

But the tolerant and open minded strain is pretty dominant. Germany is 9% foreigners. Frankfurt is like 30%

Re: Lavabit abruptly shuts down

#654
post #445

Earlier quoted context omitted.

It's not just going to be hosting providers that are affected by this. It's going to lawyers, software engineers, sys admins, writers and graphic designers who are going to lose work/business from SAAS companies. Software is one of the few areas where the US economy is growing somewhat sustainably (as opposed to banking/gambling/housing speculation/medical expenses for elderly). The NSA and all those NSA contractors…

The nails are already in the coffin for US internet behemoths. Any non-NSA cooperating country has strong interests in keeping their search engines, social networks, and cloud software internal to their country. Google, Microsoft, and Facebook basically have had billions of dollars shaved off of their future market capitalization -- though I have not seen anyone say this yet. For everyone abroad who is technically ad…

Simply not true. There aren't enough people who care. Maybe 1% care. Everyone is going to keep using windows, facebook, and google. There are no nails in any coffin for any of these companies.

Re: Lavabit abruptly shuts down

#657
post #639
post #560

Earlier quoted context omitted.

I understand what you mean but I think the term '3rd world country' could be a bit discouraging to some of our American friends who might not have a clear picture about realities in our part of the world. For example I also live in a small EU country. By no means this is a 3rd world country - we have pretty strong IT industry (e.g. some globally successful antivirus companies etc.) and the country is certainly develo…

Are you czech by any chance ? I think it's a great place and completely understand why your people would be against government surveillance. The days of asking random people for IDs just to make sure they aren't spies still aren't forgotten there.

Yep. And thanks. And to be honest, I think that asking random people for IDs was the smallest thing. People from always-free countries do not realize how much authoritarian regimes damage society. It's not just that some people became victims of the regime. Maybe the worst thing (at least in my opinion) is that society in an authoritarian regime is set in such ways that the system rewards dishonesty and cowardice and the most unscrupulous people get to the top... and stay there even after the regime falls.

Re: Lavabit abruptly shuts down

#658
post #429

Earlier quoted context omitted.

Give us a try? It seems this is the default line and that the users never get to piss off the support people because they're never given the chance. Let us burn ourselves and then we can learn to use the stove. If we never understand the importance of that key we'll never get used to maintaining it properly. Quite clearly - is there any messaging service that allows users to end-to-end encrypt? That is not PGP? There…

Adium and Jabber both support OTR for IM, which is end-to-end encryption.

Since I can't edit this anymore, I'm replying to correct my above comment from "Jabber" to "Pidgin".

Re: Lavabit abruptly shuts down

#659

Earlier quoted context omitted.

I think automatically breaking a gag order by a complicated mechanism is pretty contemptuous of someone trying to not get that information out? I am not saying they're not worthy of that contempt, merely that they don't care if they are, just if you're showing contempt for the process and violating the order

It's contemptuous of the court if I set up the mechanism because I was going to get such a gag letter. But to say that a canary I set up a decade ago is contemptuous of a court filing made a month ago is ridiculous.

>But to say that a canary I set up a decade ago is contemptuous of a court filing made a month ago is ridiculous.

No it's not: You show contempt for the idea they could demand you silently turn over information. It's seething out of your posts here on HN even.

I don't think it's right they can do this, but I do think it's quite clearly preemptively raising a middle finger to the whole thing; it is "I cross my fingers behind my back so my swears don't count" type of stuff that judges don't accept and toss you in jail for.

You don't get to outthink and out maneuver this crap: You have to beat it in the system.

Re: Lavabit abruptly shuts down

#660
post #554

Earlier quoted context omitted.

White noise has distinct statistical properties that allow to mitigate it's effect on detection of meaningful signal. E.g. filtering white noise from audio stream is a very common operation. Sending packets to all contacts at random is a form of introducing white noise, vulnerable to signal processing techniques known and used from 1950s.

Your noise can be non-white. Your noise can favour some of your peers, some time of day, messages can be elaborately routed around in circles. You can even make clients download new message distribution patterns each day. Genetically enchanced patterns.

If your noise is algorithmic, and even worse, the algorithm is known (as would be the case of an open source project), it makes your protection fairly vulnerable.

E.g. in case of biasing the method towards time of day, the attacker likely can filter it out using fairly basic statistical methods. Generally any kind of pseudo-randomization would render the method vulnerable; at least to the caliber of mathematicians which work at NSA.

If there's messaging system's own statistical analyzer, that learns your communication patterns and adjusts false messaging to rectify that, it could work. However the other messaging clients have to play along, which makes it fairly challenging problem.

Post reply on HN