Live data from Hacker News

Lavabit abruptly shuts down

lavabit.com

661–670 of 671 posts

Re: Lavabit abruptly shuts down

#661

Earlier quoted context omitted.

You could choose to take a job where you are required to lie, but no-one can force you to take such a job.

The Military Selective Service Act disagrees with you.

You couldn't be conscripted in private and compelled to lie.

Re: Lavabit abruptly shuts down

#662

Earlier quoted context omitted.

It's contemptuous of the court if I set up the mechanism because I was going to get such a gag letter. But to say that a canary I set up a decade ago is contemptuous of a court filing made a month ago is ridiculous.

>But to say that a canary I set up a decade ago is contemptuous of a court filing made a month ago is ridiculous. No it's not: You show contempt for the idea they could demand you silently turn over information. It's seething out of your posts here on HN even. I don't think it's right they can do this, but I do think it's quite clearly preemptively raising a middle finger to the whole thing; it is "I cross my fingers…

Right, it shows extreme past contempt for the very idea that it could be possible, but this is in no way contempt toward the specific judge, nor must there still be contempt at this point.

Re: Lavabit abruptly shuts down

#663

Earlier quoted context omitted.

He could still just sell it to someone in another country. Neither the service nor his 10 years of work would be lost.

Depending on how bad the government wants the data, that's essentially just charging a high premium to get all the data instead of a specific user's data. If the purchasing party is less scrupulous, you've thwarted nothing. In extreme cases (or for smaller companies), the purchaser could even be a government front.

I'm pretty sure there are known entities offshore you could sell to who are unlikely to be government fronts. Imagine selling to someone Wikileaks affiliated...

Re: Lavabit abruptly shuts down

#664
post #350
post #15

For the unfamiliar: Lavabit was a webmail service, that (claimed to) encrypt emails in such a way that they literally did not have access to the content stored on their own servers. The linked email would lend some credence to those claims. It was originally designed in contrast to gmail scanning your email for targeted advertising, but my imperfect memory says that their system should also have been resilient to "we…

Edit: I was a PM on Exchange and Exchange Hosted Encryption for some time, so it looks like Lavabit tried to fight the government on whether they are required to release private keys. I've seen one other customer try to fight, and it was not pretty either. The US government in these cases are serious. Takeaway for fellow hackers: If you are building a system that stores user-generated data, prepare for the eventualit…

I think the worst they can realistically do is 1) threaten contempt if you can comply but don't and 2) threaten to disrupt your business operations by seizing servers. There are gag orders on certain legal requests, but you don't have to talk about it to not comply (if you can't comply).

As long as you can't comply, I don't think there's an uncounterable risk in the US, since we don't have any key disclosure requirements (the exception being CALEA, which only applies to the PSTN; I'd skip CALEA for an interconnected VOIP system and fight them in the courts/media, personally). Presumably they could put other weird pressure on you like threatening to investigate your nanny's immigration status or whatever, but enh.

I still maintain that if you do things properly, you can operate safely in the US while resisting pressure from USG. You can't literally wipe your ass with an NSL in front of the agents, but if you don't have it, and can't get it, they're at worst a DoS. Forcing a provider to implement a huge new logging infrastructure would be an interesting 14A issue, and one could have a system where even that wouldn't recover customer keys.

IANAL of course.

Re: Lavabit abruptly shuts down

#665
post #376

Earlier quoted context omitted.

"It was recommended you do not do that, and use the provided Java applet" Which is equally insecure, as the company could easily insert a back door the next time you load the applet. Hushmail was and is snake oil.

For sure, but can I fault idiots for inability to read the documentation and caveats? Maybe, but not really lest most on this site could not "do computers" professionally. Unfortunately, the trust problem you mention is pervasive. It was a signed applet IIRC, but we both requires you trust the original and modified applets from the developer. I am wishing someone released an auto-encrypting PGP service and client, op…

The correct way to do a signed applet or signed extension is to give the signing key to a third party who has responsibility for auditing it, or at least being "out of the subpoena chain" so when bad stuff happens, they suddenly stop signing new versions.

I kind of wish there were a (well armed) organization which did this for other projects.

Re: Lavabit abruptly shuts down

#666
post #545
post #431

Earlier quoted context omitted.

There's StartCom (StartSSL) from Israel. Have you tried them? They even offer free SSL certs, by the way.

They are from Israel, a good friend of the US, and for free. What part of that does not scream 'run for the hills' exactly?

Lulzily, a browser trusted CA can actually fuck a customer of that CA slightly less than a non-customer, since you'd at least be vaguely aware of multiple certs issued for the same site from the same CA with different keys (maybe). No one would know if Iran were using a pet CA to go after specific users going to sites which normally used a cert from another CA.

Re: Lavabit abruptly shuts down

#667
post #544

Earlier quoted context omitted.

Aren't gag orders challengeable? I thought they were found unconstitutional. http://securitywatch.pcmag.com/privacy/309277-judge-says-fbi...

I think they were found unconstitutional when they were forcing people to not even tell their lawyers . You can tell your lawyer now, and you can fight the gag order in Court - but in secret. Until the court tells you can tell everyone about it, you can't.

I'm curious exactly what the legal sanction is for telling the world/press.

Re: Lavabit abruptly shuts down

#668

Earlier quoted context omitted.

Key exchange is still a huge issue. Sure, you can post a public key online, but I have no guarantee it is actually your key. How do I do business with somebody new? The core problem with widespread crypto use today is not encryption, it's trusted key exchange.

Put the fingerprint in your business cards? In fact, maybe we finally found a reasonable use for QR codes.

Fingerprint in hex at the bottom of the business card is something I've done for the past 15 years -- pretty much the only reason I even bother with business cards these days.

Re: Lavabit abruptly shuts down

#669

Earlier quoted context omitted.

Agreed. The nails are in for the current system, but that is not The System, just one of many potential ones. If you are non-US citizen and your customers request a product similar to US product please do exactly as AJ007 says. It will help you, the world, and the US long term. I say this as US citizen and SW dev. Please take our jobs and customers! We don't deserve those customers if we can't protect them and their…

Caveat: If you are planning to follow the above advice, and you think your country will not enforce the wishes of the US government on such matters, check that assumption carefully before you bet your fortune and your life on it.

Thus the caveat I added in the original comment: unless your country is complicit.

Re: Lavabit abruptly shuts down

#670
post #445

Earlier quoted context omitted.

The nails are already in the coffin for US internet behemoths. Any non-NSA cooperating country has strong interests in keeping their search engines, social networks, and cloud software internal to their country. Google, Microsoft, and Facebook basically have had billions of dollars shaved off of their future market capitalization -- though I have not seen anyone say this yet. For everyone abroad who is technically ad…

Simply not true. There aren't enough people who care. Maybe 1% care. Everyone is going to keep using windows, facebook, and google. There are no nails in any coffin for any of these companies.

It is a major national security issue to any country to have foreign countries spying on them. The only controversy in the US is that the NSA is spying on American citizens in America. Any and all communication by foreigners at home and abroad is fair game. There is a reason why Google & Facebook are not market leaders in either China & Russia -- vkontakte, baidu, yandex, etc.

Likewise, this is also very bad news if you are a Chinese or Russian internet company and expect to become a dominant player in the US consumer web/digital/mobile market place.

Post reply on HN