Earlier quoted context omitted.
You could choose to take a job where you are required to lie, but no-one can force you to take such a job.
The Military Selective Service Act disagrees with you.
Lavabit abruptly shuts down
661–670 of 671 posts
Re: Lavabit abruptly shuts down
#662Earlier quoted context omitted.
It's contemptuous of the court if I set up the mechanism because I was going to get such a gag letter. But to say that a canary I set up a decade ago is contemptuous of a court filing made a month ago is ridiculous.
>But to say that a canary I set up a decade ago is contemptuous of a court filing made a month ago is ridiculous. No it's not: You show contempt for the idea they could demand you silently turn over information. It's seething out of your posts here on HN even. I don't think it's right they can do this, but I do think it's quite clearly preemptively raising a middle finger to the whole thing; it is "I cross my fingers…
Re: Lavabit abruptly shuts down
#663Earlier quoted context omitted.
He could still just sell it to someone in another country. Neither the service nor his 10 years of work would be lost.
Depending on how bad the government wants the data, that's essentially just charging a high premium to get all the data instead of a specific user's data. If the purchasing party is less scrupulous, you've thwarted nothing. In extreme cases (or for smaller companies), the purchaser could even be a government front.
Re: Lavabit abruptly shuts down
#664For the unfamiliar: Lavabit was a webmail service, that (claimed to) encrypt emails in such a way that they literally did not have access to the content stored on their own servers. The linked email would lend some credence to those claims. It was originally designed in contrast to gmail scanning your email for targeted advertising, but my imperfect memory says that their system should also have been resilient to "we…
Edit: I was a PM on Exchange and Exchange Hosted Encryption for some time, so it looks like Lavabit tried to fight the government on whether they are required to release private keys. I've seen one other customer try to fight, and it was not pretty either. The US government in these cases are serious. Takeaway for fellow hackers: If you are building a system that stores user-generated data, prepare for the eventualit…
As long as you can't comply, I don't think there's an uncounterable risk in the US, since we don't have any key disclosure requirements (the exception being CALEA, which only applies to the PSTN; I'd skip CALEA for an interconnected VOIP system and fight them in the courts/media, personally). Presumably they could put other weird pressure on you like threatening to investigate your nanny's immigration status or whatever, but enh.
I still maintain that if you do things properly, you can operate safely in the US while resisting pressure from USG. You can't literally wipe your ass with an NSL in front of the agents, but if you don't have it, and can't get it, they're at worst a DoS. Forcing a provider to implement a huge new logging infrastructure would be an interesting 14A issue, and one could have a system where even that wouldn't recover customer keys.
IANAL of course.
Re: Lavabit abruptly shuts down
#665Earlier quoted context omitted.
"It was recommended you do not do that, and use the provided Java applet" Which is equally insecure, as the company could easily insert a back door the next time you load the applet. Hushmail was and is snake oil.
For sure, but can I fault idiots for inability to read the documentation and caveats? Maybe, but not really lest most on this site could not "do computers" professionally. Unfortunately, the trust problem you mention is pervasive. It was a signed applet IIRC, but we both requires you trust the original and modified applets from the developer. I am wishing someone released an auto-encrypting PGP service and client, op…
I kind of wish there were a (well armed) organization which did this for other projects.
Re: Lavabit abruptly shuts down
#666Earlier quoted context omitted.
There's StartCom (StartSSL) from Israel. Have you tried them? They even offer free SSL certs, by the way.
They are from Israel, a good friend of the US, and for free. What part of that does not scream 'run for the hills' exactly?
Re: Lavabit abruptly shuts down
#667Earlier quoted context omitted.
Aren't gag orders challengeable? I thought they were found unconstitutional. http://securitywatch.pcmag.com/privacy/309277-judge-says-fbi...
I think they were found unconstitutional when they were forcing people to not even tell their lawyers . You can tell your lawyer now, and you can fight the gag order in Court - but in secret. Until the court tells you can tell everyone about it, you can't.
Re: Lavabit abruptly shuts down
#668Earlier quoted context omitted.
Key exchange is still a huge issue. Sure, you can post a public key online, but I have no guarantee it is actually your key. How do I do business with somebody new? The core problem with widespread crypto use today is not encryption, it's trusted key exchange.
Put the fingerprint in your business cards? In fact, maybe we finally found a reasonable use for QR codes.
Re: Lavabit abruptly shuts down
#669Earlier quoted context omitted.
Agreed. The nails are in for the current system, but that is not The System, just one of many potential ones. If you are non-US citizen and your customers request a product similar to US product please do exactly as AJ007 says. It will help you, the world, and the US long term. I say this as US citizen and SW dev. Please take our jobs and customers! We don't deserve those customers if we can't protect them and their…
Caveat: If you are planning to follow the above advice, and you think your country will not enforce the wishes of the US government on such matters, check that assumption carefully before you bet your fortune and your life on it.
Re: Lavabit abruptly shuts down
#670Earlier quoted context omitted.
The nails are already in the coffin for US internet behemoths. Any non-NSA cooperating country has strong interests in keeping their search engines, social networks, and cloud software internal to their country. Google, Microsoft, and Facebook basically have had billions of dollars shaved off of their future market capitalization -- though I have not seen anyone say this yet. For everyone abroad who is technically ad…
Simply not true. There aren't enough people who care. Maybe 1% care. Everyone is going to keep using windows, facebook, and google. There are no nails in any coffin for any of these companies.
Likewise, this is also very bad news if you are a Chinese or Russian internet company and expect to become a dominant player in the US consumer web/digital/mobile market place.