Live data from Hacker News

What Exactly Did The US Government Ask Lavabit to Do?

xato.net

11–20 of 46 posts

Re: What Exactly Did The US Government Ask Lavabit to Do?

#11
post #6

Are there currently any alternatives, in terms of secure email providers? I never even knew it was a thing before the lavabit fiasco.

There are no providers who can provide full protection from a court order. The only solution is to encrypt on the client side using PGP or S/MIME and make everyone you communicate with do the same. But that means you can only login to your email from computers where your private certificate is installed. It also means no more webmail and no more search capabilities.

Re: What Exactly Did The US Government Ask Lavabit to Do?

#12
post #6

Are there currently any alternatives, in terms of secure email providers? I never even knew it was a thing before the lavabit fiasco.

This gets asked a lot currently. The sentiment seems to be that email is doomed from a security viewpoint. You'll be leaking metadata no matter what. Even if your email provider was somehow secure, you have no way of knowing if the person (and their provider) you are communicating with is secure. If it's not (which is very likely) then all your efforts to secure your end are almost for nothing.

So yeah, my suggestion currently is to acknowledge the level of secrecy (or rather lack of) available with your email setup and use it accordingly.

Re: What Exactly Did The US Government Ask Lavabit to Do?

#13
post #6

Are there currently any alternatives, in terms of secure email providers? I never even knew it was a thing before the lavabit fiasco.

Could you trust any that remain operating, after the Lavabit fiasco?

One clue is a statement Levison made is that it's not just what they asked him to do, it's also what he knows that would change our perspective of email:

“If you knew what I know about e-mail, you might not use it either.”

Re: What Exactly Did The US Government Ask Lavabit to Do?

#14
post #6

Are there currently any alternatives, in terms of secure email providers? I never even knew it was a thing before the lavabit fiasco.

Lavabit's closure highlights the fact that third-party email providers cannot be trusted to keep your email private.

Even running your own mailserver (on a computer in your home, for example) won't save you from dragnet NSA surveillance or targeted attacks, but at least you'll know if the government sends you a National Security Letter or obtains a FISA court order for your email.

Re: What Exactly Did The US Government Ask Lavabit to Do?

#15
This article seems to speculate on things that are not necessarily true. It's possible that the government simply told him that he had to be able to supply information arbitrarily on demand without an explicit warrant. This does not mean that they required him to install their own software on his machines.

Of course, one certainly still argue that this a line that the Government should not cross - I'd wholeheartedly agree with that. However, statements such as “We’ve had a couple of dozen court orders served to us over the past 10 years, but they’ve never crossed the line,” do not imply that the government required him to install software or otherwise compromise his security in a way that he was not already able to do.

Re: What Exactly Did The US Government Ask Lavabit to Do?

#16
post #6

Are there currently any alternatives, in terms of secure email providers? I never even knew it was a thing before the lavabit fiasco.

Could you trust any that remain operating, after the Lavabit fiasco?

Many people seem to forget that there are still countries where US laws are not in effect.

Even more interesting is the fact that even Lavabit's founder seemed to have overlooked this fact, and instead of relocating his servers and all the user data to Iceland, Norway or New Zealand, he chose to shut it down for good.

Why?

Re: What Exactly Did The US Government Ask Lavabit to Do?

#17
post #8
post #5

A device or piece of software designed to sniff the mail server to mail server connections would also be an option for broad based surveillance. Only a handful of mail providers (like Google) have the option to encrypt traffic server to server. Most mail servers transmit messages in the clear to each other and only encrypt the server to client side.

> Only a handful of mail providers (like Google) have the option to encrypt traffic server to server. SSL/TLS is available for everyone. > Most mail servers transmit messages in the clear to each other and only encrypt the server to client side. I hear this again and again, but I can't really find any data that confirms this claim one way or another. Anyone on HN running their own mailserver wanting to comment on how…

The entire email transation between a sender and a recipient usually looks like this:

Sending Client [--A---> Sender SMTP Server [--B---> Recipient SMTP Server [--C--> Recipient IMAP/POP server Connections A and D are easily possible to encrypt, provided your provider provides SSL/TLS on their SMTP and IMAP/POP servers. Most usually do. Connection C is usually local to a single machine, or for large email providers will go over an intranet of some kind.

What is at issue is connection B, which goes over the public internet. That is almost always in clear text, as most of this infrastructure was designed 30 years ago and hasn't evolved much since then. If you are sending email within a single provider (e.g. sender@gmail.com to recipient@gmail.com), such delivery can be trivially encrypted.

Re: What Exactly Did The US Government Ask Lavabit to Do?

#18
post #16

Earlier quoted context omitted.

Could you trust any that remain operating, after the Lavabit fiasco?

Many people seem to forget that there are still countries where US laws are not in effect. Even more interesting is the fact that even Lavabit's founder seemed to have overlooked this fact, and instead of relocating his servers and all the user data to Iceland, Norway or New Zealand, he chose to shut it down for good. Why?

Because if he got a NSL requesting a backdoor on his servers, then it doesn't matter where the servers are located. What matters where he personally and his company are located. And you can ask Snowden how fun it is to be persona non grata.

Re: What Exactly Did The US Government Ask Lavabit to Do?

#19
post #15

This article seems to speculate on things that are not necessarily true. It's possible that the government simply told him that he had to be able to supply information arbitrarily on demand without an explicit warrant. This does not mean that they required him to install their own software on his machines. Of course, one certainly still argue that this a line that the Government should not cross - I'd wholeheartedly…

That's actually the whole point, in the past he complied with warrants because there wasn't much he could supply in the first place. Yes there is a lot of reading between the lines here, but there was a clear line they crossed. In other words, he would no longer be able to just turn over a bunch of encrypted emails, this was a full compromise of the security he had in place.

If you look at the quotes he made, he strongly hints that this affects all his users, that they want to collect data for later review, and that they would have the ability to decrypt any emails they wanted. Yes, there is a lot of speculation going on here, but it is based on facts--what they technically would be able to do based on how Lavabit worked.

Edit: this wasn't just some casual speculation, I did quite a bit of research on this and carefully reviewed every statement he has given to the press. I carefully analyzed their infrastructure and encryption techniques. I'm fairly confident with my conclusions.

Re: What Exactly Did The US Government Ask Lavabit to Do?

#20
post #16

Earlier quoted context omitted.

Could you trust any that remain operating, after the Lavabit fiasco?

Many people seem to forget that there are still countries where US laws are not in effect. Even more interesting is the fact that even Lavabit's founder seemed to have overlooked this fact, and instead of relocating his servers and all the user data to Iceland, Norway or New Zealand, he chose to shut it down for good. Why?

Perhaps we had family, friends and his entire life in America, and didn't want to uproot it all to move his service overseas?
Post reply on HN