Live data from Hacker News

How Lavabit Melted Down

newyorker.com

41–50 of 177 posts

Re: How Lavabit Melted Down

#41
post #40
post #37

Earlier quoted context omitted.

> A public company would not have been able to make this play, Isnt it funny to hear that a public company would not have been able to do something when it is about something good for its consumers and ultimately its country and citizens, but when it is something extremely bad like compliance, obedience and evilness then they suddenly can and are free to do it. There is nothing stopping Google, Facebook or Microsoft…

> There is nothing stopping Google, Facebook or Microsoft to act as Lavabit did. Nothing at all except for their own cowardice, malicious intents and disregard for laws and their costumers. Try being CEO of Google, Facebook, or Microsoft, and suddenly deciding to close the entire business, and see how far you get before being removed.

There are some causes that are worth being removed as CEO for. Lavabit founder finally is allowed to speak about this.

It is enough if you threaten to shut down the business to make it known to the G-men that you wont play (the totalitarian) ball. We stopped SOPA/PIPA just with a partial blackout.

But these companies didnt make a squeek. They are accomplices.

Re: How Lavabit Melted Down

#42
post #31

Is anyone else thinking that their systems should include a self-destruct button? (for LavaBit I'd imagine a process that e-mailed each user the SSL key used to encrypt their mailbox, then deleted the key from the system. A user could still decrypt their mailbox by downloading it and using the key).

The problem is that services like Lavabit want to do something that is technically not possible: give you access to your encrypted mail from any computer i.e. the convenience of webmail. If I can just download a key and keep it on my computer, why would I not just generate the key on my computer by e.g. using PGP or S/MIME?

No ... I meant a "red" button that could be used just prior to wiping the servers clean. Your point is completely valid while the service is running.

Re: How Lavabit Melted Down

#43
post #2

I am blown away by the bravery, I know I'd never be so bold. Also confused why he didn't end up in prison on mysterious "pervert" charges out of the blue or even dead. And don't lecture me that is far fetched after this past year.

It didn't happen because that sort of thing doesn't generally happen.

Simply raising the specter of 'this past year' doesn't prove some vast conspiracy on the part of the government (or maybe it's the puppetmasters who control the 'real' government?).

Re: How Lavabit Melted Down

#44
post #21

Earlier quoted context omitted.

It has always been illegal to not comply with search warrants. Why would search warrants for digital data be any different?

It's also always been legal to say "sorry, we never record any of that information". You can get a warrant asking a bartender to provide you with names, addresses, and arrival and departure times, and transcripts of every conversation of every patron of his bar, and he can stand up in court and say "sorry, I don't have that information, and I'm not prepared to start collecting it.". Would you be happy for the FBI to…

>You can get a warrant asking a bartender to provide you with names, addresses, and arrival and departure times, and transcripts of every conversation of every patron of his bar

No, you can't; the courts don't issue warrants like that. They'd issue a warrant for that information for one particular patron whom they already had reasonable suspicion of.

If the FBI have a warrant to put a bug on one regular's table, that doesn't seem unreasonable. If the bartender's carefully built the bar so that you can hear every conversation from every table and so the only way you can place a bug is one that would also record everyone else's conversations... yeah, I'd say that's unfortunate (and pretty poor design on the owner's part), but the FBI has the right to place the bug they've got the warrant for, and if there's really no way to do that without it picking up other conversations then too bad.

Re: How Lavabit Melted Down

#45
post #7

There is a huge disconnect between the "justice" system and technology which needs to end. You've seen it before if you're in IT, that glazed eyes look when explaining why their Word document is missing… Anyone with judicial experience know if judges have trusted advisory panels that can help wrap their heads around technology to better rule on cases such as this?

Why would technology be any different from anything else? The prosecution and defense are free to call on expert witnesses to explain SSL and heart surgery to the judge and jury.

Re: How Lavabit Melted Down

#46
post #37

Earlier quoted context omitted.

We really need more companies (and those in control of those companies) that stand up for their customers this same way. A public company would not have been able to make this play, so keep that in mind when you are making decisions about where to put your data.

> A public company would not have been able to make this play, Isnt it funny to hear that a public company would not have been able to do something when it is about something good for its consumers and ultimately its country and citizens, but when it is something extremely bad like compliance, obedience and evilness then they suddenly can and are free to do it. There is nothing stopping Google, Facebook or Microsoft…

"There is nothing stopping Google, Facebook or Microsoft to act as Lavabit did. Nothing at all except for their own cowardice, malicious intents and disregard for laws and their customers."

Emphasis re-arranged by me. May I remind you that Lavabit was shut down in reaction to actions taken by law enforcement, doing something that is almost certainly actually legal? "Regard for the law" here would seem to entail doing what they want. You appear to be simultaneously criticizing public companies for disregarding the law and not disregarding the law.

(I object to its legality, but that does not change its legality.)

Re: How Lavabit Melted Down

#47
post #33

Earlier quoted context omitted.

> it's not [the government] who designed lavabit such that it was impossible to execute this without obtaining access to every other user. That's true, but they're still essentially implying that services which are explicitly designed to omit backdoor capabilities for the government to spy on you -- that is, services offering actual cryptographically guaranteed privacy, not just "no one has looked yet, and if they di…

CALEA requires that all telephone companies (and now mobile phone and cable companies) provide a means of "tapping" a phone line. To my knowledge, there's nothing similar that says a data service has to provide the ability to retrieve unencrypted data.

What they required was more like the means to tap all the phone lines simultaneously.

Re: How Lavabit Melted Down

#48
post #18

Earlier quoted context omitted.

We really need more companies (and those in control of those companies) that stand up for their customers this same way. A public company would not have been able to make this play, so keep that in mind when you are making decisions about where to put your data.

I think Qwest Communications was a public company when they refused to comply with the NSA.

Didn't they die after that due to the government canceling contracts with them?

Re: How Lavabit Melted Down

#49
post #7

There is a huge disconnect between the "justice" system and technology which needs to end. You've seen it before if you're in IT, that glazed eyes look when explaining why their Word document is missing… Anyone with judicial experience know if judges have trusted advisory panels that can help wrap their heads around technology to better rule on cases such as this?

Do you really think IT is that much harder than say medicine or the nuances of structural engineering on any of the myriad of other technical areas that no doubt show up in courtrooms every single day?

Re: How Lavabit Melted Down

#50
post #5
post #3

Earlier quoted context omitted.

Well, if they killed him, they probably wouldn't be able to get the keys. And they probably had to keep the bigger "punishment", imprisonment, looming over his head in case he reveals confidential information about the case.

It wouldn't surprise me if they had some sort of back door with Verisign or other certificate companies for this.

CA like Verisign don't have the key though, this misconception is too common. If you're doing it right the CA is just signing a cert you've generated, they never see the key.
Post reply on HN