Earlier quoted context omitted.
"It was the best current technology could offer" Sure, if we ignore the existence of things like PGP, S/MIME, smart cards, and the dozens of other ways we can have secure email without relying on some trusted third party like this. "this technology was not meant to deal with the oppressive government that can compel any company to reveal any information" Then it was not meant to deal with the evil hacker who takes co…
How PGP or S/MIME would help you if any provider could be required to turn over all the traffic it gets, unencrypted? The only way you could securely communicate is peer-to-peer with the trusted party, but the email doesn't work this way. Unless you always send mail directly to your target's SMTP server which is hosted by the recipient himself (which kind of defies the whole idea of having email as a service and turn…
This is a strawman, because Lavabit never did anything to protect headers. What you are missing is that Lavabit could respond to a demand for plaintext, if Ladar were willing to do so; on the other hand, Google cannot give anyone access to the plaintexts of PGP encrypted messages that I send through their servers because of technical barriers. That is the point of doing your encryption locally, and that is why security and privacy are not a service.
"Indeed, it is not. If the hacker gets full control of your mailserver, at least your envelope information is completely compromised."
Except that with Lavabit, an attacker could also get all your message bodies.
"Security depended on adversary not having full access to the Lavabit servers, not on Ladar's "whim"."
Let's put it this way: if you were involved in a lawsuit against Ladar, would you trust your communications with your lawyer to Lavabit? Of course not, because Ladar could have modified the code at any time and without alerting his users at all to read any plaintext that he wanted to read. If he had been willing to cooperate with the government, he could have and nobody would have a clue.
"Assuming your adversary doesn't have full access to your service is kind of a precondition of using the service as means of security."
In other words, security is not something you can get as a service. The entire model is fundamentally and fatally broken.
"That's like using lock is assuming the adversary does not have the key, if he does, the lock is useless as a security measure"
No, it is like storing your key with the bartender at your favorite night club and assuming that he will not allow your adversaries to use it.
"As soon as Lavabit became essentially useless for the purpose it was created, it was shut down."
It was shut down because Ladar chose to shut it down rather than capitulate. He could have chosen to keep it going while the government eavesdropped on it instead. That means that, as I said, security boiled down to Ladar and his principles. That is why PGP and S/MIME provide you with better security: mathematics are not subject to the choices that human beings make, and with PGP, S/MIME, etc. your security is a matter of mathematics.