Earlier quoted context omitted.
It wouldn't be resilient to interception of mail going to and coming from lavabit however, since email is essentially a plaintext public protocol.
What? I don't think this is true at all. Plaintext data, email or not, can be protected with robust encryption. Your end security is the main consideration, but that has nothing to do with the protocol or content, really.
Lavabit abruptly shuts down
111–120 of 671 posts
Re: Lavabit abruptly shuts down
#112For the unfamiliar: Lavabit was a webmail service, that (claimed to) encrypt emails in such a way that they literally did not have access to the content stored on their own servers. The linked email would lend some credence to those claims. It was originally designed in contrast to gmail scanning your email for targeted advertising, but my imperfect memory says that their system should also have been resilient to "we…
Hushmail is a similar service. There's been some speculation that authorities could compel the owners to perform a sort of internal phishing scam to get the passwords.
http://www.wired.com/threatlevel/2007/11/encrypted-e-mai/
> a federal prosecution of alleged steroid dealers reveals the Canadian company turned over 12 CDs worth of e-mails from three Hushmail accounts, following a court order obtained through a mutual assistance treaty between the U.S. and Canada.
Re: Lavabit abruptly shuts down
#113I've had a lavabit email as one of my main emails for years (close to when they first started) and this is a major inconvenience. I'm not sure I'll be able to change the email address associated with a lot of my various accounts now that they're offline.
Re: Lavabit abruptly shuts down
#114Earlier quoted context omitted.
I'd love to believe that the authorities in Germany are not also tapping lines like France or the UK. Do we have any proof that is the case? I agree this has made me think twice about hosting in the us, but also about crossing national boundaries full stop without encrypting traffic.
Encrypting is a given - obviously you'd want to only be using Saas services in Germany etc that are fully encrypted. The problem in using USA services is that even if everything is fully encrypted, the USA can and will send goons around to take your data. Encryption is simply useless when dealing with a company in the USA who is forced to hand over the keys and whose data-centers can be legally entered and modified b…
Re: Lavabit abruptly shuts down
#115Re: Lavabit abruptly shuts down
#116Earlier quoted context omitted.
Former head, and he was talking about the extremists who might attack Google or Microsoft, not lobbying groups like the EFF.
He's using the same logic that's used against extremists: if they're disenfranchised then they're a threat, and if we're disenfranchising them then they're a threat to us. Why does the military have indefinite detention? It's simple: as a matter of policy they torture suspects, but since they were tortured then it stands to reason that they will become radicalized upon release, so they're held indefinitely. Let me sp…
His choice to call them terrorists isn't something I'm going to really defend, but if it makes you feel any better, he hasn't been in charge of anything for 4 years.
Re: Lavabit abruptly shuts down
#117I've had a lavabit email as one of my main emails for years (close to when they first started) and this is a major inconvenience. I'm not sure I'll be able to change the email address associated with a lot of my various accounts now that they're offline.
Re: Lavabit abruptly shuts down
#118Takeaway: > "This experience has taught me one very important lesson: without congressional action or a strong judicial precedent, I would _strongly_ recommend against anyone trusting their private data to a company with physical ties to the United States." It's kind of fitting. The nation that spawned the internet is the nation that's killing the internet biz on its own turf.
Re: Lavabit abruptly shuts down
#119Are there any countries, anywhere, where a person can store data outside the reach of the US government's illegal overreach? Any countries friendly to the US are right out. They can tap the lines, but there are ways around that. I just want to be able to park data where some twit with a piece of paper that says "NSA" on it can't get it retrieved or deleted. Any suggestions?
But you have to get the data there. It most certainly isn't protected in transit.
Re: Lavabit abruptly shuts down
#120Earlier quoted context omitted.
I'd love to believe that the authorities in Germany are not also tapping lines like France or the UK. Do we have any proof that is the case? I agree this has made me think twice about hosting in the us, but also about crossing national boundaries full stop without encrypting traffic.
The difference is that the authorities in Germany don't have the legal framework to force someone to do this and threaten them to stay silent.