Live data from Hacker News

Lavabit Reloaded

lavabit.com

171–180 of 240 posts

Re: Lavabit Reloaded

#171

Earlier quoted context omitted.

So the employees of their "support centers in [California]"[0] can't be blackmailed and gagged? Or do they not have access to the systems? [0] https://protonmail.com/about

They can be blackmailed but can't be gagged as any request for a person's data (including access to it) from a Swiss company MUST go through Swiss court. And even gag orders can't compel someone to break the law. Same situation as three letter agencies requesting EU data from Microsofts' datacenter in Ireland, which whilst it is an American company (and thus they are obliged to deliver by law) is illegal under EU and…

Do you think that really matters ?

Re: Lavabit Reloaded

#172
post #170
post #151

Earlier quoted context omitted.

Are you saying he didn't use Lavabit and Cryptocat?

I think nyolfen probably meant to start their comment with "yes and". Maybe you should try some meditation or exercise to help you relax.

[deleted]

Re: Lavabit Reloaded

#173
post #170
post #151

Earlier quoted context omitted.

Are you saying he didn't use Lavabit and Cryptocat?

I think nyolfen probably meant to start their comment with "yes and". Maybe you should try some meditation or exercise to help you relax.

[deleted]

Re: Lavabit Reloaded

#174

Earlier quoted context omitted.

So the employees of their "support centers in [California]"[0] can't be blackmailed and gagged? Or do they not have access to the systems? [0] https://protonmail.com/about

They can be blackmailed but can't be gagged as any request for a person's data (including access to it) from a Swiss company MUST go through Swiss court. And even gag orders can't compel someone to break the law. Same situation as three letter agencies requesting EU data from Microsofts' datacenter in Ireland, which whilst it is an American company (and thus they are obliged to deliver by law) is illegal under EU and…

You seem to have a lot of faith in the law and legal process, and assume everyone else does.

Laws are a high latency side-chain of authority; a guide perhaps; and for some a business opportunity.

And then we have Organised Crime, moles, plants; informants, sympathesiers, casual snitches, quadruple agents, the desperate, and machine learning eating meta-data for breakfast.

If you've got something to hide "it's not legal for support staff to [whatever]" is most definitely not a security measure.

Re: Lavabit Reloaded

#175
post #111

Sensible choices in a nutshell: If you live in a 5-eyes nation, don't use or buy services hosted or operated from a 5 eyes nation. If you don't live in a 5 eyes nation, only use services hosted and operated from Iceland or Switzerland.( Nation states are the #1 threat, and your own nation is always the most dangerous one. )

Schweiz is in the EU. We are subject to its data-retention laws. Consider Norway.

So many ignorant people talking here...

Re: Lavabit Reloaded

#176

If you NEED encryption, don't use email. From: https://blog.fastmail.com/2016/12/10/why-we-dont-offer-pgp/ What's the tradeoff? If the server doesn't have access to the content of emails, then it reverts to a featureless blob store: Search isn't possible Previews can't be calculated If you lose your private key, we can't recover your email Spam checking on content isn't possible To access mail on multiple devices, th…

>Spam checking on content isn't possible How does encrypted spam work? Spammers encrypt message with your public key?

At the moment, encrypted spam doesn't exist. But only because there aren't enough people using encryption to make it worthwhile for the spammers to invest time doing it.

Theoretically, a spammer could scan the public keyservers for email addresses and public PGP keys and then send encrypted spam to all of those people. If ever a well targeted spam mailshot was sent, that would be it. But would you really want to get on the bad side of thousands of tech nerds?

Re: Lavabit Reloaded

#177

Earlier quoted context omitted.

> The server stores an encrypted index, and the client walks it (requesting parts as needed). It's going to little slower, and a lot more complex but it's doable. Going on a tangent, but do you know of any services that offer such a thing?

https://cryptag.org

That doesn't seem to have any email capabilities...

Re: Lavabit Reloaded

#178

Earlier quoted context omitted.

They can be blackmailed but can't be gagged as any request for a person's data (including access to it) from a Swiss company MUST go through Swiss court. And even gag orders can't compel someone to break the law. Same situation as three letter agencies requesting EU data from Microsofts' datacenter in Ireland, which whilst it is an American company (and thus they are obliged to deliver by law) is illegal under EU and…

You seem to have a lot of faith in the law and legal process, and assume everyone else does. Laws are a high latency side-chain of authority; a guide perhaps; and for some a business opportunity. And then we have Organised Crime, moles, plants; informants, sympathesiers, casual snitches, quadruple agents, the desperate, and machine learning eating meta-data for breakfast. If you've got something to hide "it's not leg…

It has kept Microsoft from sharing its EU data with American agencies so far.. and considering Microsoft has been under the microscope (haha) since it's EU antitrust suit I don't think they could pass the data without some serious ramifications. As far as ProtonMail goes.. well they certainly could force the support employees somehow, but if that ever gets out there would again be serious ramifications. Plus, why do you think the US Enterprise IT services/hardware industry took a serious hit when all the NSA leaks happened? What do you think will happen if it gets out that the US is even forcing foreign companies to obey to US law? I'm not counting on the NSA to behave - I'm counting on America as a whole to be greedy and put business above enforcement.

Re: Lavabit Reloaded

#179

Earlier quoted context omitted.

They can be blackmailed but can't be gagged as any request for a person's data (including access to it) from a Swiss company MUST go through Swiss court. And even gag orders can't compel someone to break the law. Same situation as three letter agencies requesting EU data from Microsofts' datacenter in Ireland, which whilst it is an American company (and thus they are obliged to deliver by law) is illegal under EU and…

You seem to have a lot of faith in the law and legal process, and assume everyone else does. Laws are a high latency side-chain of authority; a guide perhaps; and for some a business opportunity. And then we have Organised Crime, moles, plants; informants, sympathesiers, casual snitches, quadruple agents, the desperate, and machine learning eating meta-data for breakfast. If you've got something to hide "it's not leg…

And you seem to be painting Swiss legal system with the exact same brush as the USA governmental and legally sanctioned framework for spying on people.

Re: Lavabit Reloaded

#180
post #111

Sensible choices in a nutshell: If you live in a 5-eyes nation, don't use or buy services hosted or operated from a 5 eyes nation. If you don't live in a 5 eyes nation, only use services hosted and operated from Iceland or Switzerland.( Nation states are the #1 threat, and your own nation is always the most dangerous one. )

Schweiz is in the EU. We are subject to its data-retention laws. Consider Norway.

Absolutely not, stop spreading false information
Post reply on HN