Live data from Hacker News

Lavabit Reloaded

lavabit.com

21–30 of 240 posts

Re: Lavabit Reloaded

#22

If you NEED encryption, don't use email. From: https://blog.fastmail.com/2016/12/10/why-we-dont-offer-pgp/ What's the tradeoff? If the server doesn't have access to the content of emails, then it reverts to a featureless blob store: Search isn't possible Previews can't be calculated If you lose your private key, we can't recover your email Spam checking on content isn't possible To access mail on multiple devices, th…

Don't forget "authorities can't snoop your mails and will take us to court because we can't decrypt it."

Re: Lavabit Reloaded

#23

The explain document doesn't describe how key distribution works. How do I get a public key for somebody that I want to email, and how can I know that I am getting the right key? This is the hard part of an modern cryptosystem and the usual source of weakness.

https://darkmail.info/downloads/dark-internet-mail-environme...

Re: Lavabit Reloaded

#24
post #14

Earlier quoted context omitted.

> Former Lavabit users will be able to access their accounts in “Trustful” mode Looks like Trustful mode is how the old lavabit operated. > If you're going to operate in "trustful" mode, lavabit isny offering any real security wins over any other mail host. This level of security apparently was enough to protect email contents against FBI. The reason this "insecure" mode is kept is to allow users to continue using th…

Oh I didn't know that the contents of old accounts were now accessible again. Was that not deleted by Lavabit when they got subpoenaed?

I think Ladar deleted TLS key, not the database.

Well, https://lavabit.com/have-lavabit.html says: "With the help of these tutorials, you should be accessing your old Lavabit e-mail and sending new secure messages in just a few minutes." Maybe e-mail here means account, not messages.

I have some free accounts to test, but looks like imap.lavabit.com and smtp.lavabit.com don't have SMTP/IMAP/POP3 ports open.

Update: https://twitter.com/kingladar/status/822570163547541504 Database is not deployed yet.

Re: Lavabit Reloaded

#25

Is there any person as trustworthy as Ladar Levison for a service like email or chat? To my knowledge, he is one of the few that has gone to the mat for his users.

A good way to regain and build trust with users would have been to acknowledge his previous mistakes. Then at least you could say "he's been around the block, done it wrong and learned how to do it right". Instead, he writes:

"In August 2013, I was forced to make a difficult decision: violate the rights of the American people and my global customers or shut down. I chose Freedom."

That isn't what happened. He chose to build and sell a supposedly secure email service that was fundamentally vulnerable to government intrusion. He then decided to play chicken with the USG over a warrant no different than ones he'd complied with previously. The completely pointless escalation forced him to compromise all of his users, something the government had not been asking for. He then shut the service down.

There are a lot of ways to describe this but 'I chose Freedom' without any acknowledgment of his previous mis-steps is both misleading and shameless. I wouldn't buy supposedly secure services from him.

Re: Lavabit Reloaded

#26

If you NEED encryption, don't use email. From: https://blog.fastmail.com/2016/12/10/why-we-dont-offer-pgp/ What's the tradeoff? If the server doesn't have access to the content of emails, then it reverts to a featureless blob store: Search isn't possible Previews can't be calculated If you lose your private key, we can't recover your email Spam checking on content isn't possible To access mail on multiple devices, th…

Well, you could always use an old school local email client and would get search and previews for free. And some 3rd party not being able to "recover" my private correspondence sounds more like a feature than an issue.

Re: Lavabit Reloaded

#28
post #9

Any reason I shouldn't sign up right now? edit: Signed up. Half off for life is a sweet deal.

If you had any old account, looks like you should be able to connect now. Too bad imap.lavabit.com:143 is firewalled on their side.

The website is up now, I think it'll be a bit until the mail is up.

Re: Lavabit Reloaded

#29
post #5

Trustful seems like a strange way to refer to the insecure mode. It is indeed full of trust, but not in the way a normal read would suggest: it requires full trust in Lavabit's hosting provider and administrator. If you're going to operate in "trustful" mode, lavabit isny offering any real security wins over any other mail host.

> Former Lavabit users will be able to access their accounts in “Trustful” mode Looks like Trustful mode is how the old lavabit operated. > If you're going to operate in "trustful" mode, lavabit isny offering any real security wins over any other mail host. This level of security apparently was enough to protect email contents against FBI. The reason this "insecure" mode is kept is to allow users to continue using th…

How did it protect email contents from the FBI? They got warrants and got the emails.

Re: Lavabit Reloaded

#30
In August 2013, I was forced to make a difficult decision: violate the rights of the American people and my global customers or shut down. I chose Freedom.

Shouldn't that "or" be an "and"?

Post reply on HN