Live data from Hacker News

Two Providers of Secure E-Mail Shut Down

bits.blogs.nytimes.com

21–30 of 72 posts

Re: Two Providers of Secure E-Mail Shut Down

#21
post #16

This is why I setup my own email server... Here is a great guide for anyone interested: https://www.exratione.com/2012/05/a-mailserver-on-ubuntu-120... I set mine up on CentOS 5 using this guide. I would recommend you also look at DKIM signing and SPF records to improve deliverability! :)

email is not encrypted... they'll just have your hosting provider or ISP copy your email when it's received/sent

My e-mail system is set to prefer TLS wherever possible. Spot-checks of headers incoming from other sources show that, at the minimum, a TLS session is successfully negotiated approximately 85% of the time so messages from those sources are presumed to be encrypted while in transit. All clients must connect using TLS (either IMAP-S or HTTPS). Yes, unencrypted copies likely exist on the sending side (the data storage disks for my e-mail servers are encrypted) and the client storage for some of my users is in the clear but it's not possible for my ISP to read the bits in flight.

Re: Two Providers of Secure E-Mail Shut Down

#22
post #9

It's a victory of NSA-US govt. over the efforts of EFF and similar organizations. We must continue this fight to safeguard our future. Here are two free and secure email providers who keep themselves up only by donations: 1. https://openmailbox.org 2. https://autistici.org

SSL errors on the 2nd... seems... worrisome.

I'm but a layman but browser-side SSL verification is essentially 3rd-party centralized validation of the authenticity of one side of an encryption mechanism - predetermined vendors tell the browser whether a SSL cert is as claimed and an SSL cert is only an encryption key.

This service doesn't care whether a browser-maker thinks its cert is real; they also provide a means to validate that their downloadable cert is as claimed - the cert is valid encryption between you and them, from anyone not you and them, despite whatever errors a browser throws up.

Re: Two Providers of Secure E-Mail Shut Down

#23
post #9

It's a victory of NSA-US govt. over the efforts of EFF and similar organizations. We must continue this fight to safeguard our future. Here are two free and secure email providers who keep themselves up only by donations: 1. https://openmailbox.org 2. https://autistici.org

Previous discussion on OpenMailbox: http://news.ycombinator.com/item?id=6174603

Re: Two Providers of Secure E-Mail Shut Down

#24

Earlier quoted context omitted.

email is not encrypted... they'll just have your hosting provider or ISP copy your email when it's received/sent

My e-mail system is set to prefer TLS wherever possible. Spot-checks of headers incoming from other sources show that, at the minimum, a TLS session is successfully negotiated approximately 85% of the time so messages from those sources are presumed to be encrypted while in transit. All clients must connect using TLS (either IMAP-S or HTTPS). Yes, unencrypted copies likely exist on the sending side (the data storage…

so the nsa gets a list of IP addresses of mail servers that sent you mail, and sends a subpoena to each of those providers instead.

Re: Two Providers of Secure E-Mail Shut Down

#25
post #17

It seems like there's an opportunity for a PGP mail forwarder, a service that encrypts all incoming mail and then forwards it without saving anything in the process. I'd pay bitcoins for that.

This sounds totally useless as a 3rd party service due to how obvious a target it would be but a simple encrypting proxy or MTA config would be pretty useful for self hosted setups.

Re: Two Providers of Secure E-Mail Shut Down

#26

" Mike Janke, Silent Circle’s chief executive, said in a telephone interview late Thursday that his company had destroyed its server. “Gone. Can’t get it back. Nobody can,” he said. “We thought it was better to take flak from customers than be forced to turn it over.” That guy has brass balls. It may very well be that this will be interpreted as obstruction of justice, there is a specific element in there about destr…

What he did was equally an act of heroism (in face of Internet history) and stupidity (in face of his own life). Perhaps, he should just have wiped and destroyed the disks, and have it "seemed like a system crash at a bad timing" caused it :)

Isn't it fucked up when someone suggests that someone's life might be at risk because of some data he had (and completely had the right to delete) and it doesn't sound utterly ridiculous?

This is now the world we live in.

Re: Two Providers of Secure E-Mail Shut Down

#27

" Mike Janke, Silent Circle’s chief executive, said in a telephone interview late Thursday that his company had destroyed its server. “Gone. Can’t get it back. Nobody can,” he said. “We thought it was better to take flak from customers than be forced to turn it over.” That guy has brass balls. It may very well be that this will be interpreted as obstruction of justice, there is a specific element in there about destr…

What he did was equally an act of heroism (in face of Internet history) and stupidity (in face of his own life). Perhaps, he should just have wiped and destroyed the disks, and have it "seemed like a system crash at a bad timing" caused it :)

Lying under oath (or even when questioned by the police) is rarely a great idea. Because even if they can't prove you did anything illegal, that can still use your lie to hang you.

Re: Two Providers of Secure E-Mail Shut Down

#28
as someone who (wisely or unwisely) depends on my email account as an online datastore, the prospect of it just shutting down overnight and my losing everything is terrifying. which probably means it's time to start some sort of active backup mechanism, but more to the point i do wonder if any of lavabit's or silent circle's clients ran into the same predicament.

Re: Two Providers of Secure E-Mail Shut Down

#29

" Mike Janke, Silent Circle’s chief executive, said in a telephone interview late Thursday that his company had destroyed its server. “Gone. Can’t get it back. Nobody can,” he said. “We thought it was better to take flak from customers than be forced to turn it over.” That guy has brass balls. It may very well be that this will be interpreted as obstruction of justice, there is a specific element in there about destr…

But they weren't being prosecuted, how is that obstruction? How would they prove that it was "evidence"?

Re: Two Providers of Secure E-Mail Shut Down

#30
post #29

" Mike Janke, Silent Circle’s chief executive, said in a telephone interview late Thursday that his company had destroyed its server. “Gone. Can’t get it back. Nobody can,” he said. “We thought it was better to take flak from customers than be forced to turn it over.” That guy has brass balls. It may very well be that this will be interpreted as obstruction of justice, there is a specific element in there about destr…

But they weren't being prosecuted, how is that obstruction? How would they prove that it was "evidence"?

You're asking this of a government with a growing record of retroactively rewriting laws in its own favour?
Post reply on HN