Live data from Hacker News

Lavabit Reloaded

lavabit.com

201–210 of 240 posts

Re: Lavabit Reloaded

#201
post #9

Any reason I shouldn't sign up right now? edit: Signed up. Half off for life is a sweet deal.

As written in another comment ( https://news.ycombinator.com/item?id=13447493 ), one has to give away too much personal information without clear reason. I would suggest to use https://posteo.de instead. They offer anonymous payment by post (I'm just a happy user).

I'm not trying to have anonymous email, my personal email has my full name as the domain. I just want something that is encrypted and open-source.

I give away my name and credit card info to plenty of websites. That won't help someone crack my private key used for lavabit any easier.

Re: Lavabit Reloaded

#202

Is there any person as trustworthy as Ladar Levison for a service like email or chat? To my knowledge, he is one of the few that has gone to the mat for his users.

Phil Zimmermann

He went to prison over pgp.

But then the mail service he was involved in (silent circle mail) shut down at the same time as lavabit.

Re: Lavabit Reloaded

#203

Earlier quoted context omitted.

If Edward Snowden started a mail service, I'd probably trust it more. If you want to talk about "going to the mat" for people, I think Snowden has made the bigger sacrifice. Moxie and Whisper Systems probably would get my nod too. Perhaps even DJB or Bruce Schnier.

Moxie is not impressed with lavabit as lavabit's entire security model relied on "we totally promise we won't look at your private key." https://moxie.org/blog/lavabit-critique/ >Unlike the design of most secure servers, which are ciphertext in and ciphertext out, this is the inverse: plaintext in and plaintext out. The server stores your password for authentication, uses that same password for an encryption key, and…

Did you RTFA?

You can keep your private key private now, or, like always, just run your own server and not have to worry about ever trusting anyone with anything. Though "Paranoid" mode in DIME seems to accomplish the same thing.

Re: Lavabit Reloaded

#204
post #202

Is there any person as trustworthy as Ladar Levison for a service like email or chat? To my knowledge, he is one of the few that has gone to the mat for his users.

Phil Zimmermann He went to prison over pgp. But then the mail service he was involved in (silent circle mail) shut down at the same time as lavabit.

He never spent time in prison, but he was investigated intensely by the US gov't.

Re: Lavabit Reloaded

#205
Naming it the "Dark Internet Mail Environment" is not going to get the average person's sympathy or interest, and will be an easy target for politicians.

Re: Lavabit Reloaded

#206

Earlier quoted context omitted.

Oh no, you're describing the solution rather than the problem: a global search, copy, and seizure converted to a local one that happens on per-target basis. Way better than mass collection with FISA warrants and systems like QUANTUM.

Is QUANTUM the Swedish one or is there a new one?

It's the NSA system that operates globally that can automatically fire attacks at systems based on patterns the operations people put in. Almost all the European countries are part of a SIGINT-sharing alliance per one slide. The exceptions were Switzerland, Iceland, and one I can't remember.

Re: Lavabit Reloaded

#207
post #63

Earlier quoted context omitted.

Well, if you have not logged in since they started recording traffic and until shutdown, chances are your password is not compromised and emails are still encrypted. But no way to be sure.

Before the thing with Snowden and the cert, Lavabit simply complied with warrants, which they could since they could read everyone's email. Fundamentally, Lavabit was not in any way different than Gmail.

Any source for this? Reading everyone's emails requires them backdooring their server so that it saves plaintext password or symmetric key on login. Were they doing this?

Re: Lavabit Reloaded

#208
post #163

If you really want secure email, having it hosted and owned by a U.S. company is a recipe for disaster. Since we know that the U.S. gov't will gladly issue gag orders and blackmail, why even bother? It's great that Lavabit is innovating but Protonmail is already ahead by simply not being in the U.S..

Protonmail is a walled garden of its own because it has no IMAP or POP (hasn't had it for more than two years since it was requested). So you're stuck with using the Protonmail apps on iOS or Android or using the web version. None of them are good choices to have one's own copy of all mails in an easily portable form. The only option Protonmail provides is to individually save or print emails. So there's no easy way to export your mails and switch to another provider.

Re: Lavabit Reloaded

#210
post #63

Earlier quoted context omitted.

Before the thing with Snowden and the cert, Lavabit simply complied with warrants, which they could since they could read everyone's email. Fundamentally, Lavabit was not in any way different than Gmail.

Any source for this? Reading everyone's emails requires them backdooring their server so that it saves plaintext password or symmetric key on login. Were they doing this?

'backdooring their server to themselves' is not 'backdooring' it's just misdesigning. The alternative is believing Lavabit always scrupulously 'looked away'.

https://moxie.org/blog/lavabit-critique/

Post reply on HN