Live data from Hacker News

Two Providers of Secure E-Mail Shut Down

bits.blogs.nytimes.com

31–40 of 72 posts

Re: Two Providers of Secure E-Mail Shut Down

#31
post #16

This is why I setup my own email server... Here is a great guide for anyone interested: https://www.exratione.com/2012/05/a-mailserver-on-ubuntu-120... I set mine up on CentOS 5 using this guide. I would recommend you also look at DKIM signing and SPF records to improve deliverability! :)

email is not encrypted... they'll just have your hosting provider or ISP copy your email when it's received/sent

Right, but my email service is not likely to suddenly disappear overnight (like post) and also isn't owned and controlled by a large corporations in the same pocket as the US government (which isn't even my government... but seemingly still has access to my emails...).

Re: Two Providers of Secure E-Mail Shut Down

#32

" Mike Janke, Silent Circle’s chief executive, said in a telephone interview late Thursday that his company had destroyed its server. “Gone. Can’t get it back. Nobody can,” he said. “We thought it was better to take flak from customers than be forced to turn it over.” That guy has brass balls. It may very well be that this will be interpreted as obstruction of justice, there is a specific element in there about destr…

The reason why he destroyed it now is so that he doesn't face obstruction of justice charges later. He realized they were coming, one way or another.

A lot of lawyers advise that the only and best time to destroy evidence is before it becomes evidence.

Re: Two Providers of Secure E-Mail Shut Down

#33
Hm, i wonder why Silent Circle just went ahead and shutdown their relativly young and unknown mailservice without any clear reason other than to use the opportunity to do get some publicity for their other secure services.

Lavabit was alot bigger than Silent Circle and this announcement seems a bit suspicious to me. I might me totally wrong, but going ahead and shutting down the service on the same day a popular competitor does without any clear reason while at the same time embracing their other still running services seems a bit strange to me.

Re: Two Providers of Secure E-Mail Shut Down

#34
> Taken together, the closures signal that e-mails, even if they are encrypted, can be accessed by government authorities and that the only way to prevent turning over the data is to obliterate the servers that the data sits on.

Can someone explain to me how this is possible? Or is this inaccurate?

Re: Two Providers of Secure E-Mail Shut Down

#35

Earlier quoted context omitted.

My e-mail system is set to prefer TLS wherever possible. Spot-checks of headers incoming from other sources show that, at the minimum, a TLS session is successfully negotiated approximately 85% of the time so messages from those sources are presumed to be encrypted while in transit. All clients must connect using TLS (either IMAP-S or HTTPS). Yes, unencrypted copies likely exist on the sending side (the data storage…

so the nsa gets a list of IP addresses of mail servers that sent you mail, and sends a subpoena to each of those providers instead.

If they want to get you they're gonna get you. The point is that takes a lot more work than the analyst sitting at his desk typing in friggin Google searches on your Gmail.

Re: Two Providers of Secure E-Mail Shut Down

#36
A slashdot commenter put this up a few weeks ago, it's worthwhile viewing for an hour - you can get an idea of what the providers are going through. There's a good interview with an archive.org employee around who also received one, and tried to resist in his capacity as a librarian.

https://www.youtube.com/watch?v=C25EkdWLU1k

Re: Two Providers of Secure E-Mail Shut Down

#37
post #30
post #29

Earlier quoted context omitted.

But they weren't being prosecuted, how is that obstruction? How would they prove that it was "evidence"?

You're asking this of a government with a growing record of retroactively rewriting laws in its own favour?

Retroactive law for warrantless wiretapping, I am aware of. What other laws can you add to that list?

Re: Two Providers of Secure E-Mail Shut Down

#38

Earlier quoted context omitted.

My e-mail system is set to prefer TLS wherever possible. Spot-checks of headers incoming from other sources show that, at the minimum, a TLS session is successfully negotiated approximately 85% of the time so messages from those sources are presumed to be encrypted while in transit. All clients must connect using TLS (either IMAP-S or HTTPS). Yes, unencrypted copies likely exist on the sending side (the data storage…

so the nsa gets a list of IP addresses of mail servers that sent you mail, and sends a subpoena to each of those providers instead.

And if the other side happens to be self-hosted as well or an provider based outside the US?

Re: Two Providers of Secure E-Mail Shut Down

#39
post #33

Hm, i wonder why Silent Circle just went ahead and shutdown their relativly young and unknown mailservice without any clear reason other than to use the opportunity to do get some publicity for their other secure services. Lavabit was alot bigger than Silent Circle and this announcement seems a bit suspicious to me. I might me totally wrong, but going ahead and shutting down the service on the same day a popular comp…

I don't think 'any news is good news' applies to secure services providers. It will not make other offerings more appealing. Why bother with a provider that has to resort to this kind of behaviour to protect its customers?

Re: Two Providers of Secure E-Mail Shut Down

#40
post #5

Reminds me of when they took Megaupload down. There was a domino effect where a lot of torrent and file sharing sites decided to pack their things and go home. First the file sharers, then the secure emails. I wonder who's going to be next? The reddits? The HNs?

I think it's just going to lead to decentralization. More, smaller fish.

It's funny I think that's one of the primary results of the internet. I think of movie and music production, software, bitcoin, bittorrent and so on. I would argue they have been decentralised by the internet. I think centralised services are against the 'spirit of the internet'.
Post reply on HN