Live data from Hacker News

Lavabit abruptly shuts down

lavabit.com

551–560 of 671 posts

Re: Lavabit abruptly shuts down

#551
post #548
post #350

Earlier quoted context omitted.

Edit: I was a PM on Exchange and Exchange Hosted Encryption for some time, so it looks like Lavabit tried to fight the government on whether they are required to release private keys. I've seen one other customer try to fight, and it was not pretty either. The US government in these cases are serious. Takeaway for fellow hackers: If you are building a system that stores user-generated data, prepare for the eventualit…

Could you name some examples from Europe? Cases when police physically takes servers are common. But I never heard of case where police would require encryption keys for 'maybe we will needed it'.

Also, what prevents the guy from setting up that service in a European country (Switzerland is not subject to EU laws)?

I don't see why his 10 years of work would be lost.

Re: Lavabit abruptly shuts down

#552
post #376

Earlier quoted context omitted.

For sure, but can I fault idiots for inability to read the documentation and caveats? Maybe, but not really lest most on this site could not "do computers" professionally. Unfortunately, the trust problem you mention is pervasive. It was a signed applet IIRC, but we both requires you trust the original and modified applets from the developer. I am wishing someone released an auto-encrypting PGP service and client, op…

Well, it looks like we got ourselves a reader. http://www.youtube.com/watch?v=BwkdGr9JYmE

Unfortunately, I cannot find a clip of this from the movie Ronin. One of my favorites with Robert DeNiro as a criminal or spy, and not even his own gang of crooks are trusting of him. Among my many favorite quotes (I am reviewing all of them and laughing; the movie is a goldmine [0]):

Spence: You think too hard. Sam (DeNiro): Nobody ever told me that before.

[0] http://www.imdb.com/title/tt0122690/quotes

Re: Lavabit abruptly shuts down

#553

Earlier quoted context omitted.

I'm in the same boat. Anyone know of other services similar to Lavabit?

Switched to runbox: https://runbox.com/

MD5 message authentication for the site. No PFS (ephemeral key exchange). Mixed content. I couldn't find a statement where the servers are hosted. Not exactly encouraging.

Re: Lavabit abruptly shuts down

#554
post #385

Earlier quoted context omitted.

Filtering out the random noise wouldn't be very hard.

How are you going to figure out whether it's random encrypted noise or an unrandom encrypted message?

White noise has distinct statistical properties that allow to mitigate it's effect on detection of meaningful signal. E.g. filtering white noise from audio stream is a very common operation.

Sending packets to all contacts at random is a form of introducing white noise, vulnerable to signal processing techniques known and used from 1950s.

Re: Lavabit abruptly shuts down

#555
post #36

How long until PayPal suspends their legal defense fund? On a serious note, if you want to donate to their defense fund, consider doing so anonymously. Pay cash for an Amex or Visa gift card, and use that to make your donation.

I don't know where you live, but here in the Netherlands even for these disposable credit cards you need to present a valid passport/id.

Re: Lavabit abruptly shuts down

#556

Earlier quoted context omitted.

NSL's come with a gag order. There wouldn't have been any backlash as no one would have known about it. He shut it down because that was the only way to legally prevent the government from spying on his users.

Haven't NSL gag orders been found unconstitutional? http://securitywatch.pcmag.com/privacy/309277-judge-says-fbi... I wonder why he didn't challenge it.

Because challenging it from a solitary confinement cell might not sound that appealing.

Re: Lavabit abruptly shuts down

#557
post #554

Earlier quoted context omitted.

How are you going to figure out whether it's random encrypted noise or an unrandom encrypted message?

White noise has distinct statistical properties that allow to mitigate it's effect on detection of meaningful signal. E.g. filtering white noise from audio stream is a very common operation. Sending packets to all contacts at random is a form of introducing white noise, vulnerable to signal processing techniques known and used from 1950s.

Your noise can be non-white. Your noise can favour some of your peers, some time of day, messages can be elaborately routed around in circles. You can even make clients download new message distribution patterns each day. Genetically enchanced patterns.

Re: Lavabit abruptly shuts down

#558

So, secret court case, started by a secret spy service gets an email service shut down. We know next to nothing, except the service went down, with out an open honest explanation. The owner is left with leaving a cryptic-ish message to their users. So, I ask again: at what point is it reasonable to use words like fascist, police state, etc? What is a reasonable tipping point?

If you'd simplify it as fascism being about control instead of, say, conscience and justice, then it certainly seems to continue to be headed in that direction: http://www.theatlanticwire.com/national/2013/08/nsa-will-rep...

Re: Lavabit abruptly shuts down

#559
post #531

Earlier quoted context omitted.

I second to that. If you want security (at least on a servers/ISP level) choose some 3rd world country which government (preferably not very fond of USA) does not have technical means on surveillance. I live in a small EU country and government’s IT forces are just laughable, so I can just imagine that in less civilised countries it should be close to non-existent. Combined with strong encryption to protect data in b…

The problem is that most 3rd world countries will just come knocking on your doors and take everything away, if the US goverment requests it. After all, those countries wouldn't be 3rd world countries, if they had the power to resist US threats/requests. Or they are part of the "axis of evil" (or whatever the current propaganda term is), in which case the internet connection to that country could either be cut off, o…

I would imagine that for example in Ukraine US may request stuff, but then the low level chief of the Police in the town where you reside would give you a hint in exchange for money. That's how it rolls there. What US is going to do about that? Bribe the Ukrainian police to bring you to their Embassy? ;-)

Re: Lavabit abruptly shuts down

#560
post #531

Earlier quoted context omitted.

Dual US/Polish citizen here. Just wanted to say that in many cases abroad (i.e. Poland) the case isn't about the laws protecting your privacy but rather about the Government having no means (technical, resources, know-how, etc) to enforce ridicolous things like reading and storing email contents of all the people. Even with court order just to read stuff in your inbox, I would imagine that the Polish police would hav…

I second to that. If you want security (at least on a servers/ISP level) choose some 3rd world country which government (preferably not very fond of USA) does not have technical means on surveillance. I live in a small EU country and government’s IT forces are just laughable, so I can just imagine that in less civilised countries it should be close to non-existent. Combined with strong encryption to protect data in b…

I understand what you mean but I think the term '3rd world country' could be a bit discouraging to some of our American friends who might not have a clear picture about realities in our part of the world.

For example I also live in a small EU country. By no means this is a 3rd world country - we have pretty strong IT industry (e.g. some globally successful antivirus companies etc.) and the country is certainly developed enough to host companies providing SAAS. Yet we have certain advantages against the US:

1. our government is way weaker than the US government - their resources are obviously not even close and they would not be able to do what US government does even if they wanted to. But we are still an EU state and we can use EU as a shield when Americans come knocking.

2. it is a post-communist country and people still remember the experience of living in totalitarian/authoritarian country. Opposition against any sign of 'bad old times coming back' seem to be much stronger than the opposition of common American people against recent freedom-stripping. For example there was a proposal that our internet providers should be required to block un-licensed online gambling. The public backslash against 'censorship' was so big that the plan had to be abandoned in few days and the politician who proposed it had to apologize. Many things that are now normal in US or UK and some other western countries would not be possible here.

3. we are still an 'American ally' but the US are not nearly as popular with common people as they used to be here and anti-Americanism seem to be growing. Many politicians exploit that and see opposing to American requests as an easy way to score political points (we have seen this for example when US government wanted to build a part of their missile defence system here).

Post reply on HN