Live data from Hacker News

Lavabit abruptly shuts down

lavabit.com

581–590 of 671 posts

Re: Lavabit abruptly shuts down

#581

Earlier quoted context omitted.

Also, what prevents the guy from setting up that service in a European country (Switzerland is not subject to EU laws)? I don't see why his 10 years of work would be lost.

He might not want to relocate. It's risky to relocate the servers in another country. You will have to obey the other country's laws, but the US gov will still claim jurisdiction if the staff and/or owner is in the US. The US will even claim jurisdiction as soon as you use a ".com" domain [1] Of course the hosting nation will also claim jurisdiction. So relocating your servers to one country while staying in another…

He could still just sell it to someone in another country. Neither the service nor his 10 years of work would be lost.

Re: Lavabit abruptly shuts down

#582
post #531

Earlier quoted context omitted.

Dual US/Polish citizen here. Just wanted to say that in many cases abroad (i.e. Poland) the case isn't about the laws protecting your privacy but rather about the Government having no means (technical, resources, know-how, etc) to enforce ridicolous things like reading and storing email contents of all the people. Even with court order just to read stuff in your inbox, I would imagine that the Polish police would hav…

I second to that. If you want security (at least on a servers/ISP level) choose some 3rd world country which government (preferably not very fond of USA) does not have technical means on surveillance. I live in a small EU country and government’s IT forces are just laughable, so I can just imagine that in less civilised countries it should be close to non-existent. Combined with strong encryption to protect data in b…

Some countries have a problem with bribery and corruption. Routing sensitive data through those countries risks that data being exposed by anyone in the chain who is willing to take a bribe.

I am much more worried by corrupt workers in my ISP or telephony provider than I am about my government.

Re: Lavabit abruptly shuts down

#583

Earlier quoted context omitted.

I was surprised to see Canada green on that map. We have a great privacy commissioner ( http://www.priv.gc.ca/index_e.asp ) but the office holds no power so far as I can see, and the Canadian government has a pretty solid track record of being obsequiously cooperative with u.s. interests

Canada is green simply because nobody familiar with Canada's security politics and policies has chimed in yet and there does not seem to be any evidence of foul play that is visible from an outsider's perspective. Cooperative with U.S. interests is generally assumed by almost any country - this map is more about the (hopeful) safety of your servers in data centers in different countries.

I think you can pretty much colour the Echelon Five Eyes countries (USA, Canada, UK, Australia, New Zealand) red right off the bat. If they don't have totally intrusive surveillance legislation yet they will have soon - New Zealand is currently trying to implement it.

Re: Lavabit abruptly shuts down

#585
post #281

Earlier quoted context omitted.

As a veteran of the USPS software industry, I wouldn't worry too much.

hilarious!! since we on the subject, are there any veterans of NSA software industry who can share some insight?

I assume they would be under some sort of NDA.

Re: Lavabit abruptly shuts down

#587

Where's the "I wish you hadn't done that, lavabit, I'm a customer and I feel very screwed over by this action" comments? Or is this appropriate for any SaaS vendor? You're OK with this? Should all customers, even those who really don't care if the NSA could be watching, be put out because some feel that this cause trumps actually doing business and having customer-vendor relationships? I could see someone suing an Sa…

> Should all customers, even those who really don't care if the NSA could be watching, be put out because some feel that this cause trumps actually doing business and having customer-vendor relationships? If they don't care, why pick lavabit then? From my point of view they did exactly what they were supposed to do.

Yep, you're right. I wasn't thinking about their specific business model and customer set. Thanks for setting me straight.

I wonder what the Lavabit TOS and privacy terms actually said? Usually they say something like "we will not disclose ... Except to comply with legally served requests..." I'm curious whether Lavabit had something different here.

Perhaps this suggests a new business model, a sort of turbo canary, where the service explicitly commits to shut down rather than comply with a secret order which it would otherwise be compelled to obey.

Re: Lavabit abruptly shuts down

#588
post #183

The US government is destroying one of the few bright spots in the American economy with its out of control military. It is unconscionable. And the sad thing is it has been enabled by the betrayal by many of the web 2.0 giants, Facebook, Google etc. Google especially is sad to see since they were willing to forgo the Chinese market on principle, but then decided that taking on the authoritarian US government was too…

The actions of Lavabit actually caused me to cancel my account with Google Play All Access today (proof: http://i.imgur.com/KbmaBnS.png , if anyone cares), that I've had since day one. It's not that I didn't know that Google was ok with the spying before, but seeing the difference between the reaction of Lavabit, to the non-reaction from Google -- well THAT gave me the final push to stop doing business with the compa…

It's exactly this kind of sacrifice more people need to make if they want to see some real change.

Re: Lavabit abruptly shuts down

#589
post #582
post #531

Earlier quoted context omitted.

I second to that. If you want security (at least on a servers/ISP level) choose some 3rd world country which government (preferably not very fond of USA) does not have technical means on surveillance. I live in a small EU country and government’s IT forces are just laughable, so I can just imagine that in less civilised countries it should be close to non-existent. Combined with strong encryption to protect data in b…

Some countries have a problem with bribery and corruption. Routing sensitive data through those countries risks that data being exposed by anyone in the chain who is willing to take a bribe. I am much more worried by corrupt workers in my ISP or telephony provider than I am about my government.

That's an issue with plain text data. However, nowadays absolutely no sensitive data should be transferred/stored unencrypted. The problem is, that it seems like eavesdropping is not enough for some certain governments and now they require physical access / backdoors to companies' servers in order to bypass encryption and/or other security means. What I, and few others have suggested is to move services away from such countries so their governments would have harder times to obtain physical access.
Post reply on HN