Source: I briefed and argued the Lavabit case in the Fourth Circuit.
If I were you I wouldn't trust the guy involved in LavaBit in the future, Ladar Levison. He frankly did not seem to be up to the challenge of running a company that is prepared to navigate this space, from the way he bungled the case. He got basic things wrong about how to engage first with the FBI, then with a court over a court order, and made his position worse by ineptly arguing with the court without advice of council. He blew his shot to raise arguments with the court later as a result. Furthermore, he clearly made misleading claims about the security of the product, and I believe knowingly. LavaBit had by that point had already helped the govt surveil other users, all the while maintaining that the communications were secure and that even they couldn't read them.
I have no axe to grind with LavaBit - these are all conclusions I reached by investigating the case myself. You can see this for yourself by reading the court transcripts and news articles. While his intention to provide a secure communications product was noble in the abstract, I would personally trust neither his technology judgment nor his business judgment in how to run a company or handle tough legal circumstances in the future.
He did stupid, immature shit like, when finally ordered to provide his encryption key, he printed it out on paper in an illegibly small font. The court of course compelled him in an industry standard format. That kind of thing is just immature and makes the situation worse for him and his users by extension. http://arstechnica.com/tech-policy/2014/04/lavabit-held-in-c...
Any tech person with an adequate knowledge of encryption and security could have seen through LavaBit's security model. It's not possible to provide webmail in a mode where the webmail provider can't read your email.
http://www.infoworld.com/article/2609583/encryption/how-secu...
> "The ciphertext, key, and password," [Moxie] Marlinspike wrote [in his analysis of LavaBit], "are all stored on the server using a mechanism that is solely within the server's control and which the client has no ability to verify. There is no way to ever prove or disprove whether any encryption was ever happening at all, and whether it was or not makes little difference. ... Even though they advertised that they 'can't' read your email, what they meant was that they would choose not to." Marlinspike also took exception to the way the password supplied by the user also does double duty as an encryption key, a practice frowned upon by password researchers.
The article above also links to Levison's reply which is not convincing at all:
> Marlinspike is assuming that the Lavabit system was designed to be a substitute for the security provided by end-to-end encryption systems like PGP. It was not. Lavabit’s encrypted storage feature was designed solely to protect e-mails at rest.
Huge, huge hedging right there. If you're using PGP then there is virtually no benefit to using LavaBit at all.
> Why protect the data at rest? To limit the data Lavabit could access and therefore turn over to the government. When the government seeks a specific user’s data, it is given what is stored on disk, e.g., any metadata found in a server’s log files and any e-mail content the provider has access to.
Clearly the government wants to intercept data in transit too, and LavaBit had helped them do it prior to this case. Yet LavaBit continued running and advertising its services. Furthermore, if I recall correctly, LavaBit stored the user's data encryption key encrypted with the user's password, so all it took is one login from a user under surveillance and the government would have gotten the keys to decrypt all the data at rest too. A competent technologist should have known that was a risk from the beginning, so if he actually missed that threat vector it should tell you something; but even if he didn't know from the beginning, he knew after the first time he helped do that for the FBI.
There is only one circumstance in which LavaBit's security model would have worked, which is if the user under surveillance never logs into LavaBit again after the surveillance begins. But if they log in even once more, their password flows to LavaBit and thus the govt, which can decrypt all the user's data at rest. This is what the court initially ordered LavaBit to do IIRC: intercept the password of one user on login, and then provide the user's data. And LavaBit had done so upon earlier requests. The fact that he did not disclose this threat vector to his users from the beginning tells you something about his intentions.
If Apple were ordered to close in an instant, there would be mass upheaval, unrest, protests, and huge economic losses just because of the sheer number of people that depend on their products on a daily basis for mission-critical things. Violence would break out. We might even end up facing nothing short of a civil war, and the federal government probably wouldn't want to risk that.
* By which I mean I could see Apple purposefully fighting this to the Supreme Court, even if it means "appealing" a case they've already won so that it goes to a higher court.