Lavabit abruptly shuts down
lavabit.com
lavabit.com
Takeaway for fellow hackers: If you are building a system that stores user-generated data, prepare for the eventuality that someone other than the user will demand to see it.
In general, the prevailing theory is that all companies are required to release private keys or passwords needed to unlock evidence. As a consequence of Lavabit fighting, they likely got slapped with some pretty harsh contempt of court rulings, including a demand to record all private keys needed for decryption going forward. The worst case (that I can talk about) I saw involved requiring a specific employee be demoted due to improper care of a company's systems.
What's sad is that because Lavabit was such a small service provider, they never had the previous rounds of government threats and must have been caught off guard. As I've said in past posts (before Snowden), it is common knowledge among large-scale service providers that the local government can always come in to take a look. Doesn't matter if you are in the US, EU, or China, you have to comply. I've seen the US DOJ threaten pretty harshly a customer who simply asked about 'options' of how to comply.
Past post with explanation: https://news.ycombinator.com/item?id=5754641
P.S. Right or wrong is a separate conversation...
Would you expand on this? Are you saying that a court was meddling directly with an individual company's hierarchy?
As long as you can't comply, I don't think there's an uncounterable risk in the US, since we don't have any key disclosure requirements (the exception being CALEA, which only applies to the PSTN; I'd skip CALEA for an interconnected VOIP system and fight them in the courts/media, personally). Presumably they could put other weird pressure on you like threatening to investigate your nanny's immigration status or whatever, but enh.
I still maintain that if you do things properly, you can operate safely in the US while resisting pressure from USG. You can't literally wipe your ass with an NSL in front of the agents, but if you don't have it, and can't get it, they're at worst a DoS. Forcing a provider to implement a huge new logging infrastructure would be an interesting 14A issue, and one could have a system where even that wouldn't recover customer keys.
IANAL of course.
No it's not. This is wrong, plain and simple. Wrong is wrong, and black is black.
The guy who runs the service is one of my best friends. He's the kind of guy who would burn the server farm to the ground before he did something that violated the terms dictated in his privacy policy.
The Government has been trying to get into Lavabit longer than that.
Although, perhaps they already knew that Snowden was using Lavabit and started the process immediately after his flight to HK.
If anyone can recommend someone who can provide counsel pro-bono let me know and I'll forward the message along.
I bet that data are still valuable to the government.
I have been thinking of starting a business in the privacy space. This has shown me that that all customer data needs to be periodically obliterated in safe way and that a kill switch or nuke button is needed as well to destroy everything on a moment's notice.
Where and how to host is a major concern. Cloud, etc., is obviously out of the question.
If you'll be trying to keep this secrect by creating small cells of people not knowing each other and smart mailboxes preventing people exchanging t identify each other, you'll become suspect of supporting spying activity.
So you better work for the minimal number of clients and charge a lot to remain sustainble.
My understanding is that as long as keep the info concentrated in one spot (i.e. Paper mail) it is easy to grab it. If you dilute and spread the info using shared secret and hide it smartly in images or random text, this info would be much harder to catch but could use conventionnal transport means.
Extending this idea further, turn the mail network into one big world wide hologram. The information would then be spreaded, available from everywhere, very hard to censor, and private since you need some specific reference signal to extract the info. It's like shared secret.
Note however that the need to catch evil people using such communication system for evil means is needed. Just considering our own privacy regardless of what can go wrong with such system is in my opinion selfish. We will always need method to protect against abuses.
(might have to have multiple vessel's for redundancy purposes)
At least when the ship disappeared off the face of the earth it would be easy to figure out what happened.
The problem is that you have to connect up to the Internet somewhere, and they can always get you there. Either tapping and listening in on sessions, or just plain disconnecting you.
Of course, an MITM attack could hide the STARTTLS option and there are questions around the strength of the CA cert infrastructure, but SMTP is not just plaintext.
how is that possible? I'm curious to know as to how they achieved that technically. I mean if the user is reading an email in their browser, then it would've had to have been created on the server first.
http://www.wired.com/threatlevel/2007/11/encrypted-e-mai/
> a federal prosecution of alleged steroid dealers reveals the Canadian company turned over 12 CDs worth of e-mails from three Hushmail accounts, following a court order obtained through a mutual assistance treaty between the U.S. and Canada.
This experience has taught me one very important lesson: without congressional action or a strong judicial precedent, I would _strongly_ recommend against anyone trusting their private data to a company with physical ties to the United States.
The worst thing about this situation is that other governments like the UK, France and Germany are equally guilty.
For history on lavabit, see the cache, this page is now gone:
http://webcache.googleusercontent.com/search?sclient=tablet-...
Where did you get this one from? I think its a bit of a stretch to say he is "standing up to his users". I would rather say he is standing up against the GOV, and that's nice for a change, but we have no idea what has happened with all the emails residing on their servers.
Knowing just a bit that I know how the us gov operates, I am pretty sure he was given two options at exact the same time: either you accept our black box, OR you will not. If you not, then you are not allowed to delete or alter any messages on your servers. Given the business lavabit was in, I am sure Feds will punish him to the extends of the law (or more) if he decides to "stand up to his users" and delete content of their mailboxes.
EDIT: Relevant XKCD for people calling for technical solutions to the problem: http://xkcd.com/538/
- Politically, we should punish anything associated with the NSA.
- Socially, we should shun everyone from this date forward who works directly with or as a contractor for anything associated with NSA/FBI/CIA/DEA/DIA. We should not hire any programmer who, from this date point forward, has worked in those capacities. They are destroying our profession and businesses.
- On the engineering front, we should be designing technologies for evading the NSA et al, and spread those technologies. We need to do everything possible to make them easy to use and make them widespread.
- Any person or company who stands up to these organizations should be lionized and we should try to patronize their businesses or employee them. Especially if the suffer consequences like jail and torture.
- Facebook, Google, especially Palantir are known collaborators and we should treat them as such
Google, Microsoft, and Facebook basically have had billions of dollars shaved off of their future market capitalization -- though I have not seen anyone say this yet.
For everyone abroad who is technically adept and talented, the vaults of wealth have been unlocked for you; just copy the successful offerings of American companies. Don't worry about software patents or trademarks unless your country is complicit, you'll have the autonomy of a oligarch (said with some sarcasm.)
There is one solution here: open source, distributed software. If you want to build a company to promote real security this is your only option.
What are you doing on your own checklist? Those are some pretty extremist notions.
If part of your hiring criteria was to exclude anyone who had worked for a contractor or directly for a government organization, I doubt many people would want to work for you. Not because they had violated your criteria, either.
Not to mention, most countries will pretty much cooperate with the US when it comes to intelligence. The only ones that might not are countries like Russia or China that have their own military-industrial complexes, which are just as eager to get at your data and a lot less scrupulous about using it.
Germany is a better bet. While they are no doubt tapping lines, Germany and the EU have made no moves to actually perform hostile interventions into data-centers or private servers. This means that encryption is still a very viable security measure for protecting your data in the EU. The EU simply has a far better track record with privacy related issues.
It's not about perfect security, it's about getting the best security you can hope for - and that means moving away from anything USA hosted.
But in regards to cryptography and chances for legally fighting against such orders it could be better. At least on paper. The most likely outcome if lavabit would be hosted in germany would be a police raid that would take all servers for investigation with them. This happenend e.g. for poeple running Tor exit nodes.
If you're in the US it seems kinda pointless to try to move to overseas hosting; the NSA will probably just focus on the client side.
Focus instead on encryption.
Focus on encryption, to keep ahead and protect the data.
Move out of the US, because it sucks, is far from 'the land of the free' anymore and needs to learn that its place in the digital world is not at the top, but more around the center. Between lots of other states that fail and fail again, in terms of surveillance..
Encryption is OK but doesn't solve the problem. There's always metadata and whom can your trust with your encryption? You have to assume that hardware and software you use has backdoors. Mobile phones for example has even official backdoors, your SIM card can be remotely changed and so on …
That's infuriating. It's the same as having an insecure system and then charging a hacker millions of dollars in restitution to re-architect the system to do it right.
Those firms wouldn't have to leave the US cloud providers if they had assurances that the US wasn't spying on them for no good reason.
This was a concern earlier but my guess is that this will only increase in the near future.
Also, practical key management is still an unsolved problem. The web of trust never took off and the PKI is fucked. Encryption is only as useful as the keys being used to encrypt.
If enough people leave US based companies for foreign companies it will put pressure on the government. I have a feeling this pressure is already underway.
If they were outside of US-and-friends jurisdiction, they wouldn't be shut down and there wouldn't be a gag order.
You should try finding a SSL cert retailer that's outside of the US. The only ones I could find that would actually sell me certs without a phone call charged at least $200 for a basic certificate. https://swisssign.com/en were the most sensible looking ones I could find.
As a community, let's shun and shame all those who continue work for those agencies (NSA/CIA/FBI/DIA/DEA) both directly and as contractors from this date forward. If you didn't quite in August 2013, we don't want to hire you. If you quite now in disgust, we should view that in a positive light. If you or your company stand up to the US Gov, that should view that in a VERY positive light and we should be looking to hire them.
Let's shun and shame FB, Google, et all as collaborators. Let's make it a point to avoid google app engine and other Google services.
It would be one thing if Google, Facebook, Microsoft, and other big firms were selling out their customers' privacy for money. They do it all of the time for advertising. I wouldn't like that, but it would be somewhat understandable that a big uncaring firm would look at their bottom line as the only determining factor. But are they making more money by being the government's snitch?
The really weird thing here is that what's going on isn't even in these companies' self-interest because they're going to make people and businesses not trust online storage of their data in any way. So all of these cloud services, all of these online storage services, anything that impacts peoples' privacy in any way is going to be put at risk of customers choosing other options for managing their data.
The companies with the ability to move all operations out of US jurisdiction/coercion who don't do so are complicit in all of this.
I can imagine what would happen to Google if, through some dark miracle, their leadership decided to do this.
Most of their top engineers live in America. So do the leaders, but ignore them, we've already decided they want this. The employees don't, though: There are eleven thousand people, there, who'll need to be relocated to - where? Europe, probably Ireland, where many of them have never been.
Certainly not where they have roots, or where their family is.
Google has deep pockets. They can afford to pay massive relocation bonuses, and they'll have to do so. Still, this is eleven thousand people; we're probably talking about a billion plus, just to get a reasonable number of them to follow. After all, most of these engineers would be perfectly capable of finding work at a different company.
Okay, so they've done that. They lost a lot of good people; probably a lot of their best people, the ones that care least about money. Still, they're now in Europe.
Now what?
Most of their infrastructure is still in the US. Compute clusters, god only knows how many. Storage clusters. User data, placed in the US under safe harbor provisions because an attempt at keeping it in Europe is unfeasible given the rather diverse tapestry of privacy laws here.
They'll need to move it all to Europe. They'll need to figure out a place to put it, and they'll need to pay billions - quite a few - to rebuild and expand their infrastructure here.
By the time this is all done, they'll have new problems. Realistically, they'll go bankrupt somewhere in the middle. And that's not mentioning possible reactions from the US government.
It would be great if leaving the US was an option, but it really.. just isn't.
It's not that I didn't know that Google was ok with the spying before, but seeing the difference between the reaction of Lavabit, to the non-reaction from Google -- well THAT gave me the final push to stop doing business with the company.
I really like Google's products. I really like All Access, but I don't think I'll be supporting the company financially anymore.
It probably won't matter much, but it's still something.
Not to mention that there is no US equivalent to the rampant human rights violations and censorship in China.
Also, the U.S. government is censoring Ladar Levison of Lavabit and others in his situation.
I've never been to China to see anything for myself, so I won't make further comparison, but prison state thing definitely bothers me.
Of course we see more violations in china, but who's to say you don't have 10 times more of that from the US?
Just because they don't do it to US citizens (in most cases) it doesn't mean they don't do it.
Believing the other side is worse just cause you "see" more of that stuff, ends up being just blissful ignorance. Every party has it's faults and I have no doubt in my mind that the US has the most.
But we shouldn't worry... that's all to "protect the american citizens from terrorism" :D
So that makes it okay for them to systematically spy on their own citizens and violate their own constitution?
Saying "this country is worse" doesn't make it okay in the US.
Bad logic.
P.S. smalltalk, you're dead.
> "This experience has taught me one very important lesson: without congressional action or a strong judicial precedent, I would _strongly_ recommend against anyone trusting their private data to a company with physical ties to the United States."
It's kind of fitting. The nation that spawned the internet is the nation that's killing the internet biz on its own turf.
I guess we now know how it must have felt to watch republican institutions spiral into tyranny in ancient Rome.
Much more likely they asked him to slip in a backdoor for some specific users. That's much harder to detect.
Sure, we can fight this in the courts, and a few secret programs might get shut down, but operations will just continue under a different name. We can encrypt our data, move our services and data offshore, but that just paints a big target on our heads - doesn't actually address the fundamental issue. This is supposed to be a democracy, but I don't see any democratic way of addressing this.
What do we do?
It's what I did.
PS: It is very, very, very difficult, because most of the people you care about will not move with you.
Also, we have no idea whether Lavabit's operator's real situation is (though I certainly fault the government for the ridiculous NSL scheme that prevents him from spilling the beans). Is he objecting to installing a PRISM-style scheme, or to legitimate wiretaps?
It's all about the massive federal money to implement these surveillance systems. They are just doing their jobs because its profitable.
It's the new Military Industrial Complex. War is profitable. So we have to disrupt and eradicate that as an incentive.
Encryption and political solutions are just playing defense. Destroy the core problem : the profit incentive to violate our privacy and constitutional rights.
If instead your concern is with unchecked and expansive untargeted surveillance, we need to push hard for transparency and oversight, which is something that is politically viable and gets 99.9% of the benefit to the average person of surveillance not being possible at all.
Enough people using strong encryption (both for data over the wire and data at rest) makes big-data collection (can't dedupe random noise) and processing/datamining prohibitively expensive if not impossible.
Nobody is getting in trouble for moving their data and services offshore.
Aside from that? I'd suggest finding a few friendly people in various countries and establish a constant /dev/urandom | ssh | > /dev/null stream when your internet connection is idle.
If crypto were easier to use and presented as a default, more regular people would wind up using it and we'd slowly start stymieing the NSA and similar organizations.
Playing politics and calling your congressman isn't going to work in the long term, as you said. We might get one or two laws changed in the short term, but things can change back in the scale of decades and we could be even worse off. The only real solution is to make it mathematically impossible for agencies to read our communications now and in the future.
Governments' justification for surveillance is that it's necessary for fighting terrorism. Okay, I can't say how useful it is for that purpose, I'm not privy to the relevant data; hopefully we can all agree fighting terrorism is a good thing as far as it goes, and it's clear governments believe surveillance is part of that.
And if surveillance data was only going to be used against terrorists, that would be fine. The reason many of us are so wary of pervasive surveillance is that we reasonably fear it won't stop there.
Would it be politically easier, would governments be more amenable, to attacking that problem instead? To say: fine, the NSA and its counterparts in other countries can have their surveillance, but only if the firewall between the NSA and other branches of government is strengthened to stop the data being used for any purpose except counterterrorism.
In short -- on average and with exceptions, we deserve what we are getting.
> Lavabit processes 70 gigabytes of data per day, is made up of 26 servers, hosts 260,000 email addresses, and processes 600,000 emails a day. That’s a lot of email.
http://www.dbasoul.com/2011/1008.html
Update: According to their stats page, they had 410k email accounts hosted before shutdown https://twitter.com/georgemaschke/status/365553445538775040
So the question is, what were people sending though Lavabit that averaged 122K and would have attracted attention? Therein probably lies the reason for all of this.
http://www.salon.com/2013/08/06/cyberscare_ex_nsa_chief_call...
Too bad that he does not have donations page. I would gladly donate. Also - respect for the decision he made. If he kickstarts a campaign for restoring the service I will be there too.
Anyone know what happens if he just says "F it" and writes a massive blog post on what exactly happened or what exactly they said to him?
https://en.wikipedia.org/wiki/Qwest#Refusal_of_NSA_surveilla...
This guy didn't break the law, just "offended" the gov and his life "is over" in that he has a 7 year jail sentence and financial ruin to look forward to when he gets out.
Bradly Manning offended the gov and broke the law, and is facing over a lifetime in jail after some torture like jail conditions pretrial (and nearly faced execution).
Blogging a NSL would probably get you somewhere in between.
To be honest, I'm even a little nervous that something as innocuous as "I wish I could tell you more about the circumstances leading to the decision" could be seen as communicating the presence of an NSL indirectly, and lead to contempt of court.
I don't know how FBI/NSA notifications are received in the US. But you can communicate to your uses any FBI/NSA/LE notification before reading the content. Of course, the notification should be posted to a medium where you don't have further control over, so there's no way for you to remove the notification.
This is very unfortunate and sad. I hope he wins in Court. The NSA/administration are really trying to destroy the last bit of privacy in the world, and they will fight relentlessly until they do (especially if the People aren't fighting back).
Most likely, this is all so secret with secret courts foreseeing secret rulings that unless he has solid capital to burn on legal defense, he won't get far. He won't get far probably either if he has the money. I am sure courts would stretched it in infinity. And I am sure the owner is businessman more than a libertarian.
I guess it purely a coincedence that Snowden used a lavabit address the last few weeks. I guess there is no relation at all.
There's no reason to trust me, but if you send me bitcoins, I'll convert to dollars and send to the fund. You preserve your anonymity. I'll convert all donations at the end of each month.
173WSQxBiwswTtMBxnnhGTZJtTy2RrdLgn
Things like this remind me of the importance of anonymous (or pseudonymous) payment.
I would suspect he has tried to protect his users from a request for information (NSLs are allegedly limited to metadata), but would prefer to discontinue the service than take the other possible legal action (silently disclosing information). Perhaps it is possible he will/has been forced to disclose information anyway.
This link is a video featuring Nicholas Merrill who (if this is in fact NSL-related) went through a similar situation with his ISP Calyx, and gave as much information as legally possible about the frustrating process as a talk at the yearly Chaos Communication Congress in 2010.
https://events.ccc.de/congress/2010/Fahrplan/events/4263.en....
I also recently had a chat with their support about this (before purchasing,) and they told me something like "don't worry, we're not big enough to get hit by this stuff, and if we are we'll tell them where to shove it!" -- it looks like they were telling the truth.
SPOILERS
I thought about how the Gestapo had Lazlow in their midst, at the same TABLE as them, and yet didn't do anything immediately other than deny him further travel. Of course, it's a movie, but it was an interesting thought. Nowadays, if Snowden were known to be hiding in a foreigner's Moroccan cafe, we'ds drone half the building.
Also, I noticed the pride and the wonder that America inspired in the workers and patrons of Rick's. It was a symbol of freedom and opportunity. I wonder how many people see it that way now.
Snowden is a little fish and as such he's being treated, as an example to his uppity peers. His friends are little fish, and as such are being burnt down without a second thought.
Any people who have businesses in the US need to take a serious look at the risk now posed by their own government on the success of their business.
One rogue customer and business could go down the toilet, or you'll be forced to bend your morals to suit a rogue secret fiefdom.
What really have we come to?
Reminds me of Nazis Germany, except replace communist and socialist with Free Thinkers, The Innovators.
First they came for the communists, and I didn't speak out because I wasn't a communist.
Then they came for the socialists, and I didn't speak out because I wasn't a socialist.
Then they came for the trade unionists, and I didn't speak out because I wasn't a trade unionist.
Then they came for me, and there was no one left to speak for me.
This is not new. When a company doesn't comply with fire code, the business is shut down. When a company doesn't comply with law enforcement, it's shut down. This is the case when the law is just or not (until the courts rule it unjust, best case.)
But to your actual point: we've been a nation that enslaved an entire race, locked up another one because of war, genocided yet another, banned speech against the government, ruined careers of famous scientists and actors because of political affiliations, passed laws against sex acts, shot water cannons and unleashed dogs at protesters, shot others, tore up the shanty towns of veterans, trained our soldiers to be racist so they'd be more effective, classified encryption as munitions, and on and on and on and on.
This NSA crap is infuriating, but pretending that we've suddenly turned into Nazi Germany (and conveniently ignoring our history, such as J. Edgar Hoover,) turns a complete blind eye to the fact that we've dealt with this before. We need to tell our representatives that this is not okay -- not hyperbolize it.
Also, and most importantly, quoting things from the Holocaust is absolutely disrespectful to the survivors of the Holocaust and the millions who died. Not only is that poem diluted by it being towed out whenever a government does something that someone doesn't like, but your argument is better served by coming up with something original.
Although I've seen some mentioned, what recommendations does HN have for a new e-mail service? Preferably something stable and also respecting of a user's privacy. Or perhaps you can only have 1 of the aforementioned attributes.
EDIT: I turned my frustration into a $100 donation to his legal defense. I hope that more people do the same.
http://www.emaildiscussions.com/showthread.php?t=66968
If you're a SAAS provider, be aware if you need to shutdown that many users are not prepared for this. Several posters in the linked thread rely on a recover password feature sent to e-mail for access to other accounts. Not a prudent practice but this is common for many.
This kind of dragnet communication surveillance was literally impossible in the 1960s. The social world is still changing in reaction to the existence of the birth control pill. Hell our social reality has already been fundamentally changed on many levels by facebook & smartphones world wide. It's a balance of both.
Any countries friendly to the US are right out. They can tap the lines, but there are ways around that.
I just want to be able to park data where some twit with a piece of paper that says "NSA" on it can't get it retrieved or deleted. Any suggestions?
The alphabet gangs are really getting out of hand.
For that matter, Congress can legally restrict speech in certain national security issues, and has, again, done so for a very long time. The Supreme Court has (in my opinion, correctly) understood that restricting people handling classified documentation from repeating that information is, without extraordinary circumstances (more on that in a second), completely legal, for example.
The trick here is the sheer breadth of the NSLs. I completely agree that they're unconstitutional, and I sincerely hope they are struck down in court. But I hope that I've just highlighted why this isn't a slam-dunk situation for those on the receiving end of an NSL. Add in that, at least so far, any disputes with NSLs have to be taken up with the FISA court, and even wins against NSLs don't actually count as binding precedent, because FISA itself does not create binding precedent.
Congress can, in certain circumstances, make laws restricting freedom of speech. This isn't one of those instances. But suing our way to that conclusion will take time, money, and personal risk for the petitioner.
http://web.archive.org/web/20130116102854/http://raganwald.p...
So, I ask again: at what point is it reasonable to use words like fascist, police state, etc? What is a reasonable tipping point?
1. Can Lavabit now set up shop overseas (with a different TLD)?
2. If not 1, can Lavabit license their software infrastructure in such a way such that someone overseas can set up shop for them?
3. If not 2, can Lavabit open source their software such that someone anywhere else in world can start their own Lavabit?
The point that I am trying to get across is that if Lavabit has been forced to shutdown through no wrongdoing of their own by the US government, a case can be made that certain American government actions are making American companies uncompetitive/non-viable in an increasingly competitive global marketplace.
TL;DR jobs are leaving the United States.
See, this is why "secret laws" are so bad: you cannot legally counteract because you don't know what's legal anymore.
If someone knows of any court precedents here, I'd genuinely be interested in hearing & reading about it.
On a serious note, if you want to donate to their defense fund, consider doing so anonymously. Pay cash for an Amex or Visa gift card, and use that to make your donation.
Maybe someday someone will invent such a system. We can dream.
Can you imagine how strange it would be if such a system already existed, and we failed to use it? But that could never happen.
We need to start getting on both local communities and their representatives to emphasize the long term dangers of NSA's actions towards tax revenues, jobs, etc.
In other words speak their language and make them understand that inaction is not an option.
And yeah spare me the comments about how all Congress representatives are owned by corporations etc. It is still possible to get your representative to pay attention as they still need votes for the next election every two years.
Also, can someone recommend a trusted alternative?
America has NO 4th amendment rights and encryption is now a criminal activity.
Congrats Democrats. Your complicity here has pretty much converted me to a third-party voter.
Should we assume that any browser plugins are potential trojan horses for desktop targeting?
There's a lot of ridiculously smart folks on here who are making good money working on advertising, social networking, and other typical web 2.0 startups and companies. There's nothing wrong with these things, they are certainly enriching peoples' lives and create value.
But if what is going on in the world isn't a clarion call for a lot of these smart people to look into startups, networks, services, software, open source projects, etc that try to defend peoples' privacy I don't know what is.
I urge everybody to look at your notes, ideas, forgotten projects, and see what you can come up with to provide services and ideas and concepts that will work to defend people's security and privacy from government entities that have gone drunk with power.
Not only is this vital to everybody's liberty, but there is a ridiculously huge business opportunity here for services and software that can provide some measure of defense for people.
If we don't stop what is going on soon there will not long be a market for a lot of cloud based services that people are going to want to use.
All of my e-mail is gone.
I was a paying user. WTF.
Can anyone find me a primary source on this document? It is from http://www.wired.com/threatlevel/2013/08/lavabit-snowden/
Almost everybody here talks to move email elsewhere, etc. There are no positive comments.
Does this mean that the US government has won and can do anything they want?
And he references his troubles over the past six weeks, which would be pretty much perfect timing with this.
What if, instead, you host server space within the U.S. and run your own software (email, listserv, whatever) and data on the leased hardware? I would think there's a good argument that Fourth Amendment protections then resume, and the domestic-ness of the server would also mean the NSA is not legally allowed to look at it, at least without a real Article III warrant.
Do similar rights apply IRL, e.g. if you rent a storage closet, can law enforcement just open the door when they wish or do they need to get a warrant?
The real solution, I think, eventually incorporates HSMs. There have been reports of EU authorities seizing racks if servers while keeping them powered up for forensic analysis (presumably key recovery out of running RAM).
You should reconsider foreign hosting the next time, this sucks.
User logs in, password is used to decrypt the private key which is used to decrypt the emails.
I guess this method would mean that the password is not stored as such. Perhaps there is a method of encryption that you could use that generates different sentence structures and word choices instead of obfuscation. So even if a user tried to bruteforce the login, they would always get a message back in the language it was written with no idea if it was the correct message unless they demand the password from the user.
Therefore, all the 'keys' can be handed over but it's all meaningless.
The government said, "you must update your software to compromise your encryption, and deliver us this information we have a warrant for." Lavabit said, "well, no, that defeats the purpose of our business". The gov't said "we don't care, we have a valid warrant" and now Lavabit is out of business.
If I'm right, nobody's files were compromised because Lavabit refused, but I imagine that doesn't bode well for returning user data because there could be huge legal consequences if one of the confirmed users is strongly suspected of XYZ.
If I'm right, it shouldn't prevent the owner from starting a new secure email service outside of the US. I suggest Iceland.
It's up to us to decide if we want to continue having our cake and eating it too. What I mean is that we cannot continue incensing our shiny techno-gadgets based system, and then also be surprised that the same system tries to keep itself 'on top' by whatever mean necessary.
We need to change our attitudes and actions within the current system, anything else is simply a band-aid on an open wound.
But it's technical feasible and a desirable tool to get around being unable to legally open letters.
I really don't want to use gmail or hotmail, so what other service can I use? Ugh. It might be time to get back to the roots and invest more time and effort in decentralized services instead of relying on centralized services.
If you're just a regular joe who, one day, realizes that what he's working on is bad for the public and decides to release it to the public, surely you have had no reason to use an encrypted email service before this realization dawned on you.
Some people are aware of the long history of government surveillance, or of the lack of privacy in regular email. Some of those people will have encrypted their email in an attempt to reduce the amount of casual snooping they leave themselves open to.
Just don't do anything that would attract FSB's attention.
This service however is a general purpose tool. It would attract the attention of the FSB immediately.
You may not include the Drudge Report http://drudgereport.com in your definition of MSM, but they have huge readership. They linked the WaPo story this morning.
Let's start with Dropbox. What's the alternative?
Pretty much identical to Dropbox and just as stable, IMHO.
Pricewise? You can buy an HP Microserver for about $300 that's capable of 12TB of storage on the top end (more if you get fancy with external arrays), whack it into a APC UPS for another $50, and just run it off your home internet connection. Hang a free domain hame at afraid.org off of it, and run a script on the box to keep the hostname pointed at your dynamic IP if your ISP won't give you a static one on reasonable terms.
Seafile maybe?
Or is this appropriate for any SaaS vendor? You're OK with this? Should all customers, even those who really don't care if the NSA could be watching, be put out because some feel that this cause trumps actually doing business and having customer-vendor relationships?
I could see someone suing an SaaS vendor for an action like this, actually. "You cost me $XX in actual costs and $YYY in lost business. Your TOS says nothing about your shutting down because the government asked you to do something you didn't agree with."
So? A SaaS vendor that shuts down operations in to avoid complying with a mandate of a court is taking a major risk of losing all its assets to legal action by the government. On top of that, the risk of legal action by dissatisfied customer is a pretty small marginal cost.
> "You cost me $XX in actual costs and $YYY in lost business. Your TOS says nothing about your shutting down because the government asked you to do something you didn't agree with."
You'll probably find that, unless you have specific contract terms relating to expected costs of failure to provide service, expectation damages of the type you describe are barred by the foreseeability prong of the test for expectation damages.
Technically, you can't say that this happened, because they can't confirm that they shut down for this reason. In light of recent events this seems obvious, but in an actual court, you would not be allowed to use this as a sole defense.
If they don't care, why pick lavabit then?
From my point of view they did exactly what they were supposed to do.