Takeaway for fellow hackers: If you are building a system that stores user-generated data, prepare for the eventuality that someone other than the user will demand to see it.
In general, the prevailing theory is that all companies are required to release private keys or passwords needed to unlock evidence. As a consequence of Lavabit fighting, they likely got slapped with some pretty harsh contempt of court rulings, including a demand to record all private keys needed for decryption going forward. The worst case (that I can talk about) I saw involved requiring a specific employee be demoted due to improper care of a company's systems.
What's sad is that because Lavabit was such a small service provider, they never had the previous rounds of government threats and must have been caught off guard. As I've said in past posts (before Snowden), it is common knowledge among large-scale service providers that the local government can always come in to take a look. Doesn't matter if you are in the US, EU, or China, you have to comply. I've seen the US DOJ threaten pretty harshly a customer who simply asked about 'options' of how to comply.
Past post with explanation: https://news.ycombinator.com/item?id=5754641
P.S. Right or wrong is a separate conversation...
Would you expand on this? Are you saying that a court was meddling directly with an individual company's hierarchy?
If it's not clear, there were strong personalities involved. One way to tell the story is the director went out of his way to poke a bear and got mauled. Another way to tell the story is that a bear went walking down main street looking for trouble ("How do we know you didn't change the retention policy to protect the individual?"). In both cases the guy lost his hand and the bear is still loose.
we simply can be guilty hiding the nothing we have to hide
http://www.amazon.com/How-Be-Invisible-Protect-Children/dp/1...
More concerning are key disclosure laws [1] and their crazy penalties that seem to be creeping in all over the world.
You also need to take reasonable measures to preserve relevant data when you have reasonable cause to suspect that litigation or an investigation will begin.
Not having a policy can hurt you. If you have no deletion/retention policy, and happen to destroy data for some random reason when a litigation begins, you or your company may be in trouble.
Note: IANAL, and different industries or data categories have specific legal requirements or best practices for retaining things.
I don't see why his 10 years of work would be lost.
It's risky to relocate the servers in another country. You will have to obey the other country's laws, but the US gov will still claim jurisdiction if the staff and/or owner is in the US. The US will even claim jurisdiction as soon as you use a ".com" domain [1]
Of course the hosting nation will also claim jurisdiction. So relocating your servers to one country while staying in another will expose you to two national laws as well as any international agreements between these nations.
[1] Richard O’Dwyer, a UK citizen who ran a UK-based web site, was facing extradition to the U.S. because he used a .com domain. - http://www.theguardian.com/law/2011/jun/17/student-file-shar...
If the purchasing party is less scrupulous, you've thwarted nothing. In extreme cases (or for smaller companies), the purchaser could even be a government front.
(http://www.pcpro.co.uk/news/361693/teenager-jailed-for-refus...)
No it's not. This is wrong, plain and simple. Wrong is wrong, and black is black.
As long as you can't comply, I don't think there's an uncounterable risk in the US, since we don't have any key disclosure requirements (the exception being CALEA, which only applies to the PSTN; I'd skip CALEA for an interconnected VOIP system and fight them in the courts/media, personally). Presumably they could put other weird pressure on you like threatening to investigate your nanny's immigration status or whatever, but enh.
I still maintain that if you do things properly, you can operate safely in the US while resisting pressure from USG. You can't literally wipe your ass with an NSL in front of the agents, but if you don't have it, and can't get it, they're at worst a DoS. Forcing a provider to implement a huge new logging infrastructure would be an interesting 14A issue, and one could have a system where even that wouldn't recover customer keys.
IANAL of course.
Not that defend Hushmail. I do not, fuck 'em for that. There are plenty of services like Lavabit that avoid that problem, but that requires intelligent users/criminals/what-have-you.
Which is equally insecure, as the company could easily insert a back door the next time you load the applet. Hushmail was and is snake oil.
Unfortunately, the trust problem you mention is pervasive. It was a signed applet IIRC, but we both requires you trust the original and modified applets from the developer. I am wishing someone released an auto-encrypting PGP service and client, open-sourced on purpose.
We all know only four people would read the source of that, and two of those would verify the dev key given with the release. :-)
Spence: You think too hard. Sam (DeNiro): Nobody ever told me that before.
I kind of wish there were a (well armed) organization which did this for other projects.
From wikipedia: "The issue originally revolved around the use of the non-Java version of the Hush system. It performed the encrypt and decrypt steps on Hush's servers and then used SSL to transmit the data to the user. The data is available as cleartext during this small window; additionally the passphrase can be captured at this point. This facilitates the decryption of all stored messages and future messages using this passphrase."
"Hushmail has stated that the Java version is also vulnerable in that they may be compelled to deliver a compromised java applet to a user.[5][7]"
In [7] "Brian" working for hushmail responds to a wired journalist agreeing that the applet was an attack vector and Brian even points to a schneier.com article stating the same[2]. He did weasel around a bit about "viewing applet/HTML source" which he admits is no use for determining the validity of the applet as it is compiled.
[1] https://en.wikipedia.org/wiki/Hushmail#Compromises_to_email_...
[2] https://www.schneier.com/essay-191.html
[5] http://blog.wired.com/27bstroke6/2007/11/encrypted-e-mai.htm...
[7] http://web.archive.org/web/20071019225245/http://blog.wired....
It is not just about having a court order. The court order is not some kind of secret key that decrypts messages, it is just a way to compel Hushmail to decrypt those messages. Pointing a gun at a sysadmin would work just as well. Paying a sysadmin would also work. Getting a spy to work for Hushmail would also work.
Let's say you are trying to protect the names of activists in China. There is no reason to think that the Chinese government could not find a sympathetic Chinese immigrant / national with an IT background who is willing to pass on some messages every so often. You can imagine other scenarios -- maybe you have highly valuable business secrets, maybe you are running a political campaign, etc.
Snake oil is the right term for Hushmail, because that is what they deliver. The only term that is more polite than snake oil is "key escrow," but why should we be polite here?
The warning they gave out was to point out lower security, it does not absolve them of the obligation to try to keep their severs secure.
The guy who runs the service is one of my best friends. He's the kind of guy who would burn the server farm to the ground before he did something that violated the terms dictated in his privacy policy.
I was curious to know, of course, but I'm afraid that this could somehow be used against him later.
No, this has nothing to do with common criminals and everything to do with Snowden.
He shut it down because that was the only way to legally prevent the government from spying on his users.
http://securitywatch.pcmag.com/privacy/309277-judge-says-fbi...
I wonder why he didn't challenge it.
The Government has been trying to get into Lavabit longer than that.
Although, perhaps they already knew that Snowden was using Lavabit and started the process immediately after his flight to HK.
If anyone can recommend someone who can provide counsel pro-bono let me know and I'll forward the message along.
I bet that data are still valuable to the government.
I have been thinking of starting a business in the privacy space. This has shown me that that all customer data needs to be periodically obliterated in safe way and that a kill switch or nuke button is needed as well to destroy everything on a moment's notice.
Where and how to host is a major concern. Cloud, etc., is obviously out of the question.
If you'll be trying to keep this secrect by creating small cells of people not knowing each other and smart mailboxes preventing people exchanging t identify each other, you'll become suspect of supporting spying activity.
So you better work for the minimal number of clients and charge a lot to remain sustainble.
My understanding is that as long as keep the info concentrated in one spot (i.e. Paper mail) it is easy to grab it. If you dilute and spread the info using shared secret and hide it smartly in images or random text, this info would be much harder to catch but could use conventionnal transport means.
Extending this idea further, turn the mail network into one big world wide hologram. The information would then be spreaded, available from everywhere, very hard to censor, and private since you need some specific reference signal to extract the info. It's like shared secret.
Note however that the need to catch evil people using such communication system for evil means is needed. Just considering our own privacy regardless of what can go wrong with such system is in my opinion selfish. We will always need method to protect against abuses.
(might have to have multiple vessel's for redundancy purposes)
At least when the ship disappeared off the face of the earth it would be easy to figure out what happened.
The problem is that you have to connect up to the Internet somewhere, and they can always get you there. Either tapping and listening in on sessions, or just plain disconnecting you.
Companies could at least insist that intra-company email is encrypted, which would be a huge amount of their normal communications, and then extend that outside their boundaries with partners who also accept (say) S/MIME.
At present I sign my mails but like you have no clients who use encryption.
The core problem with widespread crypto use today is not encryption, it's trusted key exchange.
But as it happens, yes, I trust our crypto developers. They're much better at it than most of HN.
And the rest of the code is pretty shitty in places.
Of course, an MITM attack could hide the STARTTLS option and there are questions around the strength of the CA cert infrastructure, but SMTP is not just plaintext.
So even if I setup and host my own SMTP server, and even if I verify the TLS certs on my side, I have no way to verify that I'll get (1) A TLS connection (2) with an authenticated cert all the way to the ultimate destination.
It's beyond my control to ensure that I'm secured when emailing to an arbitrary domain with arbitrary configuration.
Can the US serve a warrant to a server in Europe run by Europeans? I was assuming the answer was no, in which case you don't need violate any laws or worry about repercussions.
The whole protocol and mail delivery system is fucking hopeless.
As an ex-ISP mail architect and ex-operations guy, I hope the whole existing email protocol suite and architecture dies in a fire.
how is that possible? I'm curious to know as to how they achieved that technically. I mean if the user is reading an email in their browser, then it would've had to have been created on the server first.
http://www.wired.com/threatlevel/2007/11/encrypted-e-mai/
> a federal prosecution of alleged steroid dealers reveals the Canadian company turned over 12 CDs worth of e-mails from three Hushmail accounts, following a court order obtained through a mutual assistance treaty between the U.S. and Canada.