Lavabit's founder: 'If You Knew What I Know About Email, You Might Not Use It'
forbes.com
forbes.com
My guess (and he intimates this in his comment about backdoors in Chinese products) is that the US government asked him to basically break his entire system so they could do MitM attacks.
The conversation probably went something like this:
USG: Install this machine in your datacenter. Route all traffic through it.
Accept installation of this new fiber demarc and allow us access to
configure this new router. You do not need to know where this
traffic is going. If you refuse, we'll slap you with a contempt order
and throw you in federal prison. If you tell anyone about this, we will
slap you with a contempt order and throw you in federal prison.
LL: Get fucked. I'll shut everything down instead.
-----Why beedogs is shadowbanned is beyond me. A quick glance through his comment history doesn't indicate he's done anything to deserve it.
----
Hey beedogs: I can't reply to you directly because you're hellbanned. Send an email to PG. I'm not usually a fan of posting people's contact information, but in this case it's everywhere anyway - pg [at] ycombinator.com
Can someone at least let me know what the hell I did?
You made this post https://news.ycombinator.com/item?id=6183189 and one of the admins arbitrarily decided that you needed silent punishment. nice eh?
From the FAQ: [0]
> Who are the editors?
> About 30 YC alumni. They can kill stories and edit the titles, and in extreme cases (e.g. spamming or deliberate trolling) ban users.
Are the bans evaluated? Well, no, apparently not automatically. But they can be manually reviewed by sending a nice email to PG.
Granted, its not the most useful post, probably meant to amuse, but a hellban?
Granted, there are other cases like losethos (or whatever his screenname is) that are repeat offenders and deserve to be hellbanned. (Yeah, I know his case is due to mental illness.)
---
It's just occurred to me that you're probably referring to the email field, not the about field. Anything in the email field isn't public, and I'm under the impression you don't get notified when you're hellbanned, which is pretty much how it gets its name! If, on the other hand you put your email address or other contact details in the about field, and they're no longer there, then that's a different matter. For example, my email address is in the email field of my profile but it's not public. The only public information that's there right now is my Twitter name.
It's unethical. Surely locking a thread is ok, but allowing people to toil away without any remark is just plain wrong regardless of who it is or what they say.
I mean even 4chan manages to reach a higher ethical plateau than HN on the moderation front.
edit: sorry, I didn't realize we're talking about an acount that's over 5 years old... so none of what I said applies here, and I'm just as puzzled as the next guy.
(For what it's worth, that was in reference to the "NSA to cut sysadmins by 90 percent" story from yesterday. As a SA, I can tell you right now that if someone decided to increase my workload by 1000 percent, I'd walk, too.)
beedogs, you can probably send an e-mail to the powers that be to restore your account. If they won't, then at least you've got a new story worth sharing.
Ironic indeed.
So this is censoring speech. They have the right to do it as they're a private entity. But don't confuse their right to censor with the definition of censorship. I see that happen a lot.
[Edit: ignore this part, it's wrong] If anyone gets shadowbanned (which can happen for automated reasons), use this link with your IP. https://news.ycombinator.com/unban?ip=ipaddress PG made this link as an automated appeal, he says it only works once.
I don't think that link is for un-hellbanning an account. I think that's if you have a bot that messes up, or doesn't respect the rate limiting expressed in the site's robots.txt, and the IP of the bot gets blocked. If it were for un-shadowbanning, the username would be asked for rather than the IP address. Having said that, I forgot about that unban link -- thanks!
Perhaps they can demand he continue to do business (although it seems like a pretty tenuous request), or perhaps they can blackmail him with threats of criminal prosecution lest he keep his show on the road. Who knows?
Thanks for the heads-up!
The conversation probably went something like this:
USG: Install this machine in your datacenter. Route all traffic through it.
Accept installation of this new fiber demarc and allow us access to
configure this new router. You do not need to know where this
traffic is going. If you refuse, we'll slap you with a contempt order
and throw you in federal prison. If you tell anyone about this, we will
slap you with a contempt order and throw you in federal prison.
LL: Get fucked. I'll shut everything down instead.
The truly terrifying thing about this scenario is that they're likely already doing this elsewhere on a huge scale.If we want to fight the government on this, we'd better know what we're fighting against.
PRISM and upstream are the two data siphoning programs that have names.
http://blog.ted.com/2013/07/17/security-experts-on-the-nsas-...
Bruce Schneier: First, be careful with names. PRISM is a specific NSA database, just a part of the overall NSA surveillance effort. The agency has been playing all sorts of games with names, dividing their efforts up and using many different code names in an attempt to disguise what they’re doing. It allows them to deny that a specific program is doing something, while conveniently omitting the fact that another program is doing the thing and the two programs are talking to each other. So I am less interested in what is in the specific PRISM database, and more what the NSA is doing overall with domestic surveillance.
Yes. The gov is very careful with their admissions. They have and will continue to narrow the focus of the debate as much as possible. Notice the President's proposed compromise yesterday focused on the possibility of reforming part of section 215 of the PATRIOT act. This might answer the original Snowden disclosures and should have been done weeks ago. The disclosures to date go quite a bit further than that which can reasonably be addressed by section 215 reform. They want to play a shell game, and if we aren't observant, they will turn this fiasco into a win for them.
https://www.eff.org/deeplinks/2013/08/guide-deceptions-word-...
If a reporter asks a government stooge if the NSA engages in bulk collection of Americans' data, the stooge can say no with a straight face because the NSA has officially defined "bulk collection" to mean something other than "collecting in bulk." In order to carve through their lies, we need to be able to understand and navigate their twisted terminology.
If you don't have a name to reference something with, you give it one. PRISM is fine except insofar as using it would let the government go "oh we've reformed PRISM, nothing to see here" while continuing all other kinds of malfeasance.
I'm sure he and his lawyers aware, but we've got this cool new thing called Anticipatory Obstruction. It'd probably be a pretty far reach, but stranger things have happened. See http://www.perkinscoie.com/files/upload/LIT_11_06FunkFeature....
That doesn't make much of a difference. The prosecutor only has to make the charge remotely plausible in order to coerce a guilty plea to a lesser charge. (This is what they did to Aaron Swartz.) With a 20-year maximum sentence, anticipatory obstruction is a mighty powerful lever.
Unceremoniously titled “Destruction, Alteration, or Falsification of Records in Federal Investigations and Bankruptcy,” and part of § 802 of the Sarbanes-Oxley Act of 2002, § 1519 provides:
Whoever knowingly alters, destroys, mutilates, conceals, covers up, falsifies, or makes a false entry in any record, document, or tangible object with the intent to impede, obstruct, or influence the investigation or proper administration of any matter within the jurisdiction of any department or agency of the United States or any case filed under Title 11, or in relation to or contemplation of any such matter or case, shall be fined under this title, imprisoned not more than 20 years, or both.
I learned from Hanni Fakhoury of EFF that a proposed defense in this kind of action is to have had in place a strict data retention policy. For example, prior to beginning operations, the policy would state something like "we will retain all data aged 6 weeks or less; older data will be destroyed." Now, you adhere to that policy, perhaps with some activity record around the procedure itself, and your argument is something like, "it is not obstruction and not anticipatory obstruction because we defined and abided by the policy before anything happened, before any event warranting an investigation could occur, and, therefor, before contemplation of an investigation could occur."
Bigger picture, we all know that the reason companies implement email retention policies is to minimize the risk of the discovery process in any potential lawsuit - practically the cost of storage is nil so any savings there is a drop in the bucket. The policies are huge productivity killers for all employees -- everyone I know who has worked under such conditions has had at least one case where they needed information from an expired email that they had not personally archived. The only reason for a company to shoot itself in the foot with a policy like that is because it is easy to imagine a one-shot potential million dollar liability loss compared to the essentially unmeasurable productivity loss spread across the entire company on a daily basis.
government: "Here's an NSL." recipient: "Cool deal. I will respect it and not mention it to anyone, but be aware that from this point forward I will always have a device that will broadcast every interaction verbal or electronic that anyone has to me publicly live in real-time to the Internet. You have the right to remain silent. Do you understand? Anything you say may be used against you in the court of public opinion. Do you understand? If you wish to continue to communicate with me, be aware that any statement that you or anyone from your office makes to me will instantly and irreversibly become part of the public record."
On top of that you can hand them a special email address for their use only and you can delete your own personal email. You can also wear a shirt with friends and family that informs them in big bold letters that everything is a matter of the public record.
This would essentially serve to shield you entirely from secret communication by placing a "force field" of publicity around you. There might be some law somewhere that prohibits this tactic, I cannot imagine how they would counteract this tactic legally so long as you always greet them with disclosure that your are recording everything. I imagine that they could try to force you somehow to interact with them in a location that prohibits recording devices.
If you get an NSL, shut down your business and leave the country.
This sentence (and the fact it is so hard to argue with) is one of the most chilling things I've read this year. Great work! (I guess?)
The thing is, no NSL is keeping Ladar Levison from telling us what he knows about email in general. NSLs are specific to the information being sequestered, everything else if fair game. Yet he says "if you knew what I knew." That's just immature posturing. Tell us what you know or say nothing. Waving around your supposed "big secret" in the press like some celeb for gossip? It's not what honest engineers do. Every time I hear a word from the mouth of this Ladar character, I trust him less.
This idea of "Using a force field of publicity" is completely illogical because all it does it serve to fuel wild speculations and distractions! Where are the FACTS?
Also, AFAIK, they get to read the NSL/FISA warrant but not keep a copy. So there's that, too.
The NSL is still unconstitutional in principle, it's just that it needs to be contested every time they change the law to escape the ruling. Hopefully this time Congress will stop playing along and creating new laws for them.
Watch this and you'll get it:
http://wayback.archive.org/web/20130530023856/http://lavabit.com/secure.html
But I'm still not entirely clear on what lavabit used to do to encrypt email once it arrived on its servers. As far as I can tell, they still store an encrypted version of the private key, that they can't decrypt with the other data they store: but would be able to decrypt as soon as a user logs in, and supplies them with the password (again).So while they don't store enough information to decrypt information, at any point when you log in; you provide enough information for them to decrypt all the stored emails.
Additionally, they could store a plaintext copy of all new email. If the mail you receive is already encrypted with something like GPG, the cannot read it, of course.
You want to be secure, then it needs to be in such a way that there's minimum reliance on a central server. But in that case, what happens if your local machine (which is both your mailserver and an end client) is offline? Should the email bounce around in the network (like bitmessage does)? Or should you notify the sender with the standard "Mail Subsystem Delivery failure" that we all know and love.
Actually after reading this, I want to seriously sit down and write a spec but if I include the assumption that there is a chance for the end-server/recipient to be offline, it throws everything into chaos.
You type your email into the app, which is just a word processor. When you send it - it saves an encrypted attachment, attaches it to the message and sends via email.
The other party will need the client to read the attachment, and their client will need to connect to a secure central ID entity to confirm they are the recipient client which can open the message.
Wait, that's so wrong. Why don't we just fix our laws. ...
Wait, we will always have bad actors or regimes, do we just design for that?
We need a giant public "mailstore" where everybody (or at least a large pool of people) put the encrypted messages with encrypted recipient information. Everybody who uses this mailstore gets a copy of every message posted to it, but unless they are the intended recipient with the right private key they can't make heads or tails of it.
Maybe usenet could be drafted into handling it. Usenet already handles terabytes of encrypted data on a regular basis nowadays.
NB: All presuming NSA or whoever doesn't have capability to break your encryption scheme. Great addition would be if attempt of breaking in to your package could notify you, but that's not technically possible as far as I know.
This requires at least 3 servers to be online at any time. It also assumes client-side key gen and encryption. There are a few more subtleties I'm building in, but that's my thinking so far.
Of course, the gateway could still log your messages, but the same security issue applied to Lavabit. The main advantage is that once the gateway has forwarded your message, no one can force the operator to retroactively decrypt the message.
Bitmessage sounds like one potential solution for this, but it has some scalability issues. Using RetroShare would be another approach.
I very appreciate his actions, what he has felt able to say publicly and his dilemma in general. Part of me wants to call him a coward, but I can not say I would do better. I can't criticize. What this does show is how brave and "heroic" people like Snowden, Bradley, and the like really are.
What would be interesting is to see if he tries to get his story heard via routes acceptable to government, and if so, what happens.
Where have you been all this time? Have you not read the news recently? Basically every US IT company is being NDA'd and backdoored/taped. Lavabit is the first one in choosing a different option: closing the business.
What about an alternate messaging system addressIng these issues ?
Sender ----> SMTP ---*unencrypted*---> SMTP ----> Recipient
I'm leaving out a lot of transport detail for brevity, but that's the essence.Also, email is generally stored unencrypted at rest. Even if you take precautions to secure your own mailbox, the recipient might just have it floating around in plain text in their Gmail account, just waiting for it to be nabbed by whoever can get a court order, or whatever.
Also, even if your email is encrypted, the metadata isn't. So you can figure out who is talking to whom, when, and usually from where (by the IP address). Also, there are a lot of headers indicating details about your computer (if you used a fat client rather than webmail), such as the user-agent header which indicates what software you're running (e.g. Thunderbird, version x, on Linux/Windows/OS X for x architecture, etc) which can give clues about how to attack that client with some 0day exploit.
So it's only not encrypted in 20% of the time (depending on who you communicate with).
SilentCircle's other services are still up and running, for example, because they can be made secure.
Ironic in SilentCircle's case (if you're an HNer) is that PZ noted to the BBC how important his service was because it protects Navy SEALs deployed to areas fighting terrorism where they might otherwise be detected.
In case he was talking about unencrypted email, it's obvious:
-> Only use encrypted email (with an email client).
In case he was talking about encrypted email, all the "metadata" is still open (sender/receiver address, time/frequency, message subject). Then you can cross-reference that data with other data to get a more precise picture of the users.
-> Only communicate using one of the "darknet" platforms: https://en.wikipedia.org/wiki/Darknet_%28file_sharing%29
But this isn't much different from the technological metadata needed to transport snail mail (the sender of an e-mail is usually, unless messing around, known whereas snail mail only has a return address ; the subject field isn't mandatory).
Mail encryption ensures the same level of privacy (regarding the 4th) a user of snail mail could expect.
it doesn't have to be used for all communication.
assume a world where all your emails are archived in publicly accessible databases. you've lost privacy, but could it still be a useful tool?
send birthday emails. send your friends funny cat videos.
you don't have to use email for everything you used it for before -- you can just use it in different ways. i would still like to be able to near-instantly communicate with relatives across the world.
i know bacon clogs my arteries and making bacon has a terrible environmental footprint relative to eating only grains, but i love it.
the article is about not using email.
no tool is perfect. you know what would be great? if hammers cured cancer. they don't though, so we just use them to hammer nails into wood.
speaking to people in public places is also a way to communicate, though equally bad for privacy. if there's nothing you can do to change the privacy attribute of "speaking to people in public places", does that mean you should never do it again?
or: use codes that only you and the other person know, hold hands and tap morse code into each others palms, find secure rooms.
people get upset when one tool doesn't do all the things they want, but its a weirdly tech centric thing.
"your startup doesn't do X so i'll criticize it". you can play the "need more features" game ad infinitum -- but nobody criticizes cast cups for their failure to keep drinks cold indefinitely or couches for failing to give them back massages.
Because a feature makes a tool better doesn't make it a requirement for its usage.
What? What am I some sort of criminal on the run?
You're missing the point!!! -- This whole damn thing is completely unacceptable.
I don't give a shit about "legal" the government is an institution made by men, and these actions and programs are wrong. The term "legal" holds absolutely zero meaning to me any longer.
I am in no way "kicking and screaming" in an immature manner, I am instead saying "fuck you" to a system with which I will acknowledge no further authority over me.
I am no longer interested in the opinions or doctrines of the agents of all systems in this world which are not singularly for the advancement of Humanity as a singular species.
I am not american, Jewish, atheist, ethnic, sexually-preferential or any other wedge label.
I am a conscious being who is, from this point forward, only accepting of an advancement of the Human Race without any profit motive (money, ego, power, resource) outside of that which benefits the entire planet.
1. Documenting everything so it's actually usable. At a minimum, "here is how to install the dumb thing" should probably be documented.
2. Often times there are hard-coded values that would need to be extracted out for security reasons or to simply allow someone to install it on a system not quite like yours.
3. Often times there are other dependences that would also have to be open sources such as modifications to libraries, internal libraries released, shell scrips, cron jobs, messaging queues, delayed job worker tasks, etc that the system may rely on. These all need to be packaged up, documented and/or released.
In short it is a ton of work to take something that is running in our way on our hardware and generalize it enough that anyone else can run it.
On the other hand, you wouldn't need their service to give you the protections they offered. Essentially, encrypted email storage. You can get that mostly off the shelf using any linux distro if you run your own mail service.
I didn't use Lavabit because I mostly don't use email, but I'm guessing Lavabit was an easier service to use rather than setting up your own email service. I think @ssimpson has a point though. I don't think he [Ladar Levison] would be turned off by the difficulty of the task of open sourcing his project, but he may be waiting to see how the case works out first.
Thanks for your explanation.
http://wayback.archive.org/web/20130530023856/http://lavabit...
As far as I can tell it is a service that suffers from many of the same things as other services, especially concerning email that is sent to a recipient in clear text:
1) The email can be intercepted in clear text
2) If the service is compromised; a plain text copy can be made
3) If the service is compromised; a copy of the session key can be stored
4) If the service is compromised; a predictable/insecure session key can be used
5) They store a copy of the secret key; if the service is compromised - all session keys can be recovered when the user logs in (provides the password).
I've thought about engineering a similar system; but one based around GPG -- have users upload/associate a public key with their account, and if they receive unencrypted email encrypt it to them using their public key. 1,2,3 and 4) remain though -- and 4) may be the worst as it is almost impossible to detect/defend against AFAIK.An alternative would be to set up a service that detects whether or not incoming mail is encrypted, and rejects it if it is not (along with information of where/how to install and set up GPG).
As others have mentioned this would not help with the who talks to who meta-data problem.
Is it really what I understand from this or LL is trying to say something else.
But my guess is he's referring to replacing the login page's Javascript code with a malicious one that phones back the plaintext password. Kinda like a keylogger.
However; if you could intercept this password, and already got a copy of the encrypted private key as well as the encrypted data from lavabit, you could then decrypt the data.
Presumably lavabit didn't want to back door their services, by either storing a copy of the session keys, the password, or the plain text -- and chose to shut down instead.
I am a new immigrant to America. I came with my wife from Australia 8 months ago. All my life I heard about how the US supported the freedom and rights of its people, and now that I'm here, I find that that was a sick joke. This place is a KGB state on the brink of happening.
I just thought America was a place where this stuff wouldn't happen, and where the people were protected by the Constitution. Guess I was being naive and idealistic.
The moral of the story is that the US is not nearly as bad as people might think/say, but governments watching people's every move is the first rung in the 1000 step ladder down to hell.
However, there is a difference here in frequency/intensity. My great grandfather's brother was innocent as far as I can tell. He held a fairly high city-level position as a factory manager, so when he spent enough years in his job someone decided that he got a little too comfortable and might nt fall in line if push came to shove (remember this was Stalin, the paranoid maniac bank robber who killed tens of millions of people for fear of being replaced). This kind of stuff does not happen in the US. You have to piss someone off at the Federal level to get on a kill list. Bad mouthing the government is still fine so long as you do not leak actual facts.
Circumstantial evidence is apparently now enough to both be disappeared and assassinated (never mind the collateral damage). No judge, no jury. This isn't the rule of law any more.
Add to all this the fact that we can now assume the NSA possess comprehensive evidence that could be used to indite major financial institutions in the wake of 2008 -- and yet that is seemingly impossible. The fact that "it's not quite as bad as Iraq was under Saddam Hussein, only with less government health care" -- isn't a very strong argument.
"So the poor and the ignorant go to jail
while the rich go to San Clemente"
-- We Beg your Pardon America
Gil Scott-Heron, 1975Circumstantial evidence is perfectly legal and does get many people convicted every day. One piece may not be enough, but you get supporting evidence and you have your case --it's a very basic tool.
Indicting savvy bad bankers is very very hard. That and when the investigative ranks (those who understand the intricacies of finance law, etc.) are reduced to a fraction of what they were makes it even more difficult.
1) killing someone over circumstantial evidence alone is questionable
2) killing someone based on unilateral interpretation of any evidence (as opposed to the result of a verdict from a court) is questionable
Other than that: Are you seriously arguing that it is harder to verify if someone conspired to defraud, assuming the NSA could provide rich evidence of both communication and content, than it is to prove that someone is conspiring to do harm?That is: in the latter case you (would/should) have to prove intent before any crime is committed (and that a crime is likely to be committed) -- while in the latter case you would only have to be able to document the most likely path that led to recorded events taking place? You're even able to document profit, in the case of the banks.
to the other point, yes. Securities laws, from what I can tell, are very convoluted. Even experts find it hard to tell when one enters or exits the grey areas. In addition, in 2008, there were other considerations to take. Until, I know better, I don't think the NSA is allowed to use whatever information they have, to prosecute domestic crimes. They may 'tip off' the SEC, etc. but the SEc must gather their own info and evidence. Also, it's not as if the NSA are experts in Securities. They look for physical threats rather than soft threats to the economy/population.
See some review of this in this NPR piece: http://www.npr.org/2011/07/13/137789065/why-prosecutors-dont...
No, this isn't Stalinist Russia, but the question is, if we continue down this route, could we BECOME Stalinist Russia, or something similar? I think that the consensus on that is definitely yes. Intimidation of journalists, secretive detainment, interrogation and assassination, the USA is definitely headed down a dark path.
However, I want to emphasize that if you invoke the slippery slope argument, you better realize that the slope is very very slight. Instead, I think it makes sense to talk about things on a case by case basis. For example "NSA does more harm than good" is a more rational and direct argument than "NSA is the coming of Stalin to America".
On top of this, there is the big picture: the US's largest export is weapons. This leads to a lot of people hating the US, which leads to terrorism. That leads to counterterrorism in the form of drones and spy agencies. Even if the US made nice with the various governments around the world that do not like us, we would be stifling our main export, so there is no incentive to do that.
If two countries have a problem then the problem isn't worth fixing?! I've never understood this retort. This is the USA, we're supposed to be crazy about freedom not "eh, we're slightly better than the competition for now so let's take a nap and see where we wind up in 10 years."
I was in love with the passion of the American people for civil rights. I visited in 2004 and read Archibald Cox "The Role of the Supreme Court in American Government" and "Freedom of Expression" in the Boston Public Library after some college student left it on a table, and then went and annoyed other Australians about it for years.
I came here because I wanted to create a better life (the same as any other immigrant), not because I had any axes to grind. Can you blame me for being disillusioned? Again, not cool.
I would have thought Australia was at least as free and as prosperous as the US plus better healthcare.
Are you sre you didn't just make the mistake a lot of holidaymakers do? That is, viewing your vacation destination through rose coloured glasses?
If you want me to justify my reasons for moving here, fine. Australia was starting to slide into a quiet recession(link below), and I was having serious issues with some of the decisions the government was making.
That and I had always been fascinated by the "American dream". We saw it in movies and theatre growing up and I wanted to check it out for myself. Is that so culpable?
http://www.news.com.au/business/worklife/brace-for-a-white-c...
In Canada, there is less isolation/insulation. I've stated for many years now that I'd refused to move to the US until their country is fixed. Which is a damn shame, because there is so much cool, interesting shit happening.
It's pretty heartbreaking.
The irony is that the original impetus for the Federal government to assert supremacy was to give freedom to the slaves -- the right thing to do, but it's unlikely that we'll recover from that power shift any time soon.
Based on the fact that a number of them are talking about having lost data, I suspect that at least a significant number of customers only used webmail to access their accounts, so they never had a local copy of their data.
Which will still see your data unencrypted. And there are open-source browsers too.
In any case, as I said several posts ago, a number of Lavabit customers were complaining about having lost their stored emails; if they were using a desktop email client with IMAP, that wouldn't be the case.
Good chance he had some clients who'd rather see that data destroyed.
I hope he advised all users to backup regularly, though. :)
* Keeping your secret keys on your disc. Now you crash it, format it, etc. and lose all access.
* Smartcards -- better not lose it!
The reason people use Lavabit is that they want to maintain access regardless of the system they connect from. Of course that also means that other people can gain access (your security is now reduced to the strength of your passphrase, a classic bad strategy), but Lavabit users do not really care. Hushmail and Lavabit both had headline-making stories about how they handed plaintexts over to the government and did not lose their customer base over it.
"What happens to your customer's e-mails and data?
Levison: I'm looking into setting up a site where users can download their data and set up a forwarding [e-mail] address, but that may take a week or two to set up. That's all I can do until I feel confident that I can resume the service without having to compromise its integrity.
I will make it clear that I don't plan to use any encryption for that site. [People] should only use it if they feel comfortable with the information being intercepted. And yes, I do plan to have that disclaimer on the site.
Unfortunately, what's become clear is that there's no protections in our current body of law to keep the government from compelling us to provide the information necessary to decrypt those communications in secret.
I'm still looking at seeing if that's even logistically feasible -- there's half a billion messages [sent in the 10 years Lavabit operated]. By shutting down the service, I will be losing the infrastructure that I used to support all those people.
There's stuff that I can't share with my own lawyer. This is going to be a long fight."
Wow. I didn't know you could be gagged from talking to a lawyer.