Lavabit needs your help to fight for the right to keep emails private
rally.org
rally.org
Online donations are notoriously lacking transparency. Nearly as bad as the FBI/NSA (:P).
Is that an oversight, or is it just because the 501c3 has not been finalized yet?
Consider accepting bitcoins, if you don't already. (I didn't see a bitcoin address on the rally.org page).
What I do care about though - how far in the appeals process will this take the case? Answer: $40,000 is not even 1/10th of what you'd need to make it to the supreme court, paying full freight. So assume there's going to be another fund raiser.
Should we just walk away from an opportunity to expose the demands of the FISA court in broad daylight at the behest of a superior court because they didn't present an itemized budget and an exact timetable dependent on a bunch of external circumstances beyond their control? Uhh, no - drop $5 and move on.
The guy could have easily folded, like hundreds of other companies, without a word. Instead, he shut down the service to protect its users. I would have given him $30k just for that as a bonus for being awesome.
He's a damn hero if you ask me. Along with Aaron and Snowden. They are a few and deserve every support we can give them. Even if they buy a pack of beer with fund money.
Oh give me a break with the hyperbole. The NSA likely doesn't give a fuck about your activity of pissing and moaning on hacker news.
[1] http://arstechnica.com/tech-policy/2013/05/govt-agrees-to-de...
But thanks for being so pleasant about sharing your assumptions.
...
And come on, there's no need to be pleasant the umpteenth-thousand time that someone mades a snide, ultra-paranoid remark about America that scrapes the bottom of Godwin's law.
Yeah, sure...
"Cyberscare: Ex-NSA chief calls transparency groups, hackers next terrorists"
Neither are most (all?) of the people who are detained at the airport, denied entry into America, or otherwise harassed by our government. What exactly is your point?
The NSA might be greedy for info, but they're not stupid or act [as an agency] irrationally.
[1] http://en.wikipedia.org/wiki/Martin_Luther_King,_Jr.#FBI_Sur...
That is rather the point though, isn't?
There are many other countries whose authorities would absolutely care to detain foreign nationals over being smug.
What makes you believe that some individuals within the NSA are not of that type of person?
Because the NSA just records the information, they don't get to make the call on detention. Gitmo isn't full of people that called the government a bunch of jerks or complained about wiretapping/taxes/etc.
In my humble opinion, the greatest abuse that could come from this wiretapping is much more mundane and offensive - NSA employees cyberstalking and mining data of sexual interests/current partners.
gitmo is actually full of people whose crime was to piss someone in off, get handed in for a bounty, then get caught in the middle of Republicans rousing their inbred base by opposing trials.
From the wiki article: "The Center for Policy and Research's 2006 report based on DOD released data, found that most detainees were low-level people who were not affiliated with organizations on U.S. terrorist lists." [1] One example: "The U.S. offered $5,000 per prisoner and distributed leaflets widely in the region. A perfect example would be Adel, a Chinese Uighur and dissident who had been sold to the US by Pakistani bounty hunters"
[1] http://en.wikipedia.org/wiki/Guantanamo_Bay_detention_camp#D...
Link to where this was abused to punish an innocent person?
It makes no difference whatsoever if these tactics were ever used against an innocent person. These tactics are violations of civil rights across the board. Yes, guilty people have civil rights in this country. No, our justice system is not meant to ensure that every single guilty person is punished for their crimes.
I dont know how you know what kinds of people are detained in Gitmo and other more secret locations? I believe that information is specifically kept secret?
EDIT: I am thinking you meant that you hope that Gitmo and other similar but more secret places do not contain people who piss and moan about government surveillance?
please note: IANAL, but that's what I gathered so far.
[1] Probably closer to an ordinary 5-15% once page views are factored in
Since Lavabit operates in the US and we can't tell which of our users is an American, and which are foreign, I'm of the opinion they all have the same rights.
I agree.
But the [US] constitution only protects our right to privacy on American soil...
I know. ☹
Join me in donating (even/especially you other non-US citizen HN'ers), to prove PRISM et al unconstitutional, and preserve all our rights!
Even if Mr Levinson wins his action against NSLs, that will remain true. Non-NSL warrants conform to the Constitutional protections and will continue to be served and fulfilled.
So the question is: should encrypted-hosting service designs be illegal unless they have a backdoor for the government and the service provider to get in?
We really don't even need the NSA shut down, or for it to stop the mass surveillance, in order to have secure and confidential communications. Mass wiretapping is evil but it is not such a threat as long as we are legally and practically free to work around it.
The latter freedom is what the government is now attacking. Th US currently has no statute prohibiting "encrypted-hosting service designs [without] a backdoor for the government and the service provider", nor is there any statute commanding individual 'A' to enable the government to cryptographically impersonate 'A' online to deceive 'B'. But now, the USG has practically effected these policies by secret orders approved only by secret courts, with threats of prison for even revealing the existence of such orders, and preventing the subjects from challenging the legal basis in public courts according to Constitutional principles.
This really has profound implications. Do you have a right to run software of your own choice on your own server, to provide a service that enables the fundamental human right to confidential communications? This is an important measure of the descent into fascism, totalitarianism, police state, or whatever you want to call it, and further trashing of the rule of law.
IANAL, though.
If you want private email, you need to encrypt locally before the message is sent and decrypt locally after the message is received -- end of story.
But does that mean that because you can compromise a system then the government is allowed to force you to compromise your systems to utterly betray the purposes for which they are designed and then lie about it?
I couldn't compromise the system... but as it turns out the feds have a few secret capabilities the public doesn't about... they still need certain things in order to break the security though and that's what I'm fighting. Both for the ability to tell people what those secret methods are and the right to not be forced into helping the feds compromise my system/service...
The reality is that laws can change, and that when we create systems that are technically easy to abuse, there will be people who push for the law to change so that the system is legally easy to abuse. The police are always look for more power, and if you have something like Lavabit, the police will want to have on-demand access to it -- and they will want to reduce the barriers to getting a warrant, or even remove the requirement to get a warrant in the first place (like, say, if the emails are older than 180 days). By having a back door inherent in its design, and by positioning itself as the gatekeeper for that backdoor, Lavabit invites abuse and its users were lucky that the founder is a man of principles.
To be clear, I think it is fantastic that you took a stand on this issue, and I wish more people had that kind of spine. The problem is that your system depends on you being a man who sticks to his principles.
Imagine the existence of a guy called Madar Mevinson, who runs a company Mavabit... that publicly shuts down over privacy concerns, but then reopens in triumph after a court battle... but little did we know, Madar was a government operative the whole time! (Or a non-state-actor criminal. Or just a creepy stalker. Whatever.)
And, because this is the internet, I'll mention that I am absolutely not suggesting that these things are true of Mr Levinson and Lavabit. But it's a bad security model to trust the ethics of a stranger, and from what I understand of Lavabit, that's required here. Maybe I misunderstood Lavabit?
PS: even so, 'mad props' to Mr Levinson, for taking a brave and productive stand
PGP's model works pretty well. You get the key from a key server, you communicate through a (presumably different) mail server, and if you need more protection you use the web of trust. Imperfect, sure, but no security system is perfect, and at least with this the barrier to spying is high enough to stop mass surveillance (not true of Lavabit, whose users just have to be thankful that the service was shut down over such a request).
All schemes to verify identification of an entity with a key are probabilistic and in some degree unreliable. Even if the correspondent is your best friend and you exchange keys in person, there is the possibility that one of you will fail to maintain exclusive control over his/her secret key. The question is which methods are best in a relative sense - and what qualifies as "good enough" is for each operator to decide.
Of the two major alternatives, the CA system (and other schemes of similar design, relying on trusting third parties) and the web of trust based on individuals' estimations - of these, the latter is clearly more reliable. It was hard to convince anyone of this years ago, but the tech world has (mostly) now recognized the folly of third-party systems after painful experience.
EDIT: Corrected "former" to "latter", per post below - thanks!
> Of the two major alternatives, the CA system ... and the web of trust ..., of these, the former is clearly more reliable.
That is, you wrote "the CA system is more reliable than the WoT".
I'm pretty sure you didn't mean what you wrote. It seems to contradict the rest of your post.
Elaborating for the benefit of other readers: we have lots of evidence that the Certificate Authority system has been repeatedly compromised, certainly by state actors and probably also by (other) criminals. There are semi-solutions, like certificate pinning. One alternative (the only alternative I know of) is not trusting any Authority to get good certs, but rather getting them yourself, or from people you trust, or from people trusted by people you trust, etc... thus the Web of Trust. This alternative is pretty poor, but it might be less broken than CAs.
Also, I don't know if it's currently "legal" or not to demand companies to keep encryption keys of what they're encrypting, but I'm pretty sure it's unconstitutional. So encrypting communications end to end should be constitutional/legal. The companies can still do that (if they have the will/customer pressure).
As for coerced backdoors, like they tried with Lavabit, that's just disgustingly immoral, and definitely unconstitutional.
You make an interesting point about encryption keys; it is unconstitutional to demand that an individual hand-over his keys in a speculative manner, but is not considered self-incrimination if the prosecutor knows that the relevant document is encrypted. for example, if the individual boasts that 'The Man can't read my encrypted tax evasion plan'.
But I have no idea how that reads-across to a corporation.
That is probably a legislative challenge, not a legal challenge. Is he setting up a PAC?
Even the Lavabit-Founder just wants to fight for the "rights of the American people".
Don't the American people get it, that what this form of Chauvinism really brings is bringing the world up against your country? Until America recognizes, that it is not the pride of creation, this sentiment will only grow and Americans worldwide will be regarded critically.
With every politician, that promotes this chauvinism, being elected, everyone in the US is seen once more as a supporter of these views. Not the best idea in the long term I fear.
Domain Name:LAVABIT.ORG Created On:21-Jul-2005 21:45:20 UTC Registrant Name:Ladar Levison Registrant Organization:Lavabit LLC Registrant Street1:3930 McKinney Ave #576 Registrant City:Dallas Registrant State/Province:Texas Registrant Postal Code:75204 Registrant Country:US
Mail him a check if you want to help and don't want to use electronic means. Sure, it could in theory be a scam or waste of money. But we KNOW the NSA is a scam, a waste of money, and a danger to our values.
Personally, I trust him. I received a hand-written note thanking me for a donation. Good luck Ladar!
What about the privacy rights of the 95% of the world's population that are not American people?
What about the rest of us?
But hey maybe the donations will help too
(NB: I have no idea if they did/did not refund any money; I'm taking it as a given for this comment but I'm completely relying on the comment chain for the unverified story.)
I think it's MUCH MUCH BETTER.
> For all we know the founder is just some wacky libertarian taking an opportunity to give the gov some bad press.
Needless FUD. For all I know you're an alien from outer space, for all I know we're all in The Matrix, for all I know everyone here is an automation-script and HackerNews is an experiment in how long they can keep me, smtddr, believing that I'm talking with real humans. You can't live life in FUD. I think it's more likely that you're a NSA/USgov shill who just created this account to post this comment... than the Lavabit founders set up all this encryption to a point that even Snowden trusted them, just to turn around aand give the government some bad press. And seriously, "wacky libertarian"? Define that for me. And "just to give gov some bad press?" Why? What do libs have to gain by giving USgov a bad name just for the sake of it? The USgov has given itself a bad enough name just by the NSA leaks, they don't need any help from any "wacky libs".
bankruptcies are public anyway.