Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

He shouldn't have any "cred" when it comes to security or availability. Maybe with sticking it to the man, but that doesn't a secure service make.

The system did serve sider encryption and decryption. Lavabit has, in the past, complied with court orders for data. They have access to the data. This is the fundamental problem with Lavabit.

It's rather unclear why they didn't comply with the initial court order in this case which was just for data on Snowden's account, but it's clear they could have complied (though maybe not as quickly as the Fed's wanted) and that they have in the past.

So, if you are contemplating using Lavabit II, keep in mind that sooner or latter it will get a lawful court order for data from whatever jurisdiction it's in. Either it will comply with it --- in which case it's street cred is worthless --- or it will refuse with the same apparent "fuck the police" bravado everyone likes , leading to the same set of escalations that happened here. The end of that is either/all of 1) the service failing because of computer seizure/the founder being held in contempt so he can't maintain it 2) Him caving and handing over keys again or 3) him shutting down the service to prevent 2.

None of these are good. If the court order is targeted at you, there is a decent chance your data is handed over. If it's not, there is a decent chance your data is still handed over or the service goes under.

Oh, and lastly, if your worried about the NSA's dragnet surveillance, they can just hack a foreign server.

Don't rely on non-end-to-end secure systems.



There are no end-to-end secure systems.

So you're typing this on OpenBSD? Sure, because that's secure.

Your RPM's are signed, so you're pretty sure they're safe?

Or you're using Funtoo or Arch and compiling from source? Have you read all that source? Even if you did, did you UNDERSTAND it all?

Are you using an Intel Ivy-Bridge or later processor with RdRand?

Are you using a phone?

Do you log into your webmail from one or more locations? How about email?

Do you trust SSL certificates? which ones?

And now... are all of those one other person that you're writing to that actually also uses GPG exercising the same caution? :)

I'm just saying... if you want to know that you're not being sniffed, you have to simply make it impossibly expensive to do so, which probably means get on a plane, meet and hand the person a note, and then burn it, and then scatter the ashes to the seven winds.

Then worry about the metadata of your flight, time, license plate readers, traffic and surveillance cameras.

The basic problem is that allowing this continued, blatant destruction of the 4th Amendment threatens the entire Bill of Rights which ultimately threatens the very foundation of our government and the rule of law.

Legal power, jail, and bullets trump crypto.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: