8 ms·
Lavabit code open sourced
- hartator 10y agoIt's not the original Lavabit, but dark mail.
- etotheeizzo 10y agoStill will lead to lots of development in the area. I didn't even think of working with something like this due to the learning curve, but this might help kickstart that.
- NetOpWibby 10y agoWhere's the original Lavabit?
- bt3 10y agoI would imagine a stipulation of the original subpoena would involve not sharing the source of Lavabit. It sounds as though what Ladar has done is re-engineer Lavabit in the form of Dark Mail to bypass any gag orders.
- MichaelGG 10y agoI don't it. LE should love a fundamentally insecure design like Lavabit to get picked up. When I looked at the Dark Mail draft it was incompatible with regular email. And the trust models it has were basically the same as you'd get with Gmail today. End to end remained difficult (of course). Plus it has weird stuff. Like a field for political party on all contacts or something.
- zmanian 10y agoI'm pretty sure magma is basically the original Lavabit code.
- psiconaut 10y agothe repo wasn't public before?
- tacojuan 10y agoI've seen some opensource implementations of Protonmail's stuff, any comparisons?
- deepnet 10y agoSo Ladar Levinson closed his company because he refused to provide a backdoor to his customers email encryption ? This seems similar to the Apple case, was Tim Cook just too big to bully ? Snowden had his own encryption or used GPG so a Lavabit backdoor encryption key would not lower the entropy of Snowden's encryted emails. Was Levinson's gag order lifted ? Why did Lavabit have to close but Apple didn't ? [EDIT] Levison was not jailed.
- colejohnson66 10y agoYou can't really jail Tim Cook if all the engineers quit because they refused to write a backdoor
- dexterdog 10y agoWould they?
- NickNameNick 10y agoAt least some of them threatened to. http://www.nytimes.com/2016/03/18/technology/apple-encryption-engineers-if-ordered-to-unlock-iphone-might-resist.html?_r=1 http://www.nytimes.com/2016/03/18/technology/apple-encryptio...
- dexterdog 10y agoBig difference between 'might' and 'would' there. My point is that if the company wanted it, it would not matter if some engineers had a problem. Fortunately the company stood up since this case was never truly about this one particular phone.
- WillPostForFood 10y agoLadar Levinson was never arrested or jailed, and he chose (to his credit) to shut down his own company instead of complying with a court order.
- colejohnson66 10y agoCurious: what would happen if a bunch of these popped up all over the place and used end to end encryption between each other making email truly secure between each other? Would such a thing be possible? Adopt Mega's model where they store the private key, but encrypt it with the user's password and only the browser has the decrypted copy.
- SXX 10y agoLavabit case would happen.
- pfg 10y ago> Adopt Mega's model where they store the private key, but encrypt it with the user's password and only the browser has the decrypted copy. Unless you're going to audit every single line of code Mega uses on their site every time you use it, that would leave you completely vulnerable to any backdoor included in the code (because of a court order or a $5 wrench). Secure E2E Web Crypto is a myth.
- diafygi 10y agoSerious request, what do you think about unhosted client side crypto? https://youtube.com/watch?v=WTPimUSIWbI https://youtube.com/watch?v=WTPimUSIWbI
- nickpsecurity 10y agoThanks for bringing the unhosted trend to my attention. I haven't heard of it. I'm a bit skeptical about the graphic in the front page given applications often need to perform computations on the data itself. There's probably something in the site that addresses that. I'll read it in a few days and then maybe look at your tool. Btw, you need to correct the WebCryptoAPI link in "Security and Philosophy" part of this page: https://github.com/diafygi/byoFS https://github.com/diafygi/byoFS Clicking it gives me nothing. Copy-and-pasting the link results that resembles spyware. I think it's just missing a colon after http is all.
- 10y ago
- kkl 10y agoA number of comments in this thread appear to suggest that Lavabit was end-to-end encrypted. It was not. https://moxie.org/blog/lavabit-critique/ https://moxie.org/blog/lavabit-critique/
- zmanian 10y agoLavabit wasn't end to end encrypted. DarkMail will be.(Assuming it ever materializes)
- MichaelGG 10y agoDark Mail is not End-to-End either. Last I looked, it had varying levels of security. The most practical one, from what I saw, is analogous to current SMTP+TLS. It gets the keys from the "organization" (aka gmail or your mail server). Given that it is incompatible with SMTP, I don't see the point. Use Gmail, add PGP if you need it.
- akshatpradhan 10y agoWhat does end-to-end mean encrypted mean?
- oconnor663 10y agoIt means that if Alice sends a message to Bob, that message is encrypted with a key that only Bob (or Alice) knows. No server in between them can read the message, so the question of whether they trust the server doesn't matter very much.
- sig_chld_mike 10y agoso what happens if you run this on Amazon (or any other cloud provider that would cooperate with govt intrusion)? do you need your own servers to make it work as intended?
- deleted 10y ago[deleted]
- matt_wulfeck 10y agoI never read the closing letter and it is quite unnerving. "If my experience serves any purpose, it is to illustrate what most already know: our courts must not be allowed to consider matters of great importance in secret, lest we find ourselves summarily deprived of meaningful due process. If we allow our government to continue operating in secret, it is only a matter of time before you or a loved one find yourself in a position like I was – standing in a secret courtroom, alone, and without any of the unalienable rights that are supposed to protect us from an abuse of the state’s authority."
- Buttons840 10y agoWhat is the closing letter? Can you give a link? Edit: Found the source. Link is: http://lavabit.com/ http://lavabit.com/
- jaumellado 10y agoI was also looking for it, thx
- justifier 10y agocan anyone speak to the value of the DIME spec? https://darkmail.info/downloads/dark-internet-mail-environment-march-2015.pdf https://darkmail.info/downloads/dark-internet-mail-environme...
- jauer 10y agoRelies on DNSSEC or CA to validate keys (pp. 22). Not a good idea of your threat model is governments. Defines fairly arbitrary list of non-extensible metadata including gender, alma mater & political party (pp. 60). Seems like this should be extensible and predefining a lot of that is short-sighted.
- deleted 10y ago[deleted]
- Introvertuous 10y agoI have no clue how this works but could people not just host their server outside the jurisdiction of these assholes?
- deadmaildrop 10y agoNo. Jurisdication is irrelevant. The transmission has to pass through local jurisdiction servers and wire and thus falls prey to those laws. Hosting in Aruba for your US customers does not provide any veil of safety from prosecution.
- deadmaildrop 10y agoFun. Don't believe that an open source version of Magma makes it more secure. It just means this version you see is one that looks like the one used on a server. What is actually on the server may not be the version you see in a public repository. Thanks for sharing Magma!