6 ms·
Lavabit returning in 19 days
- win_ini 10y agoGreat! Why now? Why on Inauguration Day?
- tazjin 10y agoMarketing.
- aorth 10y agoI wonder if their sysadmins will be able to read your mail or just promise not to. :/
- satysin 10y agoThis is why you always encrypt on your machine not your email service. TBH I don't get why people get excited about things like Lavabit. You shouldn't be relying on one particular email service for security when email is not secure by design. Secure your content properly and then it shouldn't really matter what email service you use.
- mistaken 10y agoI agree with you, but sadly things like PGP are not universally adopted and can be a PITA to explain to someone not technically inclined. So it all boils down to the lack of standardized an universal encryption in e-mail.
- nilved 10y agoThere is a standard, and the fact that it's not universally adopted is more of a social problem than technical.
- geocar 10y agoThen sadly you don't have security. Understanding the threat model is fundamental: If you don't know what this protects against, it might as well protect against nothing at all; My ISP received my emails in plaintext, so I have to assume that they've got a plaintext backup of those emails.
- qwertyuiop924 10y agoI believe the words Vincent Canfield, owner of cock.li (another secure email service) are relevant here: >How can I trust you? >You can't. Cock.li doesn't parse your E-mail to provide you with targeted ads, nor do I read E-mail contents unless it's for a legal court order. However, it is 100% possible for me to read E-mail, and IMAP/SMTP doesn't provide user-side/client-side encryption, so you're just going to have to take my word for it. Any encryption implementation would still technically allow me to read E-mail, too. This was true for Lavabit as well -- while your E-mail was stored encrypted (only if you were a paid member, which most people forget), E-mail could still technically be intercepted while being received / sent (SMTP), or while being read by your mail client (IMAP). For privacy, I would recommend encrypting your E-mails using PGP using a mail client add-on like Enigmail. This was originally followed by a quote from /g/, which has been redacted for obvious reasons (if you want it, you know where to find it), save this line: >Now that I think about it, administering a mail host is exactly like being a nurse, only people die slightly less often.
- diggan 10y agoHm, feels a bit weird. If they already got served with an order to share the data and they refused to comply, closing down the service instead, what can have changed today? Wouldn't this mean that someone else took up the service, agreed to the order and now this will become some sort of honeypot? Maybe I'm misunderstanding something, but I don't understand how anyone could trust Lavabit to either stick around or actually be private and/or secure.
- maaaats 10y agoOne could hope they now have solved it technically in a way that would make it impossible for them to deliver that kind of data.
- ryanlol 10y agoThat's not exactly possible for an email service provided by a third party.
- imaginenore 10y agoEnd-to-end encryption. Only the users have the keys.
- nailer 10y agoAnd SMTP 571: 'Delivery not authorized' for anyone that sends a plain text message.
- Fnoord 10y agoInteresting but isn't the data already received in plaintext at that point?
- cryptarch 10y agoYou could have a hardened gateway server with read-only storage and that only temporarily stores messages in memory. Maybe a heterogenous bunch if them so you'd have to crack all of them to get all messages. You could periodically reset them in case they still get infected. You could add a transparant proxy that specifically looks for odd, repeated requests, to detect re-infectations. You'd set up alerts for attempts at communication/scanning from those servers, to detect virusses trying to move laterally between the different instances, and/or isolate them from eachother on the network layer. You could have a separare hardware device that scans the memory of these servers to detect tampering. It could also try to detect "plaintextness" and abort as soon as it detects that, so you only have the beginning of the message in memory. This doesn't help when the ISP is recording (and it probably is), but it makes it very hard to retrieve the data from inside the email datacenter.
- akerl_ 10y agoI wonder how they plan to approach security this time, given how much of the previous demise of Lavabit centered around how they had they ability to circumvent the encryption, despite some marketing claims that that wasn't the case
- qwertyuiop924 10y agoIs this actually going to be secure? Because there is a reason they closed last time...
- legodt 10y agoSomething about me does not want to trust a webmail host who has an ad running on their front page reading "date rape appreciation station." This appalling lack of professionalism makes the entire service suspect to me. edit: I would like to thank all the misogynists in this thread voting this down. Thanks for keeping tech a welcoming place for women and victims of assault!
- qwertyuiop924 10y agoSaid person is also quoting from /g/. Why would you expect anything else? OTOH, the guy does genuinely go to great lengths to protect the security of his site (and of the mail of his users), and seems to know what he's doing. So I'm not to down on him for the unprofessionalism.
- legodt 10y agoI'm sure his service is just great, but, in the future, if you ever wonder why women don't go into tech (it seems so easy to, where are they?)- remember this. Tacit support of actors in the community like this make tech seem like a hostile place, or, at the very least, a boy's club of people okay with rape jokes. It's not a sustainable atmosphere to maintain
- rndgermandude 10y agoSpeaking of nurses (per quote), I worked with nurses before, the vast, vast majority of whom were female, and you'd probably be surprised at the never-ending stream of crude (dick) jokes and "sex-talk"... Wonder if that's the reason there are so little men in nursing?!
- legodt 10y agoThat is different than making a joke at the expense of rape victims. Please think this through. The gender gap in another industry does not negate on in another.
- nilved 10y agoThere's really no coming back for Lavabit. Nobody can trust them anymore, and this isn't just about Lavabit, but about e-mail. If a person is privacy-conscious enough not to use Google, they know not to use anyone else either.
- ycmbntrthrwaway 10y agoIt depends on your definition of email. Email has already switched from UUCP to SMTP once, and https://darkmail.info/ https://darkmail.info/ calls what is developed 'Email 3.0'.
- matt4077 10y agoI may have missed something about the original Lavabit affair, but my take-away was always "He's proven to be the rare individual willing to take a significant hit for his principles". If they now added whatever the state-of-the-art is for a service such as this, wouldn't that create quite a compelling service?
- DavideNL 10y ago> "He's proven to be the rare individual willing to take a significant hit for his principles" i agree with that... Although it seems 'incompetence' instead of 'evilness', he still provided a service which was not safe by design: https://moxie.org/blog/lavabit-critique/ https://moxie.org/blog/lavabit-critique/
- nilved 10y ago> If they now added whatever the state-of-the-art is for a service such as this, wouldn't that create quite a compelling service? Right, but that wouldn't be e-mail, and this seems to be e-mail. He made the decision to shut down e-mail accounts (including mine!) to prevent data leakage and that is not a decision that anyone should be forced to make; it is a deficiency of the system.
- Dowwie 10y agoYes, precisely
- berryg 10y agoProtonmail looks interesting. They do not store keys. They can only handover encrypted data. It is open source software. - https://protonmail.com/blog/switzerland/ https://protonmail.com/blog/switzerland/
- jimnotgym 10y agoAnd it is pretty user friendly too
- bogomipz 10y agoAnd yet Proton mail doesn't seem to offer 2FA? That seem like a fail. How can you sell yourself as a "secure service" without that.
- CretinDesAlpes 10y agoThey do actually https://protonmail.com/support/knowledge-base/two-factor-authentication/ https://protonmail.com/support/knowledge-base/two-factor-aut...
- bogomipz 10y agoAh OK, I stand corrected, thanks. This must be recent then. They did not have this 4 or 5 months ago when I looked and I remember being quite surprised by this. I was told it was a feature that was on the roadmap. Why is this not listed on security details for the product I wonder? https://protonmail.com/security-details https://protonmail.com/security-details
- cdubzzz 10y agoIt was indeed only added a month or so ago.
- homakov 10y agoWhat is 2FA & who told you 2FA is any useful? Master passphrase -> local key, there's no place for "2FA" buzzword in this scheme.
- aioprisan 10y agoWithout any details on why this time the service is secure and won't be able to hand over actual user data, it is hard to get excited about the relaunch. Also, nice marketing ploy with re-launching on Inauguration Day.
- forgotpwtomain 10y agorelevant: https://moxie.org/blog/lavabit-critique/ https://moxie.org/blog/lavabit-critique/
- ycmbntrthrwaway 10y agoLooks like everyone on HN understand that architecture should be changed. If Lavabit is just relaunched, it cannot be used.
- Canada 10y agoWill this be the debut of Dark Mail in a production service? https://darkmail.info/ https://darkmail.info/
- ycmbntrthrwaway 10y agoI guess not based on activity on GitHub: https://github.com/lavabit/ https://github.com/lavabit/
- Canada 10y agoLooks like DIME hasn't been touched in a while. After the initial talk about this stuff a couple Defcons ago there doesn't seem to be much public progress. We'll see what he puts up.
- ComputerGuru 10y agoIs this supposed to imply that they feel they'll have more freedom/less censorship under Trump (Jan 20 is inauguration day)? Does FISA change ownership/control between the parties when a president's term ends?
- matt4077 10y agoNo, it's implying a heightened need for secure communications with the new administration. And no, courts aren't owned by parties. FISA judges are appointed by the Chief Justice of the Supreme Court. That's been a conservative for the last, ugh..., well longer than FISA exists, anyway. Also, even if I subscribed to the current dystopian view of politics, I'd argue it's never the parties that excerpt control of a court, but always the administration. There is, in theory as well as in practice, a difference between the two.
- clishem 10y agoI'm running my own e-mail server now using mail-in-a-box. Don't think Lavabit can beat that. If you want secure e-mail use PGP.
- tscs37 10y agoIf it's running on a VPS on AWS or somewhere, it's still subject to the provider tampering with it. Secondly, PGP is not nearly widespread enough to be considered secure and additionally provides no anonymity properties which in this day and age should be the focus of any secure e-mail provider. Additionally, running your own email server also reduces the anonymity to basically null and leaves you with a weak pseudonymity at best.
- deleted 10y ago[deleted]
- drfuchs 10y agoDoes this mean Groklaw will come back?
- Dowwie 10y agoLadar acted with integrity and self sacrifice. He's earned trust in a way that not many others have. I am looking forward to trying darkmail, or whatever they're branding it as now.