3 ms·
The main difference being that the modification was code sent to, and then executed by, the end-user's browser in the form of a Java applet. I personally belie
by SageRaven 14y ago
The main difference being that the modification was code sent to, and then executed by, the end-user's browser in the form of a Java applet.
I personally believe that Lavabit (a tiny company composed of a few dedicated folks) would rather shut down service than do something as underhanded as what Hushmail did.
In either case, the end user is relying on a proprietary system/company to fight the good fight for them, which is foolhardy if your well being is on the line. Those in need of strong privacy would probably use PGP+tor for communication anyway.
- noibl 14y agoYou said '(be it Outlook, your phone, or the web-mail host)'. I was just providing a relevant historical example to support your point. (Lavabit does have a webmail interface.) FWIW, the Hushmail ex-CEO seems to strongly agree with you on both the ethics point and the need for users to take blind trust out of the security equation. --- So I've just gone to the Lavabit site and it looks like that they store your private key on the server.[1] That doesn't strike me as being more secure than Malone's idea of externally-audited client-side crypto. But then, as you say, you've arrived at PGPGPG. The fact, then, that Zimmerman was involved with the company so early on and they still fucked it up just goes to show that faith in the efforts of 'a few dedicated folks' doesn't get you very far. [1] http://lavabit.com/secure.html http://lavabit.com/secure.html