4 ms·
The system was only designed to protect data at rest. I followed the NIST secure coding guidelines when processing sensitive data. That should have made it diff
by ladar 13y ago
The system was only designed to protect data at rest. I followed the NIST secure coding guidelines when processing sensitive data. That should have made it difficult to compromise the system without changing the code.
- betterunix 13y ago...but it is easy to change the code, and easy to change it without alerting your users, and that is the point. I do not want to be rude to you, but the reality is that no matter how you designed the system there is a gaping and exploitable back door. The fact that secret keys are ever processed by your servers means that you have absolute power to decide if your users have any privacy at all. To be clear, I think it is fantastic that you took a stand on this issue, and I wish more people had that kind of spine. The problem is that your system depends on you being a man who sticks to his principles.
- jholman 13y agoYeah. Imagine the existence of a guy called Madar Mevinson, who runs a company Mavabit... that publicly shuts down over privacy concerns, but then reopens in triumph after a court battle... but little did we know, Madar was a government operative the whole time! (Or a non-state-actor criminal. Or just a creepy stalker. Whatever.) And, because this is the internet, I'll mention that I am absolutely not suggesting that these things are true of Mr Levinson and Lavabit. But it's a bad security model to trust the ethics of a stranger, and from what I understand of Lavabit, that's required here. Maybe I misunderstood Lavabit? PS: even so, 'mad props' to Mr Levinson, for taking a brave and productive stand