33 ms·
1. Our code is public. https://github.com/lavab https://github.com/lavab 2. We'll have Chrome/Firefox extensions for something similar to "signed binaries" 3.
by simi_ 11y ago
1. Our code is public. https://github.com/lavab https://github.com/lavab
2. We'll have Chrome/Firefox extensions for something similar to "signed binaries"
3. We offer the option to run the web client yourself (git clone https://github.com/lavab/web https://github.com/lavab/web && cd web && npm install && gulp && open "http://localhost:5000" http://localhost:5000")
4. We'll build native desktop and mobile clients.
Hope this answers your question.
- Procrastes 11y agoNative, or client-hosted javascript sounds workable. Server hosted Javascript cannot be secure even in theory (without a client-side plugin). I gave up on this problem when I shuttered Harpo Mail because of this and I am a US Citizen and realized I can't legally or ethically claim I won't turn you over to the Feds if they hold a gun to my head. It sounds like you are addressing those issues and more, and I wish you success.
- simi_ 11y agoThank you! :) Our servers and us are also based in Germany, which is a plus.
- e12e 11y agoHow is it a plus that they're hosted in Germany? The German spy service are on record spying for the NSA, and of course only German citizens are protected by German law, so if anything, for users from the US, being hosted in Germany should be even worse than being hosted in the US (Assuming, the current slow, blow-back against the NSA goes anywhere). I don't really understand this fascination with hosting things outside of the US "for security" (from apparently, mostly US citizens). Personally I'm in Norway, where the secret police have been spying on "dissidents" (it used to be the "far" left, nominally the neo-nazis/fascists (although they missed the only terror attack, despite having a tip before the fact) -- now it's the "radical" Muslims (you know, a clearly defined threat to national security, aka "brown scary people")). But regardless of how one feels about using Stasi methods to help perpetuate and sustain illegal wars on the middle east -- one thing should be abundantly clear: Nowhere (AFAIK) does foreign citizens have any rights to not be spied on by local intelligence services. And of course all of NATO is working together on gathering it (along with Sweden, which Norwegian intelligence reportedly work closely with). All that said, while I think we should all work at taking back our respective governments, and strive for a better (more free) political environment -- I don't think the only measure for an email service should be "am I now safe from state-sponsored actors". In fact, I think that should actually be pretty low on the list. Use gpg, or give up. More significantly, if you can't do the work for a proper web-of-trust/key distribution and verification, you can't be secure (in the sense indicated above). I still think services like these are miles better than you-are-the-product, like gmail/outlook.com etc. Good luck on your service!
- pzduniak 11y agoFrom what I've been told, it's significantly harder to confiscate servers in Germany - but even if that somehow happens, all they would find on our servers is a bunch of encrypted blobs.
- higherpurpose 11y agoThere's a difference between spying on something and forcing you to do something. I think the idea is there's no "Patriot Act" and National Security Letters in Germany to force providers to introduce backdoors. The "NSA can spy on you argument" doesn't really apply here. You just try to provide solid security against that. Having poor security in "America" wouldn't save you from NSA anyway.
- e12e 11y agoI don't think it's realistic to expect that a provider can't be forced to facilitate secret wire-tapping in any jurisdiction (Nor do I think that is really desirable). Wasn't the (relatively) recent child-porn ring bust an operation involving lots of jurisdictions? I also don't think Germany will be a safe haven for someone working against the drone program if that involves leaking classified information (otherwise known as espionage, even if it stems from altruistic motives). I feel people are as much in denial about the likelihood of spying by European governments, as many were about the NSA (and for no better reason -- the NSA was documented to break the law long before Snowden, and so have various European governments). I don't really see this as much of a win either way. But perhaps it's good marketing copy.