TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

What Exactly Did The US Government Ask Lavabit to Do?

161 pointsby m8urnalmost 12 years ago

10 comments

radleyalmost 12 years ago
It seems pretty clear to me (Occam&#x27;s razor):<p>1) he was told he had to use the same monitoring process all the other providers were using<p>2) as a state secret, he couldn&#x27;t reveal he was doing it ever to his users<p>3) if he complied he would totally undermine the nature of his service<p>Anything else is superfluous.
jaueralmost 12 years ago
So long as uninformed speculation is running loose... Lavabit&#x27;s comment that &quot;If you knew what I know about e-mail, you might not use it either.&quot; points in a email specific direction as opposed to simple sniffing of traffic.<p>Perhaps he is referring to the Stored Communications Act ( <a href="http://en.wikipedia.org/wiki/Stored_Communications_Act" rel="nofollow">http:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Stored_Communications_Act</a> ). I haven&#x27;t seen it referenced in coverage of this but the gist is under the right circumstances email that is older than six months and stored on a server that you don&#x27;t own can be accessed without a warrant. Lavabit&#x27;s encryption process as described would interfere with that. Not being able to comply AND being unwilling to take steps to comply in the future is the sort of thing that feds don&#x27;t like.<p>This wasn&#x27;t a big deal when it was passed in 1986 and small mail quotas were the norm but now with IMAP, multiple devices, and archiving it becomes a pretty big issue as you are talking about someone&#x27;s electronic life instead of abandoned mailboxes.<p>AFAIK the issue of Fourth Amendment issues and SCA hasn&#x27;t made it to the Supreme Court yet so interpretations vary depending on circuit.
评论 #6239939 未加载
评论 #6240182 未加载
martin_almost 12 years ago
&quot;In reality all it would take is a few lines of code code to log the user’s original password which allows you to decrypt the private key which in turn allows you to receive and send mail as that user as well as access any stored messages.&quot;<p>Is this any different to writing a few lines of code to sniff the PreMasterSecret or even just a plain ol&#x27; MitM attack?
sudocwalmost 12 years ago
Are there currently any alternatives, in terms of secure email providers? I never even knew it was a thing before the lavabit fiasco.
评论 #6239660 未加载
评论 #6239647 未加载
评论 #6240538 未加载
评论 #6239666 未加载
评论 #6240867 未加载
评论 #6239633 未加载
dangeroalmost 12 years ago
Hypothetical question:<p>What if the founder of Lavabit took the documents that the US government sent him and gagged him with and put them somewhere where they could be stolen or illegally accessed? For example, what if he put them on a computer with a public facing ip address, or even left them on his desk in his office? If he could have plausible deniability couldn&#x27;t they get stolen and leaked without him really getting in trouble?<p>This may seem like a stretch, but when you consider the government is using secret interpretations of laws how is it any different than what they are doing?
评论 #6243397 未加载
frank_boydalmost 12 years ago
As long as we don&#x27;t have a statement from either the government or Lavabit, we can only speculate. The most reasonable thing is then of course to assume the worst - complete surveillance of all customers. The rest is pretty much details.
评论 #6240802 未加载
justanotheralmost 12 years ago
Kickstarter idea: $xxx,xxx for the network operator who sniffs network traffic that discloses the basis for the Secret TSA ID law. Goose, gander, etc. I&#x27;d happily kick in 1%.
评论 #6241821 未加载
kordlessalmost 12 years ago
A device or piece of software designed to sniff the mail server to mail server connections would also be an option for broad based surveillance. Only a handful of mail providers (like Google) have the option to encrypt traffic server to server. Most mail servers transmit messages in the clear to each other and only encrypt the server to client side.
评论 #6239587 未加载
评论 #6239581 未加载
callesggalmost 12 years ago
This article gives no new information, it is stupid.<p>Now i will speculate:<p>As long as he does not know his customers passwords he can&#x27;t retroactively view the customers mails, once the mails have been encrypted and the plain-text thrown away the stuff is unreachable.<p>So the US gov probably wanted him to save his customers passwords when they logged in.
评论 #6239621 未加载
mankydalmost 12 years ago
This article seems to speculate on things that are not necessarily true. It&#x27;s possible that the government simply told him that he had to be able to supply information arbitrarily on demand without an explicit warrant. This does not mean that they required him to install their own software on his machines.<p>Of course, one certainly still argue that this a line that the Government should not cross - I&#x27;d wholeheartedly agree with that. However, statements such as “We’ve had a couple of dozen court orders served to us over the past 10 years, but they’ve never crossed the line,” do not imply that the government required him to install software or otherwise compromise his security in a way that he was not already able to do.
评论 #6239740 未加载