Hacker News new | past | comments | ask | show | jobs | submit login

Here is my hypothesis of the meaning of this story.

What the government wanted was to trojan the code (collect passwords because the encryption was based on them), and do so invisibly to the users.

Levison prevented this by shutting down the service - that is the real offence. The technicality on which he could be arrested is that he indicated the reason for the shutdown in the message to users on the front page - albeit only by implication.

The importance of this, which I think that even many techies may be missing, is that service owners no longer have a choice of what code to run on their own servers. If you run a service that enables secure communications, you can be forced to subvert the code to the detriment of users and effeectively lie about it and deceive the users. You can refuse to participate by quitting the job (unless the 13th Amendment is also being trampled) - but according to the new, defacto US policy, you have to allow the service to continue in trojaned form, otherwise you're subject to prosecution for revealing the government wiretapping to the targets.




Seeing as Lavabit handled encryption and decryption server side, the order could have required them to retain messages after decryption. Or, less insidiously, just required them to retain messages they received prior to encrypting them. In both cases, they wouldn't have forced Lavabit to put in a backdoor, just keep what they had already. (though if they only stored decrypted emails in memory, that distinction is small).

Remember, Lavabit voluntarily complied with other court orders, so they likely have the technical means to comply with what the feds want.


You have no idea what the feds want, and the previous "comply" was probably just turning over the information it had readily available including the raw cipher text which would be useless with out the key

I do not believe for a second the NSA was looking simliar information.


those "other court orders" could have been for accounts that were not encrypted, like the free accounts.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: