Hacker News new | past | comments | ask | show | jobs | submit login

I like what lavabit has done, but at the end of the day, if they are forced to, they can modify their server side software to log your password when you log in, and then use that password to decrypt all of your email on the server side.

It also doesn't secure the email on the client side. If your IMAP client stores the email on disk, then you need to make sure it is encrypting it in a secure fashion first.

Lavabit should offer an extra layer of encryption whereby they allow you to upload a public pgp key which they encrypt all your incoming email with using PGP/MIME.




I don't think even what you said is sufficient -- as long as they are within the jurisdiction of the US court system, I think a judge can order them to start saving copies of incoming mail before encrypting, etc.

I think fundamentally you can't circumvent the law with technical measures. You need to change the law to require warrants.


Sure. The method I stated would protect historical email, but it wouldn't prevent the capture of new email after an order has been made to start saving it.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: