Lavabit, Snowden's Favorite Encrypted Email Service, Returns from the Dead
Working on even stronger tech to protect from snooping.


Email service provider Lavabit famously (in tech security circles anyway) shut its doors and turned itself off back in 2013. Its owner, Ladar Levison, explained that he was doing so to keep from having to comply with federal government orders to hand over the encryption key that would give the feds access to the contents of emails by domestic surveillance whistleblower Edward Snowden.
Now, as a new administration takes control of the White House, Levison and Lavabit are returning. Lavabit is relaunching its services, now that Levison has worked to make it even harder for the federal government to attempt to gain access to emails sent by its users. On his announcement, timed to launch with Donald Trump's inauguration, Levison explained that he had developed an end-to-end encryption system that would minimize the ability to for outsiders to access users info, once it's all fully implemented.
Kim Zetter over at The Intercept has more details directly from Lavabit:
With the new architecture, Lavabit will no longer be able to hand over its SSL key, because the key is now stored in a hardware security module — a tamper-resistant device that provides a secure enclave for storing keys and performing sensitive functions, like encryption and decryption. Lavabit generates a long passphrase blindly so the company doesn't know what it is; Lavabit then inserts the key into the device and destroys the passphrase.
"Once it's in there we cannot pull that SSL key back out," says Sean, a Lavabit developer who asked to be identified only by his first name. (Many of Lavabit's coders and engineers are volunteers who work for employers who might not like them helping build a system that thwarts government surveillance.)
If anyone does try to extract the key, it will trigger a mechanism that causes the key to self-destruct.
The hardware security module is a temporary solution, however, until end-to-end encryption is available, which will encrypt email on the user's device and make the SSL encryption less critical.
The site is for Lavabit is active, and for those who want to subscribe, the price currently ranges from $15 to $30 annually depending on storage limits. And they accept bitcoins!
Reason TV has previously interviewed Levison about the importance of encryption in protecting liberty and privacy (and warnings about those who simply use vague encryption and security claims for marketing purposes). Watch below:
Editor's Note: As of February 29, 2024, commenting privileges on reason.com posts are limited to Reason Plus subscribers. Past commenters are grandfathered in for a temporary period. Subscribe here to preserve your ability to comment. Your Reason Plus subscription also gives you an ad-free version of reason.com, along with full access to the digital edition and archives of Reason magazine. We request that comments be civil and on-topic. We do not moderate or assume any responsibility for comments, which are owned by the readers who post them. Comments do not represent the views of reason.com or Reason Foundation. We reserve the right to delete any comment and ban commenters for any reason at any time. Comments may only be edited within 5 minutes of posting. Report abuses.
Please
to post comments
OT: Don't they psychologically screen Secret Service agents?
Someone must have been asleep at the polygraph.
Someone must have been asleep at the polygraph.
That would be an interesting way to pass the test. Unless you had apnea.
I don't think the lady agents are being put in tanking roles anyway. Too small to absorb bullets reliably, not intimidating enough to draw aggro.
Yes, but someone smart goes after support first to eliminate the heals.
So are you saying girls can only be kiting mages? I know a few leet trolls that would put that theory to the test. Plus if you think a Tauren Pally can't stop bullets OR draw aggro yer doin' it wrong!
/ nerd
P.S. LEEERRRROOOOYYYYYY JEEENNNNNKINS
Ya know .... I would normally admire resistance like this; how would history have changed if more people had protested Hitler for instance? But these idiots are so blind that they cannot see Hillary as being worse in her own ways, and cannot see that Trump is no Hitler. I can only guess that they are so emotionally caught up in the Obama rainbow that they have to carry that over into Hillary, yet they know how thoroughly corrupt and dishonest she is, so their disgust for the other party can only be validated by thinking Trump is much worse, ie literally as bad as Hitler.
The left went completely batshit on Trump, saying outrageous things about him in order to keep him from winning.
Now that the tactic has failed, however, they have painted themselves into a corner. If they hadn't gone full Hitler on him, they could chill out and accept the results of the election, being the loyal opposition. They can't very well just admit to being dishonest, hypocritical, and hysteric, though, so they have to keep acting like Trump really is Hitler.
I may sign up for this service. I'm not sure about their hardware solution-- but the idea that they're creating a blind system is intriguing to me.
Been following this for awhile... glad it's out. The instant key destruction is an interesting way to solve the server trust problem
I threw some bucks at a Kickstarter he had awhile back. Glad its finally getting to market.
The NSA made it extra special for users.
OT and an old link, but: Leftist Jewish lesbian defends sharia law. It's all in the interpretation of sharia, you see.
I read he first couple of paragraphs, stopped when she said Trump doesn't understand Sharia law, then tried to distinguish between personal Sharia and law Sharia. I guess she doesn't either.
Yeah, heard something similar on NPR today. Sharia law is an individual dude like crossing the waters or climbing mountains of conflict.
Far out. *fingersnap applause*
I suppose that may be true. I can think of some seriously devout scholars of the religion who say otherwise.
They say it's better to go with one of the services based in Switzerland--because the Swiss, apparently, don't respond to American subpoenas.
Also, thru have a better font. So, basically, with a Swiss server, you're getting narrow i's.
+1 pixel
They don't use the ?, so they have a worse font.
The Swiss banks already caved.
Swiss reveal American accounts
I wonder, has there been any movement on browser-based crypto? I would think such a development would be necessary for Lavabit to offer true "end-to-end" encryption.
Clarification: by "browser-based crypto" I mean the ability for web applications to perform cryptographic operations interactively, not just the browser implementing crypto at the connection layer.
If I understand, you're saying you want something better than Tor?
Tor is more about providing anonymity, not confidentiality per se.
It would be if they were making webmail clients... I don't think they're trying that yet; rather staying focused on native clients. That said, theres no reason you couldn't implement the algo's in javascript, but you'd have to trust the download sources implicitly. I could see doing it as a browser extension but a true "paranoid mode" web client would be next to impossible - you have to be able to trust that the app being put together from various sources on your machine hasn't been tampered with
you have to be able to trust that the app being put together from various sources on your machine hasn't been tampered with
True, but true of native clients as well. Trust, but verify.
native clients can be built from source, for the truly paranoid - using a browser makes the verify all but impossible
The key is what happens at the edges. Encryption in general is pretty good. That's why the state doesn't like it.
That's why it's rare that anyone cracks the encryption-- it's all about what happens at the endpoints. Is it vulnerable to MITM attacks and what not, compromised clients etc.
right - and the nature of javascript and HTML1 creates additional endpoints - all of which you have to know are populated with good actors, lest somebody take over the service returning your encryption code and have it replace AES with PEGASUS or something
If you are asking what I think you are asking, yes
Nice
If anyone does try to extract the key, it will trigger a mechanism that causes the key to self-destruct.
And spill vinegar on your papyrus.
You know else returned from the dead?
Alvaro Garza Jr?
Heart warming story, but the correct answer is "zombie Hitler".
Bob Weir?
John Huston fans?
file under: my body, my choice..other bodies also my choice
Nigeria: Muslims use babies in jihad suicide bombings
Yes, but Islam is totally not a death cult.
Do the male baby martyrs get to enjoy, you know, ...?
Seriously, 8-(
file under: fish sticks
WUSTL offering 'Politics of Kanye West: Black Genius' course
How shocking.
He sure looks like he knows it's all a scam. Also, looks like the black guy from "Scrubs".
file under: what's the matter wtih Kansas?
Flyers have appeared at the University of Kansas calling "Make America Great Again" and "anarcho-capitalist" examples of coded neo-nazi language and urging students to remove materials posted by "hate groups."
"i got it! We'll call our enemies Nazis! nobody's ever done that before!"
So they are going to "protest" people likely to join? Yeah, that's a great plan.
"anarcho-capitalist" is actually fascist?
And the lefty "anarchist" protesters are anarcho-socialists? That's an oxymoron.
So, if the posters stay up, does it mean people aren't paying attention to them?
file under: hell, it's about time.
Dutch Prime Minister Tells Immigrants To Integrate Or Leave
Will Trump have the same guts...?
Trump doesn't calculus, so...
How about shunning those who do not integrate?
You know, in more ancient cultures, there are laws of hospitality, and they certain protect guests, including foreigners, from abuse, but they also deal rather harshly with guests who abuse the hospitality of their hosts. Balance.
SPLC blames Google for racist massacre
Almost every racist used Google at least once.
But every racist uses oxygen nearly constantly.
We need to have our priorities in order.
Everyone knows everything written in "manifestos" is true.