Hacker News new | past | comments | ask | show | jobs | submit login

You may want to learn about how Lavabit was shutdown.



Lavabit's shutdown revealed the flaw in its premise. That encryption-at-rest was good enough for email security (while using a single TLS key for all in-flight data). Turns out it's not. Only end-to-end encryption—with keys only held by the end-users—can provide that. As despicable as FBI's actions in that case may be, they did the public a service by showing Lavabit's security proposition to be less than what users may have assumed.

EDIT: Nothing I wrote above detracts from your point, though. Re-enforces it, in fact. Lavabit held little or no data, which caused the FBI to escalate to the nuclear give-us-your-master-key option.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: