Lavabit secure email founder to release source code, work with former rivals

Advertisement
By Reuters | Updated: 31 October 2013 12:20 IST
Lavabit secure email founder to release source code, work with former rivals
The founder of the Lavabit encrypted email service, which shut down rather than allow potentially unlimited government interception, said he will release his programming code to the public in an effort to improve communication security.

Ladar Levison, who shuttered his startup Lavabit after a U.S. court forced him to turn over the company's cryptographic keys to federal agents, said he would work with former rivals and newcomers on an open email system designed to protect ordinary users' privacy from law enforcement, as well as insider corruption and hacking.

Lavabit and civil-liberties groups have asked an appeals court to reverse the decision favoring the federal agents, who are believed to have been seeking information about former National Security Agency contractor Edward Snowden, a Lavabit user.

Levison told Reuters that he was so concerned about mass surveillance that he did not want to wait until the appeals court ruling.

"They've effectively violated the public's trust and as a result, we've decided as a community that it's time to develop a technical solution," Levison said. "Maybe there can be 100 Lavabits if I turn over the code."

Levison's Darkmail Alliance plan ranks as one of the more dramatic examples of simmering rebellion in the technology industry against government intelligence-gathering methods, especially those revealed in secret documents leaked by Snowden.

It emerges as a fresh report showed that the NSA taps massive internal traffic at Google and Yahoo as emails and other user activity moves among international data centers owned by those companies. Google has said it is racing to encrypt such internal transmissions, though the major email service providers tend to have far less security than specialists such as Lavabit.

Several technology standards-setting groups and cryptography experts are also working to tighten security procedures and avoid formulas that were devised with help from the NSA.

Most Internet systems rely to a large extent on the users' trust of numerous companies, including the makers of the operating system and hardware, the email providers, and even advertising networks and tracking firms.

But the Snowden documents show that many of those third parties can be ordered to snoop in secret on Americans, while even major American companies can have their communications intercepted overseas.

U.S. intelligence agencies can read at least everything by non-Americans that is relevant to international politics, while many other countries and freelance hackers have no restrictions and myriad opportunities to penetrate those multilayered and complex systems.

"It really creates a situation where you can't have a trusted third party," Levison said. "If they are compromised, the entire system of trust breaks down."

Cumbersome protection
The issue closest to the front line is secure email. Though Snowden has said that email sent using cryptography based on the Pretty Good Privacy standard is fairly safe from prying eyes, it is too cumbersome for most people.

Lavabit's case shows that even very sophisticated providers that do the hard work on behalf of the users can't guarantee protection from court orders. After Levison shut his company down at least two other privacy-oriented email services, from Silent Circle and CryptoSeal, also stopped accepting customers.

Because the U.S. Justice Department's logic in the Lavabit case would allow it to access all traffic, not just one targeted user, "if it stands, it will cripple the cloud computing and software-as-a-service industries in the U.S.," said CryptoSeal co-founder Ryan Lackey.

That's because the lower court judge directed Lavabit to hand over the keys to its Secure Sockets Layer encryption, which would allow the government to see everything that the company sees.

Lavabit has appealed to the Fourth U.S. Circuit Court of Appeals in Richmond, Virginia, and last week the American Civil Liberties Union and the Electronic Frontier Foundation filed separate friend-of-the-court briefs arguing that exposing 400,000 users to possible surveillance was unreasonably burdensome, an invasion of privacy, and unconstitutionally broad.

Though federal authorities have said they would only look at the data of specific users, privacy advocates are skeptical. Previous reports based on Snowden documents showed that the NSA has amassed a stockpiles of SSL keys, some of which may have been obtained in pursuit of one target but remain on hand for other users of the same service.

In the interview, Levison said he has learned of other companies being forced to hand over their SSL keys, though he said none were household names.

Individual security keys
A part of the answer, according to Silent Circle Chief Technology Officer Jon Callas, is to make sure that only individual users have their own keys. "That's really the fundamental thing you have to do," Callas said.

Silent Circle is Lavabit's first partner in the new email project. Together they will work on the code and the protocols for implementing it correctly, a process expected to take months.

There are a number of possibilities for making sure that an email gets to the right place while keeping most information about it secret from communications carriers and even the email providers. One is a system like Tor, where a series of servers knows only the last one that the email came from and the next one along the chain.

Callas said the messages themselves could be stored in the cloud, with only the senders and recipients having access, though some users might opt to keep them stored on their own machines. He said the goal was a system that would be nearly as easy to use as everyday mail programs.

Levison said he expected that Lavabit itself will return as a provider of support services.

"I don't think the government fully realized the ethical implication of what they are doing. They are forcing businesses to spy on their customers," he said. "If the government has access to everyone's communications, we can become a totalitarian state overnight."

© Thomson Reuters 2013

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: Edward Snowden, Ladar Levison, Lavabit
Advertisement

Related Stories

Popular Mobile Brands
  1. Redmi Pad 2 With 11-Inch 2.5K Display, 9,000mAh Battery Launched in India
  2. Oppo Reno 14 5G, Reno 14 Pro 5G India Launch Timeline Leaked
  3. iQOO Z10 Lite 5G With 6,000mAh Battery Launched in India: Price, Features
  4. Apple Back to School Offer Brings Discounts on iPad Air, Other Products
  5. Nothing Headphone 1 Price, Colour Options Leaked Ahead of Launch
  6. Vivo T4 Ultra Now Available for Purchase in India: See Price, Offers
  7. Nothing Phone 3 to Offer Longer Software Support Than Its Predecessor
  8. Vivo X200 FE Launch Date, Colours, and Design Revealed Ahead of Launch
  9. Xiaomi Redmi Pad 2 First Impressions
  1. Warner Bros. Games Restructures to Focus on Harry Potter, Game of Thrones, Mortal Kombat and DC Franchises
  2. Google Pixel 10, Pixel 10 Pro Alleged Case Suggests Minor Design Changes From Predecessors
  3. Oppo Reno 14 5G, Reno 14 Pro 5G India Launch Timeline Leaked
  4. Nothing Phone 3 to Offer Longer Android and Security Update Support Than Its Predecessor
  5. Boat Wave Fortune Smartwatch With NFC Tap & Pay Feature, Bluetooth Calling Launched in India
  6. Government Announces FASTag-Based Annual Pass for Highway Commutes Priced at Rs. 3,000: See Benefits
  7. Adobe Firefly App for Android and iOS Announced, Offers AI-Powered Image and Video Tools
  8. Axiom-4 Mission Carrying Shubhanshu Shukla to International Space Station Postponed to June 22
  9. Bungie Delays Marathon, Says Will Reveal New Release Date This Fall
  10. Vivo T4 Ultra Now Available for Purchase in India: See Price, Offers, Specifications
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.