Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

http://www.lavabit.com

They (claim to) use some sort of asymmetric encryption scheme such that they literally do not have access to the data on their own servers. I'd love to have a crypto expert explain to me if it's legit.



They still have to deliver your mail, unencrypted (besides TLS) through POP3. Which means that at some point, your mail is unencrypted in their machines. But they would have to be outright malicious to intercept your messages at that point, so I think we can trust them on this.

Anyway, there is more than just your e-mail: there is your connection logs, the quantity of messages you receive (and from whom), retrieve (and when) and sent (and to whom).

Plus, the relevant authorities could compel them to surrender your logs. You may prefer that they (have to) ask you directly. (EDIT: Vivtek says this happens very rarely, if you care do ditch the logs, so this may be a small issue.)

I don't think we can get closer to truly anonymous web based mail. That may be sufficient for most people, though.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: