Snowden's preferred email provider, Lavabit, has been resurrected

Status
Not open for further replies.

HarborFront

Level 71
Thread author
Verified
Top Poster
Content Creator
Oct 9, 2016
6,026
Lavabit, the encrypted email provider Edward Snowden favored, has risen from the ashes with more security features than before. If you'll recall, company chief Ladar Levison shut it down in 2013 instead of complying with the government's demand to hand over its SSL encryption key. Authorities targeted the provider in order to get to the whistleblower's communications, but a gag order prevented Lavabit from confirming that was the case until last year. In order to ensure its users' privacy, the resurrected Lavabit uses a new architecture that physically prevents the company from handing over its SSL key.

Lavabit now stores the key in a tamper-resistant device. The service automatically generates a long passphrase that the company won't be able to see, inserts the key into the device and then destroys the passphrase. A developer for the company told The Intercept that "Once it's in there, we cannot pull that SSL key back out."

At the moment, the service is only open to previous users who were suddenly locked out of their accounts due to its sudden death. They likely won't be able to retrieve their old emails anymore, but they can now continue using their Lavabit account. The company will eventually start accepting new users, though, and they'll be able to choose between three modes: Trustful, Cautious and Paranoid.

The least secure option encrypts emails on the company's server, while Cautious will offer end-to-end encryption. Those who prefer the latter will have to install the client software on their devices to be able to generate an encryption key. But since Cautious still stores the key in the company's server and that might not be enough for some people, the service came up with Paranoid mode. It stores the key on the users' devices instead, and people will have to manually transfer it if they want to use another device. Plus, if they lose the key, it's gone for good.

In addition to three security tiers, the new Lavabit has a feature called Dark Mail to encrypt every email's metadata. It also prevents the sender's ISP from knowing the email's recipient and the recipient's ISP from knowing the sender's. The company didn't say when it will start welcoming new sign ups, but you can pre-register for an account right now on Lavabit's website.

Snowden's preferred email provider, Lavabit, has been resurrected
 

_CyberGhosT_

Level 53
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Aug 2, 2015
4,286
I don't see any advantages over ProtonMail,
who owns LavaBit now, and what servers are they
using ? Just because they were one thing in the past
does not mean thats what they are now, so be careful.
PeAcE
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top