lobihat.blogg.se

Bitmessage vs lavabit
Bitmessage vs lavabit











bitmessage vs lavabit

The technical failings and lack of cryptography knowledge were quite severe. Lavabit's biggest failure originally was really that Ladar deceived users and ultimately put them all at risk when he eventually handed over the encryption keys to the FBI. The risk of shutdown or other types of mandatory tampering is just too great, and it is unlikely that the new US presidential administration will be any friendlier than the last one towards privacy.

bitmessage vs lavabit

The key takeaway from the first Lavabit was that you can't do secure email in the US. It relies on DNSSEC which has failed to gain widespread adoption, and we have a hard time imagining a world where Google, Yahoo, etc, will rewrite all their email systems to use Darkmail.Ĥ) There is still the issue of Lavabit being based in the US. On the topic of whether or not Darkmail can gain any adoption in the future (so that it can be actually useful), we don't believe this is possible. Since nobody uses Darkmail at this time, it's rather deceptive also to claim that Lavabit has metadata protection.

bitmessage vs lavabit

However, they fail to mention that Darkmail metadata protection only works if you are communicating with an outside email provider, AND critically, if that other email provider also supports Darkmail. Lavabit is strongly touting metadata protection via Darkmail protocol. Ladar either doesn't know any better, or isn't being truthful. In other words, the original problem that killed Lavabit still exists. Now instead of asking for the SSL key, the US govt will simply ask for the HSM. However, this is disingenuous at best, deceptive at worst. Lavabit claims to have solved their fatal SSL weakness using a hardware security module (HSM). So it is still entirely dependent on SSL. Lavabit doesn't have end-to-end encryption yet. We will probably elaborate more on this later, but we took a quick look into the relaunched Lavabit and a couple things struck us immediately:













Bitmessage vs lavabit