lavabit

Because Lavabit was not as safe as it wanted it to be

lavabitWe all remember την Lavabit, την "ασφαλή" υπηρεσία ηλεκτρονικού ταχυδρομείου που έκλεισε πριν δύο μήνες από τον ιδιοκτήτη της ς Ladar Levinson.

Υπάρχουν σοβαροί λόγοι για τους οποίους θα πρέπει να αναθεωρήσουμε τον τίτλο της εταιρείας που την ήθελε " υπηρεσία ηλεκτρονικού ταχυδρομείου."  Ο ερευνητής ασφαλείας Marlinspike Moxie εξηγεί γιατί οι υπηρεσίες της Lavabit δεν ήταν και τόσο ασφαλείς και αναφέρει that the service was not built on sound security practices.

Lavabit boasted of offering an encrypted e-mail service, so secure that even company employees could not access stored e-mails. This is technically true, but it gives the false impression that Lavabit did not have access to plain text messages, which is not true.

The encryption offered by the company was server-side. The emails arrived in plain text and the encryption was done on the spot with a key before being stored on the server. This means that you understand that the messages were delivered to the servers in plain text, albeit via an encrypted HTTPS connection.

Such systems are vulnerable to potential attacks. Anyone who manages the server, legal administrator or , could access the files that were not encrypted.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).