(no title)
ds9 | 11 years ago
Both. I can't speak for tptacek but can explain his comment. Lavabit may not have known about the legal possibilities, but the technical design was such that Lavabit could expose users' communications.
The technical shortcoming was that the system used the password input by the user as a key for the encryption. I may have some details mixed up, but basically they could capture the password in plaintext and unlock the user's comms with it. They made a practice and promise of not doing so, but one of the government demands was to intercept it.
No comments yet.