We all remember Lavabit, the “secure” email service that was shut down two months ago by the company’s owner Ladar Levinson.
There are good reasons why we should reconsider the company's title of "secure email service." Security researcher Marlinspike Moxie explains why Lavabit's services weren't all that secure, and specifically states that the service wasn't built on solid security practices.
Lavabit boasted that it offered an encrypted email service, so secure that even company employees could not access stored emails. This is technically true, but it creates the false impression that Lavabit did not have access to plain text messages, which is not true.
The encryption the company offered was server-side. Emails arrived in plain text and were encrypted on-site with a key before being stored on the server. This means that messages arrived at the servers in plain text, albeit over an encrypted HTTPS connection.
Such systems are vulnerable to potential attacks. Anyone managing the server, whether a legitimate administrator or a hacker, could have access to files that were not encrypted.
