So Lavabit is gone. If you don't recognize the name, it's the encrypted email service that Edward Snowden was reportedly using, and yesterday (August 8th) its owner, a guy named Ladar Levison, just... turned it off. No warning to most users beyond a message on the front page saying he'd rather shut the whole thing down than "become complicit in crimes against the American people." He didn't say what those crimes were. He legally couldn't say, apparently, which is its own special kind of chilling.
I've been reading his statement about four times now trying to parse what isn't being said. He talks about a legal battle he's been fighting "for the past six weeks," about wanting to appeal to the Fourth Circuit, about how "this experience has taught me one very important lesson: without congressional action or a strong judicial precedent, I would strongly recommend against anyone trusting their private data to a company with physical ties to the United States." That's the founder of an American company telling you not to trust American companies with your email. Sit with that for a second.
And then, this morning, Silent Circle went and shut down their own encrypted mail product, Silent Mail, completely on their own, before anyone forced them to. Jon Callas (one of their founders, the PGP guy) basically said they saw what happened to Lavabit and didn't want to end up in the same position where they'd be legally compelled to hand something over and legally barred from telling anyone. So they killed it themselves rather than risk it. "We see the writing on the wall," is roughly how he put it. They're keeping Silent Text and Silent Phone running since those don't route through a central server the same way, but the mail piece is just gone as of today.
I don't have some grand unified theory about what this means, but I'll say this: it's a genuinely strange feeling watching two companies preemptively dismantle their own products rather than comply with something they can't even describe to their own customers. This isn't a company getting hacked or going bankrupt. This is a company deciding the safest move for its users is to not exist anymore. I can't think of many other examples of that in tech, ever.
Selfishly, this is also making me look sideways at my own inbox. I run pretty much everything through Gmail, like most people I know, and I've made my peace with that in the vague way you make peace with things you don't want to think about too hard. But watching Lavabit's front page turn into a legal statement instead of a login form kind of forces the thought back to the surface. Where does my stuff actually live. Who can ask for it. Would I even find out.
I tried, for about twenty minutes this afternoon, to look into alternatives. Hushmail's been around forever and still exists, but it's not really built for the same threat model (they've handed over data to courts before, and they're upfront about that, which I guess I respect more than pretending otherwise). There's talk in some forums about a few smaller European outfits, but nothing that felt remotely ready for someone who just wants their email to work reliably and not, you know, vanish overnight because the founder decided the alternative was worse. Which is exactly the problem, right? The service that seemed the most serious about protecting you is the one that just proved it can be forced to stop existing.
Anyway. My coffee's gone cold writing this and I've got a client call in twenty minutes about something completely unrelated (a WordPress migration, thrilling stuff), so I'll leave it here. If you're the type who cares about this stuff, go read Levison's actual statement, it's short and it's worth your five minutes more than my rambling about it is. And if you're not the type who cares about this stuff yet, I'd guess August 2013 is doing a pretty good job of changing that for a lot of people whether they wanted it to or not.