Re: Preventing government subversion in Debian, verification of binary package uploads

On Sun, Aug 25, 2013 at 08:01:37AM -0400, The Wanderer wrote:
> On 08/24/2013 07:55 PM, Robert Holtzm wrote:
> >On Sat, Aug 24, 2013 at 11:45:54PM +0200, Thomas Hood wrote:
> >>Here I assume that U.S. law is not so draconian that it can require
> >>someone who has contributed to Debian (and who is therefore
> >>trusted) to continue doing so.
> >
> >Don't be too sure. The owner of, I believe, lavabit was threatened
> >with criminal prosecution for shutting down his site rather than
> >comply with the NSA. Can't vouch for that but that's the story going
> >around.
> It's unclear, but the interpretation of the reports which I find most
> plausible is that the threat (of "contempt of court", AIUI) may have
> been not for shutting down the site or for refusing to comply but for
> effectively violating a gag order about the whole thing by the way he
> explained that - and why - he was shutting down.

Gag orders accompany NSA demands for compliance. The way I heard it, he
shut the site down out of fear that he could be forced to comply. Again,
I can't vouch for it but that's the way I heard the story.

Bob Holtzman
Your mail is being read by tight lipped 
NSA agents who fail to see humor in Doctor 
Key ID 8D549279

