The page that met anyone trying to log in to Lavabit on 8 August 2013 was not a login page. Ladar Levison, who had run the encrypted email service out of Dallas for ten years, had replaced it with a few hundred words of his own. He had been forced, he wrote, to choose between becoming "complicit in crimes against the American people" and walking away from a decade of work — and he was not permitted to say what had produced the choice. He asked for contributions towards a legal defence. Hours later, on the same day, Silent Circle closed its own encrypted email product before anyone asked it for anything, saying it could see the writing on the wall.

What had produced it became public on 2 October 2013, when the court file was unsealed with redactions. On 10 June the government had obtained an order under 18 U.S.C. 2703(d) for metadata on a single unnamed customer, followed by a pen register and trap-and-trace order. Lavabit was built so that Levison could not read stored mail, so in July prosecutors turned to a search warrant for something he did hold: the private TLS keys that encrypted every connection to the service. One set of keys covered every account on it. Published figures for the user base ranged from about forty thousand to more than four hundred thousand. On 13 July Levison offered to build the targeted collection himself and bill for the work. The offer was refused.

On 1 August 2013 the court ordered the keys handed over by the next day. On 2 August Levison delivered them: eleven pages of printout, set in four-point type. Prosecutors told the court that using them meant entering all 2,560 characters by hand, and that one wrong keystroke would leave the FBI's collection system unable to decrypt anything. Judge Claude Hilton ordered a fine of $5,000 for each day the electronic copies were withheld. Levison held out two days, produced them on 7 August, and closed the service on the 8th. Twelve days later Groklaw, which had covered the software patent wars for a decade, closed as well; its founder, Pamela Jones, wrote that there was "no way to do Groklaw without email".

The case ended without answering the question it raised. Levison appealed the contempt finding, and on 16 April 2014 the Fourth Circuit upheld it on the narrow ground that his lawyers had not properly raised the statutory and constitutional arguments in the district court — so the appeals court never reached whether a government may compel a service operator's private keys at all. The redactions held until 2016, when an error in a government filing left the target's name legible: Edward Snowden, whose Lavabit address had been the subject of the June order. Levison relaunched the service on 20 January 2017 on a protocol he called the Dark Internet Mail Environment, built so that the operator would hold nothing worth demanding.

Also that month · 1–5 August

An old browser, a hidden frame

Eric Eoin Marques was arrested in Ireland on 1 August 2013 on a provisional US extradition warrant. He was accused of running Freedom Hosting, which carried a large share of the Tor network's hidden services, among them sites distributing child sexual abuse material. Around midnight on 4 August those addresses began disappearing; the Tor Project, which said that day it had no connection to Freedom Hosting, published an advisory on the 5th. The servers had been reconfigured to inject a hidden frame into pages served to visitors, and the script inside it exploited a flaw in Firefox 17 ESR, on which the Tor Browser Bundle was then built, running a Windows-only payload that read the machine's hostname and hardware address and sent them, outside Tor, to an address researchers traced to northern Virginia. Mozilla had fixed the flaw in 17.0.7 and corrected bundles had shipped on 26 June; only people running old copies were exposed. The FBI acknowledged responsibility in a Dublin court filing on 12 September 2013. Marques pleaded guilty on 6 February 2020 and was sentenced in the United States on 15 September 2021 to twenty-seven years.

Also that month · 15–27 August

A reseller's password

The Syrian Electronic Army spent the month inside other people's supply chains. On 15 August readers of The Washington Post, Time and CNN were redirected after it compromised Outbrain, the recommendation widget embedded in their pages. On 27 August it went a level lower: shortly after three in the afternoon in New York, nytimes.com stopped resolving. The paper's own servers were untouched; the records had been altered at its registrar, Melbourne IT, which said a reseller's login credentials had been used improperly. Readers met blank screens into the night — the site was still unreachable for many at eleven — and Marc Frons, the paper's chief information officer, told staff to take care with email. Mid-month brought a smaller lesson in whose report gets read. Khalil Shreateh, a researcher in the West Bank, found that a Facebook user could post to a stranger's timeline, reported it, was told it was not a bug, and demonstrated it on Mark Zuckerberg's wall. Facebook fixed the flaw but refused the bounty because he had tested against a real account, and said on 19 August it would not change that rule. Marc Maiffret of BeyondTrust raised more than $10,000 for him by subscription.

India desk · August 2013

The mechanism, explained to Parliament

The question Lavabit put to an American court — whether the state may take the keys rather than the messages — had been settled in India already, quietly, in the state's favour. In July BlackBerry had delivered what the Department of Telecommunications recorded as a working lawful-interception facility for its Messenger and Internet Service traffic, ending a stand-off running since 2010; Enterprise Server traffic was excluded, the company maintaining it did not hold those keys. The framework underneath was older. On 7 August 2013 the Minister of State for Communications and Information Technology told Parliament that interception under the Central Monitoring System would follow the same mechanism as interception under Section 5(2) of the Indian Telegraph Act and Rule 419A. That system, built by C-DOT and rolled out state by state from April 2013, let nine central agencies take traffic without asking a telephone company.

The other Indian story was the government's own mail. At the end of August it was reported that a formal instruction would go to roughly half a million officials, requiring National Informatics Centre addresses instead of Gmail, Yahoo or Hotmail for official business; the E-mail Policy of the Government of India itself, drafted in this period, was not notified until February 2015. J. Satyanarayana, secretary of the department of electronics and information technology, said the policy was not a reaction to the surveillance disclosures and had been in preparation already. What India did not have in August 2013 was a privacy statute, a breach-notification duty, or any obligation to tell a citizen that something of theirs had been read or lost. Those gaps closed by direction in 2022, in CERT-In's six-hour rule, and by statute in 2023, in the DPDP Act.

AI Tech desk · August 2013

The Corelet and the K Computer

On 2 August 2013 researchers from RIKEN, the Okinawa Institute of Science and Technology and Forschungszentrum Jülich ran the largest neuronal network simulation attempted to that point, using Japan's K computer and the open-source NEST software: 1.73 billion model neurons and 10.4 trillion synapses across 82,944 processors and about a petabyte of memory. Forty minutes of machine time bought one second of activity in a network amounting to roughly one per cent of a human brain. RIKEN said the point was not insight into the brain but a test of the limits of the simulation technology. Six days later, on 8 August 2013, IBM presented at the International Joint Conference on Neural Networks in Dallas a way to program its neurosynaptic chips: an object-oriented language built around a unit called the corelet, a simulator named Compass, and a starting library of a hundred and fifty corelets; the work was led by Dharmendra Modha. Neither route led to what followed. The industry that grew after 2013 ran conventional networks on graphics processors, and brain-shaped silicon stayed a research programme.

Digital Guard desk · August 2013

IBM Buys Its Way to the Endpoint

On 15 August 2013 IBM announced an agreement to buy Trusteer, founded in Israel in 2006 and run out of Boston and Tel Aviv, whose software sat on the endpoint rather than the network. Rapport, its best-known product, was the browser hardening banks handed to their own customers; seven of the ten largest American banks and nine of the ten largest British ones used it. Apex, released in February 2013, applied the same approach inside companies, blocking the exploitation of unpatched browsers, Java and Reader instead of matching signatures. IBM did not disclose the price, and the figures circulating in the Israeli business press were reports, not filings. Brendan Hannigan, who ran IBM's Security Systems division, called it "enterprise endpoint defense and advanced malware prevention"; IBM said more than two hundred staff would form a security laboratory in Israel. The announcement came three weeks after Cisco agreed to buy Sourcefire; the deal closed on 3 September 2013. What Trusteer sold — watching what a program did rather than recognising what it was — is what the endpoint market spent the following decade renaming.

⏳ Time capsule — August 2013

  • On 5 August Jeff Bezos agreed to buy The Washington Post for $250 million, in a personal capacity rather than through Amazon.
  • On 12 August INS Vikrant, the first aircraft carrier designed and built in India, was launched at Cochin Shipyard in Kochi; at 262 metres she was the largest warship the country had built.
  • On 22 August the Nasdaq stock market stopped trading for a little over three hours, from 12:14 to 15:25, after a flood of messages from a rival exchange's system exposed a software flaw in the processor that publishes quotes. It was not an attack.
  • On 28 August the rupee closed at 68.80 to the dollar, a record low and its steepest single-day fall in eighteen years; the same afternoon in Washington, at the Lincoln Memorial, Barack Obama spoke at the ceremony marking fifty years since the March on Washington, with Jimmy Carter and Bill Clinton beside him.
Where it stands today — 2026

What a key is worth

The Fourth Circuit's silence in April 2014 left the central question open, and it has stayed open. It returns whenever a government asks a company for a capability rather than for data, and no American appellate court has yet answered it squarely. What changed was the engineering. Forward secrecy, uncommon on the public web in 2013, became ordinary within a few years, so a private key surrendered now no longer opens traffic recorded last year — precisely the value the Lavabit warrant was reaching for. End-to-end encryption moved from a niche product to a default in the largest messaging services. The most durable answer to a demand for keys turned out to be holding none.

The rest of the month hardened into practice. The exploit served from Freedom Hosting was the public debut of a technique American investigators went on to use at scale, and it acquired a settled name in court filings and a body of law around it. Registrar hijacking was answered by registry locks and tighter reseller controls, now routine for large publishers. Bug bounties became a profession, though the rule Facebook stated on 19 August held: test against a real account and there is no payment. A month later the disclosures moved from operators to the standards themselves, which is September 2013. And in India the interception framework explained to Parliament on 7 August 2013 is still, in 2026, the interception framework.