Live data from Hacker News

What Exactly Did The US Government Ask Lavabit to Do?

xato.net

21–30 of 46 posts

Re: What Exactly Did The US Government Ask Lavabit to Do?

#21
post #17
post #8

Earlier quoted context omitted.

> Only a handful of mail providers (like Google) have the option to encrypt traffic server to server. SSL/TLS is available for everyone. > Most mail servers transmit messages in the clear to each other and only encrypt the server to client side. I hear this again and again, but I can't really find any data that confirms this claim one way or another. Anyone on HN running their own mailserver wanting to comment on how…

The entire email transation between a sender and a recipient usually looks like this: Sending Client [--A---> Sender SMTP Server [--B---> Recipient SMTP Server [--C--> Recipient IMAP/POP server Connections A and D are easily possible to encrypt, provided your provider provides SSL/TLS on their SMTP and IMAP/POP servers. Most usually do. Connection C is usually local to a single machine, or for large email providers w…

> That is almost always in clear text, as most of this infrastructure was designed 30 years ago and hasn't evolved much since then

Email has definitely evolved since it's inception. STARTTLS (RFC3207) is the relevant standard here.

Re: What Exactly Did The US Government Ask Lavabit to Do?

#22
post #19
post #15

This article seems to speculate on things that are not necessarily true. It's possible that the government simply told him that he had to be able to supply information arbitrarily on demand without an explicit warrant. This does not mean that they required him to install their own software on his machines. Of course, one certainly still argue that this a line that the Government should not cross - I'd wholeheartedly…

That's actually the whole point, in the past he complied with warrants because there wasn't much he could supply in the first place. Yes there is a lot of reading between the lines here, but there was a clear line they crossed. In other words, he would no longer be able to just turn over a bunch of encrypted emails, this was a full compromise of the security he had in place. If you look at the quotes he made, he stro…

What I don't see is these three statements:

1. Force Lavabit to provide their private SSL keys and route all their traffic through a government machine that performed a man-in-the-middle style data collection; 2. Change their software to subvert Lavabit’s own security measures and log emails after SSL decryption but before encrypting with the users’ public keys; or 3. Require Lavabit to install malicious code to infect their own customers with government-supplied malware.

It sounds like he already has the ability to comply with demands for information. I don't see where this new stipulation by them requires any meaningful change to his existing infrastructure.

Re: What Exactly Did The US Government Ask Lavabit to Do?

#23
So long as uninformed speculation is running loose... Lavabit's comment that "If you knew what I know about e-mail, you might not use it either." points in a email specific direction as opposed to simple sniffing of traffic.

Perhaps he is referring to the Stored Communications Act ( http://en.wikipedia.org/wiki/Stored_Communications_Act ). I haven't seen it referenced in coverage of this but the gist is under the right circumstances email that is older than six months and stored on a server that you don't own can be accessed without a warrant. Lavabit's encryption process as described would interfere with that. Not being able to comply AND being unwilling to take steps to comply in the future is the sort of thing that feds don't like.

This wasn't a big deal when it was passed in 1986 and small mail quotas were the norm but now with IMAP, multiple devices, and archiving it becomes a pretty big issue as you are talking about someone's electronic life instead of abandoned mailboxes.

AFAIK the issue of Fourth Amendment issues and SCA hasn't made it to the Supreme Court yet so interpretations vary depending on circuit.

Re: What Exactly Did The US Government Ask Lavabit to Do?

#24
post #23

So long as uninformed speculation is running loose... Lavabit's comment that "If you knew what I know about e-mail, you might not use it either." points in a email specific direction as opposed to simple sniffing of traffic. Perhaps he is referring to the Stored Communications Act ( http://en.wikipedia.org/wiki/Stored_Communications_Act ). I haven't seen it referenced in coverage of this but the gist is under the rig…

Levison did make a comment once that he couldn't give the government what he didn't have, referring to deleted emails. I didn't address that in the article but it is another dimension to this. Being that this is all about something he didn't already have, chances are that archived messages was one of those things.

Nevertheless, the means to decrypt those messages still is the critical difference here.

Re: What Exactly Did The US Government Ask Lavabit to Do?

#25
post #22
post #19

Earlier quoted context omitted.

That's actually the whole point, in the past he complied with warrants because there wasn't much he could supply in the first place. Yes there is a lot of reading between the lines here, but there was a clear line they crossed. In other words, he would no longer be able to just turn over a bunch of encrypted emails, this was a full compromise of the security he had in place. If you look at the quotes he made, he stro…

What I don't see is these three statements: 1. Force Lavabit to provide their private SSL keys and route all their traffic through a government machine that performed a man-in-the-middle style data collection; 2. Change their software to subvert Lavabit’s own security measures and log emails after SSL decryption but before encrypting with the users’ public keys; or 3. Require Lavabit to install malicious code to infe…

Again, that's the whole point. He wasn't able to provide them with what they wanted, and doing so meant that he either had to allow them to intercept messages (or passwords) on Lavabit's application servers, which is the only place they could be intercepted. Doing so would require either impersonating their servers through a MitM or code changes on their server.

I do acknowledge in the article that this could simple be an overhyped reaction to placing a black box on his network, but the statements Levison made seem to indicate otherwise. And hey I could be wrong about this whole thing, it still is largely speculation based on circumstantial evidence.

Re: What Exactly Did The US Government Ask Lavabit to Do?

#26
It seems pretty clear to me (Occam's razor):

1) he was told he had to use the same monitoring process all the other providers were using

2) as a state secret, he couldn't reveal he was doing it ever to his users

3) if he complied he would totally undermine the nature of his service

Anything else is superfluous.

Re: What Exactly Did The US Government Ask Lavabit to Do?

#27
post #7
post #5

A device or piece of software designed to sniff the mail server to mail server connections would also be an option for broad based surveillance. Only a handful of mail providers (like Google) have the option to encrypt traffic server to server. Most mail servers transmit messages in the clear to each other and only encrypt the server to client side.

Perhaps only a handful such as Google will use SSL but Google is a HUGE percentage of email.

I completely assume that Google will turn over your entire email history to the US government whenever they ask, and without telling you, then or later.

Re: What Exactly Did The US Government Ask Lavabit to Do?

#28
post #23

So long as uninformed speculation is running loose... Lavabit's comment that "If you knew what I know about e-mail, you might not use it either." points in a email specific direction as opposed to simple sniffing of traffic. Perhaps he is referring to the Stored Communications Act ( http://en.wikipedia.org/wiki/Stored_Communications_Act ). I haven't seen it referenced in coverage of this but the gist is under the rig…

Had it been because of the Stored Communications Act, would that explain why he couldn't talk about it?

Re: What Exactly Did The US Government Ask Lavabit to Do?

#29
"In reality all it would take is a few lines of code code to log the user’s original password which allows you to decrypt the private key which in turn allows you to receive and send mail as that user as well as access any stored messages."

Is this any different to writing a few lines of code to sniff the PreMasterSecret or even just a plain ol' MitM attack?

Re: What Exactly Did The US Government Ask Lavabit to Do?

#30
post #23

So long as uninformed speculation is running loose... Lavabit's comment that "If you knew what I know about e-mail, you might not use it either." points in a email specific direction as opposed to simple sniffing of traffic. Perhaps he is referring to the Stored Communications Act ( http://en.wikipedia.org/wiki/Stored_Communications_Act ). I haven't seen it referenced in coverage of this but the gist is under the rig…

Had it been because of the Stored Communications Act, would that explain why he couldn't talk about it?

Someone else can probably answer this more accurately, but I don't see that these two things are related.

That is, they may have referenced the Stored Communications Act when requesting the information, but that is not what puts a gag on Lavabit.

Post reply on HN