Live data from Hacker News

How Lavabit Melted Down

newyorker.com

11–20 of 177 posts

Re: How Lavabit Melted Down

#11
post #3
post #2

I am blown away by the bravery, I know I'd never be so bold. Also confused why he didn't end up in prison on mysterious "pervert" charges out of the blue or even dead. And don't lecture me that is far fetched after this past year.

Well, if they killed him, they probably wouldn't be able to get the keys. And they probably had to keep the bigger "punishment", imprisonment, looming over his head in case he reveals confidential information about the case.

The guardian said Snowden is to release US gov't assassination program documentation in a weeks time. So perhaps we will get insight on the in inner workings of systematic killing.

Re: How Lavabit Melted Down

#12
post #10

The more I read the more sympathy I have for the government here. They had a (presumably lawfully obtained) warrant against a specific user; it's not they who designed lavabit such that it was impossible to execute this without obtaining access to every other user. The proposal that Levison would extract the information himself rather than turning over the keys strikes me as completely unrealistic - any information s…

Regardless of "fruit of poison tree" laws, information known is hard to unknow, and it wouldn't be surprising if information leaked to others could be used to lead hounds to foxes via different paths.

Re: How Lavabit Melted Down

#13
post #10

The more I read the more sympathy I have for the government here. They had a (presumably lawfully obtained) warrant against a specific user; it's not they who designed lavabit such that it was impossible to execute this without obtaining access to every other user. The proposal that Levison would extract the information himself rather than turning over the keys strikes me as completely unrealistic - any information s…

> it's not [the government] who designed lavabit such that it was impossible to execute this without obtaining access to every other user.

That's true, but they're still essentially implying that services which are explicitly designed to omit backdoor capabilities for the government to spy on you -- that is, services offering actual cryptographically guaranteed privacy, not just "no one has looked yet, and if they did, it'll all turn out okay in the end trust us" -- are broadly illegal and will get you criminal contempt.

Re: How Lavabit Melted Down

#14
post #12
post #10

The more I read the more sympathy I have for the government here. They had a (presumably lawfully obtained) warrant against a specific user; it's not they who designed lavabit such that it was impossible to execute this without obtaining access to every other user. The proposal that Levison would extract the information himself rather than turning over the keys strikes me as completely unrealistic - any information s…

Regardless of "fruit of poison tree" laws, information known is hard to unknow, and it wouldn't be surprising if information leaked to others could be used to lead hounds to foxes via different paths.

Indeed: what they routinely do in those cases is take some otherwise-ignorant agent, give them a little advice like "hey, you really should check out some stuff in this area" (nudge-nudge/wink-wink) and have him "rediscover" this information. Then they tell the court that it was Obtained Through That Agent's Normal Ordinary Investigations. "Parallell construction" aka "intelligence laundering".

https://www.eff.org/deeplinks/2013/08/dea-and-nsa-team-intel...

Re: How Lavabit Melted Down

#15
post #10

The more I read the more sympathy I have for the government here. They had a (presumably lawfully obtained) warrant against a specific user; it's not they who designed lavabit such that it was impossible to execute this without obtaining access to every other user. The proposal that Levison would extract the information himself rather than turning over the keys strikes me as completely unrealistic - any information s…

> it's not [the government] who designed lavabit such that it was impossible to execute this without obtaining access to every other user. That's true, but they're still essentially implying that services which are explicitly designed to omit backdoor capabilities for the government to spy on you -- that is, services offering actual cryptographically guaranteed privacy, not just "no one has looked yet, and if they di…

It has always been illegal to not comply with search warrants. Why would search warrants for digital data be any different?

Re: How Lavabit Melted Down

#16
post #10

The more I read the more sympathy I have for the government here. They had a (presumably lawfully obtained) warrant against a specific user; it's not they who designed lavabit such that it was impossible to execute this without obtaining access to every other user. The proposal that Levison would extract the information himself rather than turning over the keys strikes me as completely unrealistic - any information s…

You are incorrect. The usual process in cases where the government subpoenas data from service providers is for the service providers to gather the data and supply it to the government. Doing anything else is nearly nonsensical since the government does not have the domain knowledge of the systems of the service provider to be capable of retrieving the data.

Re: How Lavabit Melted Down

#17
post #5
post #3

Earlier quoted context omitted.

Well, if they killed him, they probably wouldn't be able to get the keys. And they probably had to keep the bigger "punishment", imprisonment, looming over his head in case he reveals confidential information about the case.

It wouldn't surprise me if they had some sort of back door with Verisign or other certificate companies for this.

I'm 100% sure they do, but if you're careful when setting p your SSL/TLS keys, verisign (or any other CA) never sees your private keys, they just sign your CSR. If the FBI had wanted to, they could have seized the servers, and either broken into them and replaced the private key with their own, or replaced the servers with ones they'd built with their own ssl key pairs. But, as the article points out - what they were trying _very_ hard to get was complete infiltration of the entire Lavanit operation without any of the 400,000 paying customers of the supposedly secure email provider knowing about it. Kudos to Levinson for not allowing that to happen, to his great personal cost. (I doubt I'd have the courage to do the same)

Re: How Lavabit Melted Down

#18
post #4

The integrity and bravery he has shown in this fight is impressive. He has definitely earned enough "cred" to restart this business outside the US and be very successful.

We really need more companies (and those in control of those companies) that stand up for their customers this same way. A public company would not have been able to make this play, so keep that in mind when you are making decisions about where to put your data.

I think Qwest Communications was a public company when they refused to comply with the NSA.

Re: How Lavabit Melted Down

#19
post #7

There is a huge disconnect between the "justice" system and technology which needs to end. You've seen it before if you're in IT, that glazed eyes look when explaining why their Word document is missing… Anyone with judicial experience know if judges have trusted advisory panels that can help wrap their heads around technology to better rule on cases such as this?

You mean like Judge Alsup, who taught himself Java so that he could rule that Oracle's APIs are not copyrightable? Or Judge Wells, who ordered SCO to show him the code and then threw the case out when the failed to do so? We haven't done so bad on tech judges recently - it seems to me that the problem with the lavabit/NSA cases is not so much the technical side, but the classic one of government powers, and the fact that there is no explicit constitutional protections of privacy.

Re: How Lavabit Melted Down

#20
post #10

The more I read the more sympathy I have for the government here. They had a (presumably lawfully obtained) warrant against a specific user; it's not they who designed lavabit such that it was impossible to execute this without obtaining access to every other user. The proposal that Levison would extract the information himself rather than turning over the keys strikes me as completely unrealistic - any information s…

Surely there must have been a way to have Levison decrypt that users account that would have been satisfactory to the government. I agree that him extracting the information himself isn't a solution, but surely there's a way to do it properly.

The solution isn't either of the extremes, 1) Give access to all Lavabit users or 2) Refuse to comply with a legal warrent, it's somewhere in the middle.

Post reply on HN