Live data from Hacker News

How Lavabit Melted Down

newyorker.com

61–70 of 177 posts

Re: How Lavabit Melted Down

#61
post #5

Earlier quoted context omitted.

It wouldn't surprise me if they had some sort of back door with Verisign or other certificate companies for this.

CA like Verisign don't have the key though, this misconception is too common. If you're doing it right the CA is just signing a cert you've generated, they never see the key.

Most people aren't verifying that the cert doesn't change every time they visit a site though - if they have Verisign sign a new cert and replace the old one 99% of users will never notice, because their browsers won't yell at them.

Re: How Lavabit Melted Down

#62

The fact the government wanted the SSL keys is obvious they wanted to get at all his customers, not just the one they were targeting. Levison offered multiple times to write a specific script for the single user that would do what they wanted and at a minimal cost to the government - and they refused. A pretty clear indication they wanted unfettered access to his client base and his network. Then you add in the lack…

Do you really consider the judicial warrant system a lack of ANY oversight?

After Levison's lack of cooperation, could the investigators really trust Levison to hand over all the information?

Re: How Lavabit Melted Down

#63
post #4

The integrity and bravery he has shown in this fight is impressive. He has definitely earned enough "cred" to restart this business outside the US and be very successful.

He shouldn't have any "cred" when it comes to security or availability. Maybe with sticking it to the man, but that doesn't a secure service make.

The system did serve sider encryption and decryption. Lavabit has, in the past, complied with court orders for data. They have access to the data. This is the fundamental problem with Lavabit.

It's rather unclear why they didn't comply with the initial court order in this case which was just for data on Snowden's account, but it's clear they could have complied (though maybe not as quickly as the Fed's wanted) and that they have in the past.

So, if you are contemplating using Lavabit II, keep in mind that sooner or latter it will get a lawful court order for data from whatever jurisdiction it's in. Either it will comply with it --- in which case it's street cred is worthless --- or it will refuse with the same apparent "fuck the police" bravado everyone likes , leading to the same set of escalations that happened here. The end of that is either/all of 1) the service failing because of computer seizure/the founder being held in contempt so he can't maintain it 2) Him caving and handing over keys again or 3) him shutting down the service to prevent 2.

None of these are good. If the court order is targeted at you, there is a decent chance your data is handed over. If it's not, there is a decent chance your data is still handed over or the service goes under.

Oh, and lastly, if your worried about the NSA's dragnet surveillance, they can just hack a foreign server.

Don't rely on non-end-to-end secure systems.

Re: How Lavabit Melted Down

#64
post #18

Earlier quoted context omitted.

I think Qwest Communications was a public company when they refused to comply with the NSA.

And if I recall correctly their ex-CEO is now in jail on allegedly trumped up charges. If true this is utterly despicable by the government. Alas, I'm not surprised.

Is insider trading a trumped-up charge? I didn't hear the internet outrage about Enron's CFO being indicted for the same charge.

Re: How Lavabit Melted Down

#65
post #10

The more I read the more sympathy I have for the government here. They had a (presumably lawfully obtained) warrant against a specific user; it's not they who designed lavabit such that it was impossible to execute this without obtaining access to every other user. The proposal that Levison would extract the information himself rather than turning over the keys strikes me as completely unrealistic - any information s…

The more I read the less I have. why? Because it is individuals within the government, who know that what they truly need it limited access, but rely on the backing of the US Government to just get everything in hopes something neat falls out. Worded differently, far too many of these agents are willing to abuse the power of the courts, the secrecy of it all, to intimidate anyone because it makes the feel equally pow…

Since when are search warrants conducted without being under seal? Warrants persuant to a murder or racketeering case are not public information prior to execution. Otherwise the evidence would be disposed of by the perpetrators.

Re: How Lavabit Melted Down

#66
I've been skeptical of LavaBit, chalking it up to the general deification that HN gives to its heroes du jour, but he really seems to have made a highly principled stand while still allowing the government to intercept any individual for which it had a warrant.

Re: How Lavabit Melted Down

#67
post #31

Is anyone else thinking that their systems should include a self-destruct button? (for LavaBit I'd imagine a process that e-mailed each user the SSL key used to encrypt their mailbox, then deleted the key from the system. A user could still decrypt their mailbox by downloading it and using the key).

This isn't any different than shredding all your business documents when you hear the cops knocking on your door. It was frowned upon when Enron undertook a mass shredding during their investigation.

Re: How Lavabit Melted Down

#68

The fact the government wanted the SSL keys is obvious they wanted to get at all his customers, not just the one they were targeting. Levison offered multiple times to write a specific script for the single user that would do what they wanted and at a minimal cost to the government - and they refused. A pretty clear indication they wanted unfettered access to his client base and his network. Then you add in the lack…

Do you really consider the judicial warrant system a lack of ANY oversight? After Levison's lack of cooperation, could the investigators really trust Levison to hand over all the information?

Why should Levison trust a government who has proven to be untrustworthy when it comes to data collection? Levison didn't lie or mislead anyone, he even offered to get the data for them as long as it was targeted. The government has basically zero credibility in matters like this, and yet he was expected to trust them with no oversight (in the article, he was told there was no independent audit of their use of the data)?

Re: How Lavabit Melted Down

#69
post #10

The more I read the more sympathy I have for the government here. They had a (presumably lawfully obtained) warrant against a specific user; it's not they who designed lavabit such that it was impossible to execute this without obtaining access to every other user. The proposal that Levison would extract the information himself rather than turning over the keys strikes me as completely unrealistic - any information s…

This situation exemplifies a type of conundrum: conditions or goals X and Y are incompatible; they cannot coexist. Persons A and B observe this fact, and A concludes "Therefore X must be sacrificed to protect Y" and B concludes "Therefore Y must be sacrificed to protect X".

Your argument starts with the premise that the government is always entitled to data on particular individuals being investigated, and all other values must always be sacrificed to that end. Your review of the costs imposed, however, recognizes only the wiretapping of "every other user".

There is also an additional price paid, which is even more significant and unfortunately not recognized in your argument nor even in Leveson's arguments in the case. The SSL private key is not only for encryption, it also is designed to authenticate the server to the user. Thus, revealing it enables the additional party to impersonate the server owner online. (In this case, the impersonation would have taken the form of a compromised server, no longer under the owner's control, purporting to be the uncompromised server still under the owner's control.)

The evil comes in with the combination of this demand and the gag order. If the server owner could either keep the key secret or warn the users, this evil could not happen - but when both are prohibited, he is forced to enable the third party to lie to the users and make his server a fraud.

Accordingly, my view is that one of these things must yield - either the secret key demands or the gag orders. This is a higher social value than the wiretapping of persons alleged to be suspected of crimes ("alleged" because the secrecy of the process prevents the citizens verifying that the government has any legitimate grounds at all).

Re: How Lavabit Melted Down

#70

The amount of support for Levison and ire toward the government in this case is absurd. The FBI followed the Constitutional process of obtaining a warrant for the information of the "one user". I suspect that the only reason anyone cares about this case is because Lord Snowden the Infallible deigned to grace Lavabit with his email traffic. Would the internet outrage be the same if the targeted user was found out to b…

Er yeah, he offered to backdoor the one user for them and they refused.
Post reply on HN