Earlier quoted context omitted.
The problem is that services like Lavabit want to do something that is technically not possible: give you access to your encrypted mail from any computer i.e. the convenience of webmail. If I can just download a key and keep it on my computer, why would I not just generate the key on my computer by e.g. using PGP or S/MIME?
No ... I meant a "red" button that could be used just prior to wiping the servers clean. Your point is completely valid while the service is running.
How Lavabit Melted Down
71–80 of 177 posts
Re: How Lavabit Melted Down
#72Earlier quoted context omitted.
> it's not [the government] who designed lavabit such that it was impossible to execute this without obtaining access to every other user. That's true, but they're still essentially implying that services which are explicitly designed to omit backdoor capabilities for the government to spy on you -- that is, services offering actual cryptographically guaranteed privacy, not just "no one has looked yet, and if they di…
CALEA requires that all telephone companies (and now mobile phone and cable companies) provide a means of "tapping" a phone line. To my knowledge, there's nothing similar that says a data service has to provide the ability to retrieve unencrypted data.
http://www.justice.gov/archive/ll/subs/add_myths.htm#s216
Yet another reason to repeal the "Patriot" Act.
Re: How Lavabit Melted Down
#73News outlets keep repeating "11 pages of 4-point type totaling 2560 characters", which just doesn't match up since that number of characters fits on one page in a fairly normal font size. Also, RSA keys just aren't that big, so the 11 pages must have either been many keys or some other data. As I understand Lavabit's architecture, there is no "master" key. Instead, incoming mail is encrypted using an asymmetric per-u…
Re: How Lavabit Melted Down
#74The integrity and bravery he has shown in this fight is impressive. He has definitely earned enough "cred" to restart this business outside the US and be very successful.
This wasn't untested water, either. The exact same thing happened to Hushmail for the exact same reason, and should have been evidence enough that the model isn't viable.
So I think we should definitely support Ladar as a person, but we also need to be careful not to confuse that with supporting Lavabit, which was a very real danger that should never be repeated again (again).
Re: How Lavabit Melted Down
#75The more I read the more sympathy I have for the government here. They had a (presumably lawfully obtained) warrant against a specific user; it's not they who designed lavabit such that it was impossible to execute this without obtaining access to every other user. The proposal that Levison would extract the information himself rather than turning over the keys strikes me as completely unrealistic - any information s…
This is what the battle over the clipper chip was about, and the government lost that one. Communications providers, absent any prior court orders, have no legal obligation to make their systems mass backdoor-compliant. It is the government, nominally, which is burdened here by the obligation to conduct their investigation without trampling the rights of 400,000 other people.
> "Even if he had turned over the SSL keys, the US still has a fairly strong "fruit of the poison tree" doctrine: any information the government happened to obtain on other users would be invalid for prosecution because it wouldn't be covered by their search warrant."
Which is why the government uses "parallel construction" to get around this restriction. And because the original source of the evidence remains classified, nobody can say for sure why the defendent was randomly stopped on the highway.
Re: How Lavabit Melted Down
#76The fact the government wanted the SSL keys is obvious they wanted to get at all his customers, not just the one they were targeting. Levison offered multiple times to write a specific script for the single user that would do what they wanted and at a minimal cost to the government - and they refused. A pretty clear indication they wanted unfettered access to his client base and his network. Then you add in the lack…
i don't think this is the correct interpretation. in a court of laws, acquiring evidence is something procedural and governed by rules and regulations. having a third party (lavabit) acquire the evidence and then turn it over to the government is probably something that wouldn't pass muster in court due to chain of custody and other rules.
the government investigators had a particular target, and they needed to collect evidence that would be admissible in a court of law. its actually pretty tough to come up with a good alternative here for the government.
Re: How Lavabit Melted Down
#77Earlier quoted context omitted.
Well, if they killed him, they probably wouldn't be able to get the keys. And they probably had to keep the bigger "punishment", imprisonment, looming over his head in case he reveals confidential information about the case.
The guardian said Snowden is to release US gov't assassination program documentation in a weeks time. So perhaps we will get insight on the in inner workings of systematic killing.
Re: How Lavabit Melted Down
#78Earlier quoted context omitted.
The more I read the less I have. why? Because it is individuals within the government, who know that what they truly need it limited access, but rely on the backing of the US Government to just get everything in hopes something neat falls out. Worded differently, far too many of these agents are willing to abuse the power of the courts, the secrecy of it all, to intimidate anyone because it makes the feel equally pow…
Since when are search warrants conducted without being under seal? Warrants persuant to a murder or racketeering case are not public information prior to execution. Otherwise the evidence would be disposed of by the perpetrators.
Re: How Lavabit Melted Down
#79The amount of support for Levison and ire toward the government in this case is absurd. The FBI followed the Constitutional process of obtaining a warrant for the information of the "one user". I suspect that the only reason anyone cares about this case is because Lord Snowden the Infallible deigned to grace Lavabit with his email traffic. Would the internet outrage be the same if the targeted user was found out to b…
Re: How Lavabit Melted Down
#80The integrity and bravery he has shown in this fight is impressive. He has definitely earned enough "cred" to restart this business outside the US and be very successful.
We should celebrate Ladar for making the decision to put himself at risk in order to protect his users, but I think we should be careful not to forget that Ladar was forced to make that decision because the security of Lavabit was all a total handwave. This wasn't untested water, either. The exact same thing happened to Hushmail for the exact same reason, and should have been evidence enough that the model isn't viab…