Live data from Hacker News

How Lavabit Melted Down

newyorker.com

81–90 of 177 posts

Re: How Lavabit Melted Down

#81
post #74
post #4

The integrity and bravery he has shown in this fight is impressive. He has definitely earned enough "cred" to restart this business outside the US and be very successful.

We should celebrate Ladar for making the decision to put himself at risk in order to protect his users, but I think we should be careful not to forget that Ladar was forced to make that decision because the security of Lavabit was all a total handwave. This wasn't untested water, either. The exact same thing happened to Hushmail for the exact same reason, and should have been evidence enough that the model isn't viab…

Unless he actually used properly implemented forward secure SSL for every connection, which I doubt all of either his customers browsers or the SMTP servers he talked to supported, didn't his choices actually put his customers in more danger?

He could have complied with one of the several valid court orders that requested he give the FBI data on a specific account but stopped short if installing FBI code or devices on his system or handing over the keys. Had he done so, it would have stop there.

Instead, it escalated to the point where he actually was forced to expose all his users. Anyone who has transcripts of those connections (e.g the NSA), can now read them, get the passwords, and decrypt any mail they got form the server. It seems like a boneheaded move unless his only goal was to protect Snowden at all costs.

Re: How Lavabit Melted Down

#82
post #24

I still don't get one thing about this story: >> To make use of these keys, the F.B.I. would have to manually input all two thousand five hundred and sixty characters, and one incorrect keystroke in this laborious process would render the F.B.I. collection system incapable of collecting decrypted data Don't FBI have some ultra DPI scanner with advanced OCR software? Let's say they live under a rock, it's still not so…

This assumes that it was printed with a high-dpi printer. From the reports I've read he intentionally chose a font that would be hard for a computer to read. There's also no evidence that he printed it on any special high-dpi printer, so the process almost certainly lost enough information as to make the printed text not-fully-recoverable.

Re: How Lavabit Melted Down

#83

Earlier quoted context omitted.

> it's not [the government] who designed lavabit such that it was impossible to execute this without obtaining access to every other user. That's true, but they're still essentially implying that services which are explicitly designed to omit backdoor capabilities for the government to spy on you -- that is, services offering actual cryptographically guaranteed privacy, not just "no one has looked yet, and if they di…

Lavabit had no such guarantees. First, the court order was for meta-data which wasn't encrypted. Second, encryption was done server side, so they did have access to the data the government requested. The judge wasn't talking about end-to-end encryption. They were talking about Lavabit's assertion that it was difficult to get the data they admitted to having.

You say "Lavabit had no such guarantees."

Without me arguing one way or another whether that's true -- do you think if they had better guarantees, that anything would be different here? That the government would say "oh no, we'll back down now"?

Re: How Lavabit Melted Down

#84
post #31

Is anyone else thinking that their systems should include a self-destruct button? (for LavaBit I'd imagine a process that e-mailed each user the SSL key used to encrypt their mailbox, then deleted the key from the system. A user could still decrypt their mailbox by downloading it and using the key).

This isn't any different than shredding all your business documents when you hear the cops knocking on your door. It was frowned upon when Enron undertook a mass shredding during their investigation.

It was frowned upon because what Enron was doing was both illegal and immoral. What Lavabit was doing was neither. Further, Lavbit's founder took a stand on a believe in the right to anonymous communication. Compare this to Enron, where destruction of evidence was purely in an effort to hide evidence of culpability by those who ordered the destruction.

Re: How Lavabit Melted Down

#85

Earlier quoted context omitted.

Lavabit had no such guarantees. First, the court order was for meta-data which wasn't encrypted. Second, encryption was done server side, so they did have access to the data the government requested. The judge wasn't talking about end-to-end encryption. They were talking about Lavabit's assertion that it was difficult to get the data they admitted to having.

You say "Lavabit had no such guarantees." Without me arguing one way or another whether that's true -- do you think if they had better guarantees, that anything would be different here? That the government would say "oh no, we'll back down now"?

Suppose that Lavabit sold smart cards for end-to-end encryption, and as a service would store ciphertexts for you. The government shows up with a warrant, Lavabit says, "Sorry, we cannot comply because we cannot access secret keys or decrypt messages by some other means." What exactly does the government do after that?

The point is that Lavabit's architecture did not resist these kinds of demands at all. At best all Lavabit could do is protect your mail until you log in.

Re: How Lavabit Melted Down

#86
post #72
post #33

Earlier quoted context omitted.

CALEA requires that all telephone companies (and now mobile phone and cable companies) provide a means of "tapping" a phone line. To my knowledge, there's nothing similar that says a data service has to provide the ability to retrieve unencrypted data.

See Section 216 of the Patriot Act, which throws in the ability to get "pen register" information (metadata) from Internet communications. http://www.justice.gov/archive/ll/subs/add_myths.htm#s216 Yet another reason to repeal the "Patriot" Act.

Wouldn't metadata in this case be like "Ip X connected at Y and transferred Z bytes"? Similar to what a pen register produces with a phone call.

Re: How Lavabit Melted Down

#87
post #74

Earlier quoted context omitted.

We should celebrate Ladar for making the decision to put himself at risk in order to protect his users, but I think we should be careful not to forget that Ladar was forced to make that decision because the security of Lavabit was all a total handwave. This wasn't untested water, either. The exact same thing happened to Hushmail for the exact same reason, and should have been evidence enough that the model isn't viab…

How was it a handwave if it actually worked? And this is the first time I've heard that Hushmail was forced to betray their users, rather than doing it in response to a simple request. Do you have more information on that?

Being legally bound to give up the information is equivalent to being forced. If it wasn't forcible, why did Lavabit have to choose between compliance and shutting down?

Could you clarify what you mean by "How was it a handwave if it actually worked?" Lavabit, like Hushmail, has had no problem giving up information to law enforcement in the past.

Re: How Lavabit Melted Down

#88
post #84

Earlier quoted context omitted.

This isn't any different than shredding all your business documents when you hear the cops knocking on your door. It was frowned upon when Enron undertook a mass shredding during their investigation.

It was frowned upon because what Enron was doing was both illegal and immoral. What Lavabit was doing was neither. Further, Lavbit's founder took a stand on a believe in the right to anonymous communication. Compare this to Enron, where destruction of evidence was purely in an effort to hide evidence of culpability by those who ordered the destruction.

Knowingly and willfully destroying evidence that's been legally subpoenaed is indeed illegal, whether done by Enron "immorally" or $tech_company "morally".

Re: How Lavabit Melted Down

#89

Earlier quoted context omitted.

How was it a handwave if it actually worked? And this is the first time I've heard that Hushmail was forced to betray their users, rather than doing it in response to a simple request. Do you have more information on that?

Being legally bound to give up the information is equivalent to being forced. If it wasn't forcible, why did Lavabit have to choose between compliance and shutting down? Could you clarify what you mean by "How was it a handwave if it actually worked?" Lavabit, like Hushmail, has had no problem giving up information to law enforcement in the past.

[deleted]

Re: How Lavabit Melted Down

#90
post #10

The more I read the more sympathy I have for the government here. They had a (presumably lawfully obtained) warrant against a specific user; it's not they who designed lavabit such that it was impossible to execute this without obtaining access to every other user. The proposal that Levison would extract the information himself rather than turning over the keys strikes me as completely unrealistic - any information s…

I have not reviewed the documents in question, so forgive me if I'm wasting your time, but I suspect it was not, in fact, a warrant. Generally requests for so-called 'metadata' don't require the same amount of supporting evidence as search warrants (the theory being that you shouldn't have an expectation of privacy for that data). Lavabit was a service that explicitly provided a secure and private email to its paying…

I don't mean to be mean or rude, but yes, you are wasting our time. It was, in fact, a warrant.
Post reply on HN