The fact the government wanted the SSL keys is obvious they wanted to get at all his customers, not just the one they were targeting. Levison offered multiple times to write a specific script for the single user that would do what they wanted and at a minimal cost to the government - and they refused. A pretty clear indication they wanted unfettered access to his client base and his network. Then you add in the lack…
Do you really consider the judicial warrant system a lack of ANY oversight? After Levison's lack of cooperation, could the investigators really trust Levison to hand over all the information?
How Lavabit Melted Down
101–110 of 177 posts
Re: How Lavabit Melted Down
#102Earlier quoted context omitted.
How was it a handwave if it actually worked? And this is the first time I've heard that Hushmail was forced to betray their users, rather than doing it in response to a simple request. Do you have more information on that?
"How was it a handwave if it actually worked?" Ladar claimed that he had no way to access user emails. The hidden subtext of that, which was sort of hand-waved away, was that he had no such access with the code he had written , and that all that stood between your mail and his eyes was his own willingness to write that code. The entire security of Lavabit depends on Ladar and his principles.
These systems are entirely built on code, and code is malleable. If you have control over the code that gets executed at every point in the stack (which the operator of a web app certainly does), there's always room for the operator to change the code and therefore change the behavior to do anything, including log things that were previously considered secure.
> The entire security of Lavabit depends on Ladar and his principles.
That has always been true. If he was a less scrupulous individual, he could have run an off-the-shelf e-mail solution with 0 fancy security, but claimed that it was all secure on the backend in his marketing. You wouldn't know the difference, because you can't audit the source code.
Unless you have the access, time, and expertise to perform your own source audit, any claims of security are always implicitly built upon a foundation of trust that the operator is doing what it claims.
Re: How Lavabit Melted Down
#103> While he opposes the bulk collection of domestic communications, he has no such strong feelings about the N.S.A.’s foreign-surveillance efforts. As a non-American, I have a problem with this seemingly widespread idea even among privacy advocates in the USA that only Americans are entitled to the protection of their rights from the American government.
Re: How Lavabit Melted Down
#104Earlier quoted context omitted.
"How was it a handwave if it actually worked?" Ladar claimed that he had no way to access user emails. The hidden subtext of that, which was sort of hand-waved away, was that he had no such access with the code he had written , and that all that stood between your mail and his eyes was his own willingness to write that code. The entire security of Lavabit depends on Ladar and his principles.
Isn't that always going to be true? These systems are entirely built on code, and code is malleable. If you have control over the code that gets executed at every point in the stack (which the operator of a web app certainly does), there's always room for the operator to change the code and therefore change the behavior to do anything, including log things that were previously considered secure. > The entire security…
Which is exactly why nobody should have believed Ladar's claims in the first place. He trumpeted the fact that he had not yet developed any wiretapping capability and tried to distract everyone from the hard reality of "encrypted webmail."
This is why real security and privacy require end-to-end encryption.
Re: How Lavabit Melted Down
#105Earlier quoted context omitted.
We should celebrate Ladar for making the decision to put himself at risk in order to protect his users, but I think we should be careful not to forget that Ladar was forced to make that decision because the security of Lavabit was all a total handwave. This wasn't untested water, either. The exact same thing happened to Hushmail for the exact same reason, and should have been evidence enough that the model isn't viab…
How was it a handwave if it actually worked? And this is the first time I've heard that Hushmail was forced to betray their users, rather than doing it in response to a simple request. Do you have more information on that?
I remember this happening. Since whoever runs Hushmail didn't go to the press and his blog and make a big scene after being approached by the feds (both for the US and Canada, mind you, since Hushmail's a canadian company). There's a reason why Hushmail was targeted, it was at the time the best way to figure out who's shipping large quantities of drugs everywhere. In the same year, Hushmail and eGold became compromised and Bush passed a law stating police can open your mail in USPS if they think you're a terrorist (previously they needed a warrant which by the time they obtained one you'd already have your package). Coincidentally, this was I believe around the time Silk Road started up. :)
So, Hushmail was involved in the pre-Silk Road days of internet drug trafficking, and I'm pretty sure that is not the position they wanted to be in. We'll never know if Hushmail was "forced" to give up users' information, but I would say that even if they didn't want to, they pretty much would have no other choice other than shutting their doors.
Re: How Lavabit Melted Down
#106Earlier quoted context omitted.
And if I recall correctly their ex-CEO is now in jail on allegedly trumped up charges. If true this is utterly despicable by the government. Alas, I'm not surprised.
Is insider trading a trumped-up charge? I didn't hear the internet outrage about Enron's CFO being indicted for the same charge.
Re: How Lavabit Melted Down
#107Earlier quoted context omitted.
We should celebrate Ladar for making the decision to put himself at risk in order to protect his users, but I think we should be careful not to forget that Ladar was forced to make that decision because the security of Lavabit was all a total handwave. This wasn't untested water, either. The exact same thing happened to Hushmail for the exact same reason, and should have been evidence enough that the model isn't viab…
It wasn't a handwave. It was the best current technology could offer, but this technology was not meant to deal with the oppressive government that can compel any company to reveal any information. As soon as Ladar realized that, and the fact that he is in the jurisdiction of the oppressive government, Lavabit was done.
Sure, if we ignore the existence of things like PGP, S/MIME, smart cards, and the dozens of other ways we can have secure email without relying on some trusted third party like this.
"this technology was not meant to deal with the oppressive government that can compel any company to reveal any information"
Then it was not meant to deal with the evil hacker who takes control of the server and grabs valuable information.
"As soon as Ladar..."
There's the handwave. The security of the system depends not on technology, math, or physical laws, but on the whims of just one man. What if Ladar was less principled?
Re: How Lavabit Melted Down
#108The fact the government wanted the SSL keys is obvious they wanted to get at all his customers, not just the one they were targeting. Levison offered multiple times to write a specific script for the single user that would do what they wanted and at a minimal cost to the government - and they refused. A pretty clear indication they wanted unfettered access to his client base and his network. Then you add in the lack…
> Levison offered multiple times to write a specific script for the single user ... A pretty clear indication they wanted unfettered access to his client base and his network i don't think this is the correct interpretation. in a court of laws, acquiring evidence is something procedural and governed by rules and regulations. having a third party (lavabit) acquire the evidence and then turn it over to the government i…
- The government is granted the right to snoop on Snowden's e-mail from a court. The court implores Lavabit to provide the technical expertise necessary to make this successful. - Lavabit replies that all traffic is encrypted, and that it would be a expensive to change that. Lavabit offers to make those changes so long as the government covers the costs of the change (in this case, one week of developer time). - The government balks at the prospect of paying for the change and tries to snoop themselves. They realize that the encrypted data they can snoop on themselves is worthless, and demand the ability to decrypt it themselves.
All of this seems to hinge on Lavabit's demand that it be paid to make the changes necessary to make the pen register effective. Presuming the government was willing to pay him (or he was willing to work for free), there would be a http://fbi.lavabit.com/snowden that mirrored all of Snowden's metadata and it would interoperate with the government's pen register. There would be no need to compromise everyone else's SSL key.
I'm not familiar with legal procedure, but how does that corrupt the chain of custody in a way that other solutions would not?
Re: How Lavabit Melted Down
#109> While he opposes the bulk collection of domestic communications, he has no such strong feelings about the N.S.A.’s foreign-surveillance efforts. As a non-American, I have a problem with this seemingly widespread idea even among privacy advocates in the USA that only Americans are entitled to the protection of their rights from the American government.
To be fair, your government should be working to protect you from foreign threats like this. You should not rely on foreign powers to protect you.
Re: How Lavabit Melted Down
#110> While he opposes the bulk collection of domestic communications, he has no such strong feelings about the N.S.A.’s foreign-surveillance efforts. As a non-American, I have a problem with this seemingly widespread idea even among privacy advocates in the USA that only Americans are entitled to the protection of their rights from the American government.
Personally, I don't like the existence of national borders of any kind, but I also can't wish them away. And when you draw a line, that says there's something you want to exclude on the other side of it, and the stuff over there just might decide to cross the line in a way you don't like.
My general strategy has been to support inclusive immigration policies, globalization efforts, and joint international operations. The more of these that exist, the less meaningful national boundaries become, the less necessary national defense will be.