Live data from Hacker News

How Lavabit Melted Down

newyorker.com

111–120 of 177 posts

Re: How Lavabit Melted Down

#111

> While he opposes the bulk collection of domestic communications, he has no such strong feelings about the N.S.A.’s foreign-surveillance efforts. As a non-American, I have a problem with this seemingly widespread idea even among privacy advocates in the USA that only Americans are entitled to the protection of their rights from the American government.

To be fair, your government should be working to protect you from foreign threats like this. You should not rely on foreign powers to protect you.

Right, but it's not an either-or thing.

Re: How Lavabit Melted Down

#112

Earlier quoted context omitted.

Having CA access does allow them to create a silent MITM in the absence of certificate pinning.

With a different key though. Once you've got this new cert. you can MITM, but you can't use it to decrypt the traffic already captured. Also anyone paying attention sees the cert. fingerprint change out of the blue.

A) Law enforcement doesn't need to decrypt previously-captured traffic; they either want to fish for criminal activity or they'll allow their target to build up new incriminating evidence. B) Who pays attention?

Re: How Lavabit Melted Down

#113
post #71
post #42

Earlier quoted context omitted.

No ... I meant a "red" button that could be used just prior to wiping the servers clean. Your point is completely valid while the service is running.

Here's a Defcon talk about more or less that: http://www.youtube.com/watch?v=1M73USsXHdc

Thanks for sharing that link. I couldn't find that talk last time the question of emergency data destruction came up.

Re: How Lavabit Melted Down

#114
post #74

Earlier quoted context omitted.

We should celebrate Ladar for making the decision to put himself at risk in order to protect his users, but I think we should be careful not to forget that Ladar was forced to make that decision because the security of Lavabit was all a total handwave. This wasn't untested water, either. The exact same thing happened to Hushmail for the exact same reason, and should have been evidence enough that the model isn't viab…

Unless he actually used properly implemented forward secure SSL for every connection, which I doubt all of either his customers browsers or the SMTP servers he talked to supported, didn't his choices actually put his customers in more danger? He could have complied with one of the several valid court orders that requested he give the FBI data on a specific account but stopped short if installing FBI code or devices o…

Read the article.

Re: How Lavabit Melted Down

#115
post #94

Earlier quoted context omitted.

It wasn't a handwave. It was the best current technology could offer, but this technology was not meant to deal with the oppressive government that can compel any company to reveal any information. As soon as Ladar realized that, and the fact that he is in the jurisdiction of the oppressive government, Lavabit was done.

"It was the best current technology could offer" Sure, if we ignore the existence of things like PGP, S/MIME, smart cards, and the dozens of other ways we can have secure email without relying on some trusted third party like this. "this technology was not meant to deal with the oppressive government that can compel any company to reveal any information" Then it was not meant to deal with the evil hacker who takes co…

Have you heard about "thermorectal decryption"?

Re: How Lavabit Melted Down

#116
post #97

Earlier quoted context omitted.

I believe the preferred nomenclature is 'targeted killing'.

I'll be surprised if it doesn't have some whitewashed name like "Citzenship Revocation Program" that lets people talk about it without saying "killing".

More like "Citizen Revocation Program". Wouldn't want citizenship reduced and people earning and paying taxes to other countries.

Re: How Lavabit Melted Down

#117

Earlier quoted context omitted.

Isn't that always going to be true? These systems are entirely built on code, and code is malleable. If you have control over the code that gets executed at every point in the stack (which the operator of a web app certainly does), there's always room for the operator to change the code and therefore change the behavior to do anything, including log things that were previously considered secure. > The entire security…

"These systems are entirely built on code, and code is malleable. If you have control over the code that gets executed at every point in the stack (which the operator of a web app certainly does), there's always room for the operator to change the code and therefore change the behavior to do anything, including log things that were previously considered secure." Which is exactly why nobody should have believed Ladar'…

You might be missing the point a little bit. You're correct, but end-to-end encryption is irrelevant if the operator changes the (e.g., Javascript) code in a webmail app and maybe even just for a single user.

The trust model has to include the device/OS/browser/etc that you're accessing the device on as well as all code and keys (including WOT servers, GPG keys, and the webmail code itself, or, if locally installed, all binary packages, updates, etc).

Which I think is the point is really that in the face of a government who can compel, e.g.,

* an OS vendor to install a backdoor in their software, * a microprocessor vendor to critically weaken the Random Number Generator, * the author and BDFL of a key operating system kernel to use said RNG, * a distribution to include compromised or even unsigned packages, * a mobile carrier who will allow random hardware on their network that can sniff, MITM, and inject evil data, * a mobile phone manufacturer who will install CarrierIQ, * (heavens!) a user/customer who visits an app store and installs an application with either a trojan attached or one that is directly a trojan,..

In other words, no amount of end-to-end crypto will save us if we're attacked at each end and in the middle by people who will stop at literally NOTHING (jail) just to get at the data. This is why Schneier wrote "The Government has betrayed the Internet."

http://www.theguardian.com/commentisfree/2013/sep/05/governm...

Encryption is no panacea when you're dealing with someone who controls both ends and the middle. :( To put this on Lavabit is poor form, IMO. This is one end who stood up and fought and paid a huge price.

Re: How Lavabit Melted Down

#118
post #22

Earlier quoted context omitted.

wtf? The site's [ https://lavabit.com ] SSL cert been revoked: http://d.pr/i/sc71 [IMG]

Great! It's because the private certificate was forcibly supplied to the government. No longer secure => revoke it.

Ah, makes sense. I donated, anyway.

Re: How Lavabit Melted Down

#119
post #4

The integrity and bravery he has shown in this fight is impressive. He has definitely earned enough "cred" to restart this business outside the US and be very successful.

He shouldn't have any "cred" when it comes to security or availability. Maybe with sticking it to the man, but that doesn't a secure service make. The system did serve sider encryption and decryption. Lavabit has, in the past, complied with court orders for data. They have access to the data. This is the fundamental problem with Lavabit. It's rather unclear why they didn't comply with the initial court order in this…

There are no end-to-end secure systems.

So you're typing this on OpenBSD? Sure, because that's secure.

Your RPM's are signed, so you're pretty sure they're safe?

Or you're using Funtoo or Arch and compiling from source? Have you read all that source? Even if you did, did you UNDERSTAND it all?

Are you using an Intel Ivy-Bridge or later processor with RdRand?

Are you using a phone?

Do you log into your webmail from one or more locations? How about email?

Do you trust SSL certificates? which ones?

And now... are all of those one other person that you're writing to that actually also uses GPG exercising the same caution? :)

I'm just saying... if you want to know that you're not being sniffed, you have to simply make it impossibly expensive to do so, which probably means get on a plane, meet and hand the person a note, and then burn it, and then scatter the ashes to the seven winds.

Then worry about the metadata of your flight, time, license plate readers, traffic and surveillance cameras.

The basic problem is that allowing this continued, blatant destruction of the 4th Amendment threatens the entire Bill of Rights which ultimately threatens the very foundation of our government and the rule of law.

Legal power, jail, and bullets trump crypto.

Re: How Lavabit Melted Down

#120
post #46
post #37

Earlier quoted context omitted.

> A public company would not have been able to make this play, Isnt it funny to hear that a public company would not have been able to do something when it is about something good for its consumers and ultimately its country and citizens, but when it is something extremely bad like compliance, obedience and evilness then they suddenly can and are free to do it. There is nothing stopping Google, Facebook or Microsoft…

"There is nothing stopping Google, Facebook or Microsoft to act as Lavabit did. Nothing at all except for their own cowardice, malicious intents and disregard for laws and their customers." Emphasis re-arranged by me. May I remind you that Lavabit was shut down in reaction to actions taken by law enforcement , doing something that is almost certainly actually legal? "Regard for the law" here would seem to entail doin…

The Supreme Law of the Land is the Constitution, right?

The Fourth Amendment has a few things to say on this. I'd strongly advise you to actually read it -- it's only a few sentences -- and make your own determination on what you think it actually says.

The FISC, authorized under the FISA, goes back to the 70's and was in reaction to the crimes that Nixon committed. Meet the new boss, same as the old boss. Obama has taken that ball and run with it in a big way. Most transparent administration, ha.

And even then, the FISC was and is itself contradictory to the Bill of Rights, 14th Amendment, etc,....

Guess which law wins? Assuming the Supreme Court agrees (and there's no guarantee they would.)

So if you're ordered to do something awful, but you know that there is a higher law that trumps that law, you can simultaneously be disregarding "the law" whilst maintaining "regard" for the law.

The key is: which law?

Post reply on HN