Live data from Hacker News

How Lavabit Melted Down

newyorker.com

121–130 of 177 posts

Re: How Lavabit Melted Down

#121
post #76

The fact the government wanted the SSL keys is obvious they wanted to get at all his customers, not just the one they were targeting. Levison offered multiple times to write a specific script for the single user that would do what they wanted and at a minimal cost to the government - and they refused. A pretty clear indication they wanted unfettered access to his client base and his network. Then you add in the lack…

> Levison offered multiple times to write a specific script for the single user ... A pretty clear indication they wanted unfettered access to his client base and his network i don't think this is the correct interpretation. in a court of laws, acquiring evidence is something procedural and governed by rules and regulations. having a third party (lavabit) acquire the evidence and then turn it over to the government i…

> i don't think this is the correct interpretation. in a court of laws, acquiring evidence is something procedural and governed by rules and regulations. having a third party (lavabit) acquire the evidence and then turn it over to the government is probably something that wouldn't pass muster in court due to chain of custody and other rules.

Search for "$" on this page: http://paranoia.dubfire.net/2009/12/8-million-reasons-for-re... It is very common for third party service providers to search records themselves on behalf of law enforcement, and law enforcement has historically trusted that and even compensated them.

It's the only way that really makes sense IMO. Can the FBI really bust down, say, Verizon's doors, seize all their hard drives, and correctly generate evidence based on systems that aren't theirs, and may in fact be unique among the phone systems of the entire world? Maybe an email system is simpler, but still.

Also, I think it's inappropriate to seize 400,000 users' data just to (ostensibly) get to one person. But I'm not a lawyer, maybe it is arguably legal.

P.S. Also see https://www.eff.org/files/filenode/social_network/Yahoo_SN_L... for all the things Yahoo does on behalf of LE.

Re: How Lavabit Melted Down

#122

Earlier quoted context omitted.

"These systems are entirely built on code, and code is malleable. If you have control over the code that gets executed at every point in the stack (which the operator of a web app certainly does), there's always room for the operator to change the code and therefore change the behavior to do anything, including log things that were previously considered secure." Which is exactly why nobody should have believed Ladar'…

You might be missing the point a little bit. You're correct, but end-to-end encryption is irrelevant if the operator changes the (e.g., Javascript) code in a webmail app and maybe even just for a single user. The trust model has to include the device/OS/browser/etc that you're accessing the device on as well as all code and keys (including WOT servers, GPG keys, and the webmail code itself, or, if locally installed,…

"You might be missing the point a little bit. You're correct, but end-to-end encryption is irrelevant if the operator changes the (e.g., Javascript) code in a webmail app and maybe even just for a single user."

Which is why, as I have said elsewhere, webmail is the problem here; more generally, you cannot have security or privacy as a service.

As for the government pushing back doors into products, that is at least upping the ante. It is harder to sneak back doors into software that people are actually using, especially software that is widely used, than it is to sneak a back door onto a server than only a handful of people can inspect. It is also harder to sneak in a back door when there are many, separately maintained implementations of a common protocol; you are forced to try to sneak a back door into an abstract description, which a lot of experts will be reviewing (see e.g. DUAL_EC_DBRG; the backdoor was discovered within a year of the PRNG being publicized).

There are also limits to what sort of back doors can be put at a lower level. Suppose you sneak a back door into my CPU, but I am running software that was developed after you developed your back door. You can make a straightforward computability argument that in general, your back door will be rendered useless by unexpected changes to software, particularly sweeping changes to it.

In any case, my point is not that encryption is a panacea, but rather that webmail is, by its nature, insecure. There was no way that Lavabit's security could have ever been more than just a handwave.

Re: How Lavabit Melted Down

#123
post #41

Earlier quoted context omitted.

There are some causes that are worth being removed as CEO for. Lavabit founder finally is allowed to speak about this. It is enough if you threaten to shut down the business to make it known to the G-men that you wont play (the totalitarian) ball. We stopped SOPA/PIPA just with a partial blackout. But these companies didnt make a squeek. They are accomplices.

> There are some causes that are worth being removed as CEO for. Yeah, but not if it's an empty gesture that doesn't change anything. Any CEO of Google both wouldn't be able to shut it down rather than comply, and would be removed for trying. It would accomplish nothing.

So, you think the hyper publicity of a billion dollar tech darling CEO being ousted because he wanted to defend American liberties would accomplish nothing?

The first thing it does is piss off one very wealthy person, whoever this CEO is. The second thing it does is piss off all of their very connected, wealthy friends. The third thing it does is serve as an egregious example of abuse to the public at large.

Hmm. Wealthy, influential people with large public support? Nah, these are two things politicians don't concern themselves about.

Re: How Lavabit Melted Down

#124

Earlier quoted context omitted.

To be fair, your government should be working to protect you from foreign threats like this. You should not rely on foreign powers to protect you.

Believe me, I'm not happy that my government is all-in on the American mass surveillance game. But my specific concern here is with Americans who think it's okay for the US government to conduct mass surveillance on the rest of the planet, just not on Americans.

Because we never know where the next threat will come from, or perhaps the threat after that.

Your country may be perfectly at peace with the US now, but there is no way to guarantee that peace unless we have people to continually watch for potential threats. Even that is, in itself, no guarantee, but it's better than nothing.

Maybe someday, mankind will be able to share universal goodwill and peace, but until that time, trust, but verify, at a minimum.

Re: How Lavabit Melted Down

#125
Of wonderful note:

At approximately 1:30 p.m. CDT on August 2, 2013, Mr. Levison gave the F.B.I. a printout of what he represented to be the encryption keys needed to operate the pen register. This printout, in what appears to be four-point type, consists of eleven pages of largely illegible characters. To make use of these keys, the F.B.I. would have to manually input all two thousand five hundred and sixty characters, and one incorrect keystroke in this laborious process would render the F.B.I. collection system incapable of collecting decrypted data.

I tip my hat to this magnificent bastard.

EDIT:

The core issue is summed up nicely thereafter:

Levison believes that when the government was faced with the choice between getting information that might lead it to its target in a constrained manner or expanding the reach of its surveillance, it chose the latter.

Re: How Lavabit Melted Down

#126
post #99

The most scary quote in the whole article is this: THE COURT: You want to do it in a way that the government has to trust you /.../ THE COURT: And you won’t trust the government. So why would the government trust you? It was that the whole idea on which US is built on - the Constitution and other founding ideas - was based on trusting the government only with very little that is necessary for it to function and no mo…

That quote made me feel sick to my stomach. I mean, I knew it had gotten that bad...I've been involved in Restore The Fourth organizing, and before that I've been paying close attention to all the previous leaks about the surveillance state. But, knowing it and seeing a judge state it outright is two very different things. It used to be under cover. It only happened in the darkness of secret documents and agencies. Now, it's come out into the light of day...and they're getting away with it. Not even getting away with it, really...they're wearing it proudly, as though they are the people in the right; they honestly believe they are the people who have nothing to hide or be ashamed of.

It's astonishing that more of our reps aren't standing up and shouting about this. So many of the people in power are complicit, it feels hopeless at times.

Re: How Lavabit Melted Down

#127
post #74

Earlier quoted context omitted.

We should celebrate Ladar for making the decision to put himself at risk in order to protect his users, but I think we should be careful not to forget that Ladar was forced to make that decision because the security of Lavabit was all a total handwave. This wasn't untested water, either. The exact same thing happened to Hushmail for the exact same reason, and should have been evidence enough that the model isn't viab…

Unless he actually used properly implemented forward secure SSL for every connection, which I doubt all of either his customers browsers or the SMTP servers he talked to supported, didn't his choices actually put his customers in more danger? He could have complied with one of the several valid court orders that requested he give the FBI data on a specific account but stopped short if installing FBI code or devices o…

According to the article, the FBI jumped straight to "give us all the SSL keys for everything", and would not let him to that selective warrant.

He rightly observed that those leaked keys would then get into the hands of God-only-knows-who.

Re: How Lavabit Melted Down

#128
post #74

Earlier quoted context omitted.

We should celebrate Ladar for making the decision to put himself at risk in order to protect his users, but I think we should be careful not to forget that Ladar was forced to make that decision because the security of Lavabit was all a total handwave. This wasn't untested water, either. The exact same thing happened to Hushmail for the exact same reason, and should have been evidence enough that the model isn't viab…

Unless he actually used properly implemented forward secure SSL for every connection, which I doubt all of either his customers browsers or the SMTP servers he talked to supported, didn't his choices actually put his customers in more danger? He could have complied with one of the several valid court orders that requested he give the FBI data on a specific account but stopped short if installing FBI code or devices o…

You definitely did not read the article.

Re: How Lavabit Melted Down

#129

Earlier quoted context omitted.

You might be missing the point a little bit. You're correct, but end-to-end encryption is irrelevant if the operator changes the (e.g., Javascript) code in a webmail app and maybe even just for a single user. The trust model has to include the device/OS/browser/etc that you're accessing the device on as well as all code and keys (including WOT servers, GPG keys, and the webmail code itself, or, if locally installed,…

"You might be missing the point a little bit. You're correct, but end-to-end encryption is irrelevant if the operator changes the (e.g., Javascript) code in a webmail app and maybe even just for a single user." Which is why, as I have said elsewhere, webmail is the problem here; more generally, you cannot have security or privacy as a service. As for the government pushing back doors into products, that is at least u…

Which is why, as I have said elsewhere, webmail is the problem here; more generally, you cannot have security or privacy as a service.

This is it in a nutshell.

Re: How Lavabit Melted Down

#130
Demanding the SSL keys to the entire database was clearly an insane overreach on the FBI's part, a mistake that they compounded if it's true that they refused to work with Lavar on the more targeted approach he suggested. I would like to kick in some bucks towards Ladar's defense, but I'd rather do it through the EFF (where I'm already a member) rather than rally.org, which I've never heard of.

Does anyone have any experience with (or thoughts about) rally.org -- or, for that matter, any knowledge of why the EFF isn't running point on this case?

Post reply on HN