To my understanding this is what I would expect to happen. He handed over the cert to the FBI, so from a security standpoint it's useless now and should be considered compromised.
Lavabit SSL Cert Revoked
21–30 of 321 posts
Re: Lavabit SSL Cert Revoked
#22Was there some change in Firefox's security model or is it my config? It's rather annoying.
Re: Lavabit SSL Cert Revoked
#23Can someone weight in on what this means or why it is an issue?
Today the owner, Ladar Levison, had to hand over the SSL certificates by court order. It marks the ending of a long battle in court, with unfortunately it ending in the govenment's favor. I'm assuming the post is just a hacker way of acknowledging the event. Related article: http://www.newyorker.com/online/blogs/elements/2013/10/how-l...
Re: Lavabit SSL Cert Revoked
#24To my understanding this is what I would expect to happen. He handed over the cert to the FBI, so from a security standpoint it's useless now and should be considered compromised.
Will having the private key allow the decryption of ciphertext that was previously intercepted (while the service was active) and stored? Lavabit was already shut down, so this revocation is equally useless for user security. :(
Re: Lavabit SSL Cert Revoked
#25Re: Lavabit SSL Cert Revoked
#26To my understanding this is what I would expect to happen. He handed over the cert to the FBI, so from a security standpoint it's useless now and should be considered compromised.
Will having the private key allow the decryption of ciphertext that was previously intercepted (while the service was active) and stored? Lavabit was already shut down, so this revocation is equally useless for user security. :(
Re: Lavabit SSL Cert Revoked
#27I cannot ignore this warning in Firefox 24 from official repository on Ubuntu 13.04. Actually, I cannot ignore outdated certificates, or those with unknown OCSP status (for example freshly issued certs) either. Was there some change in Firefox's security model or is it my config? It's rather annoying.
Firefox doesn't allow the user to override "revoked." The thinking behind our cert error override strategy is that cert error overrides are intended mostly to allow the user to fix something that is probably supposed to work, but a revocation is a very explicit signal that the certificate isn't supposed to work.
Also, ensure Options -> Advanced -> Certificates -> Validation -> When an OCSP server connection fails, treat the certificate as invalid is unchecked.
Re: Lavabit SSL Cert Revoked
#28Earlier quoted context omitted.
No. This does not affect their ability to use it. This certificate is simply no longer trusted by other parties (rightfully, because it was compromised). As matter of fact, this may not even be his doing.
What if the 3rd party the FBI wanted to intercept via this Cert has now been 1) notified that there is a problem and 2) can no longer be intercepted (unless their browser does no CRL or OCSP checks on the domain's cert)?
On the other hand, it would be hard to prove any actual obstruction, since the service was shut down and all users notified about this whole situation.
Re: Lavabit SSL Cert Revoked
#29Can someone weight in on what this means or why it is an issue?