Earlier quoted context omitted.
No. This does not affect their ability to use it. This certificate is simply no longer trusted by other parties (rightfully, because it was compromised). As matter of fact, this may not even be his doing.
What if the 3rd party the FBI wanted to intercept via this Cert has now been 1) notified that there is a problem and 2) can no longer be intercepted (unless their browser does no CRL or OCSP checks on the domain's cert)?
Lavabit SSL Cert Revoked
31–40 of 321 posts
Re: Lavabit SSL Cert Revoked
#32Earlier quoted context omitted.
Will having the private key allow the decryption of ciphertext that was previously intercepted (while the service was active) and stored? Lavabit was already shut down, so this revocation is equally useless for user security. :(
If the connection was using a forward-secret key exchange (like DHE or ECDHE), then no. Unfortunately it's common not to and browsers don't do anything to warn people that they're using a low-security mode.
I found "Calomel SSL Validation," which I am about to install. The PFS reporting only works with Firefox 25 and up.
https://addons.mozilla.org/en-US/firefox/addon/calomel-ssl-v...
Re: Lavabit SSL Cert Revoked
#33I cannot ignore this warning in Firefox 24 from official repository on Ubuntu 13.04. Actually, I cannot ignore outdated certificates, or those with unknown OCSP status (for example freshly issued certs) either. Was there some change in Firefox's security model or is it my config? It's rather annoying.
Firefox treats an explicit "unknown" OCSP status as equivalent to being revoked, except we don't cache the "unknown" status. Firefox doesn't allow the user to override "revoked." The thinking behind our cert error override strategy is that cert error overrides are intended mostly to allow the user to fix something that is probably supposed to work, but a revocation is a very explicit signal that the certificate isn't…
Yes, I have it unchecked. Is there some about:config magic or "kamikaze mode" that I could enable that would allow me to ignore at least outdated certs?
Last night I locked myself out of my own website. The old cert expired and the OCSP server didn't know about the new one yet.
Re: Lavabit SSL Cert Revoked
#34Re: Lavabit SSL Cert Revoked
#35See his last update on the rally page.
Re: Lavabit SSL Cert Revoked
#36Earlier quoted context omitted.
Firefox treats an explicit "unknown" OCSP status as equivalent to being revoked, except we don't cache the "unknown" status. Firefox doesn't allow the user to override "revoked." The thinking behind our cert error override strategy is that cert error overrides are intended mostly to allow the user to fix something that is probably supposed to work, but a revocation is a very explicit signal that the certificate isn't…
Thanks for answering. Yes, I have it unchecked. Is there some about:config magic or "kamikaze mode" that I could enable that would allow me to ignore at least outdated certs? Last night I locked myself out of my own website. The old cert expired and the OCSP server didn't know about the new one yet.
[0] - http://patrol.psyced.org
Re: Lavabit SSL Cert Revoked
#37For me, govt and internet should almost be like church and state. Where is the data around foiled terrorist plots? I just can't stomach the obtuse logic that we need to pay our taxes to employ these virtual minders. This is not what the internet is about. It just seems so incredibly difficult to mobilise and take action against this shit ...
Btw, Ladar ... you've been incredible in all of this (tips Stetson)
Re: Lavabit SSL Cert Revoked
#38Re: Lavabit SSL Cert Revoked
#39Earlier quoted context omitted.
What if the 3rd party the FBI wanted to intercept via this Cert has now been 1) notified that there is a problem and 2) can no longer be intercepted (unless their browser does no CRL or OCSP checks on the domain's cert)?
Following that line of reasoning down the slimy slippery slope, developing better encryption systems could be construed as obstruction of justice, no?
Re: Lavabit SSL Cert Revoked
#40Consider donating to https://rally.org/lavabit . Lavabit needs at least 250k to continue fighting in the supreme court. See his last update on the rally page.