Live data from Hacker News

Lavabit SSL Cert Revoked

lavabit.com

31–40 of 321 posts

Re: Lavabit SSL Cert Revoked

#31
post #14

Earlier quoted context omitted.

No. This does not affect their ability to use it. This certificate is simply no longer trusted by other parties (rightfully, because it was compromised). As matter of fact, this may not even be his doing.

What if the 3rd party the FBI wanted to intercept via this Cert has now been 1) notified that there is a problem and 2) can no longer be intercepted (unless their browser does no CRL or OCSP checks on the domain's cert)?

Following that line of reasoning down the slimy slippery slope, developing better encryption systems could be construed as obstruction of justice, no?

Re: Lavabit SSL Cert Revoked

#32
post #24

Earlier quoted context omitted.

Will having the private key allow the decryption of ciphertext that was previously intercepted (while the service was active) and stored? Lavabit was already shut down, so this revocation is equally useless for user security. :(

If the connection was using a forward-secret key exchange (like DHE or ECDHE), then no. Unfortunately it's common not to and browsers don't do anything to warn people that they're using a low-security mode.

FWIW, just now I went looking for a firefox plugin that reports (in a human-friendly way) whether or not the SSL connection for a page is using perfect forward secrecy (PFS).

I found "Calomel SSL Validation," which I am about to install. The PFS reporting only works with Firefox 25 and up.

https://addons.mozilla.org/en-US/firefox/addon/calomel-ssl-v...

Re: Lavabit SSL Cert Revoked

#33

I cannot ignore this warning in Firefox 24 from official repository on Ubuntu 13.04. Actually, I cannot ignore outdated certificates, or those with unknown OCSP status (for example freshly issued certs) either. Was there some change in Firefox's security model or is it my config? It's rather annoying.

Firefox treats an explicit "unknown" OCSP status as equivalent to being revoked, except we don't cache the "unknown" status. Firefox doesn't allow the user to override "revoked." The thinking behind our cert error override strategy is that cert error overrides are intended mostly to allow the user to fix something that is probably supposed to work, but a revocation is a very explicit signal that the certificate isn't…

Thanks for answering.

Yes, I have it unchecked. Is there some about:config magic or "kamikaze mode" that I could enable that would allow me to ignore at least outdated certs?

Last night I locked myself out of my own website. The old cert expired and the OCSP server didn't know about the new one yet.

Re: Lavabit SSL Cert Revoked

#34

Earlier quoted context omitted.

Did he actually use forward secure SSL cipher suites for everything?

The site currently negotiates for DHE-RSA-AES256-SHA, which is forward secure.

Right. But if you connect with a browser that doesn't support that? And what about SMTP connections?

Re: Lavabit SSL Cert Revoked

#36

Earlier quoted context omitted.

Firefox treats an explicit "unknown" OCSP status as equivalent to being revoked, except we don't cache the "unknown" status. Firefox doesn't allow the user to override "revoked." The thinking behind our cert error override strategy is that cert error overrides are intended mostly to allow the user to fix something that is probably supposed to work, but a revocation is a very explicit signal that the certificate isn't…

Thanks for answering. Yes, I have it unchecked. Is there some about:config magic or "kamikaze mode" that I could enable that would allow me to ignore at least outdated certs? Last night I locked myself out of my own website. The old cert expired and the OCSP server didn't know about the new one yet.

You can disable querying OCSP servers by setting the "security.OCSP.enabled" to false. This adds some privacy (otherwise OCSP servers can know and collect what SSL enabled sites you visit). Combined with the Certificate Patrol add-on [0] (to track certificate changes) this must be pretty secure, except when a certificate is being revoked you will not know about it automatically.

[0] - http://patrol.psyced.org

Re: Lavabit SSL Cert Revoked

#37
I'm so sick of being sickened. I hate that this is becoming the norm and we can't do anything about it. I hate to spit cliches, but is this where my tax dollars go?

For me, govt and internet should almost be like church and state. Where is the data around foiled terrorist plots? I just can't stomach the obtuse logic that we need to pay our taxes to employ these virtual minders. This is not what the internet is about. It just seems so incredibly difficult to mobilise and take action against this shit ...

Btw, Ladar ... you've been incredible in all of this (tips Stetson)

Re: Lavabit SSL Cert Revoked

#39

Earlier quoted context omitted.

What if the 3rd party the FBI wanted to intercept via this Cert has now been 1) notified that there is a problem and 2) can no longer be intercepted (unless their browser does no CRL or OCSP checks on the domain's cert)?

Following that line of reasoning down the slimy slippery slope, developing better encryption systems could be construed as obstruction of justice, no?

No.

Re: Lavabit SSL Cert Revoked

#40

Consider donating to https://rally.org/lavabit . Lavabit needs at least 250k to continue fighting in the supreme court. See his last update on the rally page.

And our contribution becomes part of our "permanent record" with the NSA? So glad I'm a US citizen and need not fear about such things.
Post reply on HN