Live data from Hacker News

How Lavabit Melted Down

newyorker.com

141–150 of 177 posts

Re: How Lavabit Melted Down

#141
post #94

Earlier quoted context omitted.

It wasn't a handwave. It was the best current technology could offer, but this technology was not meant to deal with the oppressive government that can compel any company to reveal any information. As soon as Ladar realized that, and the fact that he is in the jurisdiction of the oppressive government, Lavabit was done.

"It was the best current technology could offer" Sure, if we ignore the existence of things like PGP, S/MIME, smart cards, and the dozens of other ways we can have secure email without relying on some trusted third party like this. "this technology was not meant to deal with the oppressive government that can compel any company to reveal any information" Then it was not meant to deal with the evil hacker who takes co…

I want secure email but I have yet to figure it out. What are "the dozens of other ways we can have secure email"? Honest question

Re: How Lavabit Melted Down

#142

Earlier quoted context omitted.

"It was the best current technology could offer" Sure, if we ignore the existence of things like PGP, S/MIME, smart cards, and the dozens of other ways we can have secure email without relying on some trusted third party like this. "this technology was not meant to deal with the oppressive government that can compel any company to reveal any information" Then it was not meant to deal with the evil hacker who takes co…

Sure, if we ignore the existence of things like PGP, S/MIME, smart cards, and the dozens of other ways we can have secure email without relying on some trusted third party like this. As I understand it Snowden was using Lavabit to communicate with journalists who didn't themselves have/use/understand PGP. Lavabit is technology you can use even if no-one else uses it. How do PGP and S/MIME solve the bootstrapping prob…

There is no bootstrapping problem. Snowden was also able to get journalists to use OTR, without relying on some web interface with questionable security claims. The problem with PGP and S/MIME is that the existing software is too hard to set up. It is hard to tell journalists to go use Thunderbird, get Enigmail set up, and publish a key. The situation is even worse with S/MIME, despite the built-in support in many email clients.

Basically, the problem is that PGP and S/MIME as they exist today are (and I shudder to say it) too security conscious. The reality is that most users are not going to take the time to maintain their public keys, to verify others' public keys, etc., nor are most users going to spend the time to get their keys verified by a CA. We need a "lite" PGP client that is less obnoxious about using untrusted keys, and basically a "newbie" PGP that is more vulnerable to active MITM attacks (which are actually much harder to pull off than one might expect). It would also be nice if public keys could be easily published via QR codes, so that someone can literally hand their public key to another person.

The worst thing we can do is lie to people about the security they receive e.g. telling them things like "Lavabit is set up so that nobody but you can read your email!"

Re: How Lavabit Melted Down

#143

Earlier quoted context omitted.

You say "Lavabit had no such guarantees." Without me arguing one way or another whether that's true -- do you think if they had better guarantees, that anything would be different here? That the government would say "oh no, we'll back down now"?

Suppose that Lavabit sold smart cards for end-to-end encryption, and as a service would store ciphertexts for you. The government shows up with a warrant, Lavabit says, "Sorry, we cannot comply because we cannot access secret keys or decrypt messages by some other means." What exactly does the government do after that? The point is that Lavabit's architecture did not resist these kinds of demands at all. At best all…

So here's a hypothetical for you. Suppose we build an architecture which you feel is more secure. Then the NSA people say "we have analyzed it, and there's a theoretical information leak. because that information leak exists you have to install our software which will exploit it. but if you'd designed your system better you would have been okay. also, incidentally, you're now legally forbidden from fixing this leak."

Then the legal obligations of the architecture are primary determined by the effectiveness of your security architecture; the existence of defects in the architecture which would preserve security in the absence of their exploitation is the thing matters to the court system.

That sounds tantamount to what you're proposing; is that really the sort of legal framework you think we have / should have? I personally think it's ridiculous, and I reject your justification and others which rely on a technical deficiency in Lavabit's implementation to endorse the legality and moral authority of the court's orders.

Re: How Lavabit Melted Down

#144

Earlier quoted context omitted.

Unless he actually used properly implemented forward secure SSL for every connection, which I doubt all of either his customers browsers or the SMTP servers he talked to supported, didn't his choices actually put his customers in more danger? He could have complied with one of the several valid court orders that requested he give the FBI data on a specific account but stopped short if installing FBI code or devices o…

You definitely did not read the article.

I did. You either didn't or read what you wanted to read. The FBI didn't ask for SSL keys right off the bat. They asked for info on Snowden's account. After Lavabit refusing and then agreeing but allegedly dragging it's feet on doing so, a federal judge issued an order for the SSL keys.

See my response above. https://news.ycombinator.com/edit?id=6517845

Re: How Lavabit Melted Down

#145

Earlier quoted context omitted.

Unless he actually used properly implemented forward secure SSL for every connection, which I doubt all of either his customers browsers or the SMTP servers he talked to supported, didn't his choices actually put his customers in more danger? He could have complied with one of the several valid court orders that requested he give the FBI data on a specific account but stopped short if installing FBI code or devices o…

Read the article.

I did. I even quoted it here https://news.ycombinator.com/edit?id=6517845

Re: How Lavabit Melted Down

#146
post #94

Earlier quoted context omitted.

It wasn't a handwave. It was the best current technology could offer, but this technology was not meant to deal with the oppressive government that can compel any company to reveal any information. As soon as Ladar realized that, and the fact that he is in the jurisdiction of the oppressive government, Lavabit was done.

"It was the best current technology could offer" Sure, if we ignore the existence of things like PGP, S/MIME, smart cards, and the dozens of other ways we can have secure email without relying on some trusted third party like this. "this technology was not meant to deal with the oppressive government that can compel any company to reveal any information" Then it was not meant to deal with the evil hacker who takes co…

How PGP or S/MIME would help you if any provider could be required to turn over all the traffic it gets, unencrypted? The only way you could securely communicate is peer-to-peer with the trusted party, but the email doesn't work this way. Unless you always send mail directly to your target's SMTP server which is hosted by the recipient himself (which kind of defies the whole idea of having email as a service and turns it into just a peer-to-peer chat with funny headers), the adversary would have access at least to the envelope information.

>>> Then it was not meant to deal with the evil hacker who takes control of the server and grabs valuable information.

Indeed, it is not. If the hacker gets full control of your mailserver, at least your envelope information is completely compromised.

>>> The security of the system depends not on technology, math, or physical laws, but on the whims of just one man

This is completely false. Security depended on adversary not having full access to the Lavabit servers, not on Ladar's "whim". As soon as Ladar realized there's no possibility of legally providing it in the US, he closed the service. Assuming your adversary doesn't have full access to your service is kind of a precondition of using the service as means of security. That's like using lock is assuming the adversary does not have the key, if he does, the lock is useless as a security measure. As soon as Lavabit became essentially useless for the purpose it was created, it was shut down.

Re: How Lavabit Melted Down

#147

Earlier quoted context omitted.

"It was the best current technology could offer" Sure, if we ignore the existence of things like PGP, S/MIME, smart cards, and the dozens of other ways we can have secure email without relying on some trusted third party like this. "this technology was not meant to deal with the oppressive government that can compel any company to reveal any information" Then it was not meant to deal with the evil hacker who takes co…

Sure, if we ignore the existence of things like PGP, S/MIME, smart cards, and the dozens of other ways we can have secure email without relying on some trusted third party like this. As I understand it Snowden was using Lavabit to communicate with journalists who didn't themselves have/use/understand PGP. Lavabit is technology you can use even if no-one else uses it. How do PGP and S/MIME solve the bootstrapping prob…

The mere fact Snowden was talking to someone in Guardian would be quite damning even if the contents of the messages were not known. The problem in catching the leak is knowing who's talking, not what they're saying - finding out what is the easy part, who is the hard one. Access to envelope info solves the who part, and full access to mail server gives full access to envelope.

Re: How Lavabit Melted Down

#148

> While he opposes the bulk collection of domestic communications, he has no such strong feelings about the N.S.A.’s foreign-surveillance efforts. As a non-American, I have a problem with this seemingly widespread idea even among privacy advocates in the USA that only Americans are entitled to the protection of their rights from the American government.

It's not a "widespread idea"... it's the legal reality. As a non-American, you do not share the rights of US citizens under the constitution. Period. They are the only people entitled to the protection of their rights from the American government, unless your country has signed some sort of treaty with the US government giving you extended rights from the US, which I doubt it has. Without such an agreement, this is n…

Well that's nice; I'm glad to see that our common interests as HN users extends only to the US border.

Widespread unchecked surveillance is evil in and of itself, it doesn't matter _who_ is doing the surveilling.

Following your argument, if the Chinese government engaged in exactly the same sort of surveillance against you that the NSA does, you'd be fine with it, since it would merely be international espionage. But in the end, the same information about you is being stored. And your information is probably less trustworthy with the Chinese government than even with the NSA!

'Spying' in the traditional meaning is qualitatively different to dragnet surveillance of all communications.

I understand that all countries engage in a level of spying, and that friends may not always remain so, but the US' seemingly widespread lack of trust in _any_ other country, only works when you're (1) right and (2) the most powerful country.

These may not always hold true, and it's when bad things happen that you need friends you can trust (and that can trust you).

Re: How Lavabit Melted Down

#149

Earlier quoted context omitted.

According to the article, the FBI jumped straight to "give us all the SSL keys for everything", and would not let him to that selective warrant. He rightly observed that those leaked keys would then get into the hands of God-only-knows-who.

The story, as far as I have read from this article and others, was they asked for data(probably with an NSL), he said no. They got a court order. He said no. At some-point he was willing to cooperate, but by that point, they didn't care because they thought he was jerking them around.They then requested the SSL keys. This article is more clear about the exact sequence of events[0], but the the posted one says so as w…

This is an inaccurate account of events. If you read the actual documents [1], you can see that the FBI had exactly 2 demands: A pen register device, attached to his servers; and his SSL private key. That is the sum total of what they wanted: complete, near-real-time access to all of Lavabit's data. A physical device to copy the server traffic and send it to the FBI, and the SSL key, to decrypt that traffic.

The stated use of these two things was to get information concerning a single person, but they never wanted just that information. On page 100, Levison states that he can manage to get the information the FBI is looking for, without providing the FBI with Lavabit's encryption keys. Someone (AUSA[censored]) says that the proposed solution does not satisfy the subpoenas and court orders, because it would not provide real-time access to the data.

---

[1]: http://cryptome.org/2013/10/lavabit-orders.pdf

Re: How Lavabit Melted Down

#150
post #76

Earlier quoted context omitted.

> Levison offered multiple times to write a specific script for the single user ... A pretty clear indication they wanted unfettered access to his client base and his network i don't think this is the correct interpretation. in a court of laws, acquiring evidence is something procedural and governed by rules and regulations. having a third party (lavabit) acquire the evidence and then turn it over to the government i…

> i don't think this is the correct interpretation. in a court of laws, acquiring evidence is something procedural and governed by rules and regulations. having a third party (lavabit) acquire the evidence and then turn it over to the government is probably something that wouldn't pass muster in court due to chain of custody and other rules. Search for "$" on this page: http://paranoia.dubfire.net/2009/12/8-million-r…

On page 100 of the actual documents [1], the refusal was not based on chain-of-evidence concerns, but that by using the solution proposed by Levison, the FBI would not have real-time access to the data:

    The e-mail again confirmed that Lavabit is capable of providing the means for the FBI to 
    install the pen-trap device and obtain the requested information in an unencrypted form. 
    AUSA[censored] replied to Mr. Levison's e-mail that same day, explaining that the 
    proposal was inadequate because, among other things, it did not provide for real-time 
    transmission of results...
---

[1]: http://cryptome.org/2013/10/lavabit-orders.pdf

Post reply on HN