Earlier quoted context omitted.
It wasn't a handwave. It was the best current technology could offer, but this technology was not meant to deal with the oppressive government that can compel any company to reveal any information. As soon as Ladar realized that, and the fact that he is in the jurisdiction of the oppressive government, Lavabit was done.
"It was the best current technology could offer" Sure, if we ignore the existence of things like PGP, S/MIME, smart cards, and the dozens of other ways we can have secure email without relying on some trusted third party like this. "this technology was not meant to deal with the oppressive government that can compel any company to reveal any information" Then it was not meant to deal with the evil hacker who takes co…
How Lavabit Melted Down
141–150 of 177 posts
Re: How Lavabit Melted Down
#142Earlier quoted context omitted.
"It was the best current technology could offer" Sure, if we ignore the existence of things like PGP, S/MIME, smart cards, and the dozens of other ways we can have secure email without relying on some trusted third party like this. "this technology was not meant to deal with the oppressive government that can compel any company to reveal any information" Then it was not meant to deal with the evil hacker who takes co…
Sure, if we ignore the existence of things like PGP, S/MIME, smart cards, and the dozens of other ways we can have secure email without relying on some trusted third party like this. As I understand it Snowden was using Lavabit to communicate with journalists who didn't themselves have/use/understand PGP. Lavabit is technology you can use even if no-one else uses it. How do PGP and S/MIME solve the bootstrapping prob…
Basically, the problem is that PGP and S/MIME as they exist today are (and I shudder to say it) too security conscious. The reality is that most users are not going to take the time to maintain their public keys, to verify others' public keys, etc., nor are most users going to spend the time to get their keys verified by a CA. We need a "lite" PGP client that is less obnoxious about using untrusted keys, and basically a "newbie" PGP that is more vulnerable to active MITM attacks (which are actually much harder to pull off than one might expect). It would also be nice if public keys could be easily published via QR codes, so that someone can literally hand their public key to another person.
The worst thing we can do is lie to people about the security they receive e.g. telling them things like "Lavabit is set up so that nobody but you can read your email!"
Re: How Lavabit Melted Down
#143Earlier quoted context omitted.
You say "Lavabit had no such guarantees." Without me arguing one way or another whether that's true -- do you think if they had better guarantees, that anything would be different here? That the government would say "oh no, we'll back down now"?
Suppose that Lavabit sold smart cards for end-to-end encryption, and as a service would store ciphertexts for you. The government shows up with a warrant, Lavabit says, "Sorry, we cannot comply because we cannot access secret keys or decrypt messages by some other means." What exactly does the government do after that? The point is that Lavabit's architecture did not resist these kinds of demands at all. At best all…
Then the legal obligations of the architecture are primary determined by the effectiveness of your security architecture; the existence of defects in the architecture which would preserve security in the absence of their exploitation is the thing matters to the court system.
That sounds tantamount to what you're proposing; is that really the sort of legal framework you think we have / should have? I personally think it's ridiculous, and I reject your justification and others which rely on a technical deficiency in Lavabit's implementation to endorse the legality and moral authority of the court's orders.
Re: How Lavabit Melted Down
#144Earlier quoted context omitted.
Unless he actually used properly implemented forward secure SSL for every connection, which I doubt all of either his customers browsers or the SMTP servers he talked to supported, didn't his choices actually put his customers in more danger? He could have complied with one of the several valid court orders that requested he give the FBI data on a specific account but stopped short if installing FBI code or devices o…
You definitely did not read the article.
See my response above. https://news.ycombinator.com/edit?id=6517845
Re: How Lavabit Melted Down
#145Earlier quoted context omitted.
Unless he actually used properly implemented forward secure SSL for every connection, which I doubt all of either his customers browsers or the SMTP servers he talked to supported, didn't his choices actually put his customers in more danger? He could have complied with one of the several valid court orders that requested he give the FBI data on a specific account but stopped short if installing FBI code or devices o…
Read the article.
Re: How Lavabit Melted Down
#146Earlier quoted context omitted.
It wasn't a handwave. It was the best current technology could offer, but this technology was not meant to deal with the oppressive government that can compel any company to reveal any information. As soon as Ladar realized that, and the fact that he is in the jurisdiction of the oppressive government, Lavabit was done.
"It was the best current technology could offer" Sure, if we ignore the existence of things like PGP, S/MIME, smart cards, and the dozens of other ways we can have secure email without relying on some trusted third party like this. "this technology was not meant to deal with the oppressive government that can compel any company to reveal any information" Then it was not meant to deal with the evil hacker who takes co…
>>> Then it was not meant to deal with the evil hacker who takes control of the server and grabs valuable information.
Indeed, it is not. If the hacker gets full control of your mailserver, at least your envelope information is completely compromised.
>>> The security of the system depends not on technology, math, or physical laws, but on the whims of just one man
This is completely false. Security depended on adversary not having full access to the Lavabit servers, not on Ladar's "whim". As soon as Ladar realized there's no possibility of legally providing it in the US, he closed the service. Assuming your adversary doesn't have full access to your service is kind of a precondition of using the service as means of security. That's like using lock is assuming the adversary does not have the key, if he does, the lock is useless as a security measure. As soon as Lavabit became essentially useless for the purpose it was created, it was shut down.
Re: How Lavabit Melted Down
#147Earlier quoted context omitted.
"It was the best current technology could offer" Sure, if we ignore the existence of things like PGP, S/MIME, smart cards, and the dozens of other ways we can have secure email without relying on some trusted third party like this. "this technology was not meant to deal with the oppressive government that can compel any company to reveal any information" Then it was not meant to deal with the evil hacker who takes co…
Sure, if we ignore the existence of things like PGP, S/MIME, smart cards, and the dozens of other ways we can have secure email without relying on some trusted third party like this. As I understand it Snowden was using Lavabit to communicate with journalists who didn't themselves have/use/understand PGP. Lavabit is technology you can use even if no-one else uses it. How do PGP and S/MIME solve the bootstrapping prob…
Re: How Lavabit Melted Down
#148> While he opposes the bulk collection of domestic communications, he has no such strong feelings about the N.S.A.’s foreign-surveillance efforts. As a non-American, I have a problem with this seemingly widespread idea even among privacy advocates in the USA that only Americans are entitled to the protection of their rights from the American government.
It's not a "widespread idea"... it's the legal reality. As a non-American, you do not share the rights of US citizens under the constitution. Period. They are the only people entitled to the protection of their rights from the American government, unless your country has signed some sort of treaty with the US government giving you extended rights from the US, which I doubt it has. Without such an agreement, this is n…
Widespread unchecked surveillance is evil in and of itself, it doesn't matter _who_ is doing the surveilling.
Following your argument, if the Chinese government engaged in exactly the same sort of surveillance against you that the NSA does, you'd be fine with it, since it would merely be international espionage. But in the end, the same information about you is being stored. And your information is probably less trustworthy with the Chinese government than even with the NSA!
'Spying' in the traditional meaning is qualitatively different to dragnet surveillance of all communications.
I understand that all countries engage in a level of spying, and that friends may not always remain so, but the US' seemingly widespread lack of trust in _any_ other country, only works when you're (1) right and (2) the most powerful country.
These may not always hold true, and it's when bad things happen that you need friends you can trust (and that can trust you).
Re: How Lavabit Melted Down
#149Earlier quoted context omitted.
According to the article, the FBI jumped straight to "give us all the SSL keys for everything", and would not let him to that selective warrant. He rightly observed that those leaked keys would then get into the hands of God-only-knows-who.
The story, as far as I have read from this article and others, was they asked for data(probably with an NSL), he said no. They got a court order. He said no. At some-point he was willing to cooperate, but by that point, they didn't care because they thought he was jerking them around.They then requested the SSL keys. This article is more clear about the exact sequence of events[0], but the the posted one says so as w…
The stated use of these two things was to get information concerning a single person, but they never wanted just that information. On page 100, Levison states that he can manage to get the information the FBI is looking for, without providing the FBI with Lavabit's encryption keys. Someone (AUSA[censored]) says that the proposed solution does not satisfy the subpoenas and court orders, because it would not provide real-time access to the data.
---
Re: How Lavabit Melted Down
#150Earlier quoted context omitted.
> Levison offered multiple times to write a specific script for the single user ... A pretty clear indication they wanted unfettered access to his client base and his network i don't think this is the correct interpretation. in a court of laws, acquiring evidence is something procedural and governed by rules and regulations. having a third party (lavabit) acquire the evidence and then turn it over to the government i…
> i don't think this is the correct interpretation. in a court of laws, acquiring evidence is something procedural and governed by rules and regulations. having a third party (lavabit) acquire the evidence and then turn it over to the government is probably something that wouldn't pass muster in court due to chain of custody and other rules. Search for "$" on this page: http://paranoia.dubfire.net/2009/12/8-million-r…
The e-mail again confirmed that Lavabit is capable of providing the means for the FBI to
install the pen-trap device and obtain the requested information in an unencrypted form.
AUSA[censored] replied to Mr. Levison's e-mail that same day, explaining that the
proposal was inadequate because, among other things, it did not provide for real-time
transmission of results...
---