Live data from Hacker News

Lavabit SSL Cert Revoked

lavabit.com

51–60 of 321 posts

Re: Lavabit SSL Cert Revoked

#51
post #37

I'm so sick of being sickened. I hate that this is becoming the norm and we can't do anything about it. I hate to spit cliches, but is this where my tax dollars go? For me, govt and internet should almost be like church and state. Where is the data around foiled terrorist plots? I just can't stomach the obtuse logic that we need to pay our taxes to employ these virtual minders. This is not what the internet is about.…

I have mocked-up a system for policy creation. The project is open; please contribute your thoughts. People say "it has flaws" but never explain the flaws, nor how to address them.

https://bitbucket.org/djarvis/world-politics/

Would greatly appreciate constructive criticism. The system serves to educate everyone (openly and transparently) on implications of existing and upcoming policies.

If the idea intrigues you, check out what other people are doing along the same lines:

https://bitbucket.org/djarvis/world-politics/wiki/Related%20...

Rather than getting to the point where citizens have to "mobilize against" the current government, we should be seeking to self-govern in such a way that mobilization is not necessary.

Re: Lavabit SSL Cert Revoked

#52

Earlier quoted context omitted.

And our contribution becomes part of our "permanent record" with the NSA? So glad I'm a US citizen and need not fear about such things.

That just sounds like fearmongering. I can't see any way that helping to fund someone's court case can be considering a crime, even if he were completely in the wrong. I strongly suspect that there are favourable legal precedents, even.

It's not that it's a crime, it's that it puts you on a list. Posting on this site probably puts you on a list.

Re: Lavabit SSL Cert Revoked

#55
post #37

I'm so sick of being sickened. I hate that this is becoming the norm and we can't do anything about it. I hate to spit cliches, but is this where my tax dollars go? For me, govt and internet should almost be like church and state. Where is the data around foiled terrorist plots? I just can't stomach the obtuse logic that we need to pay our taxes to employ these virtual minders. This is not what the internet is about.…

I have mocked-up a system for policy creation. The project is open; please contribute your thoughts. People say "it has flaws" but never explain the flaws, nor how to address them. https://bitbucket.org/djarvis/world-politics/ Would greatly appreciate constructive criticism. The system serves to educate everyone (openly and transparently) on implications of existing and upcoming policies. If the idea intrigues you, c…

I like the ideas you present.

Does this site exist? If not, what existing sites do you think are closest to your vision?

Re: Lavabit SSL Cert Revoked

#56

Earlier quoted context omitted.

Right. But if you connect with a browser that doesn't support that? And what about SMTP connections?

Presumably if you care about security you are using a browser that does PFS and have personally verified that it is working.

If you cared about security and knew enough to check that, you probably knew enough not to trust server side crypto and were using PGP or S/MIME on top of it or using OTR instead of email for secure conversations.

That aside, this still leaves the very important question of SMTP traffic.

Re: Lavabit SSL Cert Revoked

#57

Earlier quoted context omitted.

Right. But if you connect with a browser that doesn't support that? And what about SMTP connections?

Presumably if you care about security you are using a browser that does PFS and have personally verified that it is working.

You mean browsers actually fall back to non-perfect-forward-secrecy? They even have the option of doing that? That's interesting if true. Ideally it should be enforced by the server, and if the browser can't support it, then the browser can't see the webpage.

Re: Lavabit SSL Cert Revoked

#59

Earlier quoted context omitted.

Thanks for answering. Yes, I have it unchecked. Is there some about:config magic or "kamikaze mode" that I could enable that would allow me to ignore at least outdated certs? Last night I locked myself out of my own website. The old cert expired and the OCSP server didn't know about the new one yet.

You can disable querying OCSP servers by setting the "security.OCSP.enabled" to false. This adds some privacy (otherwise OCSP servers can know and collect what SSL enabled sites you visit). Combined with the Certificate Patrol add-on [0] (to track certificate changes) this must be pretty secure, except when a certificate is being revoked you will not know about it automatically. [0] - http://patrol.psyced.org

Which begs the question: "Better to enable OSCP and leak info or run the risk of a bad cert and disable OSCP?"

Re: Lavabit SSL Cert Revoked

#60
I wondered why Safari (running on an older OS X 10.6 system) didn't report the certificate as revoked, although Firefox on the same system did.

The answer appears to be as described here: http://www.intego.com/mac-security-blog/protect-safari-from-...

After setting the proper options in Keychain Access, Safari reported the revocation correctly.

Post reply on HN