Live data from Hacker News

Lavabit SSL Cert Revoked

lavabit.com

61–70 of 321 posts

Re: Lavabit SSL Cert Revoked

#61
post #43

Earlier quoted context omitted.

Today the owner, Ladar Levison, had to hand over the SSL certificates by court order. It marks the ending of a long battle in court, with unfortunately it ending in the govenment's favor. I'm assuming the post is just a hacker way of acknowledging the event. Related article: http://www.newyorker.com/online/blogs/elements/2013/10/how-l...

Interesting link, and much more informative than the other Lavabit news articles. It's a shame the government didn't work with Levison to either allow Levison to add the requested intercept himself (which, yes, would have required Uncle Sam to trust him) or to allow a third-party (or even a third party requested from both sides) to audit the proposed interception code. The judge is correct in stating that if Levison…

> The judge is correct in stating that if Levison doesn't trust the government, then why should the government trust Levison

The judge is incorrect. The U.S. Government was designed to not completely trust itself. That's why there are checks and balances. Giving the FBI the private key lets them have unchecked access to data encrypted with it. It is wrong to asked to not be checked.

[edited for format]

Re: Lavabit SSL Cert Revoked

#62
post #37

I'm so sick of being sickened. I hate that this is becoming the norm and we can't do anything about it. I hate to spit cliches, but is this where my tax dollars go? For me, govt and internet should almost be like church and state. Where is the data around foiled terrorist plots? I just can't stomach the obtuse logic that we need to pay our taxes to employ these virtual minders. This is not what the internet is about.…

I have mocked-up a system for policy creation. The project is open; please contribute your thoughts. People say "it has flaws" but never explain the flaws, nor how to address them. https://bitbucket.org/djarvis/world-politics/ Would greatly appreciate constructive criticism. The system serves to educate everyone (openly and transparently) on implications of existing and upcoming policies. If the idea intrigues you, c…

I agree with your strategy. The internet is an unprecedented communication mechanism, for the first time in history we have the tools for mass self representation in an organized way. A new kind of society.

Re: Lavabit SSL Cert Revoked

#63
Lavabit has revealed something incredibly important.

The US Government has no problem with seizing your private keys. It claims the right to impersonate you without your permission.

It no longer matters which system you use, Sovereign Keys, PGP web-of-trust, traditional PKI, they're all the same. Services based in the US can be MITM'd without leaving any traces.

If this is allowed to continue uncontested there will no be no way to stay secure online. The only solution is a partial solution, to create decentralized services. This, at least, will require the government to seize the private keys of each individual they want to track.

Re: Lavabit SSL Cert Revoked

#64

Earlier quoted context omitted.

I have mocked-up a system for policy creation. The project is open; please contribute your thoughts. People say "it has flaws" but never explain the flaws, nor how to address them. https://bitbucket.org/djarvis/world-politics/ Would greatly appreciate constructive criticism. The system serves to educate everyone (openly and transparently) on implications of existing and upcoming policies. If the idea intrigues you, c…

I like the ideas you present. Does this site exist? If not, what existing sites do you think are closest to your vision?

The site I have mocked-up does not exist. I want to work on it, but it does not pay, and I need to eat. :-) I am working on a side-project (yes, a start-up) that will provide the income I need to work full-time on the World Politics idea.

The closest idea is probably: https://canada.yrpri.org/

It has a number of issues, though.

Re: Lavabit SSL Cert Revoked

#65
post #54

Consider donating to https://rally.org/lavabit . Lavabit needs at least 250k to continue fighting in the supreme court. See his last update on the rally page.

Where are you reading that? I see $96k as the goal, and no mention of $250k

See the latest post in the update tab of the http://rally.org/lavabit

He continues by saying “defending the constitution is expensive – even more so if my fight is to have a chance of reaching the Supreme Court – my legal claims I will need to raise at least $250,000.”

Re: Lavabit SSL Cert Revoked

#66
post #16

Can this be classified as - http://en.wikipedia.org/wiki/Obstruction_of_justice ? That is, I'm sure he understands that this action might be interfering with an investigation, and that it's reasonable to believe it was a willful act on his part. Can you get into trouble for doing something like this?

When did unconstitutional massive surveillance become justice?

The same day that everyone agreed "Roadside Safety Checks" (police looking for drunk drivers under the auspices of checking children's carseats at 1AM) was the lesser of two evils (Drunk drivers killing innocent people is a greater evil than everyone's 4th amendment rights being violated).

To a lesser extent, anytime that politicians frame an issue with the two phrases "it's for the good of the public" and "it's not a problem if you aren't guilty", they're generally trouncing a constitutional right, or greasing the tracks for it to inevitably happen.

Re: Lavabit SSL Cert Revoked

#67
post #37

I'm so sick of being sickened. I hate that this is becoming the norm and we can't do anything about it. I hate to spit cliches, but is this where my tax dollars go? For me, govt and internet should almost be like church and state. Where is the data around foiled terrorist plots? I just can't stomach the obtuse logic that we need to pay our taxes to employ these virtual minders. This is not what the internet is about.…

I have mocked-up a system for policy creation. The project is open; please contribute your thoughts. People say "it has flaws" but never explain the flaws, nor how to address them. https://bitbucket.org/djarvis/world-politics/ Would greatly appreciate constructive criticism. The system serves to educate everyone (openly and transparently) on implications of existing and upcoming policies. If the idea intrigues you, c…

[deleted]

Re: Lavabit SSL Cert Revoked

#68
post #37

I'm so sick of being sickened. I hate that this is becoming the norm and we can't do anything about it. I hate to spit cliches, but is this where my tax dollars go? For me, govt and internet should almost be like church and state. Where is the data around foiled terrorist plots? I just can't stomach the obtuse logic that we need to pay our taxes to employ these virtual minders. This is not what the internet is about.…

I have mocked-up a system for policy creation. The project is open; please contribute your thoughts. People say "it has flaws" but never explain the flaws, nor how to address them. https://bitbucket.org/djarvis/world-politics/ Would greatly appreciate constructive criticism. The system serves to educate everyone (openly and transparently) on implications of existing and upcoming policies. If the idea intrigues you, c…

I agree with what you say about self-governing. By mobilizing, I simply meant forming something more cohesive than clicktivist petitions which most often go nowhere. Your wiki addresses this perfectly. I think you should continue pursuing and refining. The concept is fantastic.

Re: Lavabit SSL Cert Revoked

#70

Earlier quoted context omitted.

Presumably if you care about security you are using a browser that does PFS and have personally verified that it is working.

You mean browsers actually fall back to non-perfect-forward-secrecy? They even have the option of doing that? That's interesting if true. Ideally it should be enforced by the server, and if the browser can't support it, then the browser can't see the webpage.

You can only support forward secure cipher suits. This will result in rejected connections as you suggested.

Lavabit doesn't do this, they support non-forward secure ones. Worse, they don't offer a cipher-suit order preference and the cipher suits they offer are actually pretty shitty (no ECDH_ECDSA, 1024bit DHE).

The way they have it configured now means anyone using the default browser on windows(IE) or OSX(Safari) doesn't end up negotiating a forward secure session. Chrome and Firefox do end up being forward secure. See SSL Lab's test result here[0]

They support TLS_RSA_WITH_3DES_EDE_CBC_SHA TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA TLS_RSA_WITH_AES_256_CBC_SHA TLS_DHE_RSA_WITH_AES_256_CBC_SHA

[0]https://www.ssllabs.com/ssltest/analyze.html?d=https%3A%2F%2...

Post reply on HN