Live data from Hacker News

Lavabit SSL Cert Revoked

lavabit.com

131–140 of 321 posts

Re: Lavabit SSL Cert Revoked

#131
post #129

Earlier quoted context omitted.

Explain to me how a PGP web-of-trust can be MITM'd? Presumably you exchange keys in person?

The govt coerces somebody you trust (either directly or through the web of trust) to hand over their private keys and then begins impersonating them.

Well, this was circumvented here, right? The guy revoked his cert. That's what revocation is for.

I guess the next step is a secret law that makes this illegal?

Re: Lavabit SSL Cert Revoked

#132
post #129

Earlier quoted context omitted.

Explain to me how a PGP web-of-trust can be MITM'd? Presumably you exchange keys in person?

The govt coerces somebody you trust (either directly or through the web of trust) to hand over their private keys and then begins impersonating them.

Also, honestly, the govt could coerce you into being a mole for that matter, right?

Re: Lavabit SSL Cert Revoked

#133

Consider donating to https://rally.org/lavabit . Lavabit needs at least 250k to continue fighting in the supreme court. See his last update on the rally page.

And our contribution becomes part of our "permanent record" with the NSA? So glad I'm a US citizen and need not fear about such things.

Fuck them, if we have to be worried about being on this list the whole thing is a complete loss. We can't be afraid of letting them know just how many of us are against them.

Re: Lavabit SSL Cert Revoked

#134
post #121

Earlier quoted context omitted.

That just sounds like fearmongering. I can't see any way that helping to fund someone's court case can be considering a crime, even if he were completely in the wrong. I strongly suspect that there are favourable legal precedents, even.

It doesn't have to be illegal for it to be a weapon in the wrong hands. "Are you now, or have you ever been, a member of the Lavabit Party?" [1] "Your Honor, respected members of the jury: In 2013 Mr. Karana donated funds to an organization known to be in collusion with terrorists, as designated by the State Department and the Department of Homeland Security. He is by no means an 'innocent man' as he claims in this t…

Is his lawyer also in danger?

Re: Lavabit SSL Cert Revoked

#135
post #129

Earlier quoted context omitted.

The govt coerces somebody you trust (either directly or through the web of trust) to hand over their private keys and then begins impersonating them.

Well, this was circumvented here, right? The guy revoked his cert. That's what revocation is for. I guess the next step is a secret law that makes this illegal?

Or they detain you so you can't revoke it

Re: Lavabit SSL Cert Revoked

#136

Consider donating to https://rally.org/lavabit . Lavabit needs at least 250k to continue fighting in the supreme court. See his last update on the rally page.

And our contribution becomes part of our "permanent record" with the NSA? So glad I'm a US citizen and need not fear about such things.

"Paranoia strikes deep

Into your life it will creep

It starts when you're always afraid

You step out of line, the man come and take you away"

Buffalo Springfield, "for What it's Worth" 1966.

Timeless tune, not written about internet surveillance obviously. Recently that I find that song, and that line in particular coming to mind

linkage if you want a listen: http://www.youtube.com/watch?v=gp5JCrSXkJY

Re: Lavabit SSL Cert Revoked

#137
post #28

Earlier quoted context omitted.

What if the 3rd party the FBI wanted to intercept via this Cert has now been 1) notified that there is a problem and 2) can no longer be intercepted (unless their browser does no CRL or OCSP checks on the domain's cert)?

Interesting point. AFAIK they requested the key to decrypt previous communications. From security point of view, his move makes perfect sense. If FBI wanted to decrypt future communications, they would probably have specified that in their request. Then he would indeed break court order and could be hold responsible. On the other hand, it would be hard to prove any actual obstruction, since the service was shut down…

Who would make future secure communications with Lavabit at this point? Certainly not Edward Snowden.

Re: Lavabit SSL Cert Revoked

#138
post #115
post #47

Earlier quoted context omitted.

Non-citizens can be turned away at the US border for any reason, or no reason at all. Considering that a person's ability to travel to the US is so professionally important in this industry (for conferences, business meetings, etc.), I do not believe this is fearmongering. Remember the case of the man refused entry after a misinterpreted Tweet about 'destroying America'? [1] It seems clear NSA surveillance informs CB…

If you really believed that kind of fear were justified, why would you post a comment like this? It seems a lot more like you are just making up excuses to support your already-formed decision to not donate.

I really do believe this kind of fear is justified.

I posted this comment because:

1) I believe my analysis is sound

2) As I have posted previously, I am a US citizen and therefore cannot be denied entry to the US

I have already donated, and though my speech (through both keyboard and wallet) might bring additional attention from the alphabet-soup agencies, I believe it's important to speak up rather than give in to fear.

Re: Lavabit SSL Cert Revoked

#139
post #47

Earlier quoted context omitted.

Non-citizens can be turned away at the US border for any reason, or no reason at all. Considering that a person's ability to travel to the US is so professionally important in this industry (for conferences, business meetings, etc.), I do not believe this is fearmongering. Remember the case of the man refused entry after a misinterpreted Tweet about 'destroying America'? [1] It seems clear NSA surveillance informs CB…

If such donations really cause problems at borders, then it will be a sign that the place is FUBAR and you (and everyone else) should avoid traveling there.

As posted in this same thread, David House discovered that donations to legal defense funds can indeed cause problems (even for citizens) at the US border.

I do not think the US is FUBAR: FU, certainly, but not BAR. And although I refuse to be frightened into Appelbaum-esque total exile from my own country, I do take appropriate precautions before crossing the US border (CBP take note before sending me to secondary screening next time...).

Re: Lavabit SSL Cert Revoked

#140

Lavabit has revealed something incredibly important. The US Government has no problem with seizing your private keys . It claims the right to impersonate you without your permission. It no longer matters which system you use, Sovereign Keys, PGP web-of-trust, traditional PKI, they're all the same. Services based in the US can be MITM'd without leaving any traces. If this is allowed to continue uncontested there will…

The government already got to seize private keys when they got search warrants and ceased servers. I'd imagine this is the case in all of Western Europe.

Yes, but they weren't able to use them for MITM attacks, as seizing servers either equaled to shutting down a service, or allowed service operator to change the keys, so seized keys were useless. Now they feel they have right to obtain the private keys for you, and impose a gag order, so that you cannot change the compromised key.

I doubt that significant amount (if any) of western European countries are able to force you to keep using compromised private key, and keep you silent about this using a gag order.

Post reply on HN