Live data from Hacker News

How Lavabit Melted Down

newyorker.com

151–160 of 177 posts

Re: How Lavabit Melted Down

#151

Earlier quoted context omitted.

The story, as far as I have read from this article and others, was they asked for data(probably with an NSL), he said no. They got a court order. He said no. At some-point he was willing to cooperate, but by that point, they didn't care because they thought he was jerking them around.They then requested the SSL keys. This article is more clear about the exact sequence of events[0], but the the posted one says so as w…

This is an inaccurate account of events. If you read the actual documents [1], you can see that the FBI had exactly 2 demands: A pen register device, attached to his servers; and his SSL private key. That is the sum total of what they wanted: complete, near-real-time access to all of Lavabit's data. A physical device to copy the server traffic and send it to the FBI, and the SSL key, to decrypt that traffic. The stat…

It's entirely possible it's an inaccurate account of events. I haven't read all of the primary documents, just secondary sources.

In your linked documents,Exhibit 1 is the original June 10th order. Attachment A of it(page 4 of the PDF) details what he was order to hand over. It does not mention SSL keys at all. Instead it asks for a bunch of meta-data. In fact, it explicitly doesn't even cover communication contents. It also doesn't specify how Lavabit has to execute the order, just that it must provide the data.

This was the order Lavabit apparently initially refused.

Can you point to the first point they demanded the SSL keys? The stuff on page 100 looks like it pertains to the July 16th order. Which is, again, considerably after the June 10th order that originally asked for the data and after Lavabit refused that order. Also, totally inline with narrative of events as I presented it.

Regardin pen-registers: a pen-register can be done in software and is typically done by the service provider, not the government. The term is an anacranism dating back to telgraphs. It doesn't necessarly mean government hardware or software[0]. Hence the discussion page 99 of the pdf about "implementing the pen-trap device" in section d. So that's not blanket access

[0]http://en.wikipedia.org/wiki/Pen_register

Re: How Lavabit Melted Down

#152

Earlier quoted context omitted.

The story, as far as I have read from this article and others, was they asked for data(probably with an NSL), he said no. They got a court order. He said no. At some-point he was willing to cooperate, but by that point, they didn't care because they thought he was jerking them around.They then requested the SSL keys. This article is more clear about the exact sequence of events[0], but the the posted one says so as w…

This is an inaccurate account of events. If you read the actual documents [1], you can see that the FBI had exactly 2 demands: A pen register device, attached to his servers; and his SSL private key. That is the sum total of what they wanted: complete, near-real-time access to all of Lavabit's data. A physical device to copy the server traffic and send it to the FBI, and the SSL key, to decrypt that traffic. The stat…

So all they wanted was... everything.

Re: How Lavabit Melted Down

#153

Earlier quoted context omitted.

With a different key though. Once you've got this new cert. you can MITM, but you can't use it to decrypt the traffic already captured. Also anyone paying attention sees the cert. fingerprint change out of the blue.

A) Law enforcement doesn't need to decrypt previously-captured traffic; they either want to fish for criminal activity or they'll allow their target to build up new incriminating evidence. B) Who pays attention?

A) That's what they were after though: “all information necessary to decrypt data stored in or otherwise associated with [the account].” A rogue cert and MITM would get the password for the account though, unless B.

B) Anyone who knows what they're doing and has something they really want to keep secret? Maybe if someone had such a secret they'd learn to check the cert, maybe even install an extension that would highlight unexpected changes.

Re: How Lavabit Melted Down

#154
post #10

The more I read the more sympathy I have for the government here. They had a (presumably lawfully obtained) warrant against a specific user; it's not they who designed lavabit such that it was impossible to execute this without obtaining access to every other user. The proposal that Levison would extract the information himself rather than turning over the keys strikes me as completely unrealistic - any information s…

> the US still has a fairly strong "fruit of the poison tree" doctrine: any information the government happened to obtain on other users would be invalid for prosecution because it wouldn't be covered by their search warrant.

After everything we've seen from the Snowden leaks until now, do you honestly still believe this? Parallel construction? Hello??

Re: How Lavabit Melted Down

#155

Earlier quoted context omitted.

You definitely did not read the article.

I did. You either didn't or read what you wanted to read. The FBI didn't ask for SSL keys right off the bat. They asked for info on Snowden's account. After Lavabit refusing and then agreeing but allegedly dragging it's feet on doing so, a federal judge issued an order for the SSL keys. See my response above. https://news.ycombinator.com/edit?id=6517845

"On August 8th, rather than turning over the master key, Levison shut down Lavabit." seems to imply that they never got the information necessary to decrypt the data.

Re: How Lavabit Melted Down

#156

Earlier quoted context omitted.

I did. You either didn't or read what you wanted to read. The FBI didn't ask for SSL keys right off the bat. They asked for info on Snowden's account. After Lavabit refusing and then agreeing but allegedly dragging it's feet on doing so, a federal judge issued an order for the SSL keys. See my response above. https://news.ycombinator.com/edit?id=6517845

"On August 8th, rather than turning over the master key, Levison shut down Lavabit." seems to imply that they never got the information necessary to decrypt the data.

I did actually miss that part. I figured he gave them an electronic copy when he shut down.

Minimally, he gave them an "illegible copy." in 4 point font.Assuming its the actual key, I'm sure the FBI or NSA can OCR that. Even if parts of it are screwed up, SSL private keys actually have a fair amount of structure in them(at least enough to recover from someone writer "FUCK A DUCK" over and over again over part of one [0]) and even if say half the bits of the key give are illegible totally, the rest give you more than enough to factor it.

[0]http://crypto.2012.rump.cr.yp.to/87d4905b6d2fbc6ad2389debb73...

Re: How Lavabit Melted Down

#157

Earlier quoted context omitted.

Believe me, I'm not happy that my government is all-in on the American mass surveillance game. But my specific concern here is with Americans who think it's okay for the US government to conduct mass surveillance on the rest of the planet, just not on Americans.

Because we never know where the next threat will come from, or perhaps the threat after that. Your country may be perfectly at peace with the US now, but there is no way to guarantee that peace unless we have people to continually watch for potential threats. Even that is, in itself, no guarantee, but it's better than nothing. Maybe someday, mankind will be able to share universal goodwill and peace, but until that t…

I call "Bullshit" on that.

For all of the talk about "all men created equal" and "do to others as you would have them do to you", fundamentally Americans are brought up to believe they are different or "exceptional" to other humans. This belief let's them distort reality so that spying on innocent foreigners is ok but spying on innocent Americans is an abomination. Hypocrisy.

Timothy McVeigh and others prove that the domestic threat to the US is as serious as the foreign.

Re: How Lavabit Melted Down

#158

Earlier quoted context omitted.

"These systems are entirely built on code, and code is malleable. If you have control over the code that gets executed at every point in the stack (which the operator of a web app certainly does), there's always room for the operator to change the code and therefore change the behavior to do anything, including log things that were previously considered secure." Which is exactly why nobody should have believed Ladar'…

You might be missing the point a little bit. You're correct, but end-to-end encryption is irrelevant if the operator changes the (e.g., Javascript) code in a webmail app and maybe even just for a single user. The trust model has to include the device/OS/browser/etc that you're accessing the device on as well as all code and keys (including WOT servers, GPG keys, and the webmail code itself, or, if locally installed,…

Are you really alleging that CarrierIQ was installed at the behest of a government?

If you're going to use an appeal to authority, then Bruce Schneier is not the way to go. He's a cryptologist but he does make many unfounded claims.

Re: How Lavabit Melted Down

#159
post #68

Earlier quoted context omitted.

Do you really consider the judicial warrant system a lack of ANY oversight? After Levison's lack of cooperation, could the investigators really trust Levison to hand over all the information?

Why should Levison trust a government who has proven to be untrustworthy when it comes to data collection? Levison didn't lie or mislead anyone, he even offered to get the data for them as long as it was targeted. The government has basically zero credibility in matters like this, and yet he was expected to trust them with no oversight (in the article, he was told there was no independent audit of their use of the da…

What is this monolithic government you speak of? Are you saying that the FBI and the NSA are synonymous? I'm sure plenty of FBI investigators would take exception to an accusation like that.

I can play this game too. Dread Pirate Roberts used StackExchange, so therefore StackExchange users cannot be trusted to build websites that don't host drug deals and supposed hitmen.

Re: How Lavabit Melted Down

#160
post #68

Earlier quoted context omitted.

Why should Levison trust a government who has proven to be untrustworthy when it comes to data collection? Levison didn't lie or mislead anyone, he even offered to get the data for them as long as it was targeted. The government has basically zero credibility in matters like this, and yet he was expected to trust them with no oversight (in the article, he was told there was no independent audit of their use of the da…

What is this monolithic government you speak of? Are you saying that the FBI and the NSA are synonymous? I'm sure plenty of FBI investigators would take exception to an accusation like that. I can play this game too. Dread Pirate Roberts used StackExchange, so therefore StackExchange users cannot be trusted to build websites that don't host drug deals and supposed hitmen.

Why the constant influx of throwaways?
Post reply on HN