Live data from Hacker News

Lavabit SSL Cert Revoked

lavabit.com

161–170 of 321 posts

Re: Lavabit SSL Cert Revoked

#161
post #32
post #24

Earlier quoted context omitted.

If the connection was using a forward-secret key exchange (like DHE or ECDHE), then no. Unfortunately it's common not to and browsers don't do anything to warn people that they're using a low-security mode.

FWIW, just now I went looking for a firefox plugin that reports (in a human-friendly way) whether or not the SSL connection for a page is using perfect forward secrecy (PFS). I found "Calomel SSL Validation," which I am about to install. The PFS reporting only works with Firefox 25 and up. https://addons.mozilla.org/en-US/firefox/addon/calomel-ssl-v...

Also the Netcraft Extension gives you this information: http://news.netcraft.com/archives/2013/09/06/perfect-forward...

Re: Lavabit SSL Cert Revoked

#162

Earlier quoted context omitted.

According to the New Yorker piece on Lavabit yesterday ( http://www.newyorker.com/online/blogs/elements/2013/10/how-l... ), the owner was willing to add code tailored to tracing only Snowden's (or whoever it belonged to) account. The FBI turned him down and demanded the less surgical option.

...and a solution that would fail to preserve the chain of evidence. If there's a black box at any point, e.g. Levison produces information and emails it to the investigating officers, the doctrine of "fruit of the poisoned tree" applies.

It's a disruption of the chain of evidence, but my understanding is that "fruit of the poisonous tree" is something different: evidence gathered because of information the police should not have had access to.

Re: Lavabit SSL Cert Revoked

#163

Earlier quoted context omitted.

According to the New Yorker piece on Lavabit yesterday ( http://www.newyorker.com/online/blogs/elements/2013/10/how-l... ), the owner was willing to add code tailored to tracing only Snowden's (or whoever it belonged to) account. The FBI turned him down and demanded the less surgical option.

...and a solution that would fail to preserve the chain of evidence. If there's a black box at any point, e.g. Levison produces information and emails it to the investigating officers, the doctrine of "fruit of the poisoned tree" applies.

By that logic, doesn't Lavabit itself, or the entire SMTP system, serve as a black box? It's really not any different from the intercept features in telecommunications equipment.

Re: Lavabit SSL Cert Revoked

#164

Earlier quoted context omitted.

> Nobody complains that they can [force?] Public Storage to open storage units with a warrant If they can get a warrant from a court under fair laws, personally I don't mind the government having equivalent powers in the online world. There are people doing bad things online, and I want there to be mechanisms to minimise that. I don't know the specifics of the Lavabit case, but from the NSA revelations, it seems like…

How do you defend yourself against a rogue government? Furthermore, who gets to define when a government becomes rogue? All definitions aside, how do you defend yourself from a large, well-funded organization that's determined to do what ever it wants to you? Fair laws? The fact that someone else decides what's right and wrong means we've already lost.

Surely we've found that using technical means to thwart a large, well-funded organization that is targeting you is useless.

Re: Lavabit SSL Cert Revoked

#165
post #115

Earlier quoted context omitted.

If you really believed that kind of fear were justified, why would you post a comment like this? It seems a lot more like you are just making up excuses to support your already-formed decision to not donate.

I really do believe this kind of fear is justified. I posted this comment because: 1) I believe my analysis is sound 2) As I have posted previously, I am a US citizen and therefore cannot be denied entry to the US I have already donated, and though my speech (through both keyboard and wallet) might bring additional attention from the alphabet-soup agencies, I believe it's important to speak up rather than give in to…

> I am a US citizen and therefore cannot be denied entry to the US

That's what the no-fly list is for.

There have been some court cases where they have ruled that forbidding a US citizen to fly on his return trip to the US is stranding/abandonment[0], but... even then, it took a while to get those rulings, and things were pretty messy for the person in the meantime.

[0] I'm blanking on the legal term but there is a specific term for this.

Re: Lavabit SSL Cert Revoked

#167
post #149

Earlier quoted context omitted.

I disagree with the premise. I don't believe that a service should be required by law to provide the possibility for the government to intercept the activity of its users. You can always say "but the child pornographers!" or, "but the terrorists!"... but... no, sorry. I believe that people should have the ability to engage in total privacy. The fact that the US gov't is doing this because of Snowden (a person I admir…

Your argument against the ability to wiretap child pornographers and terrorists is "no, sorry". That's not a very complete argument.

His argument is clearly that people have a right to privacy. It says so in his next sentence.

The 'no, sorry' is him discarding the emotional plea that often justifies invading a person's privacy in the first place ("please, won't somebody think of the children!").

Re: Lavabit SSL Cert Revoked

#168
post #149

Earlier quoted context omitted.

I disagree with the premise. I don't believe that a service should be required by law to provide the possibility for the government to intercept the activity of its users. You can always say "but the child pornographers!" or, "but the terrorists!"... but... no, sorry. I believe that people should have the ability to engage in total privacy. The fact that the US gov't is doing this because of Snowden (a person I admir…

Your argument against the ability to wiretap child pornographers and terrorists is "no, sorry". That's not a very complete argument.

That's perfectly valid, since those examples were first trotted out prior to that with no argument. If it's so obvious why we should treat those as special cases, it should be trivial to explain why.

Re: Lavabit SSL Cert Revoked

#169
This is both chilling and depressing. The only reason why the general public is barely phased or even cares about this nonsense is that they don't even understand what a SSL Cert is or what it means to have it taken away.

Re: Lavabit SSL Cert Revoked

#170

Lavabit has revealed something incredibly important. The US Government has no problem with seizing your private keys . It claims the right to impersonate you without your permission. It no longer matters which system you use, Sovereign Keys, PGP web-of-trust, traditional PKI, they're all the same. Services based in the US can be MITM'd without leaving any traces. If this is allowed to continue uncontested there will…

Ok, let's keep this in perspective. The problem here is Lavabit was specifically designed to disallow lawful intercepts of individuals. Targeting individuals is absolutely the right way to go about a lawful intercept. Sucking up all traffic like the NSA has been doing is totally overbroad and invasive. But the whole point of the asymmetric encryption feature of Lavabit was to make it impossible for anyone but the acc…

"The problem here is Lavabit was specifically designed to disallow lawful intercepts of individuals."

This is not True.

Lavabit made it clear in their TOS that they had no interest in concealing illegality, they complied fully and willingly with all warrants targeting individual users.

Their premise was to protect your privacy from untargetted blanket surveillance.

Post reply on HN