Live data from Hacker News

Lavabit SSL Cert Revoked

lavabit.com

191–200 of 321 posts

Re: Lavabit SSL Cert Revoked

#191

Earlier quoted context omitted.

Why should privacy be restricted to select mediums?

That's a loaded question and I'm not going to play that game.

That's a perfectly reasonable question, actually.

One possible answer is that communicating on the internet requires the use of a physical commons, which one could reasonably argue carries either innate restrictions or restrictions legitimately imposed by the owners of said infrastructure.

Re: Lavabit SSL Cert Revoked

#192
post #32
post #24

Earlier quoted context omitted.

If the connection was using a forward-secret key exchange (like DHE or ECDHE), then no. Unfortunately it's common not to and browsers don't do anything to warn people that they're using a low-security mode.

FWIW, just now I went looking for a firefox plugin that reports (in a human-friendly way) whether or not the SSL connection for a page is using perfect forward secrecy (PFS). I found "Calomel SSL Validation," which I am about to install. The PFS reporting only works with Firefox 25 and up. https://addons.mozilla.org/en-US/firefox/addon/calomel-ssl-v...

Thanks for finding this. Calomel's website [1] gives much more information about how the scoring is done as well as security in general; very interesting.

[1] https://calomel.org/firefox_ssl_validation.html

Re: Lavabit SSL Cert Revoked

#193

Lavabit has revealed something incredibly important. The US Government has no problem with seizing your private keys . It claims the right to impersonate you without your permission. It no longer matters which system you use, Sovereign Keys, PGP web-of-trust, traditional PKI, they're all the same. Services based in the US can be MITM'd without leaving any traces. If this is allowed to continue uncontested there will…

The only way to stop this is to dismantle the police state. We have no chance of keeping up with their anti-privacy arms race

Re: Lavabit SSL Cert Revoked

#194

Earlier quoted context omitted.

According to the New Yorker piece on Lavabit yesterday ( http://www.newyorker.com/online/blogs/elements/2013/10/how-l... ), the owner was willing to add code tailored to tracing only Snowden's (or whoever it belonged to) account. The FBI turned him down and demanded the less surgical option.

...and a solution that would fail to preserve the chain of evidence. If there's a black box at any point, e.g. Levison produces information and emails it to the investigating officers, the doctrine of "fruit of the poisoned tree" applies.

Yeah you are shill, actually

If the government needs to preserve the chain of evidence by controlling every step of information flow in every criminal case, well clearly the government needs to ... sniff/control/spy-on the entire Internet. Whatda-ya-know...

Re: Lavabit SSL Cert Revoked

#195

Earlier quoted context omitted.

That's a loaded question and I'm not going to play that game.

That's a perfectly reasonable question, actually. One possible answer is that communicating on the internet requires the use of a physical commons, which one could reasonably argue carries either innate restrictions or restrictions legitimately imposed by the owners of said infrastructure.

No, it's not. He's making an assumption. He's assuming I think privacy should be restricted to select mediums, which is not the point of my comment. It would be the same thing as me asking you or him why you want to assist child rapists or people killing other people?

And yes, it might be a bit pedantic, but I'm tired of these childish games on HN.

Re: Lavabit SSL Cert Revoked

#196

I've read quite a few complaints about the government on this post. My suggestion is to simply do something. You have (a) the ability to vote, so stop voting in Republicans OR Democrats (both equally as bad) OR even run yourselves. (b) send a letter to your representative, they occasionally will read the mail, plus you at least can vent your frustration at someone who CAN do something.

[deleted]

Re: Lavabit SSL Cert Revoked

#197

Earlier quoted context omitted.

> That's perfectly valid, since those examples were first trotted out prior to that with no argument. Except the burden lies with those wanting to add a right to privacy to the list of rights we have. The right to privacy simply doesn't exist. There is a right against unreasonable search and seizure. But that's hardly a right of total privacy. > If it's so obvious why we should treat those as special cases, it should…

I think you misunderstood me, or extrapolated a position far beyond anything implied in my statement.

No.

Re: Lavabit SSL Cert Revoked

#198

Lavabit has revealed something incredibly important. The US Government has no problem with seizing your private keys . It claims the right to impersonate you without your permission. It no longer matters which system you use, Sovereign Keys, PGP web-of-trust, traditional PKI, they're all the same. Services based in the US can be MITM'd without leaving any traces. If this is allowed to continue uncontested there will…

The only way to stop this is to dismantle the police state. We have no chance of keeping up with their anti-privacy arms race

Let's replace them with an app while they are in halt mode.

Re: Lavabit SSL Cert Revoked

#199

Earlier quoted context omitted.

That's a loaded question and I'm not going to play that game.

That's a perfectly reasonable question, actually. One possible answer is that communicating on the internet requires the use of a physical commons, which one could reasonably argue carries either innate restrictions or restrictions legitimately imposed by the owners of said infrastructure.

That is a reasonable response. I would counter by saying that I see that as a justification for why they [government, ISP, whoever] should be allowed make demands about the use of the physical commons, but isn't a reason why they should exercise this conceded right.

For example: I, a hypothetical bar owner, have a right to ban silly hats in my bar. Why? Because I own it. However that's not a reason that I should ban silly hats. Just saying "I'm the owner, so I can." doesn't actually explain why I should.

I do also disagree that the government specifically is entitled to restrict privacy on the internet because much of the infrastructure is owned or otherwise controlled by them. The government owns nearly all roads, yet while using that infrastructure I still enjoy certain privacies. For example, if a cop pulls me over and asks me where I am going or where I have been, I have no obligation to answer him.

Re: Lavabit SSL Cert Revoked

#200

Lavabit has revealed something incredibly important. The US Government has no problem with seizing your private keys . It claims the right to impersonate you without your permission. It no longer matters which system you use, Sovereign Keys, PGP web-of-trust, traditional PKI, they're all the same. Services based in the US can be MITM'd without leaving any traces. If this is allowed to continue uncontested there will…

Ok, let's keep this in perspective. The problem here is Lavabit was specifically designed to disallow lawful intercepts of individuals. Targeting individuals is absolutely the right way to go about a lawful intercept. Sucking up all traffic like the NSA has been doing is totally overbroad and invasive. But the whole point of the asymmetric encryption feature of Lavabit was to make it impossible for anyone but the acc…

> But surely we can all agree there exist circumstances under which some lawful intercepts are justified

Perhaps, but there are means of communication that are impervious to interception, and that cannot be compromised the way Lavabit might have been.

Should such technologies be outlawed?

Post reply on HN