Live data from Hacker News

Lavabit SSL Cert Revoked

lavabit.com

221–230 of 321 posts

Re: Lavabit SSL Cert Revoked

#221
post #211

Earlier quoted context omitted.

Impervious?

Sure: Strong encryption and ephemeral keys. The only thing to do in that situation is to compromise one of the communicating parties. If the communicating parties have arranged a safeword to signal they have been compromised, even that technique is useless. In the case of Snowden and Greenwald, that wasn't going to happen. It is possible to make storage and communication immune to surveillance. So I ask: should that…

That is not impervious: compromise an endpoint. It takes work, but in the course of a serious investigation it can get done. At the limit, Van Eck or similar analog-hole analogues.

Anyway, my position is "no, that should not be illegal", though I am not entirely confident in that.

Re: Lavabit SSL Cert Revoked

#222

Lavabit has revealed something incredibly important. The US Government has no problem with seizing your private keys . It claims the right to impersonate you without your permission. It no longer matters which system you use, Sovereign Keys, PGP web-of-trust, traditional PKI, they're all the same. Services based in the US can be MITM'd without leaving any traces. If this is allowed to continue uncontested there will…

Ok, let's keep this in perspective. The problem here is Lavabit was specifically designed to disallow lawful intercepts of individuals. Targeting individuals is absolutely the right way to go about a lawful intercept. Sucking up all traffic like the NSA has been doing is totally overbroad and invasive. But the whole point of the asymmetric encryption feature of Lavabit was to make it impossible for anyone but the acc…

> But surely we can all agree there exist circumstances under which some lawful intercepts are justified: child pornographers, terrorists actively planning murders, missing persons, etc.

Oh come on, don't be so naive.

> child pornographers

As defined by which country? Is that 16 years old, or 18? Maybe even 21. Just because something is illegal where you are, does not make it illegal in my country/culture.

> terrorists actively planning murders

And now we know the US Govt actively murders it's own citizens without trial, surely we'd have to count them as terrorists, wouldn't we? (let alone what they do it non-citizens)

> missing persons

How long does someone have to be "missing" for that to justify the government having unlimited power? Surely they should just kick down everyone's door until they find what they want [1]

For every example you come up with, it's trivial to point out that it's an extremely slippery slope.

[1] http://www.youtube.com/watch?v=cfOvHuojEB4 (etc.)

Re: Lavabit SSL Cert Revoked

#223

Lavabit has revealed something incredibly important. The US Government has no problem with seizing your private keys . It claims the right to impersonate you without your permission. It no longer matters which system you use, Sovereign Keys, PGP web-of-trust, traditional PKI, they're all the same. Services based in the US can be MITM'd without leaving any traces. If this is allowed to continue uncontested there will…

Ok, let's keep this in perspective. The problem here is Lavabit was specifically designed to disallow lawful intercepts of individuals. Targeting individuals is absolutely the right way to go about a lawful intercept. Sucking up all traffic like the NSA has been doing is totally overbroad and invasive. But the whole point of the asymmetric encryption feature of Lavabit was to make it impossible for anyone but the acc…

"The problem here is Lavabit was specifically designed to disallow lawful intercepts of individuals."

You say that as though that's the only possible explanation for why the service was designed the way it is.

Tarsnap is also - arguably - designed in much the same way. What do you think Colin's response ought to be if the FBI/NSA come to him saying "we think one of your users might be doing $bad_thing, so we want your private keys so we can impersonate you, decrypt anything any of your users have backed up using tarsnap, and undermine the very basis of the business you've built." (note: this is a bit more difficult to execute - they'd need to have some good reason to update the tarsnap software on all end user's machines, since Colin doesn't have the private key my backups are encrypted with…)

You say "it's designed to disallow law enforcement certain abilities", I say "it's designed with best-practice modern digital privacy techniques, and is _entirely_ legal, legitimate, and a perfectly good premise to base a business on - and which the government _doesn't_ have the right to claim is 'unlawful', the same as building doorlocks without government skeleton keys, or banksafes without hidden vulnerabilities that the FBI or NSA know about, is also not 'unlawful'".

If you want to make privacy illegal - take it to the polls and ask the public if they agree. Until then - designing, deploying, and using well engineered systems to protect your privacy is every citizen's right should they choose to use it. Sure " … some lawful intercepts are justified", but that _doesn't_ imply all systems must be designed in a way that lawful intercepts are possible, and it doesn't give the government the right to coerce people not suspected of illegal acts into destroying their businesses and livelihoods just because they " … didn't trust him to act as a spy on their behalf". That's just _so_ wrong. So _very_ wrong.

Re: Lavabit SSL Cert Revoked

#224

Lavabit has revealed something incredibly important. The US Government has no problem with seizing your private keys . It claims the right to impersonate you without your permission. It no longer matters which system you use, Sovereign Keys, PGP web-of-trust, traditional PKI, they're all the same. Services based in the US can be MITM'd without leaving any traces. If this is allowed to continue uncontested there will…

Ok, let's keep this in perspective. The problem here is Lavabit was specifically designed to disallow lawful intercepts of individuals. Targeting individuals is absolutely the right way to go about a lawful intercept. Sucking up all traffic like the NSA has been doing is totally overbroad and invasive. But the whole point of the asymmetric encryption feature of Lavabit was to make it impossible for anyone but the acc…

> But surely we can all agree there exist circumstances under which some lawful intercepts are justified: child pornographers, terrorists actively planning murders, missing persons, etc. The problem is Lavabit was not designed to facilitate intercepts under any circumstances.

That's not true, though. Levison could and did help the government with intercepts before, and offered to provide the same service again; this time, the government was not satisfied with the offer (from the New Yorker, emphasis mine):

"The documents, and Levison’s comments to us, suggest that although he is a skeptic, he was willing to work with the government: he offered to write intercept code himself to capture their target’s metadata, and acknowledged that the government might have a right to the person’s information. He was willing to turn that information over, as he did in a case involving child pornography; Lavabit’s archived site in fact explicitly states that one of the reasons its most secure services are available to paying customers only is so that if an account “is used for illegal purposes that money trail can be used to track down the account owner.” But the government refused Levison’s offer. It wanted the keys to everything, so he gave it nothing."

Re: Lavabit SSL Cert Revoked

#225

Earlier quoted context omitted.

> His argument is clearly that people have a right to privacy. Except there is no right to engage in total privacy. There is a right against unreasonable search and seizure. But that's hardly a right of total privacy. Maybe his argument is that he thinks people should have a right to total privacy?

Does asking for a site's private SSL key sound like a reasonable search? I realize "reasonable" is entirely subjective, which is why I don't put much faith in out justice system.

Putting aside the vague term reasonable for a moment, we should really examine that the fourth amendment states "... and no Warrants shall issue, but upon probable cause, supported by Oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized."

I think we need to analyze "persons" or "things" in an electronic light... could things be roughly analogous to "a mailbox" and could persons be "a person's electronic mail account"?

You can't just state on your warrant "I want all of the things!", you must stipulate that "I want Ben's mail account and logs of all his activity on your service." If there is no way of extracting that information without compromising everyone else's privacy, does the law state "in cases like this, the constitution should be violated to satisfy the terms of the warrant"? or does the law state "the terms of this warrant cannot be enforced without breaching the constitutional rights of at least one other party and thus is illegal"?

It's my guess (and I'd like to emphasise the word guess as I really have no idea), that any reasonable judge (that wasn't on the payroll of the NSA or FISA court) would deem this is an illegal search warrant because it's in violation of every other Lavabit user's fourth amendment rights.

Anyway, that's all by-the-by. The judge who is attempting to enforce this ridiculous debacle (and I use the word ridiculous in the sense of hilarity because every new development is a source of mirth) clearly doesn't give a shit about anyone's fourth amendment rights, and he's pissed at Levison's continued contempt of court so he's stamping his feet like a spoiled little four year old who's just been told he's not getting Dunkin' Donuts for dinner, while getting a schooled by an internet Hero... with a capital H.

Re: Lavabit SSL Cert Revoked

#226

Lavabit has revealed something incredibly important. The US Government has no problem with seizing your private keys . It claims the right to impersonate you without your permission. It no longer matters which system you use, Sovereign Keys, PGP web-of-trust, traditional PKI, they're all the same. Services based in the US can be MITM'd without leaving any traces. If this is allowed to continue uncontested there will…

Ok, let's keep this in perspective. The problem here is Lavabit was specifically designed to disallow lawful intercepts of individuals. Targeting individuals is absolutely the right way to go about a lawful intercept. Sucking up all traffic like the NSA has been doing is totally overbroad and invasive. But the whole point of the asymmetric encryption feature of Lavabit was to make it impossible for anyone but the acc…

I totally disagree. People have the right to have private and secure conversations and we shouldn't have to give up that privacy to ensure that the government can spy on our conversations in order to catch bad guys.

Re: Lavabit SSL Cert Revoked

#227

Earlier quoted context omitted.

That's a loaded question and I'm not going to play that game.

That's a perfectly reasonable question, actually. One possible answer is that communicating on the internet requires the use of a physical commons, which one could reasonably argue carries either innate restrictions or restrictions legitimately imposed by the owners of said infrastructure.

That is total bullshit. All you should really have to have in order to keep a conversation private is the intentions. Even if it's a plain text email, only myself and the recipient of the email address should have the privilege of it's contents. If you want you can agree to let the provider use an automated system to scan for keyword for ads or whatever, but no one other than the recipients and agreed upon thrid parties should have permission to read those messages and anyone else doing so should be punished by law. We need to add an amendment which augments the 1st to say this clearly.

Re: Lavabit SSL Cert Revoked

#228

Earlier quoted context omitted.

No, it's not. He's making an assumption. He's assuming I think privacy should be restricted to select mediums, which is not the point of my comment. It would be the same thing as me asking you or him why you want to assist child rapists or people killing other people? And yes, it might be a bit pedantic, but I'm tired of these childish games on HN.

You could have just answered "I don't think that." Or, you know, given me the exact response you just typed.... It really was not my intention to ask you a loaded question. Instead of calling my question childish, you should consider the possibility that your comment is not nearly as clear as you seem to think.

I agree. Talk about a conversation killer.

Considering he was speaking for kelnos at the time, I think your query seems reasonable and actually expands on the concept around what types of conversations should be managed by our government. Shouting "FIRE" in a theater is, and should be, against the law. It's a clear violation of trust, poses significant risk the the recipients, and is being done in a place that is clearly owned by someone. I'm cool with the police being in charge of enforcing rules that prevent this.

Assuming they are also in charge of policing the Internet effectively is another matter entirely.

Re: Lavabit SSL Cert Revoked

#229
post #189

Earlier quoted context omitted.

Well, what about the children? Serious question. I say it's an incomplete argument because there is no mention of how we should go about prosecuting child pornographers and terrorists, rescuing missing persons when phone/email records are our only clue, and so on. There's just "no, sorry", the right to privacy trumps these things under all possible circumstances. The question remains.. why? Why is a world with ideall…

Do you believe that we should all give up our right to privacy just in case it allows us to save a few people here and there? I know that makes me sound like a dick at first glance, but do you really believe that if you answer "yes" to the question above, we are guaranteed that this system will never be abused? I think the answer to that has already been provided in light of recent events.

No, we all should not give up our right to privacy. There should be lawful means to investigate crimes with proper judicial oversight.

For example, today, and for much of the history of democratic society, the police have the power to search your person under certain circumstances. I hope you would agree that you still enjoy a "right to privacy" in our society.

"Right to privacy" has always encompassed a body of law governing privacy. It has never been an absolute.

By comparison, the same is true for "free speech". We should not give up our right to free speech. Nor should we all start shouting fire in crowded theaters.

Of course there are no guarantees that abuse is impossible. That's what the fight for free speech and privacy is about: proper and just oversight by the citizenry -- not the abolition of lawful society.

Re: Lavabit SSL Cert Revoked

#230
post #167

Earlier quoted context omitted.

His argument is clearly that people have a right to privacy. It says so in his next sentence. The 'no, sorry' is him discarding the emotional plea that often justifies invading a person's privacy in the first place ("please, won't somebody think of the children!").

Well, what about the children? Serious question. I say it's an incomplete argument because there is no mention of how we should go about prosecuting child pornographers and terrorists, rescuing missing persons when phone/email records are our only clue, and so on. There's just "no, sorry", the right to privacy trumps these things under all possible circumstances. The question remains.. why? Why is a world with ideall…

If that is the case, why stop at child pornography. Physical child abuse like beatings present a far greater threat in terms of children impacted, but we aren't discussing the wholesale monitoring of every adult with a child, are we? Are the children that are victims of physical abuse not deserving of the same attention we give to those that are victims of sexual abuse?

There are alternatives that mitigate the problem without centralized government involvement and dragnet surveillance. Opting for a law enforcement-based government solution from day one pretty much eliminates all creative thinking on how the damages from child pornography can be reduced to acceptable levels.

I emphasize acceptable levels, because the correction of all ills and dangers carries with it diminishing returns. If you want to completely eradicate something, it's going to cost you an order of magnitude more to eliminate the last 20% of the problem than the first 80%. Costs here a both financial and freedom-wise. The in both time and freedoms for services (telecoms, etc.) and places (homes, offices, etc.) is good enough for probably 80% of the benefit. Beyond that the cost is just too high for too little benefit.

You can also get 80% of the benefit by just identifying the small subset of children that present the highest at risk group and providing special services for the monitoring and social support for that group. No need to drag in the rest of society.

First, child pornography itself isn't really the problem, but the problem we focus on because its visible and elicits emotions. We focus on the end product, but the root problem is how child pornography is made. Child porn doesn't only exist in electronic form. Getting convictions of users of child porn isn't going to protect any children. We know undeniably that a market exists. Going after the buy-side is never going to have a meaningful impact, because there are a lot more buyers than creators and the amount of effort to bag a few consumers here and there is a drop in the bucket and will never be sufficient to reduce demand enough that there isn't incentive for the supply side to keep producing it. If you make it harder, then the price just go up. Profits don't change.

Personally, I would like us make the consumption of child pornography legal but keep it illegal to manufacture or distribute child pornography. By keeping the buy side legal, you gain enormous amounts of visibility into the market dynamics that don't exist, when you force both sides to go underground making observation difficult enough that the privacy of many innocent people needs to be compromised to make policing even marginally effective. Furthermore, it would still be considered taboo and a sickness and we'd encourage purveyors of child porn to seek psychiatric care, where we would counsel them on their addiction and show them the damages caused by their consumption. To get access to free psychiatric care, we can solicit cooperation from the buy side in discovering who is operating on the sell side. This removes a lot of trust in that market, because instead of both sides being driven to trust one another for fear from prosecution of the same law enforcement entity, the sell side will end up with a healthy mistrust of their customers.

The fastest way to destroy a market is to destroy trust in that market. TBH, I'm surprised we don't really spend any attention on how you effectively undermine markets like we spend time on how to foster liquidity in markets and making them more efficient.

Post reply on HN