Live data from Hacker News

Lavabit SSL Cert Revoked

lavabit.com

251–260 of 321 posts

Re: Lavabit SSL Cert Revoked

#251

The lavabit case highlights something interesting that we need. We need that not only individuals have privacy, but that businesses have privacy of who their users are. The same way we provide anonymity to users through centralized means, is there not a way to provide a way for service provider to have a sufficient level of opaqueness of who their customers are. You can't subpeona Service Provider A if you don't know…

Customer: I wish to make a complaint.

Shopkeeper: Go away. I don't know you.

Dead parrot problem solved.

Re: Lavabit SSL Cert Revoked

#252
post #159
post #107

Earlier quoted context omitted.

no. no. no. the judge's trust talk was a falacy time waster. - give me your bank password so i can get the $5 you own me. - why dont i give you a check for $5? - so i have to trust your check is good but you cant trust me with your bank password? see? it is just crazy talk to push him around. the judge knows here his/her obedience rests. he is not even listening to the defense.

What if it was more like - You owe me $25 - I only keep my money in bitcoin - Well, I don't do that bitcoin thing, and I don't really want to set a whole thing just to transfer the money - OK, I could get it for you in cash, but you'll have to give me a few days ...a few days later - Uhh...so about that money - Oh, haven't gotten around to transferring that - OK, but I could use it. Or, I could borrow your phone and…

Agreed, I feel like Levison lost a lot of credibility and damaged his case by dragging his feet initially. However when the judge said "why should we trust you?" he didn't explicitly tie it into that history. Perhaps in context it was a given. It seemed the opposing attorney immediately after argued that Levison couldn't be trusted, because he'd delayed on prior orders, and the judge agreed.

Re: Lavabit SSL Cert Revoked

#253
post #208

Earlier quoted context omitted.

So you don't think law enforcement should be able to do its job? If we lived in total privacy, and I were to start a ponzi scheme completely online, then I would not be able to be stopped because : 1. My e-mail wouldn't be looked at 2. My bank accounts couldn't be looked at Almost all evidence gathering during criminal investigation involves a loss of privacy at one point

I don't for a minute agree that law enforcement's operational problems trump every other right citizens have. I find it _astounding_ that people are supporting the idea of forcing Levinson to back down on the guarantee of privacy he'd made to his _other_, not under any probable cause level of suspicion, 400,000 fully-entitled-to-the-privacy-they've-chosen-to-pay-for customers. Violating the privacy of four hundred TH…

from the New Yorker piece my impression was that, for the FBI, the easiest way was to have the SSL keys, and the Judge didn't understand the implications so granted the request.

Initially, the FBI was willing to let Levison modify the site so that just the target would have his stuff intercepted . But Levison wanted to charge the gov't $3500 for the work, also asked for external audits to make sure the FBI wouldn't goof off with the info. The FBI stopped trusting him, and for them it was just easier to have the keys.

Re: Lavabit SSL Cert Revoked

#254

Earlier quoted context omitted.

That's a perfectly reasonable question, actually. One possible answer is that communicating on the internet requires the use of a physical commons, which one could reasonably argue carries either innate restrictions or restrictions legitimately imposed by the owners of said infrastructure.

That is total bullshit. All you should really have to have in order to keep a conversation private is the intentions. Even if it's a plain text email, only myself and the recipient of the email address should have the privilege of it's contents. If you want you can agree to let the provider use an automated system to scan for keyword for ads or whatever, but no one other than the recipients and agreed upon thrid part…

I believe you're referring to the 4th amendment.

Re: Lavabit SSL Cert Revoked

#255

Lavabit has revealed something incredibly important. The US Government has no problem with seizing your private keys . It claims the right to impersonate you without your permission. It no longer matters which system you use, Sovereign Keys, PGP web-of-trust, traditional PKI, they're all the same. Services based in the US can be MITM'd without leaving any traces. If this is allowed to continue uncontested there will…

> Lavabit has revealed something incredibly important.

That Ladar Levison is incompetent. The FBI should probably have beat him to death in an alley for fraud.

Because whatever the FBI can do with a search warrant, we must assume the mafia has already done with a rubber hose. In fact, if we apply the parent comment's raving paranoia to the whole system, we find that Levison wept for joy because the FBI was giving him a way to publicly throw in the towel and retire from his mob involvement.

If Levison had been competent, instead of putting on a TSA-style security theater, he would have been using tamper-detecting self-erasing computers, jurisdictional redundancy, pre-distributed certificate revocation lists, etc.

TL,DR: he did this to himself by not following NSA standards.

Re: Lavabit SSL Cert Revoked

#256

Lavabit has revealed something incredibly important. The US Government has no problem with seizing your private keys . It claims the right to impersonate you without your permission. It no longer matters which system you use, Sovereign Keys, PGP web-of-trust, traditional PKI, they're all the same. Services based in the US can be MITM'd without leaving any traces. If this is allowed to continue uncontested there will…

Ok, let's keep this in perspective. The problem here is Lavabit was specifically designed to disallow lawful intercepts of individuals. Targeting individuals is absolutely the right way to go about a lawful intercept. Sucking up all traffic like the NSA has been doing is totally overbroad and invasive. But the whole point of the asymmetric encryption feature of Lavabit was to make it impossible for anyone but the acc…

Yes, I agree that there are circumstances... But now without case by case decision from a court or whatever the actualy legal system requires. Citizens should be able to protect their privacy and it can be overridden only in those special circumstances and approved by a judge (or whatever the given state requires).

Re: Lavabit SSL Cert Revoked

#257
post #253

Earlier quoted context omitted.

I don't for a minute agree that law enforcement's operational problems trump every other right citizens have. I find it _astounding_ that people are supporting the idea of forcing Levinson to back down on the guarantee of privacy he'd made to his _other_, not under any probable cause level of suspicion, 400,000 fully-entitled-to-the-privacy-they've-chosen-to-pay-for customers. Violating the privacy of four hundred TH…

from the New Yorker piece my impression was that, for the FBI, the easiest way was to have the SSL keys, and the Judge didn't understand the implications so granted the request. Initially, the FBI was willing to let Levison modify the site so that just the target would have his stuff intercepted . But Levison wanted to charge the gov't $3500 for the work, also asked for external audits to make sure the FBI wouldn't g…

It'd no-doubt be "easier" for the FBI to "do their job" if they had copies of everybodies house keys and office keys and safe-deposit-box keys too – so they could have a quick snoop whenever they got curious about whether you were doing anything wrong.

But we don't let them force builders/landlords/lockmakers to hand everybodies private physical house keys over, just because somebody somewhere is doing $bad_thing inside a house.

The FBI didn't trust him – boo hoo – they need to find another way to get their job done then.

(Does anybody _really_ think this was about "trusting" Levinson? Or that it was instead about trying to strong-arm Levinson/Lavabit into illegally and immorally participating in the NSA's ubiquitous surveillance program, almost certainly something they've gotten so used to having work for them that they've forgotten that occasionally they'll bump into someone prepared to throw their business away instead of compromising about "doing the _right_ thing"?)

Re: Lavabit SSL Cert Revoked

#258
post #149

Earlier quoted context omitted.

I disagree with the premise. I don't believe that a service should be required by law to provide the possibility for the government to intercept the activity of its users. You can always say "but the child pornographers!" or, "but the terrorists!"... but... no, sorry. I believe that people should have the ability to engage in total privacy. The fact that the US gov't is doing this because of Snowden (a person I admir…

> I believe that people should have the ability to engage total privacy. They already have the ability to do this. That's not what you are asking for. What you are really asking for is: "I believe that people should have the ability to engage total privacy through any means of communication they so choose."

I believe my statement is more broad than your clarification and so I did say that, but for the sake of the argument, yes, that is indeed what I'm asking for, and I believe that's entirely reasonable. If you have the ability to send encrypted data over any particular communication channel in such a way that no untrusted third party can ever decrypt it (let's assume that it's possible), then I think that should be entirely lawful.

I'm not saying that all communication channels are designed in such a way as to make that possible, but for those that are, I believe that's completely ok.

Re: Lavabit SSL Cert Revoked

#259
post #208
post #149

Earlier quoted context omitted.

I disagree with the premise. I don't believe that a service should be required by law to provide the possibility for the government to intercept the activity of its users. You can always say "but the child pornographers!" or, "but the terrorists!"... but... no, sorry. I believe that people should have the ability to engage in total privacy. The fact that the US gov't is doing this because of Snowden (a person I admir…

So you don't think law enforcement should be able to do its job? If we lived in total privacy, and I were to start a ponzi scheme completely online, then I would not be able to be stopped because : 1. My e-mail wouldn't be looked at 2. My bank accounts couldn't be looked at Almost all evidence gathering during criminal investigation involves a loss of privacy at one point

Law enforcement has a variety of ways with which it can gather evidence. Ignoring the internet and tech world entirely, there are plenty of criminals who are clever enough to cover their tracks sufficiently so there is no way that evidence can be brought against them.

I don't see why the law should require that all services should be built with wiretap points. If a user of a service wishes to ensure perfect secrecy, and a service allows that use case (ideally by never seeing the user's cleartext or keys), I see no reason why the law should be allowed to interfere and require that the service be changed to disallow that.

Sure, that might make law enforcement's job harder in that case, but too bad. Catching a few extra criminals here and there is not a good reason to weaken the possibility of privacy for the rest of us.

Re: Lavabit SSL Cert Revoked

#260

Earlier quoted context omitted.

I have mocked-up a system for policy creation. The project is open; please contribute your thoughts. People say "it has flaws" but never explain the flaws, nor how to address them. https://bitbucket.org/djarvis/world-politics/ Would greatly appreciate constructive criticism. The system serves to educate everyone (openly and transparently) on implications of existing and upcoming policies. If the idea intrigues you, c…

I created a kind of micro discussion/decision making system that didn't generate much interest from people I talked to and perhaps shares a flaw with this concept. Basically if you look at what people use text for online it usually isn't anything serious, even these discussions don't have all that much gravity and HN is probably the most serious site I've seen. Text also has less emotion and involvement attached and…

You may be interested in http://caae.phil.cmu.edu/picola/current.html http://caae.phil.cmu.edu/picola/ . I'm not too familiar with it and i don't think it automatically splits people into groups but it was created with Fishkin's Deliberative Polling in mind.
Post reply on HN