Live data from Hacker News

Lavabit SSL Cert Revoked

lavabit.com

271–280 of 321 posts

Re: Lavabit SSL Cert Revoked

#271
post #37

I'm so sick of being sickened. I hate that this is becoming the norm and we can't do anything about it. I hate to spit cliches, but is this where my tax dollars go? For me, govt and internet should almost be like church and state. Where is the data around foiled terrorist plots? I just can't stomach the obtuse logic that we need to pay our taxes to employ these virtual minders. This is not what the internet is about.…

I have mocked-up a system for policy creation. The project is open; please contribute your thoughts. People say "it has flaws" but never explain the flaws, nor how to address them. https://bitbucket.org/djarvis/world-politics/ Would greatly appreciate constructive criticism. The system serves to educate everyone (openly and transparently) on implications of existing and upcoming policies. If the idea intrigues you, c…

You may or may not also be interested in some of the projects discussed at:

http://online-deliberation.net/

and in some of the projects linked from:

* http://www.communitywiki.org/ArgumentMap

* http://www.communitywiki.org/en/MappingArguments

* http://www.communitywiki.org/en/DebateTool

* .. and other related pages at that wiki

Re: Lavabit SSL Cert Revoked

#272
post #47

Earlier quoted context omitted.

Non-citizens can be turned away at the US border for any reason, or no reason at all. Considering that a person's ability to travel to the US is so professionally important in this industry (for conferences, business meetings, etc.), I do not believe this is fearmongering. Remember the case of the man refused entry after a misinterpreted Tweet about 'destroying America'? [1] It seems clear NSA surveillance informs CB…

If such donations really cause problems at borders, then it will be a sign that the place is FUBAR and you (and everyone else) should avoid traveling there.

Challenge accepted.

As a non US-citizen, I have, upon entering the US in the past, almost without fail been subjected to "additional scrutiny" and questions upon entry simply because I live on a farm, which triggers an automatic customs red-flag. (I understand the concern about having been on a farm - they don't want me importing foreign weed-seeds or insect eggs via my shoes. But the customs system makes no distinction between someone flagged for such concerns versus someone flagged for more legitimately nefarious reasons.)

Since things got more draconian it has become one of my very, very few non-negotiable conditions of contract that I do not travel to or through the USA or any of its territories. It's just not worth the hassle.

Re: Lavabit SSL Cert Revoked

#273
post #170

Earlier quoted context omitted.

"The problem here is Lavabit was specifically designed to disallow lawful intercepts of individuals." This is not True. Lavabit made it clear in their TOS that they had no interest in concealing illegality, they complied fully and willingly with all warrants targeting individual users. Their premise was to protect your privacy from untargetted blanket surveillance.

What's your source? That conflicts with the New Yorker reporting on the trial proceedings. It also belies common sense, since Lavabit offers a form of encryption that even they cannot decrypt. Source: http://www.newyorker.com/online/blogs/elements/2013/10/how-l...

I can't see any part of that article that supports your claim. On the contrary, the article appears to claim that one of the reasons he was resisting so strongly was that handing over the keys would allow full access, though the reporting isn't very clear when it comes to already stored e-mails.

From the article:

' On July 25th, Lavabit petitioned to cancel the subpoena and warrant, arguing that if the “government gains access to Lavabit’s Master Key, it will have unlimited access to not only [the account], but all of the communications and data stored in each of Lavabit’s 400,000 e-mail accounts.” Lavabit also asked the court to unseal its records and permit Levison to speak. '

Re: Lavabit SSL Cert Revoked

#274
post #170

Earlier quoted context omitted.

"The problem here is Lavabit was specifically designed to disallow lawful intercepts of individuals." This is not True. Lavabit made it clear in their TOS that they had no interest in concealing illegality, they complied fully and willingly with all warrants targeting individual users. Their premise was to protect your privacy from untargetted blanket surveillance.

What's your source? That conflicts with the New Yorker reporting on the trial proceedings. It also belies common sense, since Lavabit offers a form of encryption that even they cannot decrypt. Source: http://www.newyorker.com/online/blogs/elements/2013/10/how-l...

My source is (was) the lavabit ToS. I was a paying customer of Lavabit and familiar with their ToS.

He made it pretty clear that if you wanted to use his service to hide illegal activity you were SOL.

The TOS seems to be long gone. But wikipedia summarises his stance on legit warrants as opposed to "hand over your SSL private key": http://en.wikipedia.org/wiki/Lavabit

Re: Lavabit SSL Cert Revoked

#275
post #208

Earlier quoted context omitted.

So you don't think law enforcement should be able to do its job? If we lived in total privacy, and I were to start a ponzi scheme completely online, then I would not be able to be stopped because : 1. My e-mail wouldn't be looked at 2. My bank accounts couldn't be looked at Almost all evidence gathering during criminal investigation involves a loss of privacy at one point

I don't for a minute agree that law enforcement's operational problems trump every other right citizens have. I find it _astounding_ that people are supporting the idea of forcing Levinson to back down on the guarantee of privacy he'd made to his _other_, not under any probable cause level of suspicion, 400,000 fully-entitled-to-the-privacy-they've-chosen-to-pay-for customers. Violating the privacy of four hundred TH…

They've got the warrant; it was a reasonable warrant, in a standard form, that he could reasonably have anticipated. The FBI have the right to execute it. (If you're arguing that this particular warrant shouldn't have been issued then that's a separate issue). It's Levinson's fault and his problem, not the government's, that Levinson specifically designed his site such that he couldn't execute this kind of ordinary, reasonable warrant without failing to provide the service his customers were paying him for.

Re: Lavabit SSL Cert Revoked

#276

Lavabit has revealed something incredibly important. The US Government has no problem with seizing your private keys . It claims the right to impersonate you without your permission. It no longer matters which system you use, Sovereign Keys, PGP web-of-trust, traditional PKI, they're all the same. Services based in the US can be MITM'd without leaving any traces. If this is allowed to continue uncontested there will…

Ok, let's keep this in perspective. The problem here is Lavabit was specifically designed to disallow lawful intercepts of individuals. Targeting individuals is absolutely the right way to go about a lawful intercept. Sucking up all traffic like the NSA has been doing is totally overbroad and invasive. But the whole point of the asymmetric encryption feature of Lavabit was to make it impossible for anyone but the acc…

The premise behind your post is incorrect. There is no obligation to create a mechanism for eavesdropping by the government.

In other words: if you can design a system to "disallow lawful intercepts of individuals", you are allowed to do so.

Or: a lawful intercept is lawful to use, but not legally compelled to exist.

The fact that we are so far down the rabbit hole that intelligent technologists like yourself accept this as a premise is incredibly disturbing.

Re: Lavabit SSL Cert Revoked

#277

Earlier quoted context omitted.

> As long as the engineers who design and build the internet care, we can do ok. If the engineers who designed and built the internet cared about privacy, internet protocols wouldn't completely ignore privacy. They designed a massive routed network that involves packet forwarding between random untrusted nodes and then built a bunch of plain-text protocols on top (SMTP, HTTP, etc). > how many of them want their webca…

I often agree with you, but the statement that the Internet founders didn't care about privacy is factually incorrect: Vint Cerf (as mentioned by the sibling comment) is on record as not only being in favor of privacy but wishing the technology had existed for practical cryptographically secure authentication at the protocol level at the time the Internet was designed.

I know he's in favor of it now, but was it something he was thinking of when he designed these protocols?

Re: Lavabit SSL Cert Revoked

#278
post #208

Earlier quoted context omitted.

So you don't think law enforcement should be able to do its job? If we lived in total privacy, and I were to start a ponzi scheme completely online, then I would not be able to be stopped because : 1. My e-mail wouldn't be looked at 2. My bank accounts couldn't be looked at Almost all evidence gathering during criminal investigation involves a loss of privacy at one point

I don't for a minute agree that law enforcement's operational problems trump every other right citizens have. I find it _astounding_ that people are supporting the idea of forcing Levinson to back down on the guarantee of privacy he'd made to his _other_, not under any probable cause level of suspicion, 400,000 fully-entitled-to-the-privacy-they've-chosen-to-pay-for customers. Violating the privacy of four hundred TH…

Yes, I think it's OK.

The problem here is that Levison set up a Rube Goldberg machine. If the (in my opinion reasonable) law says you have to be able to provide access to anyone's data when you are given a warrant, you can't get out of that requirement by making your technology require you give everyone else's data, or kill a kitten, or any other requirement.

Edit: Changed 'levinson', UK report about the media, to 'levison', owner of lavabit.

Re: Lavabit SSL Cert Revoked

#279

Lavabit has revealed something incredibly important. The US Government has no problem with seizing your private keys . It claims the right to impersonate you without your permission. It no longer matters which system you use, Sovereign Keys, PGP web-of-trust, traditional PKI, they're all the same. Services based in the US can be MITM'd without leaving any traces. If this is allowed to continue uncontested there will…

Ok, let's keep this in perspective. The problem here is Lavabit was specifically designed to disallow lawful intercepts of individuals. Targeting individuals is absolutely the right way to go about a lawful intercept. Sucking up all traffic like the NSA has been doing is totally overbroad and invasive. But the whole point of the asymmetric encryption feature of Lavabit was to make it impossible for anyone but the acc…

Isn't any software with a goal of eliminating security holes essentially "specifically designed to disallow lawful intercepts of individuals"? Should all software providers be forced by law to implement backdoors so that the FBI can intercept its communications, just in case Snowden uses the software?

Re: Lavabit SSL Cert Revoked

#280
post #208
post #149

Earlier quoted context omitted.

I disagree with the premise. I don't believe that a service should be required by law to provide the possibility for the government to intercept the activity of its users. You can always say "but the child pornographers!" or, "but the terrorists!"... but... no, sorry. I believe that people should have the ability to engage in total privacy. The fact that the US gov't is doing this because of Snowden (a person I admir…

So you don't think law enforcement should be able to do its job? If we lived in total privacy, and I were to start a ponzi scheme completely online, then I would not be able to be stopped because : 1. My e-mail wouldn't be looked at 2. My bank accounts couldn't be looked at Almost all evidence gathering during criminal investigation involves a loss of privacy at one point

For the sake of arguments, let's just assume Windows is perfectly secure. Then if child pornographers or ponzi scammers use direct, encrypted links instead of emails to exchange information, what will the FBI do? Is it reasonable for it to hack into the computer of a suspect to gather evidence? Is it reasonable for it to force Microsoft to implement a hole in their OS so that they can do that? Is it Microsoft's fault for implementing their OS in such a way that it's difficult for the FBI to (lawfully) intercept its users?

Maybe we all blamed Microsoft unjustly, maybe they were forced by law to create all those holes, and maybe they were forced by law to not disclose the fact that they were forced by law to create all those holes.

Post reply on HN