Live data from Hacker News

Lavabit SSL Cert Revoked

lavabit.com

281–290 of 321 posts

Re: Lavabit SSL Cert Revoked

#281

Earlier quoted context omitted.

I don't for a minute agree that law enforcement's operational problems trump every other right citizens have. I find it _astounding_ that people are supporting the idea of forcing Levinson to back down on the guarantee of privacy he'd made to his _other_, not under any probable cause level of suspicion, 400,000 fully-entitled-to-the-privacy-they've-chosen-to-pay-for customers. Violating the privacy of four hundred TH…

Yes, I think it's OK. The problem here is that Levison set up a Rube Goldberg machine. If the (in my opinion reasonable) law says you have to be able to provide access to anyone's data when you are given a warrant, you can't get out of that requirement by making your technology require you give everyone else's data, or kill a kitten, or any other requirement. Edit: Changed 'levinson', UK report about the media, to 'l…

I have jumped in to this thread, so forgive me if I have missed something, but do not understand the reference to 'Levinson'.

I am from the UK, claim no expertise in the field, but the following might help.

'Levinson' is the name of a report on the media (a very long topic in itself), which has no bearing on giving up data.

The law which covers that,I believe, is known by its abbreviation as RIPPA and,amongst other things, sets out the powers that the UK government have to ask for data from companies. In particular, I understand that it makes it an offence to refuse to provide the key to encrypted material.

Re: Lavabit SSL Cert Revoked

#282

Lavabit has revealed something incredibly important. The US Government has no problem with seizing your private keys . It claims the right to impersonate you without your permission. It no longer matters which system you use, Sovereign Keys, PGP web-of-trust, traditional PKI, they're all the same. Services based in the US can be MITM'd without leaving any traces. If this is allowed to continue uncontested there will…

Ok, let's keep this in perspective. The problem here is Lavabit was specifically designed to disallow lawful intercepts of individuals. Targeting individuals is absolutely the right way to go about a lawful intercept. Sucking up all traffic like the NSA has been doing is totally overbroad and invasive. But the whole point of the asymmetric encryption feature of Lavabit was to make it impossible for anyone but the acc…

PGP is designed to disallow lawful intercepts. Should the government be allowed to prevent strong cryptography software on my own computer?

If not, then why should they be allowed to do the same on a hosted service?

If so, then is it also ok for oppressive governments in other countries to backdoor cryptography, so they can throw dissidents in prison? Or should dissidents have tools to protect themselves? If they should, then why shouldn't people in this supposedly-free country have the same tools?

Re: Lavabit SSL Cert Revoked

#283
post #170

Earlier quoted context omitted.

Ok, let's keep this in perspective. The problem here is Lavabit was specifically designed to disallow lawful intercepts of individuals. Targeting individuals is absolutely the right way to go about a lawful intercept. Sucking up all traffic like the NSA has been doing is totally overbroad and invasive. But the whole point of the asymmetric encryption feature of Lavabit was to make it impossible for anyone but the acc…

"The problem here is Lavabit was specifically designed to disallow lawful intercepts of individuals." This is not True. Lavabit made it clear in their TOS that they had no interest in concealing illegality, they complied fully and willingly with all warrants targeting individual users. Their premise was to protect your privacy from untargetted blanket surveillance.

I think the issue some people seem to be missing in this discussion is that the technology is morally neutral.

A system designed to protect the privacy of its users' data even if its operator is subjected to coercion does not care whether the coercion comes in the form of a court order, a bribe, a threat to reveal a secret or a man holding a gun to the operator's head.

A system designed to be secure against coercion of its operator necessarily resists lawful intercepts just as it resists blackmail. Designing a system in such a way does not imply that the designer wishes to promote illegal behavior nor hinder the ability of the police to investigate it.

Re: Lavabit SSL Cert Revoked

#284

Earlier quoted context omitted.

You mean browsers actually fall back to non-perfect-forward-secrecy? They even have the option of doing that? That's interesting if true. Ideally it should be enforced by the server, and if the browser can't support it, then the browser can't see the webpage.

They have to, because many sites don't support any PFS ciphersuites. For instance, banks. https://www.ssllabs.com/ssltest/analyze.html?d=www.bankofame... https://www.ssllabs.com/ssltest/analyze.html?d=chaseonline.c... https://www.ssllabs.com/ssltest/analyze.html?d=online.citiba... https://www.ssllabs.com/ssltest/analyze.html?d=us.hsbc.com&s... https://www.ssllabs.com/ssltest/analyze.html?d=online.wellsf... Ideally, M…

Well, the browsers could disable non PFS ciphers by default. When a site doesn't match any PFS cipher list, show a pop-up with a way to add an exception for the site.

Much more graceful than a complete switch-over and doesn't require co-ordination from other vendors.

Re: Lavabit SSL Cert Revoked

#285

Earlier quoted context omitted.

I don't for a minute agree that law enforcement's operational problems trump every other right citizens have. I find it _astounding_ that people are supporting the idea of forcing Levinson to back down on the guarantee of privacy he'd made to his _other_, not under any probable cause level of suspicion, 400,000 fully-entitled-to-the-privacy-they've-chosen-to-pay-for customers. Violating the privacy of four hundred TH…

Yes, I think it's OK. The problem here is that Levison set up a Rube Goldberg machine. If the (in my opinion reasonable) law says you have to be able to provide access to anyone's data when you are given a warrant, you can't get out of that requirement by making your technology require you give everyone else's data, or kill a kitten, or any other requirement. Edit: Changed 'levinson', UK report about the media, to 'l…

Like I've said elsewhere in the thread - what about Tarsnap?

Tarsnap is also - arguably - designed in much the same way. What do you think Colin's response ought to be if the FBI/NSA come to him saying "we think one of your users might be doing $bad_thing, so we want your private keys so we can impersonate you, decrypt anything any of your users have backed up using tarsnap, and undermine the very basis of the business you've built."

Has Colin built "a Rube Goldberg machine"? Should all of his paying customers have their privacy violated because the only way Colin has to make Tarsnap reveal one customers data would be to backdoor a software update? Is it unreasonable to charge a sum on the order of $3.5k if Colin offered to set something up to allow only a single customer's software update to be backdoored? (Christ - I'll bet the FBI ran up an order of magnitude more than $3.5k in legal costs arguing that $3.5k was "too expensive"!)

Do any of us have to consider when building our products - along with all our _real_ concerns, just how amenable our technology decisions and architectural concepts turn out to be for state surveillance purposes? Are we to be scrutinized as though modern digital privacy best practice and effective use of crypto implies we've intentionally set out to make the FBI's job more difficult than necessary? Should any of our scarce development resources be squandered trying to ensure we've got built-in ways to comply with any possible law enforcement demand?

I say no. Resoundingly no. Sure the FBI have a job to do. But that doesnt make it OK to run roughshod over innocent peoples rights and to force business owners to back down on guarantees they've made to paying customers and then throw gag orders on them to stop them telling anyone.

I think you're wrong - and I think people who think like you are part of a much greater problem.

Re: Lavabit SSL Cert Revoked

#286
post #243
post #149

Earlier quoted context omitted.

I disagree with the premise. I don't believe that a service should be required by law to provide the possibility for the government to intercept the activity of its users. You can always say "but the child pornographers!" or, "but the terrorists!"... but... no, sorry. I believe that people should have the ability to engage in total privacy. The fact that the US gov't is doing this because of Snowden (a person I admir…

The constitution of the US only guarantees freedom from unreasonable search. Reasonable search is absolutely authorized.

And the search of Lavabit's _other four hundred thousand paying customers is "reasonable"?

Or is being concerned enough about privacy to pay money to a service claiming to provide it now considered enough "probable cause"?

Re: Lavabit SSL Cert Revoked

#287
post #253

Earlier quoted context omitted.

I don't for a minute agree that law enforcement's operational problems trump every other right citizens have. I find it _astounding_ that people are supporting the idea of forcing Levinson to back down on the guarantee of privacy he'd made to his _other_, not under any probable cause level of suspicion, 400,000 fully-entitled-to-the-privacy-they've-chosen-to-pay-for customers. Violating the privacy of four hundred TH…

from the New Yorker piece my impression was that, for the FBI, the easiest way was to have the SSL keys, and the Judge didn't understand the implications so granted the request. Initially, the FBI was willing to let Levison modify the site so that just the target would have his stuff intercepted . But Levison wanted to charge the gov't $3500 for the work, also asked for external audits to make sure the FBI wouldn't g…

Trust is NOT a prerequisite for cooperation.

Re: Lavabit SSL Cert Revoked

#288

Earlier quoted context omitted.

Yes, I think it's OK. The problem here is that Levison set up a Rube Goldberg machine. If the (in my opinion reasonable) law says you have to be able to provide access to anyone's data when you are given a warrant, you can't get out of that requirement by making your technology require you give everyone else's data, or kill a kitten, or any other requirement. Edit: Changed 'levinson', UK report about the media, to 'l…

I have jumped in to this thread, so forgive me if I have missed something, but do not understand the reference to 'Levinson'. I am from the UK, claim no expertise in the field, but the following might help. 'Levinson' is the name of a report on the media (a very long topic in itself), which has no bearing on giving up data. The law which covers that,I believe, is known by its abbreviation as RIPPA and,amongst other t…

"Ladar Levison" is the name of the founder/operator of Lavabit. (The misspelled "Levinson" version of his surname in various bits of this thread may well be my fault. Apologies.)

Re: Lavabit SSL Cert Revoked

#289
post #208

Earlier quoted context omitted.

So you don't think law enforcement should be able to do its job? If we lived in total privacy, and I were to start a ponzi scheme completely online, then I would not be able to be stopped because : 1. My e-mail wouldn't be looked at 2. My bank accounts couldn't be looked at Almost all evidence gathering during criminal investigation involves a loss of privacy at one point

I don't for a minute agree that law enforcement's operational problems trump every other right citizens have. I find it _astounding_ that people are supporting the idea of forcing Levinson to back down on the guarantee of privacy he'd made to his _other_, not under any probable cause level of suspicion, 400,000 fully-entitled-to-the-privacy-they've-chosen-to-pay-for customers. Violating the privacy of four hundred TH…

If circumstances are such that monitoring one customer means all customers have to be potentially monitored then that, in practice, is the way things are. After all the TSA operate on exactly the same principle.

It may not, in some airy-fairy, hippy, juvenile world view, be "OK", but again, it is the way things are.

Re: Lavabit SSL Cert Revoked

#290

Lavabit has revealed something incredibly important. The US Government has no problem with seizing your private keys . It claims the right to impersonate you without your permission. It no longer matters which system you use, Sovereign Keys, PGP web-of-trust, traditional PKI, they're all the same. Services based in the US can be MITM'd without leaving any traces. If this is allowed to continue uncontested there will…

Ok, let's keep this in perspective. The problem here is Lavabit was specifically designed to disallow lawful intercepts of individuals. Targeting individuals is absolutely the right way to go about a lawful intercept. Sucking up all traffic like the NSA has been doing is totally overbroad and invasive. But the whole point of the asymmetric encryption feature of Lavabit was to make it impossible for anyone but the acc…

abalone : "The problem here is Lavabit was specifically designed to disallow lawful intercepts of individuals ... And this is why the government resorted to threatening to seize the keys and trying to impersonate the service."

Some of us reject your implication that the government is always entitled to the comms, regardless of harms imposed on innocent parties. Forcibly seizing the means of impersonating someone online, while preventing that person from revealing the fact, is a step too far. It is an injustice against the person impersonated, and wrongly deprives him of reputational integrity, and wrongly deprives others of the value of the service for which they contracted in good faith.

Statements like yours attempt to depict the combination of seizing private keys + gag orders as a minor invasion, acceptable in certain cases. In fact it amounts to removal of the basic human right of communicating privately - and as brian_cloutier points out, removes the whole basis of trust online. If the policy is allowed to continue, it removes the ability of cryptography to give an assurance of the identity of any entity online.

It is better for a few criminals to go free, if necessary, to preserve more important values (and the government can probably find evidence by other means in most of those cases anyway, and if not, too bad).

Post reply on HN