Live data from Hacker News

Lavabit SSL Cert Revoked

lavabit.com

291–300 of 321 posts

Re: Lavabit SSL Cert Revoked

#291
post #149

Earlier quoted context omitted.

I disagree with the premise. I don't believe that a service should be required by law to provide the possibility for the government to intercept the activity of its users. You can always say "but the child pornographers!" or, "but the terrorists!"... but... no, sorry. I believe that people should have the ability to engage in total privacy. The fact that the US gov't is doing this because of Snowden (a person I admir…

> I believe that people should have the ability to engage total privacy. They already have the ability to do this. That's not what you are asking for. What you are really asking for is: "I believe that people should have the ability to engage total privacy through any means of communication they so choose."

So according to you, if people can still communicate secretly by meeting in person and whispering in a forest or such, then it's no impairment of their rights to destroy their ability to do the equivalent with electronics.

Kinda like Bush's "free speech zones", where protesters are kept in a little cage far from the public to whom they would like to express their opinions - as long as they're free to speak in this one little place, they're not totally silenced and there is no invasion of their rights, according to the clever lawyers.

The right of communicating confidentially with persons of one's choice, and not with others, is a robust right which is not to be reduced to a formality.

The fascist mentality is strong in the US right now, but citizens are going to work around the police state until it's reformed or overthrown, and they are on the right side of history.

Re: Lavabit SSL Cert Revoked

#292

Earlier quoted context omitted.

Yes, I think it's OK. The problem here is that Levison set up a Rube Goldberg machine. If the (in my opinion reasonable) law says you have to be able to provide access to anyone's data when you are given a warrant, you can't get out of that requirement by making your technology require you give everyone else's data, or kill a kitten, or any other requirement. Edit: Changed 'levinson', UK report about the media, to 'l…

Like I've said elsewhere in the thread - what about Tarsnap? Tarsnap is also - arguably - designed in much the same way. What do you think Colin's response ought to be if the FBI/NSA come to him saying "we think one of your users might be doing $bad_thing, so we want your private keys so we can impersonate you, decrypt anything any of your users have backed up using tarsnap, and undermine the very basis of the busine…

From my reading of the court details (which might differ from yours), lavamail was not trying to make it easy for a particular user's data to be accessed. I have no problem with Lavamail, or Colin, providing access to a single user's data, if they have the ability to do that in a reasonable way.

The problem is that there seem to be two extreme worlds we could end up reaching.

1) The security forces can access all data, anywhere, anytime, freely and without limit.

2) The security forces can access no data at all, and become useless.

Both of these are a bad situation to end up in, but I would consider the second worse. Hopefully we can end up with a more sensible world, where the police can access data with a warrant and the proper authority.

While there are some current big cases, and big problems, it is important to remember there are large numbers of lower level people in the security forces, solving real crimes every day. They must not become over-powerful, or hobbled, by a few high profile cases.

Re: Lavabit SSL Cert Revoked

#293
post #149

Earlier quoted context omitted.

I disagree with the premise. I don't believe that a service should be required by law to provide the possibility for the government to intercept the activity of its users. You can always say "but the child pornographers!" or, "but the terrorists!"... but... no, sorry. I believe that people should have the ability to engage in total privacy. The fact that the US gov't is doing this because of Snowden (a person I admir…

> I believe that people should have the ability to engage total privacy. They already have the ability to do this. That's not what you are asking for. What you are really asking for is: "I believe that people should have the ability to engage total privacy through any means of communication they so choose."

> What you are really asking for is: "I believe that people should have the ability to engage total privacy through any means of communication they so choose."

No. What he's really asking for is "I believe that people should have the ability to engage total privacy on the main means of communication of our age."

I agree, up to a point. Remember that lavabit had already complied with targeted access requests. He objected to the rooting of his service to enable a mass surveillance dragnet. Are you Ok with that specifically?

Re: Lavabit SSL Cert Revoked

#294
post #161
post #32

Earlier quoted context omitted.

FWIW, just now I went looking for a firefox plugin that reports (in a human-friendly way) whether or not the SSL connection for a page is using perfect forward secrecy (PFS). I found "Calomel SSL Validation," which I am about to install. The PFS reporting only works with Firefox 25 and up. https://addons.mozilla.org/en-US/firefox/addon/calomel-ssl-v...

Also the Netcraft Extension gives you this information: http://news.netcraft.com/archives/2013/09/06/perfect-forward...

Sadly it comes with an awful toolbar.

Re: Lavabit SSL Cert Revoked

#295

Earlier quoted context omitted.

I often agree with you, but the statement that the Internet founders didn't care about privacy is factually incorrect: Vint Cerf (as mentioned by the sibling comment) is on record as not only being in favor of privacy but wishing the technology had existed for practical cryptographically secure authentication at the protocol level at the time the Internet was designed.

I know he's in favor of it now, but was it something he was thinking of when he designed these protocols?

Had the original TCP/IP protocols as they were designed included cryptographic security, the designers of those protocols would themselves have had to be be pioneers of cryptography. This is a little like asking why Henry Ford didn't just start with the electric car. I mean, sure, there was electricity when he started...

Re: Lavabit SSL Cert Revoked

#296

Lavabit has revealed something incredibly important. The US Government has no problem with seizing your private keys . It claims the right to impersonate you without your permission. It no longer matters which system you use, Sovereign Keys, PGP web-of-trust, traditional PKI, they're all the same. Services based in the US can be MITM'd without leaving any traces. If this is allowed to continue uncontested there will…

Ok, let's keep this in perspective. The problem here is Lavabit was specifically designed to disallow lawful intercepts of individuals. Targeting individuals is absolutely the right way to go about a lawful intercept. Sucking up all traffic like the NSA has been doing is totally overbroad and invasive. But the whole point of the asymmetric encryption feature of Lavabit was to make it impossible for anyone but the acc…

The premise is incorrect. Lavabit had provided data for lawful intercepts in the past. The government continued to press for unfettered access to all of Lavabit's data which then forced the shutdown.

Lavabit offered to develop a more involved solution for the government in order to prevent unfettered access to all of their customer's data. The court's assertion that the government could trust Lavabit because Lavabit didn't trust the government is both childish and assinine.

Source: same article as parent post.

Re: Lavabit SSL Cert Revoked

#298

Lavabit has revealed something incredibly important. The US Government has no problem with seizing your private keys . It claims the right to impersonate you without your permission. It no longer matters which system you use, Sovereign Keys, PGP web-of-trust, traditional PKI, they're all the same. Services based in the US can be MITM'd without leaving any traces. If this is allowed to continue uncontested there will…

Ok, let's keep this in perspective. The problem here is Lavabit was specifically designed to disallow lawful intercepts of individuals. Targeting individuals is absolutely the right way to go about a lawful intercept. Sucking up all traffic like the NSA has been doing is totally overbroad and invasive. But the whole point of the asymmetric encryption feature of Lavabit was to make it impossible for anyone but the acc…

Did you mean UNLAWFUL intercepts of individuals? There are no lawful intercepts between two private parties.

Do you get to hear everything about a deal between two big corporations other than the stuff released in the press?

Go to a retail store and ask for information about an employer. They don't give out any information (unless there is a probable cause of course).

The only time government can intervene is when a 3rd party is hurt by someone. In this case it's their own fault for snooping around and reading everyone's private conversations and some of there were used for stalking hot girls! and now they're acting like kids trying to force lavabit by threatening the owner.

Re: Lavabit SSL Cert Revoked

#299

Earlier quoted context omitted.

I explained exactly why wasn't going to answer your question in my response. "That's a loaded question and I'm not going to play that game" I picked the words carefully and precisely. http://en.wikipedia.org/wiki/Loaded_question > you should consider the possibility that your comment is not nearly as clear as you seem to think. I realize that people might not be native english speakers. I make the assumption people w…

I am sensing a lot of continued hostility here. I am not sure why, since we apparently do not disagree, and since I have made it clear that I did not have any malicious intent. > I make the assumption people will ask if they are unsure or not clear. You have misunderstood me. I did not find your comment to be unclear after reading it. However my take-away from your comment was incorrect. Complaining about a loaded qu…

> I am sensing a lot of continued hostility here.

There is zero in my last comment. Maybe you could highlight what statement I made that was in any way hostile. I was precise, polite, and stated clearly my position. The only one being hostile is you.

> I am not sure why, since we apparently do not disagree

What makes you think that?

> instead of simply and civilly correcting me ("I don't think that")

Why do you keep making assumptions? Why do you keep trying to assert my position, despite me never saying "I don't think that." Heck, putting it in quotes is dangerous enough.

> "conversation killer"

Your continued attempts to put words in my mouth is a conversation killer, even if you don't intend to do it.

Your problem is that from the first reply, you've been trying to read more into what I said. You've been trying to categorize me. Rather than simply take the comment I said at face value, you've been trying to see some inner motive. This is clear from your loaded question, or your belief that I'm trying to dodge a question. Even now you continue to try to pin me down into a belief that I find beside the point, would have derailed the original conversation.

> I hope this clears up any lingering confusion.

I'm not confused with what I've said. And, frankly, I've stated it clearly from the first comment. That you've inferred more every step of the way is simply because you are confused.

I honestly don't think whatever I type here will matter though, as despite being factual, precise, and concise in my previous comments, people have found ways to ignore the facts, infer whatever they wanted, and consider the brevity to be something more.

It would be far easier if we read what was written, and stopped trying to imagine more.

Re: Lavabit SSL Cert Revoked

#300
post #159
post #107

Earlier quoted context omitted.

no. no. no. the judge's trust talk was a falacy time waster. - give me your bank password so i can get the $5 you own me. - why dont i give you a check for $5? - so i have to trust your check is good but you cant trust me with your bank password? see? it is just crazy talk to push him around. the judge knows here his/her obedience rests. he is not even listening to the defense.

What if it was more like - You owe me $25 - I only keep my money in bitcoin - Well, I don't do that bitcoin thing, and I don't really want to set a whole thing just to transfer the money - OK, I could get it for you in cash, but you'll have to give me a few days ...a few days later - Uhh...so about that money - Oh, haven't gotten around to transferring that - OK, but I could use it. Or, I could borrow your phone and…

[deleted]
Post reply on HN