Live data from Hacker News

CertiVox confirms it withdrew PrivateSky after GCHQ issued warrant

itsecurityguru.org

41–50 of 86 posts

Re: CertiVox confirms it withdrew PrivateSky after GCHQ issued warrant

#41
post #7

Earlier quoted context omitted.

The article also mentions this company's new product where additional security is possible because decryption requires data kept only by the customer. Perhaps that is the new way to go?

I was wondering about that, it is described as: "where rather than hold the data, it is split in two so CertiVox has one half and the user has the other, and law enforcement would need both to access the data." By data here, do they mean encryption key? If so then I'm not sure what splitting it in two does as you presumably have to join them together somewhere and GCHQ would presumably just attack wherever the comple…

Defining some terms: Alice, Bob, the company, and GCHQ (Eve).

Alice sends Bob stuff, via the company.

GCHQ sends RIPA requests to the company, which means that GCHQ get Alice's communications. Neither Alice nor Bob are aware.

So, a new scheme where Alice and the company need keys to decrypt means that GCHQ send RIPA requests to the company, and to Alice. Now Alice, and the company, are aware of the RIPA request. Bob isn't. But at least Alice can stop sending things to Bob.

Re: CertiVox confirms it withdrew PrivateSky after GCHQ issued warrant

#42

Earlier quoted context omitted.

> They weren't forced to close down per se... That's the crux of the issue. They weren't forced to close down, they chose to. End of discussion. EDIT: Actually, why don't we see what the CEO of CertiVox has to say on the matter? "The headline strongly infers our friends at GCHQ “forced” us to take PrivateSky down. That’s hogwash." Source: https://news.ycombinator.com/item?id=6894316

End of discussion? No, sir, it is not! Your interpretation is extremely naïve. I could hold a gun to your head, for example. You wouldn't be forced per se to meet my demands, but you probably would because it would be extremely unreasonable not to. In the same way, the consequences for not complying are: an extremely expensive and possibly unaffordable rewrite, going to jail for a few years, or giving up their custom…

Why is it extremely unreasonable to not comply when there is a gun at your head but not in this case?

Re: CertiVox confirms it withdrew PrivateSky after GCHQ issued warrant

#43
post #42

Earlier quoted context omitted.

End of discussion? No, sir, it is not! Your interpretation is extremely naïve. I could hold a gun to your head, for example. You wouldn't be forced per se to meet my demands, but you probably would because it would be extremely unreasonable not to. In the same way, the consequences for not complying are: an extremely expensive and possibly unaffordable rewrite, going to jail for a few years, or giving up their custom…

Why is it extremely unreasonable to not comply when there is a gun at your head but not in this case?

I think you've misread what I wrote.

Re: CertiVox confirms it withdrew PrivateSky after GCHQ issued warrant

#44
post #3

Wow, shows a lot of integrity closing the product instead of still keeping it up in a compromised state to comply with the warrant. We've seen some other providers here in the US even changed functionality to retain keys used in web clients of secure email at the behest of government orders. This does mean that the UK is now on the list, along with the US, of places where no credible crypto startup is possible, thoug…

> This does mean that the UK is now on the list, along with the US, of places where no credible crypto startup is possible, though.

I can think of very few developed countries that, when the rubber hits the road, will let you do what you want. Taking measures to aid official police or court investigations is simply an implied obligation in most countries with developed legal systems. Very few countries will tolerate service providers whose raison d'etre is "we won't cooperate with the authorities" except in limited situations like off-shore banking when the primary purpose is to hide assets or information from people in other countries.

This isn't specific to crypto or police investigations either. Say you want to start an accounting firm that guarantees it will never share your records if subpoenaed in a civil lawsuit. This would never fly in the U.S., not now or one hundred years ago, and while I'm not super familiar with European law, I can't imagine it would fly in any western European country either.

Re: CertiVox confirms it withdrew PrivateSky after GCHQ issued warrant

#45
post #36

Earlier quoted context omitted.

> They weren't forced to close down per se... That's the crux of the issue. They weren't forced to close down, they chose to. End of discussion. EDIT: Actually, why don't we see what the CEO of CertiVox has to say on the matter? "The headline strongly infers our friends at GCHQ “forced” us to take PrivateSky down. That’s hogwash." Source: https://news.ycombinator.com/item?id=6894316

So if I put a gun to your head, and you give me money, you haven't been forced to, right? Are you PG? No? Then who are you to decide when a discussion ends round here?

> So if I put a gun to your head, and you give me money, you haven't been forced to, right?

Wrong. I HAVE been forced. You have threatened me with death if I don't comply with your demand.

GCHQ never demanded that CertiVox shut down their service. They (or, rather, the Home Secretary) demanded that they hand over the key(s) required to decrypt one (or more) of CertiVox's customer's data.

If CertiVox took it upon themselves to then shut down the PrivateSky service, that is their choice. But it is a lie to claim that GCHQ forced them to.

CertiVox could claim that they "felt they had no option but to shut down the service" or that they "could no longer, in all conscience, continue to offer and market a service that" blah blah blah but, the fact is that they always knew that PrivateSky was vulnerable to section 49 notices.

RIPA's been on the statute books for over a decade and section 49 has been in force since 2007. CertiVox launched PrivateSky in 2011, which means that they either built a service that they knew was vulnerable to RIPA disclosure requirements or they didn't know about RIPA. I don't believe that they didn't know about RIPA.

It doesn't matter what special snowflake rationale you come up with about what's reasonable or unreasonable. The simple fact of the matter is that the headline is misleading. GCHQ did not force PrivateSky to shut down.

EDIT: Even the CEO of CertiVox refutes the claim that GCHQ forced the closure of PrivateSky!

"The headline strongly infers our friends at GCHQ “forced” us to take PrivateSky down. That’s hogwash."

Source: https://news.ycombinator.com/item?id=6894316

Re: CertiVox confirms it withdrew PrivateSky after GCHQ issued warrant

#46

Earlier quoted context omitted.

> They weren't forced to close down per se... That's the crux of the issue. They weren't forced to close down, they chose to. End of discussion. EDIT: Actually, why don't we see what the CEO of CertiVox has to say on the matter? "The headline strongly infers our friends at GCHQ “forced” us to take PrivateSky down. That’s hogwash." Source: https://news.ycombinator.com/item?id=6894316

End of discussion? No, sir, it is not! Your interpretation is extremely naïve. I could hold a gun to your head, for example. You wouldn't be forced per se to meet my demands, but you probably would because it would be extremely unreasonable not to. In the same way, the consequences for not complying are: an extremely expensive and possibly unaffordable rewrite, going to jail for a few years, or giving up their custom…

> I could hold a gun to your head, for example. You wouldn't be forced per se to meet my demands, but you probably would because it would be extremely unreasonable not to.

GCHQ never demanded that CertiVox shut down their service. That is the bottom line and, no matter what sort of ridiculous "gun against your head" rationale you come up with or how firmly you plug your ears while shouting "LALALA!" at the top of your voice; you cannot refute that fact.

EDIT: Actually, why don't we see what the CEO of CertiVox has to say on the matter?

"The headline strongly infers our friends at GCHQ “forced” us to take PrivateSky down. That’s hogwash."

Source: https://news.ycombinator.com/item?id=6894316

Re: CertiVox confirms it withdrew PrivateSky after GCHQ issued warrant

#47
post #29

Earlier quoted context omitted.

And after a Tory-led government came to power...

What's that got to do with it? (genuinely interested).

I think it's ironic that those who are in favour of personal liberties are often on the left of the political spectrum whereas, in this instance, it was the Tories who rolled back aspects of surveillance legislation that was introduced by Labour.

Re: CertiVox confirms it withdrew PrivateSky after GCHQ issued warrant

#48

Earlier quoted context omitted.

End of discussion? No, sir, it is not! Your interpretation is extremely naïve. I could hold a gun to your head, for example. You wouldn't be forced per se to meet my demands, but you probably would because it would be extremely unreasonable not to. In the same way, the consequences for not complying are: an extremely expensive and possibly unaffordable rewrite, going to jail for a few years, or giving up their custom…

> I could hold a gun to your head, for example. You wouldn't be forced per se to meet my demands, but you probably would because it would be extremely unreasonable not to. GCHQ never demanded that CertiVox shut down their service. That is the bottom line and, no matter what sort of ridiculous "gun against your head" rationale you come up with or how firmly you plug your ears while shouting "LALALA!" at the top of you…

I think you should direct your fingers-in-ears comment towards yourself. In any event, I can't make a further argument without being repetitive.

Re: CertiVox confirms it withdrew PrivateSky after GCHQ issued warrant

#49

Earlier quoted context omitted.

> They weren't forced to close down per se... That's the crux of the issue. They weren't forced to close down, they chose to. End of discussion. EDIT: Actually, why don't we see what the CEO of CertiVox has to say on the matter? "The headline strongly infers our friends at GCHQ “forced” us to take PrivateSky down. That’s hogwash." Source: https://news.ycombinator.com/item?id=6894316

End of discussion? No, sir, it is not! Your interpretation is extremely naïve. I could hold a gun to your head, for example. You wouldn't be forced per se to meet my demands, but you probably would because it would be extremely unreasonable not to. In the same way, the consequences for not complying are: an extremely expensive and possibly unaffordable rewrite, going to jail for a few years, or giving up their custom…

Sounds like these services actually shutting down is a good thing for the end users, since they aren't actually securely designed in the first place! They even admit in the article they'd have to properly design their system to make email unreadable by their staff, and they chose to shutter their service vs trying to figure out how to make that work and still make money.

Re: CertiVox confirms it withdrew PrivateSky after GCHQ issued warrant

#50
post #28
post #4

There are some details of the legislation in question here[1]. It allows the UK to monitor "in the interests of the economic well-being of the United Kingdom" which seems a little broad! It would be interesting to know if this warrant targeted all users or a specific subset? I wonder how they decide whether to issue a warrant or just break into the site in question. A warrant could imply that they are unable to attac…

From https://wiki.openrightsgroup.org/wiki/In_the_interests_of_th... - "The House will notice that the Bill restricts the activities of the SIS and GCHQ for safeguarding the economic well-being of the country to the acts or intentions of persons outside the United Kingdom. The agencies may not and do not get involved in domestic economic, commercial or financial affairs." So it's not quite as broad reaching as it rea…

Also, one can argue that it's a good thing in general that our intelligence and security services' activities are regulated by laws like this (instead of operating in grey areas beyond the law).

And, by the way, activities carried out by the UK's intelligence and security services OUTSIDE the UK are also subject to RIPA.

Post reply on HN