Live data from Hacker News

How Lavabit Melted Down

newyorker.com

171–177 of 177 posts

Re: How Lavabit Melted Down

#171

> While he opposes the bulk collection of domestic communications, he has no such strong feelings about the N.S.A.’s foreign-surveillance efforts. As a non-American, I have a problem with this seemingly widespread idea even among privacy advocates in the USA that only Americans are entitled to the protection of their rights from the American government.

It's not a "widespread idea"... it's the legal reality. As a non-American, you do not share the rights of US citizens under the constitution. Period. They are the only people entitled to the protection of their rights from the American government, unless your country has signed some sort of treaty with the US government giving you extended rights from the US, which I doubt it has. Without such an agreement, this is n…

No, it is a widespread and very dangerous misconception. Rights as conceived at the time of the drafting of the US Constitution are not granted but rather inherent. The Bill of Rights enumerated rights the founders believed all people had. It was a list but not meant to be complete. In fact one strong argument against enumerating them at all was that people would come to believe the list was complete or that it somehow granted the enumerated rights.

The religious ones thought these rights came from God but in any case most all agreed these are "Natural Rights" that you have because you are a human being. Such rights can only be violated by governments. They cannot be granted or taken away.

This attitude that rights only adhere to citizens of the US, common among united statesians, is a pathetic indicator of the level of indoctrination. It's also morally and philosophically appalling. It's the same attitude that allows united statesians to support bombing brown people on the other side of the world for whatever reasons their leaders give them.

Re: How Lavabit Melted Down

#172
post #170

Earlier quoted context omitted.

Sure, but we have key servers for distributing the actual keys. You would only need the fingerprint in the QR code.

Kind of defeats the point - how do you know you're downloading the private key you scanned? While someone might have their business cards replaced, it's a lot easier just to send a different key to someone.

I thought a QR code could be effectively any size - I certainly remember a Japanese billboard that used shadows etc.

A QR code can have ~4000 chars of a-z and ~3000 Latin1 iirc

so with my limited gpg knowledge that handles my public key quite happily.

would be interested on the business card front though

Re: How Lavabit Melted Down

#173
post #170

Earlier quoted context omitted.

Sure, but we have key servers for distributing the actual keys. You would only need the fingerprint in the QR code.

Kind of defeats the point - how do you know you're downloading the private key you scanned? While someone might have their business cards replaced, it's a lot easier just to send a different key to someone.

"Kind of defeats the point - how do you know you're downloading the private key you scanned?"

Assuming that "private key" is a typo (you download public keys), you can just check the fingerprint of the key against the fingerprint you were given. That is easily automated.

Re: How Lavabit Melted Down

#174
post #163

Earlier quoted context omitted.

>>> This is a strawman, because Lavabit never did anything to protect headers. Since SSL keys are mentioned, I assume SSL was used in communication. This means the claim that Lavabit did nothing to protect headers is false. >>> Except that with Lavabit, an attacker could also get all your message bodies. This is true, however body of the message may contain encrypted information, which is useless to observer. Envelop…

"Since SSL keys are mentioned, I assume SSL was used in communication. This means the claim that Lavabit did nothing to protect headers is false." That is like saying that GMail is protecting the privacy of your headers, because GMail uses SSL. "This is true, however body of the message may contain encrypted information, which is useless to observer" Except that in the case of Lavabit, that encryption was just a side…

>>> That is like saying that GMail is protecting the privacy of your headers, because GMail uses SSL.

It does. Unlike Lavabit, though, there is ample reason to assume they invalidate this protection by granting governmental adversaries access to the information stored on their servers - the thing that Lavabit refused to do, at least on mass scale.

>>> since all the cryptographic operations were performed on the server.

I don't see what precludes you from sending emails already encrypted. Security has layers. You are not limited to using just one.

>>> leaves the server unable to fulfill demands for plaintexts.

You forgot to read the part of my answer where I use the word "envelope".

>>> Really, you think I am not using email anymore if I am running my own personal mail server?

It is irrelevant what you personally are doing - it is relevant what Lavabit was trying to do. They were trying to provide certain service - for people that - like, I assume, most of Guardian journalists - are not technically advanced enough to run a secure mail server on their personal computer and set up everything else in a way that allows it to accept email from the internet. This proved impossible, thus Lavabit is not with us anymore. That was my whole point.

>>> Ladar could have sold smartcards instead of selling cryptography as a service.

He could also have sold hotdogs and Carribean timeshares, how that's related to the topic? He was trying to create a secure email as a service - for those that can not create the same by themselves, which in 99.999% of the population of email users. Not provide solution for completely different problem such as key exchange and creating VPNs and other stuff.

Re: How Lavabit Melted Down

#175
post #170

Earlier quoted context omitted.

Kind of defeats the point - how do you know you're downloading the private key you scanned? While someone might have their business cards replaced, it's a lot easier just to send a different key to someone.

"Kind of defeats the point - how do you know you're downloading the private key you scanned?" Assuming that "private key" is a typo (you download public keys), you can just check the fingerprint of the key against the fingerprint you were given. That is easily automated.

This puts us back in the same kind of problem that was being complained about though - keyservers, publishing keys etc.

Re: How Lavabit Melted Down

#176
post #175

Earlier quoted context omitted.

"Kind of defeats the point - how do you know you're downloading the private key you scanned?" Assuming that "private key" is a typo (you download public keys), you can just check the fingerprint of the key against the fingerprint you were given. That is easily automated.

This puts us back in the same kind of problem that was being complained about though - keyservers, publishing keys etc.

Not really. The problem is not about publishing keys or key servers, but with the cumbersome process of having to enter a hexadecimal string (and having to check an even longer string). The point of using QR codes is to simplify things: the user just scans a QR code, and the key is fetched and assumed to be valid (i.e. no need for the user to check fingerprints).

Re: How Lavabit Melted Down

#177

Earlier quoted context omitted.

It's not a "widespread idea"... it's the legal reality. As a non-American, you do not share the rights of US citizens under the constitution. Period. They are the only people entitled to the protection of their rights from the American government, unless your country has signed some sort of treaty with the US government giving you extended rights from the US, which I doubt it has. Without such an agreement, this is n…

Well that's nice; I'm glad to see that our common interests as HN users extends only to the US border. Widespread unchecked surveillance is evil in and of itself, it doesn't matter _who_ is doing the surveilling. Following your argument, if the Chinese government engaged in exactly the same sort of surveillance against you that the NSA does, you'd be fine with it, since it would merely be international espionage. But…

Firstly, I'm not from the US. Nextly, yes. Yes, I would be ok with the Chinese government spying on me, if they were able to.

In the case of the NSA, the NSA coerced/worked with many private US companies and took the data from them (rather than somehow collecting the data themselves). Such coercion of American companies is what I believe should be curtailed.

The thing is, China has no such reach in my life. I don't use any Chinese websites to store my data. I don't use any Chinese social networks to keep up with my friends. I don't use a Chinese email service.

Post reply on HN