Live data from Hacker News

Lavabit SSL Cert Revoked

lavabit.com

241–250 of 321 posts

Re: Lavabit SSL Cert Revoked

#241
post #114

Earlier quoted context omitted.

As long as the engineers who design and build the internet care, we can do ok. If the protocols that run the web are so easily compromised, it raises all kinds of problems with the underlying, somewhat invisible, functions to how the world works. That manifests itself as a liability to for-profit corporations. It also is something that the cat pictures people care about -- how many of them want their webcams capturin…

> As long as the engineers who design and build the internet care, we can do ok. If the engineers who designed and built the internet cared about privacy, internet protocols wouldn't completely ignore privacy. They designed a massive routed network that involves packet forwarding between random untrusted nodes and then built a bunch of plain-text protocols on top (SMTP, HTTP, etc). > how many of them want their webca…

I often agree with you, but the statement that the Internet founders didn't care about privacy is factually incorrect: Vint Cerf (as mentioned by the sibling comment) is on record as not only being in favor of privacy but wishing the technology had existed for practical cryptographically secure authentication at the protocol level at the time the Internet was designed.

Re: Lavabit SSL Cert Revoked

#242
post #43

Earlier quoted context omitted.

Today the owner, Ladar Levison, had to hand over the SSL certificates by court order. It marks the ending of a long battle in court, with unfortunately it ending in the govenment's favor. I'm assuming the post is just a hacker way of acknowledging the event. Related article: http://www.newyorker.com/online/blogs/elements/2013/10/how-l...

Interesting link, and much more informative than the other Lavabit news articles. It's a shame the government didn't work with Levison to either allow Levison to add the requested intercept himself (which, yes, would have required Uncle Sam to trust him) or to allow a third-party (or even a third party requested from both sides) to audit the proposed interception code. The judge is correct in stating that if Levison…

> The judge is correct in stating that if Levison doesn't trust the government, then why should the government trust Levison, but Levison is clearly correct when he notes that giving up his SSL private keys would destroy the security of his whole infrastructure.

This doesn't make any sense -- it's not symmetrical. The gov't should trust Levison they same reason we trust anyone that testifies in court. The power of the criminal justice system punishes those that are caught lying. Mr Levison has no recourse if the Gov't lies to him. He has a very strong incentive to carry out the modifications that they ask for to avoid fines and jail time if he lies about them. I'm sure they'd tack on "aid and abet" if he covered up any evidence.

Re: Lavabit SSL Cert Revoked

#243
post #149

Earlier quoted context omitted.

Ok, let's keep this in perspective. The problem here is Lavabit was specifically designed to disallow lawful intercepts of individuals. Targeting individuals is absolutely the right way to go about a lawful intercept. Sucking up all traffic like the NSA has been doing is totally overbroad and invasive. But the whole point of the asymmetric encryption feature of Lavabit was to make it impossible for anyone but the acc…

I disagree with the premise. I don't believe that a service should be required by law to provide the possibility for the government to intercept the activity of its users. You can always say "but the child pornographers!" or, "but the terrorists!"... but... no, sorry. I believe that people should have the ability to engage in total privacy. The fact that the US gov't is doing this because of Snowden (a person I admir…

The constitution of the US only guarantees freedom from unreasonable search. Reasonable search is absolutely authorized.

Re: Lavabit SSL Cert Revoked

#244
post #107
post #43

Earlier quoted context omitted.

Interesting link, and much more informative than the other Lavabit news articles. It's a shame the government didn't work with Levison to either allow Levison to add the requested intercept himself (which, yes, would have required Uncle Sam to trust him) or to allow a third-party (or even a third party requested from both sides) to audit the proposed interception code. The judge is correct in stating that if Levison…

no. no. no. the judge's trust talk was a falacy time waster. - give me your bank password so i can get the $5 you own me. - why dont i give you a check for $5? - so i have to trust your check is good but you cant trust me with your bank password? see? it is just crazy talk to push him around. the judge knows here his/her obedience rests. he is not even listening to the defense.

That and the whole power imbalance. He has no recourse if the gov't lies to him, but if he lies or covers up evidence he will be ground beneath the wheels of justice.

Re: Lavabit SSL Cert Revoked

#245

Earlier quoted context omitted.

That is a reasonable response. I would counter by saying that I see that as a justification for why they [government, ISP, whoever] should be allowed make demands about the use of the physical commons, but isn't a reason why they should exercise this conceded right. For example: I, a hypothetical bar owner, have a right to ban silly hats in my bar. Why? Because I own it. However that's not a reason that I should ban…

It's that last point that's so strong: "Yes, yes, you have the right not be subjected to unreasonable search and seizure, but not if you're walking on the public sidewalk." The key here is that the government is not like a private land owner. That's why government workers have so much leeway in criticizing their employers, and why you're allowed to protest on government land, and why schools can't have daily prayers…

Yes, I agree.

A hypothetical bar owner could get away with banning silly hats. We can defend that with assertions about ownership of property and the privileges that gives somebody... that isn't particularly problematic within reason. Governments though? They need to play by a different, stricter, set of rules. "Ownership of infrastructure" should not be accepted as a defense of a government banning silly hats on their sidewalks.

Governments operate in a privileged space where they are permitted to do many things that individuals and companies are not allowed to do (as a quick example, they can levying taxes against the general population). That has to come at a cost though; they aren't allowed to do things that individuals and companies are permitted to do (as a quick US-centric example, they cannot endorse and support a particular religion).

For this reason, comparisons and analogies between what governments and individuals/companies can do are very frequently worthless at best. These sort of comparisons are just unavoidably apples and oranges.

Re: Lavabit SSL Cert Revoked

#246

Lavabit has revealed something incredibly important. The US Government has no problem with seizing your private keys . It claims the right to impersonate you without your permission. It no longer matters which system you use, Sovereign Keys, PGP web-of-trust, traditional PKI, they're all the same. Services based in the US can be MITM'd without leaving any traces. If this is allowed to continue uncontested there will…

Ok, let's keep this in perspective. The problem here is Lavabit was specifically designed to disallow lawful intercepts of individuals. Targeting individuals is absolutely the right way to go about a lawful intercept. Sucking up all traffic like the NSA has been doing is totally overbroad and invasive. But the whole point of the asymmetric encryption feature of Lavabit was to make it impossible for anyone but the acc…

Everybody in this entire debate is just talking past each other.

On the pro-government side, the position is something like "We have such a thing as a lawful search warrant, and if you get one you have to comply."

Meanwhile on the crypto-anarchist side, the position is something like "We can design a crypto-system that is indifferent to your lawful warrants."

But these are really two different arguments, that proceed as follows: the anarchists say "Because X is possible, therefore it should be legal", meanwhile the pro-governmentals say "Because X is required by law, therefore people should do it." But neither of these necessarily follow.

Re: Lavabit SSL Cert Revoked

#247
post #143

So I wonder, if he has been banned from revealing that he has handed over the key, does revoking it count as such a revelation? At this point, the authorities have Streisand'ed their own case - anybody they were interested in would have stopped using Lavabit months ago. So they seem to be pursuing it out of pure belligerence at this point.

which isn't all that surprising. The feds act like spoiled children when they don't get their way.

Re: Lavabit SSL Cert Revoked

#248

Lavabit has revealed something incredibly important. The US Government has no problem with seizing your private keys . It claims the right to impersonate you without your permission. It no longer matters which system you use, Sovereign Keys, PGP web-of-trust, traditional PKI, they're all the same. Services based in the US can be MITM'd without leaving any traces. If this is allowed to continue uncontested there will…

Ok, let's keep this in perspective. The problem here is Lavabit was specifically designed to disallow lawful intercepts of individuals. Targeting individuals is absolutely the right way to go about a lawful intercept. Sucking up all traffic like the NSA has been doing is totally overbroad and invasive. But the whole point of the asymmetric encryption feature of Lavabit was to make it impossible for anyone but the acc…

> The problem here is Lavabit was specifically designed to disallow lawful intercepts of individuals.

The problem is that computer-mediated communication systems are not able to distinguish between lawful intercepts and unlawful intercepts and thus their security against unlawful intercept is premised on being able to guard against all types of interception, lawful or otherwise.

Re: Lavabit SSL Cert Revoked

#249
post #43

Earlier quoted context omitted.

Today the owner, Ladar Levison, had to hand over the SSL certificates by court order. It marks the ending of a long battle in court, with unfortunately it ending in the govenment's favor. I'm assuming the post is just a hacker way of acknowledging the event. Related article: http://www.newyorker.com/online/blogs/elements/2013/10/how-l...

Interesting link, and much more informative than the other Lavabit news articles. It's a shame the government didn't work with Levison to either allow Levison to add the requested intercept himself (which, yes, would have required Uncle Sam to trust him) or to allow a third-party (or even a third party requested from both sides) to audit the proposed interception code. The judge is correct in stating that if Levison…

> It's a shame the government didn't work with Levison to either allow Levison to add the requested intercept himself (which, yes, would have required Uncle Sam to trust him) or to allow a third-party (or even a third party requested from both sides) to audit the proposed interception code.

They did. See the unsealed orders (http://cryptome.org/2013/10/lavabit-orders.pdf) The original order from 6/10 only compelled the production of a bunch of metadata from a single specific, named account (see page 4 of the PDF).

There was then an order to compel (basically: "We mean it, don't yank our chain") on 6/28 because earlier that day, FBI agents met with him (according to a later motion) and, quote, "Mr Levison told the agents that he would not comply with the pen register order and wanted to speak to an attorney."

After that order was issued, the FBI claims it "made numerous attempts, without success to speak and meet directly with Mr. Levison to discuss the pen register order and his failure to provide [the specific data requested in the original subpoena]."

It wasn't until 7/9, a month after the original order was served, that they then demanded the production of his SSL keys.

Re: Lavabit SSL Cert Revoked

#250

Earlier quoted context omitted.

> Does asking for a site's private SSL key sound like a reasonable search? Considering that was far from the first thing they asked for, no. Were their goals reasonable? Yes. Was Levison trying to cooperate? No.

> Was Levison trying to cooperate? No. You sound astounded that someone on the receiving side of legal action is trying not to cooperate. Next you'll be stating that him hiring a lawyer is proof of non-cooperation and evidence of guilt. If you got to do overbroad things every time a defendant was "non-cooperative" it would apply to every single court case.

See my comment here[1]. While I'm not normally a government apologist, from the unsealed court documents, it appears that they did everything by the book here. The original order was for metadata related to a single, specific named account. There were several follow up orders and court proceedings before the request was broadened to turn over the SSL keys.

I'd claim that not producing evidence in response to a lawful subpoena and court order is proof that he's guilty of contempt of court[2].

[1] https://news.ycombinator.com/item?id=6519732

[2] There are lawful ways to resist such an orders - you file a motion to oppose in the case. While I don't have access to PACER to confirm that no such motion was filed, the judge's orders have no mention of such a motion in the established facts.

Post reply on HN