Live data from Hacker News

Lavabit SSL Cert Revoked

lavabit.com

311–320 of 321 posts

Re: Lavabit SSL Cert Revoked

#311
post #291

Earlier quoted context omitted.

> I believe that people should have the ability to engage total privacy. They already have the ability to do this. That's not what you are asking for. What you are really asking for is: "I believe that people should have the ability to engage total privacy through any means of communication they so choose."

So according to you, if people can still communicate secretly by meeting in person and whispering in a forest or such, then it's no impairment of their rights to destroy their ability to do the equivalent with electronics. Kinda like Bush's "free speech zones", where protesters are kept in a little cage far from the public to whom they would like to express their opinions - as long as they're free to speak in this on…

Not equivalent. It's at least possible to tail someone to the forest (private house, etc.) and surveil them, with proper judicial oversight. Not so with systems designed to defeat lawful intercept.

There is no "robust right" to defeat lawful intercept. The right to privacy has always been subject to a body of law governing lawful surveillance and policework. Example: mobsters meeting in a private home can be bugged with a warrant.

Re: Lavabit SSL Cert Revoked

#312

Earlier quoted context omitted.

Listen, I'm not a robot. When I read a post, I read what is literally being said, and I read between the lines; I look for subtext, and implications. I am not going to stop doing tihs. Maybe when you write those things never exist, but I don't believe that. I'm going back with my original assumption, which is that are dodging any attempt to address the subtext and implications in your posts because you want them to g…

> When I read a post, I read what is literally being said, and I read between the lines; I look for subtext, and implications. I am not going to stop doing tihs. But then you need to be prepared to be called out when you are wrong. > which is that are dodging any attempt to address the subtext and implications in your posts because you want them to go unchallenged. Because, honestly, their is no subtext. I don't have…

I'd suggest reading a bit on NVC: http://en.wikipedia.org/wiki/Nonviolent_Communication

The primary problem I see with your comments is a slew of blaming statements. You started this whole thing by SPEAKING FOR SOMEONE ELSE, and it's continued through to this morning with comments like "Any attempt to turn the conversation in any other direction is an attempt by others to push their own agenda." Blaming statements like this shows you are trying to simulate why others MIGHT be intending - instead of just listening to what they are SAYING they intended.

I know you are frustrated about not being heard here, but I don't think it's anyone's fault but your own. It's a choice my friend. A choice.

Re: Lavabit SSL Cert Revoked

#313

Earlier quoted context omitted.

Like I've said elsewhere in the thread - what about Tarsnap? Tarsnap is also - arguably - designed in much the same way. What do you think Colin's response ought to be if the FBI/NSA come to him saying "we think one of your users might be doing $bad_thing, so we want your private keys so we can impersonate you, decrypt anything any of your users have backed up using tarsnap, and undermine the very basis of the busine…

From my reading of the court details (which might differ from yours), lavamail was not trying to make it easy for a particular user's data to be accessed. I have no problem with Lavamail, or Colin, providing access to a single user's data, if they have the ability to do that in a reasonable way. The problem is that there seem to be two extreme worlds we could end up reaching. 1) The security forces can access all dat…

I actually think (1) is the bigger deal and by a significant margin, however...

I do agree with you that there needs to be a reasonable and lawful way to tap very specific and targeted conversations, regardless of the medium. Just like bugging the mafia's phones etc. And by reasonable, I mean a real frikin' judge and with total public transparency, not some secret court and definitely not some blanket surveillance program. Accountability for any abuses is a key requirement that currently seems to be lacking.

I'm practically a conspiracy theorist these days, but I think you're being completely logical while most others aren't.

Re: Lavabit SSL Cert Revoked

#314

Earlier quoted context omitted.

Part of the reason why some people may say your system has flaws but never address is them is that they may not be able to be addressed. Your system looks like it strives to be purely democratic, but pure democracies have inherent flaws such as being open to tyranny by the majority or irrational voter behavior. It is clear that some of your solutions try to mitigate these issues, but there are tradeoffs. For example,…

http://vimeo.com/22531716 ? The reputation bonuses are just that: bonuses. If you contribute in a positive fashion, your reputation would increase as well. Yet all ideas (including those from anyone receiving a "bonus" boost) must still pass the moderation phase. Or perhaps bonuses are a bad idea altogether. I thought that someone who graduated from environmental studies would be able to propose environmental policie…

Thats the correct debate, although you are probably better off just reading their books and deciding for yourself. I think that particular debate session got hung up on a lot of minutiae.

As for the direction of your project, I think as opposed to solving all the problems at once, you may want to construct things piecemeal, while laying out the factual pros and cons of each political "module". For example, using Arrow's Impossibility Theorem, there is no way to create a perfect voting mechanism, so any voting mechanism you put in place will be a traeoff. At one extreme, is unanimous consent, this guarantees everyone is signing off and thus reasonably happy. However, unanimous consent creates a new problem of the holdout position. To balance, voting systems like majority rules limit the holdout problem, but also introduce consent issues like swings in opinion from mob rule and the tyranny of the majority. On the opposite end of the spectrum, you could create an elected dictator that could decide. This would be a trustee style system and while it would limit the above issues, it would introduce principal agent problems. By building these individual modules, you could allow your system to be adapted to many situations and allow for the actors themselves to police the less desirable behaviors (IE they know to watch out for holdouts before the process begins), which would be listed in the cons. A similar decision process could apply to the bonus systems (should education enter into it?), systems for evaluating relevant info in the debate section (types of source material, reputation voting) and so on.

In sum, allow the users to determine how they want to decide and mediate each decision before they enter into the process. A module setup may also help you make more progress on your own and get contributions.

Re: Lavabit SSL Cert Revoked

#315

Earlier quoted context omitted.

> Nobody complains that they can [force?] Public Storage to open storage units with a warrant If they can get a warrant from a court under fair laws, personally I don't mind the government having equivalent powers in the online world. There are people doing bad things online, and I want there to be mechanisms to minimise that. I don't know the specifics of the Lavabit case, but from the NSA revelations, it seems like…

How do you defend yourself against a rogue government? Furthermore, who gets to define when a government becomes rogue? All definitions aside, how do you defend yourself from a large, well-funded organization that's determined to do what ever it wants to you? Fair laws? The fact that someone else decides what's right and wrong means we've already lost.

All of these questions are at least as pressing in the physical world as they are in the online one. So you're asking philosophical questions about the nature of government and the rule of law that I'm not properly qualified to answer.

I think there has to be a socially defined code of what behaviour is allowed and what is not - even without written laws, lynch mobs would enforce some kind of rules. Since people don't all agree on such things, many people will inevitably disagree with parts of that code. The question of how we decide on the code - both the written laws and the social conventions of overlooking some violations of those laws - is difficult. But we can't put society on hold and wait for the philosophers come up with a perfect system.

To take an example which almost everyone here will see from the same perspective: the UK government recently pushed for a form of opt-out web filtering. To HN readers, it was a clear sign of out-of-control government censorship, championed by politicians too out of touch to understand the internet. But plenty of other people were quite happy with the idea of web filtering. You may deride them as 'think of the children' types and media industry lobbyists, but that's how democracy works. You don't get your way just because you say your opponents are stupid. You have to persuade and educate people to get support for your position.

To be clear, I agree that the web filtering plan was a bad idea.

Re: Lavabit SSL Cert Revoked

#316

Earlier quoted context omitted.

I created a kind of micro discussion/decision making system that didn't generate much interest from people I talked to and perhaps shares a flaw with this concept. Basically if you look at what people use text for online it usually isn't anything serious, even these discussions don't have all that much gravity and HN is probably the most serious site I've seen. Text also has less emotion and involvement attached and…

Could you provide a link to your system? I'm curious.

http://www.unbaa.com

Re: Lavabit SSL Cert Revoked

#317
post #291

Earlier quoted context omitted.

So according to you, if people can still communicate secretly by meeting in person and whispering in a forest or such, then it's no impairment of their rights to destroy their ability to do the equivalent with electronics. Kinda like Bush's "free speech zones", where protesters are kept in a little cage far from the public to whom they would like to express their opinions - as long as they're free to speak in this on…

Not equivalent. It's at least possible to tail someone to the forest (private house, etc.) and surveil them, with proper judicial oversight. Not so with systems designed to defeat lawful intercept. There is no "robust right" to defeat lawful intercept. The right to privacy has always been subject to a body of law governing lawful surveillance and policework. Example: mobsters meeting in a private home can be bugged w…

I don't agree that there should be any robust right to "lawful" interception.

Re: Lavabit SSL Cert Revoked

#318

The lavabit case highlights something interesting that we need. We need that not only individuals have privacy, but that businesses have privacy of who their users are. The same way we provide anonymity to users through centralized means, is there not a way to provide a way for service provider to have a sufficient level of opaqueness of who their customers are. You can't subpeona Service Provider A if you don't know…

Customer: I wish to make a complaint. Shopkeeper: Go away. I don't know you. Dead parrot problem solved.

Not exactly the same. The company can know that I am a customer. What I'm talking about is a third party not knowing that I am a customer of the company.

Re: Lavabit SSL Cert Revoked

#319
post #308

Earlier quoted context omitted.

> That's perfectly valid, since those examples were first trotted out prior to that with no argument. Except the burden lies with those wanting to add a right to privacy to the list of rights we have. The right to privacy simply doesn't exist. There is a right against unreasonable search and seizure. But that's hardly a right of total privacy. > If it's so obvious why we should treat those as special cases, it should…

The right to privacy simply doesn't exist. You've posted at least a dozen responses in this thread and it is plain you have no idea what you are talking about in almost every one of them. Are you unfamiliar with the 14th Amendment? http://en.wikipedia.org/wiki/Fourteenth_Amendment_to_the_Uni... the Due Process Clause is also the foundation of a constitutional right to privacy. The Court first ruled that privacy was p…

You're right, but that doesn't make me wrong. Only that we are saying 2 different things. I didn't mean to imply that you have no expectation of privacy, only that privacy as a whole does not exist. For example, in public, I cannot reasonably suggest that my right to privacy trumps your ability to overhear my conversation.

After all, while you elected to quote one sentence, in context, it's clear that I'm making a distinction between a total right to privacy and limits to intrusions into privacy.

"The right to privacy simply doesn't exist. There is a right against unreasonable search and seizure. But that's hardly a right of total privacy"

So, basically what I'm saying is that their is no simple right to privacy. Actually, the text you quote provides a link that explains it better than I obviously did.

http://en.wikipedia.org/wiki/Privacy_laws_of_the_United_Stat...

"Although the word "privacy" is actually never used in the text of the United States Constitution,[20] there are Constitutional limits to the government's intrusion into individuals' right to privacy."

These limits protect aspects of privacy, not privacy itself. And that's an important distinction, especially in this context. If you explicitly had a right to privacy, one could argue that search warrants could never be legal, as your rights to privacy were being violated.

I 100% realize how my statements in that manner could be misinterpreted, and I don't fault you for challenging me on that.

> It is unbelievable that someone like you will post a dozen responses to people filled with such unbelievably false statements.

If that's the case, why wouldn't you assume you were misinterpreting what I said?

As for people down voting me, don't be too harsh on them for misunderstanding me on this context. As I said, it's reasonable that they could think that. Luckily, you made it clear you couldn't believe I would post something so obviously false, and looked for clarification rather than just assuming. =)

Re: Lavabit SSL Cert Revoked

#320

Earlier quoted context omitted.

> Does asking for a site's private SSL key sound like a reasonable search? Considering that was far from the first thing they asked for, no. Were their goals reasonable? Yes. Was Levison trying to cooperate? No.

> Was Levison trying to cooperate? No. You sound astounded that someone on the receiving side of legal action is trying not to cooperate. Next you'll be stating that him hiring a lawyer is proof of non-cooperation and evidence of guilt. If you got to do overbroad things every time a defendant was "non-cooperative" it would apply to every single court case.

dlgeek explains the entire situation better than I. However, I wanted to apologize for poor wording. It wasn't that he wasn't trying to cooperate. Rather, than it seemed like he was trying to be unreasonably uncooperative to what was a reasonable and lawful order (starting with the information/traffic of a single individual). The distinction is important, I think.
Post reply on HN