Live data from Hacker News

CertiVox confirms it withdrew PrivateSky after GCHQ issued warrant

itsecurityguru.org

81–86 of 86 posts

Re: CertiVox confirms it withdrew PrivateSky after GCHQ issued warrant

#81

we had the choice to make - either architect the world's most secure encryption system on the planet, so secure that CertiVox cannot see your data, or spend £500,000 building a backdoor into the system So, just like Lavabit as 'moxie keeps pointing out[1][2], it wasn't actually secure. Still, I like the principled stand they took. [1] https://news.ycombinator.com/item?id=6672442 [2] http://www.thoughtcrime.org/blog/l…

If they had to spend money building in the back door, that would imply it didn't exist already.

Re: CertiVox confirms it withdrew PrivateSky after GCHQ issued warrant

#82
post #29

Earlier quoted context omitted.

What's that got to do with it? (genuinely interested).

I think it's ironic that those who are in favour of personal liberties are often on the left of the political spectrum whereas, in this instance, it was the Tories who rolled back aspects of surveillance legislation that was introduced by Labour.

>> I think it's ironic that those who are in favour of personal liberties are often on the left of the political spectrum whereas, in this instance, it was the Tories who rolled back aspects of surveillance legislation that was introduced by Labour.

Those on what passes for the 'left' of UK politics spent over a decade stripping rights and liberties away just as far as they can in the name of protecting people.

I don't personally think it's much of a left-right issue. It's another axis.

Re: CertiVox confirms it withdrew PrivateSky after GCHQ issued warrant

#83
post #53

Earlier quoted context omitted.

There is no actually secure - that's the problem. The best you can do is secure against specific threat models. Up until recently, most people didn't necessarily view government intrusion as a particularly credible threat, so didn't spend the extra time/effort/money mitigating against it. One of the best things to come out of all these revelations, in my opinion, is a revised view of what threats we should consider w…

You're right that we may have been naive about trusting our governments. What I don't understand is why anyone trusted businesses (such as CertiVox and Lavabit) to keep their emails secure? If the businesses themselves couldn't decrypt these emails, there's nothing the government could usefully ask them for.

You can trust an established business with a reputation to lose, not to defecate where it eats.

The upset in the threat model is that you can no longer trust that a business is free to choose according to self interest. You have to assume the government will be force-feeding it laxatives.

Re: CertiVox confirms it withdrew PrivateSky after GCHQ issued warrant

#84

Earlier quoted context omitted.

End of discussion? No, sir, it is not! Your interpretation is extremely naïve. I could hold a gun to your head, for example. You wouldn't be forced per se to meet my demands, but you probably would because it would be extremely unreasonable not to. In the same way, the consequences for not complying are: an extremely expensive and possibly unaffordable rewrite, going to jail for a few years, or giving up their custom…

Sounds like these services actually shutting down is a good thing for the end users, since they aren't actually securely designed in the first place! They even admit in the article they'd have to properly design their system to make email unreadable by their staff, and they chose to shutter their service vs trying to figure out how to make that work and still make money.

No, re-read the article, your wrong. We made our system's data unreadable by staff, that's the first thing we did. Making it readable by GCHQ would have incurred the cost.

Re: CertiVox confirms it withdrew PrivateSky after GCHQ issued warrant

#85
post #44
post #3

Wow, shows a lot of integrity closing the product instead of still keeping it up in a compromised state to comply with the warrant. We've seen some other providers here in the US even changed functionality to retain keys used in web clients of secure email at the behest of government orders. This does mean that the UK is now on the list, along with the US, of places where no credible crypto startup is possible, thoug…

> This does mean that the UK is now on the list, along with the US, of places where no credible crypto startup is possible, though. I can think of very few developed countries that, when the rubber hits the road, will let you do what you want. Taking measures to aid official police or court investigations is simply an implied obligation in most countries with developed legal systems. Very few countries will tolerate…

I think it falls into three groups for communications providers:

1) Laws like CALEA, which (if applicable) require a provider to develop and expose backdoors to the government in advance of a request

2) Building systems where an operator doesn't have access, but where a court order can compel changes to the system, including ultimately shutting it down.

3) Being able to build a system where operator doesn't have access to data, and upon a request, if no data can be turned over, continues operating. Must turn over any data which you do have.

4) No requirement to cooperate, or something equiv to 4th/5th A protections for the end user being extended to service providers.

I used to think the US was #3. I don't believe #4 exists anywhere, at least outside specific kinds of data (medical, legal). The US is at least #2 now, and might actually be #1 in more and more domains.

Post reply on HN