8 ms·
How Lavabit Melted Down
- ck2 13y agoI am blown away by the bravery, I know I'd never be so bold. Also confused why he didn't end up in prison on mysterious "pervert" charges out of the blue or even dead. And don't lecture me that is far fetched after this past year.
- tomp 13y agoWell, if they killed him, they probably wouldn't be able to get the keys. And they probably had to keep the bigger "punishment", imprisonment, looming over his head in case he reveals confidential information about the case.
- jobu 13y agoIt wouldn't surprise me if they had some sort of back door with Verisign or other certificate companies for this.
- bigiain 13y agoI'm 100% sure they do, but if you're careful when setting p your SSL/TLS keys, verisign (or any other CA) never sees your private keys, they just sign your CSR. If the FBI had wanted to, they could have seized the servers, and either broken into them and replaced the private key with their own, or replaced the servers with ones they'd built with their own ssl key pairs. But, as the article points out - what they were trying _very_ hard to get was complete infiltration of the entire Lavanit operation without any of the 400,000 paying customers of the supposedly secure email provider knowing about it. Kudos to Levinson for not allowing that to happen, to his great personal cost. (I doubt I'd have the courage to do the same)
- alexwright 13y agoCA like Verisign don't have the key though, this misconception is too common. If you're doing it right the CA is just signing a cert you've generated, they never see the key.
- nitrogen 13y agoHaving CA access does allow them to create a silent MITM in the absence of certificate pinning.
- alexwright 13y agoWith a different key though. Once you've got this new cert. you can MITM, but you can't use it to decrypt the traffic already captured. Also anyone paying attention sees the cert. fingerprint change out of the blue.
- delinka 13y agoA) Law enforcement doesn't need to decrypt previously-captured traffic; they either want to fish for criminal activity or they'll allow their target to build up new incriminating evidence. B) Who pays attention?
- alexwright 13y agoA) That's what they were after though: “all information necessary to decrypt data stored in or otherwise associated with [the account].” A rogue cert and MITM would get the password for the account though, unless B. B) Anyone who knows what they're doing and has something they really want to keep secret? Maybe if someone had such a secret they'd learn to check the cert, maybe even install an extension that would highlight unexpected changes.
- renata 13y agoMost people aren't verifying that the cert doesn't change every time they visit a site though - if they have Verisign sign a new cert and replace the old one 99% of users will never notice, because their browsers won't yell at them.
- 3327 13y agoThe guardian said Snowden is to release US gov't assassination program documentation in a weeks time. So perhaps we will get insight on the in inner workings of systematic killing.
- hobolobo 13y agoI believe the preferred nomenclature is 'targeted killing'.
- gknoy 13y agoI'll be surprised if it doesn't have some whitewashed name like "Citzenship Revocation Program" that lets people talk about it without saying "killing".
- sigkill 13y agoMore like "Citizen Revocation Program". Wouldn't want citizenship reduced and people earning and paying taxes to other countries.
- annnnd 13y agoMaybe they read 1984 as a manual: don't destroy him, convert him. Or at least make an example of him.
- JshWright 13y agoIt didn't happen because that sort of thing doesn't generally happen. Simply raising the specter of 'this past year' doesn't prove some vast conspiracy on the part of the government (or maybe it's the puppetmasters who control the 'real' government?).
- jobu 13y agoThe integrity and bravery he has shown in this fight is impressive. He has definitely earned enough "cred" to restart this business outside the US and be very successful.
- redbeard0x0a 13y agoWe really need more companies (and those in control of those companies) that stand up for their customers this same way. A public company would not have been able to make this play, so keep that in mind when you are making decisions about where to put your data.
- wyck 13y agoI think Qwest Communications was a public company when they refused to comply with the NSA.
- lnanek2 13y agoDidn't they die after that due to the government canceling contracts with them?
- lymie 13y agoDidn't Eric Schmidt lose his discount NASA airplane fuel when Google's lawyers started fighting their gag orders in court?
- jessaustin 13y agoThey've been merged into CenturyLink, but I doubt that's because of losing some government contracts. Those would be a drop in the bucket for an ILEC. USA telco consolidation is inexorable, for anti-consumer reasons. Actually it's only a matter of time before VZN acquires CenturyLink and then spins its less profitable/deadwood pieces back out to private equity firms. Much money will be made by executives, and much wailing to PUCs will be heard when service craters.
- CaptainZapp 13y ago
- gregd 13y agoThere is a huge disconnect between the "justice" system and technology which needs to end. You've seen it before if you're in IT, that glazed eyes look when explaining why their Word document is missing… Anyone with judicial experience know if judges have trusted advisory panels that can help wrap their heads around technology to better rule on cases such as this?
- frossie 13y agoYou mean like Judge Alsup, who taught himself Java so that he could rule that Oracle's APIs are not copyrightable? Or Judge Wells, who ordered SCO to show him the code and then threw the case out when the failed to do so? We haven't done so bad on tech judges recently - it seems to me that the problem with the lavabit/NSA cases is not so much the technical side, but the classic one of government powers, and the fact that there is no explicit constitutional protections of privacy.
- majelix 13y agoWhy would technology be any different from anything else? The prosecution and defense are free to call on expert witnesses to explain SSL and heart surgery to the judge and jury.
- dagw 13y agoDo you really think IT is that much harder than say medicine or the nuances of structural engineering on any of the myriad of other technical areas that no doubt show up in courtrooms every single day?
- pionar 13y agoIt is up to the participants to bring in experts to make sure the judge has enough relevant information to make an informed decision. Really, even in this case, it does not seem like the judge is doing that badly on grokking the technology. I think it's actually the other way around, where Lavabit doesn't understand the judicial system and the concept of evidentiary chain of custody.
- selmnoo 13y agoFor the fortitude he has shown in fighting the good fight, please consider donating to his defense fund: http://lavabit.com/ http://lavabit.com/ (link at the end).
- frenger 13y agowtf? The site's [https://lavabit.com https://lavabit.com] SSL cert been revoked: http://d.pr/i/sc71 http://d.pr/i/sc71 [IMG]
- lmm 13y agoThe more I read the more sympathy I have for the government here. They had a (presumably lawfully obtained) warrant against a specific user; it's not they who designed lavabit such that it was impossible to execute this without obtaining access to every other user. The proposal that Levison would extract the information himself rather than turning over the keys strikes me as completely unrealistic - any information so obtained would be quite rightly thrown out of court, because there's no reliable evidentiary chain, only (in effect) Levison's word. Even if he had turned over the SSL keys, the US still has a fairly strong "fruit of the poison tree" doctrine: any information the government happened to obtain on other users would be invalid for prosecution because it wouldn't be covered by their search warrant.
- Klinky 13y agoRegardless of "fruit of poison tree" laws, information known is hard to unknow, and it wouldn't be surprising if information leaked to others could be used to lead hounds to foxes via different paths.
- fennecfoxen 13y agoIndeed: what they routinely do in those cases is take some otherwise-ignorant agent, give them a little advice like "hey, you really should check out some stuff in this area" (nudge-nudge/wink-wink) and have him "rediscover" this information. Then they tell the court that it was Obtained Through That Agent's Normal Ordinary Investigations. "Parallell construction" aka "intelligence laundering". https://www.eff.org/deeplinks/2013/08/dea-and-nsa-team-intelligence-laundering https://www.eff.org/deeplinks/2013/08/dea-and-nsa-team-intel...
- fennecfoxen 13y ago> it's not [the government] who designed lavabit such that it was impossible to execute this without obtaining access to every other user. That's true, but they're still essentially implying that services which are explicitly designed to omit backdoor capabilities for the government to spy on you -- that is, services offering actual cryptographically guaranteed privacy, not just "no one has looked yet, and if they did, it'll all turn out okay in the end trust us" -- are broadly illegal and will get you criminal contempt.
- kbart 13y agoI still don't get one thing about this story: >> To make use of these keys, the F.B.I. would have to manually input all two thousand five hundred and sixty characters, and one incorrect keystroke in this laborious process would render the F.B.I. collection system incapable of collecting decrypted data Don't FBI have some ultra DPI scanner with advanced OCR software? Let's say they live under a rock, it's still not so hard to manually type ~2k characters using magnifying glass. If so, what was the point to shut down Lavabit AFTER turning in printed keys? P.S. I still highly respect Lavabit and people behind it, but this point in a story doesn't make sense at all.
- andylei 13y agowhat really happened is that the court then ordered him to turn over the key on a CD, or continue to face the $5k / day fine. so he eventually did turn over the key on a CD
- plorg 13y agoThis assumes that it was printed with a high-dpi printer. From the reports I've read he intentionally chose a font that would be hard for a computer to read. There's also no evidence that he printed it on any special high-dpi printer, so the process almost certainly lost enough information as to make the printed text not-fully-recoverable.
- jedbrown 13y agoNews outlets keep repeating "11 pages of 4-point type totaling 2560 characters", which just doesn't match up since that number of characters fits on one page in a fairly normal font size. Also, RSA keys just aren't that big, so the 11 pages must have either been many keys or some other data. As I understand Lavabit's architecture, there is no "master" key. Instead, incoming mail is encrypted using an asymmetric per-user key. All the key pairs were created by Lavabit and stored on-site, but locked by a password to be provided over TLS. Since Levison probably didn't compromise his system to store users' passwords, presumably the keys that he was handing over in 4-point type were still locked with a password.
- JshWright 13y ago>News outlets keep repeating "11 pages of 4-point type totaling 2560 characters", which just doesn't match up since that number of characters fits on one page in a fairly normal font size. Also, RSA keys just aren't that big, so the 11 pages must have either been many keys or some other data. You're making assumptions about the encoding...
- aubergene 13y agoIt was five keys and included the full certificate chain
- CamperBob2 13y agoI don't understand why, if he was making a principled stand, he would have bothered with the printout in 4-point type. That was sort of a juvenile move, one that could only serve to justify the government's attitude towards him. Weird.
- smoyer 13y agoIs anyone else thinking that their systems should include a self-destruct button? (for LavaBit I'd imagine a process that e-mailed each user the SSL key used to encrypt their mailbox, then deleted the key from the system. A user could still decrypt their mailbox by downloading it and using the key).
- betterunix 13y agoThe problem is that services like Lavabit want to do something that is technically not possible: give you access to your encrypted mail from any computer i.e. the convenience of webmail. If I can just download a key and keep it on my computer, why would I not just generate the key on my computer by e.g. using PGP or S/MIME?
- smoyer 13y agoNo ... I meant a "red" button that could be used just prior to wiping the servers clean. Your point is completely valid while the service is running.
- 65_196_127_226 13y agoThis isn't any different than shredding all your business documents when you hear the cops knocking on your door. It was frowned upon when Enron undertook a mass shredding during their investigation.
- at-fates-hands 13y agoThe fact the government wanted the SSL keys is obvious they wanted to get at all his customers, not just the one they were targeting. Levison offered multiple times to write a specific script for the single user that would do what they wanted and at a minimal cost to the government - and they refused. A pretty clear indication they wanted unfettered access to his client base and his network. Then you add in the lack of ANY oversight on either Lavabit's or the government's, and you have to praise him for what he did.
- 65_196_127_226 13y agoDo you really consider the judicial warrant system a lack of ANY oversight? After Levison's lack of cooperation, could the investigators really trust Levison to hand over all the information?
- lhc- 13y agoWhy should Levison trust a government who has proven to be untrustworthy when it comes to data collection? Levison didn't lie or mislead anyone, he even offered to get the data for them as long as it was targeted. The government has basically zero credibility in matters like this, and yet he was expected to trust them with no oversight (in the article, he was told there was no independent audit of their use of the data)?
- MustBeAShill 13y agoWhat is this monolithic government you speak of? Are you saying that the FBI and the NSA are synonymous? I'm sure plenty of FBI investigators would take exception to an accusation like that. I can play this game too. Dread Pirate Roberts used StackExchange, so therefore StackExchange users cannot be trusted to build websites that don't host drug deals and supposed hitmen.
- jlgreco 13y agoWhy the constant influx of throwaways?
- 65_196_127_226 13y agoThe amount of support for Levison and ire toward the government in this case is absurd. The FBI followed the Constitutional process of obtaining a warrant for the information of the "one user". I suspect that the only reason anyone cares about this case is because Lord Snowden the Infallible deigned to grace Lavabit with his email traffic. Would the internet outrage be the same if the targeted user was found out to be a Goldman Sachs executive or a Westboro Baptist Church minister?
- nwh 13y agoEr yeah, he offered to backdoor the one user for them and they refused.
- zentiggr 13y agoWell, if the hallowed FBI et al had actually taken the reasonable offers of access to one user and not escalated it into full access to the entire service's and customer's content/traffic, there might be a lot less to be outraged about, hmm?
- pyrocat 13y agonice troll attempt
- CamperBob2 13y agoThe FBI followed the Constitutional process of obtaining a warrant for the information of the "one user". Not a big fan of reading the article, are you? The government's demand was constitutional for one user, and unconstitutional for 399,999 others.
- danielweber 13y agoI've been skeptical of LavaBit, chalking it up to the general deification that HN gives to its heroes du jour, but he really seems to have made a highly principled stand while still allowing the government to intercept any individual for which it had a warrant.
- RyanMcGreal 13y ago> While he opposes the bulk collection of domestic communications, he has no such strong feelings about the N.S.A.’s foreign-surveillance efforts. As a non-American, I have a problem with this seemingly widespread idea even among privacy advocates in the USA that only Americans are entitled to the protection of their rights from the American government.
- betterunix 13y agoTo be fair, your government should be working to protect you from foreign threats like this. You should not rely on foreign powers to protect you.
- RyanMcGreal 13y agoBelieve me, I'm not happy that my government is all-in on the American mass surveillance game. But my specific concern here is with Americans who think it's okay for the US government to conduct mass surveillance on the rest of the planet, just not on Americans.
- drivingmenuts 13y agoBecause we never know where the next threat will come from, or perhaps the threat after that. Your country may be perfectly at peace with the US now, but there is no way to guarantee that peace unless we have people to continually watch for potential threats. Even that is, in itself, no guarantee, but it's better than nothing. Maybe someday, mankind will be able to share universal goodwill and peace, but until that time, trust, but verify, at a minimum.
- jruthers 13y agoI call "Bullshit" on that. For all of the talk about "all men created equal" and "do to others as you would have them do to you", fundamentally Americans are brought up to believe they are different or "exceptional" to other humans. This belief let's them distort reality so that spying on innocent foreigners is ok but spying on innocent Americans is an abomination. Hypocrisy. Timothy McVeigh and others prove that the domestic threat to the US is as serious as the foreign.
- smsm42 13y agoThe most scary quote in the whole article is this: THE COURT: You want to do it in a way that the government has to trust you /.../ THE COURT: And you won’t trust the government. So why would the government trust you? It was that the whole idea on which US is built on - the Constitution and other founding ideas - was based on trusting the government only with very little that is necessary for it to function and no more, and having the ultimate power reside in the hands of the citizens. Now it comes to trust in the government being implied and if the citizen doesn't trust the government, he is not to be trusted and must be subjected to coercion. And that's coming from courts, that are supposed to be protecting the constitutional rights. America has come a long and very sad way since its noble origins.
- SwellJoe 13y agoThat quote made me feel sick to my stomach. I mean, I knew it had gotten that bad...I've been involved in Restore The Fourth organizing, and before that I've been paying close attention to all the previous leaks about the surveillance state. But, knowing it and seeing a judge state it outright is two very different things. It used to be under cover. It only happened in the darkness of secret documents and agencies. Now, it's come out into the light of day...and they're getting away with it. Not even getting away with it, really...they're wearing it proudly, as though they are the people in the right; they honestly believe they are the people who have nothing to hide or be ashamed of. It's astonishing that more of our reps aren't standing up and shouting about this. So many of the people in power are complicit, it feels hopeless at times.
- angersock 13y agoOf wonderful note: At approximately 1:30 p.m. CDT on August 2, 2013, Mr. Levison gave the F.B.I. a printout of what he represented to be the encryption keys needed to operate the pen register. This printout, in what appears to be four-point type, consists of eleven pages of largely illegible characters. To make use of these keys, the F.B.I. would have to manually input all two thousand five hundred and sixty characters, and one incorrect keystroke in this laborious process would render the F.B.I. collection system incapable of collecting decrypted data. I tip my hat to this magnificent bastard. EDIT: The core issue is summed up nicely thereafter: Levison believes that when the government was faced with the choice between getting information that might lead it to its target in a constrained manner or expanding the reach of its surveillance, it chose the latter.
- CamperBob2 13y agoDemanding the SSL keys to the entire database was clearly an insane overreach on the FBI's part, a mistake that they compounded if it's true that they refused to work with Lavar on the more targeted approach he suggested. I would like to kick in some bucks towards Ladar's defense, but I'd rather do it through the EFF (where I'm already a member) rather than rally.org, which I've never heard of. Does anyone have any experience with (or thoughts about) rally.org -- or, for that matter, any knowledge of why the EFF isn't running point on this case?