A Government Error Just Revealed Snowden Was the Target in the Lavabit Case
wired.com
wired.com
Could you legally reveal the target of an active phone wiretap? Intercepting email metadata for a specific person under investigation seems like a reasonable thing for law enforcement to attempt. Is his problem with it the action, or the idea of a secretive court allowing this?
The other issue is having to turn over encryption keys. This is much more of a grey area, and I can see why he would shut down rather than set that precedent. This is why if you want your data safe you should have the keys.
Citation needed.
I'd argue they destroyed it because it doesn't align with their view of how the country should work. The government hasn't moved much from treating encryption like munitions—they probably viewed lavabit as an existential threat.
I'm curious, from anyone who knows about this stuff, is the argument in https://www.xkcd.com/504/ valid? I.E. could crypto be protected under the Second Amendment? To my IANAL eyes, it seems to me to be a completely legitimate argument.
However, crypto not being a munition means that a good argument could be made that it is speech, and therefore falling under the much more firmly challenged and discussed First Amendment, so restricting crypto could be considered a prior restraint.
I can see how recognizing it as speech and protecting it under the First Amendment would be superior.
Thanks!
RSA-2048 is definitely in "common use."
RSA-2048 will be the small arms equivalent of a musket in 2040. Since the US government controls so much of the global brainpower for crypto, that's not a standard that is acceptable.
I am not saying that they won't be able to pwn you; just that they won't do so by directly cracking 2k+ RSA.
Even if RSA-2048 is secure in 25 years, it will almost certainly not be in the same place in it's lifecycle. Even today, NSA guidance recommends RSA-3072, or RSA-2048 with an accelerated migration to Quantum-resistant crypto in the future. (https://www.nsa.gov/ia/programs/suiteb_cryptography)
My fear is that there won't be an "AES 2", and the commercial/individual world will return to a place where we don't have access to quality, trustworthy crypto for communications and commerce. Without security, there is no trust, and without trust many of the advances in productivity and and collaboration that we've gained in the last 20 years will be substantially weakened.
It have never, for example, applied to ordnance. (hence, the asinine argument "where does it end - should we allow everyone to have nukes?!" does make any sense, at least politically)
It also meant cannons (which are crew-served), and up through the War of 1812 and beyond, privateers owned the vast majority of them.
Were cannons protected by the 2nd amendment? Or merely not prohibited in a legal environment in which the government claimed the authority to prohibit them?
I can't find any reference to discussion of cannons as "bearing arms."
>the Ninth Circuit Court of Appeals ruled that software source code was speech protected by the First Amendment and that the government's regulations preventing its publication were unconstitutional
So at least the implementation of crypto in software seems to be protected under the First Amendment.
I remember some of the expert testimony presenting versions of the source code as all kinds of speech (someone even wrote a song I think) to make the point that code should be protected, but in the end they still lost the overall case.
It's one thing to classify code as speech, it's another thing to give it complete protection from censorship or criminalization in any scenario.
However, they figured out that First Amendment protected their free speech to the extent that they were allowed to publish human readable listings of their source code in the book, even though a floppy disk was right out.
So just for that book, they invented a machine readable easy-to-scan "paper floppy disk" system that printed hex checksums of each line in the left column (which coincidentally looked enough like line numbers that it flew under the radar unnoticed), so you could scan and OCR the source code and checksums from the book, then validate it against the checksums to correct all the scanning errors.
> "Cracking DES" has been published only in print because US export controls on encryption make it a crime to publish such information on the Internet, but the book is designed to be easy to scan into computers. (EFF is also sponsoring a lawsuit by Professor Daniel Bernstein to overturn the law and regulations that make Internet publication of such research results illegal. The case now rests with the Ninth Circuit Court of Appeals.) [2]
[1] https://w2.eff.org/Privacy/Crypto/Crypto_misc/DESCracker
A quick Google search confirms: not only would he have used crypto, he did use crypto:
> Jefferson had used ciphers before with official as well as unofficial correspondence; letters to James Madison, John Adams, James Monroe, Robert Livingston, among others include communication in cipher. It was a way to keep "matters merely personal to ourselves" as well as a way to "have at hand a mask for whatever may need it."
https://www.monticello.org/site/jefferson/jeffersons-cipher-...
Oh the irony.
Ignorance is bliss. Personally I'd rather be informed, that way when I do have the power to exert a little influence (such as in the voting booth) I'm more likely to make a decision that will steer away from more mess. Even so that almost always feels like decisions between various grades of bad rather than something good.
- John Stuart Mill
- Thomas Nagle paraphrased :)
A casual Google search says that "happy" == "feeling or showing pleasure or contentment".
The more informed you are, the more problems you will see and the less content you will be with the state of things. Problems aren't particularly conducive to happiness.
That said, ignorance is not necessarily bliss. It is better to be informed and be able to protect oneself from possible problems than it is to continue to pretend everything is fine and fall victim to eventual problems.
But more seriously, if you correlate happiness with ignorance and pass that off as something you don't have the power to change, that is a mistake. Happiness and your attitude towards things is something you can work on.
Intelligence, "smartness", and ignorance are all orthogonal.
Even very intelligent and very smart people can approach an issue with extreme bias and blatantly ignore (get it ;) news, facts, etc. that contradicts that bias.
I would argue that William Dembski[1] is both smart and intelligent, but I would also call him ignorant.
[Edit: my point being that people who choose to ignore the things that contradict their bias are happier as a result of their ignorance]
> I too am very smart.
is a reference to the subreddit at https://www.reddit.com/r/iamverysmart which points out people describing themselves as very smart, often in ironic ways. I realize now that it may have looked like I was actually making a claim about my own intelligence; I was not.
I read a comment somewhere (I think it was here, or perhaps another site) that Snowden was to HN what the SCO case was to Slashdot back in the day. That is - times were happier until it seemed like politics took over.
I'm not trying to knock either site. What I'm trying to get at is that there's a certain amount of group-think (group-angst in this case?) and if you immerse yourself exclusively in that, you start taking on that view. This 'existential angst' (I really can't think of a better term, though I know this isn't wholly adequate for what I'm trying to describe) is contagious.
HN became my daily news source when I finally got tired of Slashdot's political bent. After Snowden, HN has taken on a somewhat similar flavor. Don't get me wrong - I agree with a lot of it. I also know that sometimes I just have to step away from it, for my own happiness.
It's not about willful ignorance - it's about picking your battles and guarding your own interpretation and mood against the thoughts and mood of the group.
It just makes me sad... There's so much good that could come from computers, but our own governments just want to use them to spy on people. :-(
As far as I can see, they delivered on their promise.
Then, there was Lavabit founder acting snobby talkinv about how he used same security as banks. What might that be? HSM's for keys, link encryption, and per user policies? No, one SSL key protecting everyone like a generic website. Ohhh....
Definitely foresight on my part when I avoided that and similar services. Not to mention I thought they'd 0-day the servers. Still not sure why they didnt. You dont need US government in your threat profile to know top notch hackers like Chinese, Russians, and Israelis might target you to see who you're hiding with "bank style" security.
Note: I protect my Hacker News posts with bank-grade security. I require a login, name, and HTTPS on all posts. I feel safer already.
They did not create a secure communications platform. Any email sent to a user would be delivered plaintext (SMTP), and nothing stopped Lavabit from intercepting that info other than them saying so.
This is why (afaik) Silent Circle stopped offering their "secure" email system, because Lavabit made it clear that such a service is not really secure.
As a side note, Snowden also used Cryptocat so the fact he used Lavabit isn't necessarily a positive endorsement.
I have no idea about how Lavabit operated but that's the service I would offer.
With SSL only on the incoming port then interception is in the hands of the sender (modulo errors in SSL).
Seems to be an all out assault by the 'leadership' of a lot of western countries at the moment.
That's the entire unique selling proposition of this American business (and a direct quote from their website), and it was a bald-faced lie. The DOJ didn't "destroy" this business; it revealed it for the sham it was. It could have continued operating long after DOJ remanded its keys; it was no less secure after than it was before.
The nuance I'm trying to get to here - is that the fundamental security flaw / backdoor is already present on the iPhone5C, the FBI is just trying to utilize it. Something as simple as a mandatory hardware-enforced increasing timeout would have made brute-forcing the passcode prohibitively expensive. (50 ms, 100 ms, 250 ms, 500 ms, 1sec, 2sec, 5 sec, 10 sec, 30 sec, 1min, etc...)
You can read on pg. 15 [0], for example, that Lavabit informed the FBI that it had the capability to obtain the information the FBI wanted.
Also, read page 100. Levison wanted to give the FBI the information as long as he was compensated for it.
[0] Court documents: http://www.documentcloud.org/documents/801182-redacted-plead...
The whole thing is worth a read but here's the gist
"Unlike the design of most secure servers, which are ciphertext in and ciphertext out, this is the inverse: plaintext in and plaintext out. The server stores your password for authentication, uses that same password for an encryption key, and promises not to look at either the incoming plaintext, the password itself, or the outgoing plaintext.
The ciphertext, key, and password are all stored on the server using a mechanism that is solely within the server’s control and which the client has no ability to verify. There is no way to ever prove or disprove whether any encryption was ever happening at all, and whether it was or not makes little difference... The operator can at any time stop averting their eyes, an attacker who compromises the server can log the password a user transmits, and an attacker who can intercept communication to the server can obtain the password as well as the plaintext email."
The model Lavabit used, is the same security model 99% of cloud services use even today.
The same model that iCloud, Google, and other use, all of which have control over the encrytion stored on their servers, all of which will turn over data (not shut down like lavabit did) when asked by the government to turn over said data.
Apple has never, and will likely never refuse to turn over data stored on their servers.
I cannot imagine statement more de-attached from reality than that. If the companies like Apple who sells millions of products to customers and rely on customer's trust are not a good indication or source of information whether the Gov is doing good job, then I don't know who is...
"We the People".... you'd think.
From my point of view, whenever "we the people" demand more "answers/solutions" from the government, what ends up happening is more bureaucracy that ends up failing us all.
[1]https://en.wikipedia.org/wiki/United_States_Office_of_Person...
That said I don't think that there is anybody out there who is shocked by this confirmation, it was as far as I'm concerned a certainty, the timing would have been too much of a coincidence.
(edit) Ahh - it turns out that Firefox's built-in "tracking protection" feature triggers their ad-blocker-blocker.
javascript:(function(){document.styleSheets[0].addRule(".highlighted_to_remove","background:red !important");var e=function(e){if(e.keyCode==27){i()}};document.addEventListener("keydown",e);var t=function(e){e.stopPropagation();this.classList.add("highlighted_to_remove");return false};var n=function(e){e.stopPropagation();this.classList.remove("highlighted_to_remove");return false};var r=function(e){this.parentNode.removeChild(this);i();e.preventDefault();e.stopPropagation();return false};var i=function(){var i=0;var s=document;while(s=document.body.getElementsByTagName("*").item(i++)){s.removeEventListener("mouseover",t);s.removeEventListener("mouseout",n);s.removeEventListener("click",r);s.classList.remove("highlighted_to_remove")}document.removeEventListener("keydown",e)};var s=0;var o=document;while(o=document.body.getElementsByTagName("*").item(s++)){o.addEventListener("mouseover",t);o.addEventListener("mouseout",n);o.addEventListener("click",r)}})()
The only downside is you lose the ability to scroll. : / I don't know how to fix that.http://www.engadget.com/2016/01/08/you-say-advertising-i-say...
Ads are annoying... but more importantly, they are another attack vector.
Don't give in.
The amount of times little things slip out in conversation when you don't mean to makes me think that it is only inevitable that somebody, someday, will make a similar mistake to the government here. I don't think they will get treated lightly when that happens, either.
a) Safely store and analyse the results of mass public surveillance.
b) Hold 'master' keys to encrypted systems.
Of course no-one in the know seriously believes either claim, but this is a great counter-example to put to the general public.
What things can Levison still not talk about, aside from the identity of the target?
Even if in this case, it was non-intentional transparency.
No.
> how is that better?
Why ask the question at all if you already made up your mind about the answer?
(No cookies get saved, so it's a win as far as privacy goes.)
It's eye-opening how much of the internet relies on Javascript that you don't notice- and how much works totally fine.
There should be a backlash against this idiotic adblocking-blocking, I'm just not sure what form it should take.
Seems fair.
But I find some value in the GP post. It tells us that Wired is taking an active stance against ad blockers. This information can be used when considering sources for submission or deciding whether to click a link. Many of the responses to the GP provide value as well by shedding light on which ad blockers are more effective and/or are triggering the issue.
So, this is a really shitty false positive for Wired's system.
In Chrome, go to DevTools (CMD+Option+I). Press F1 for settings then check "Disable JavaScript" and reload the page. There are similar ways to do it in other browsers too.
Saying "you can't view this content unless you register/disable adblock" is NEVER polite, no matter how many times you say "please".
That's a very strange and unwarranted assumption.
Nonetheless, there is an external "Just let me ignore this!" button here:
It lets you bypass registration with the most extremely annoying websites, so you don't have to register.
Or just keep your privacy, browse using TOR/VPN, and you can ignore ToS completely with no real-life consequences.
Thankfully, the battle between users and lawyers usually favor former.
Today, its just an un-redacted email address. Tomorrow, it could be the keys to the back-door that the government wants to impose on the world.
https://en.wikipedia.org/wiki/Lavabit
I don't think anybody had a reasonable doubt that it wasn't about Snowden, but it's nice to have confirmation from the horse's mouth.
> It’s been one of the worst-kept secrets for years: the identity of the person the government was investigating in 2013 [...]
>IT’S BEEN ONE of the worst-kept secrets for years: the identity of the person the government was investigating in 2013 when it served the secure email firm Lavabit with a court order demanding help spying on a particular customer.
We all knew it, but it hadn't been confirmed by the government until now. See [0] for example:
>The name of the target is redacted from the unsealed records, but the offenses under investigation are listed as violations of the Espionage Act and theft of government property — the exact charges that have been filed against NSA whistleblower Snowden in the same Virginia court.
Or maybe we already know all that matters about the case.