I'd argue they destroyed it because it doesn't align with their view of how the country should work. The government hasn't moved much from treating encryption like munitions—they probably viewed lavabit as an existential threat.
I'm curious, from anyone who knows about this stuff, is the argument in https://www.xkcd.com/504/ valid? I.E. could crypto be protected under the Second Amendment? To my IANAL eyes, it seems to me to be a completely legitimate argument.
However, crypto not being a munition means that a good argument could be made that it is speech, and therefore falling under the much more firmly challenged and discussed First Amendment, so restricting crypto could be considered a prior restraint.
I can see how recognizing it as speech and protecting it under the First Amendment would be superior.
Thanks!
RSA-2048 is definitely in "common use."
RSA-2048 will be the small arms equivalent of a musket in 2040. Since the US government controls so much of the global brainpower for crypto, that's not a standard that is acceptable.
I am not saying that they won't be able to pwn you; just that they won't do so by directly cracking 2k+ RSA.
Even if RSA-2048 is secure in 25 years, it will almost certainly not be in the same place in it's lifecycle. Even today, NSA guidance recommends RSA-3072, or RSA-2048 with an accelerated migration to Quantum-resistant crypto in the future. (https://www.nsa.gov/ia/programs/suiteb_cryptography)
My fear is that there won't be an "AES 2", and the commercial/individual world will return to a place where we don't have access to quality, trustworthy crypto for communications and commerce. Without security, there is no trust, and without trust many of the advances in productivity and and collaboration that we've gained in the last 20 years will be substantially weakened.
It have never, for example, applied to ordnance. (hence, the asinine argument "where does it end - should we allow everyone to have nukes?!" does make any sense, at least politically)
It also meant cannons (which are crew-served), and up through the War of 1812 and beyond, privateers owned the vast majority of them.
Were cannons protected by the 2nd amendment? Or merely not prohibited in a legal environment in which the government claimed the authority to prohibit them?
I can't find any reference to discussion of cannons as "bearing arms."
>the Ninth Circuit Court of Appeals ruled that software source code was speech protected by the First Amendment and that the government's regulations preventing its publication were unconstitutional
So at least the implementation of crypto in software seems to be protected under the First Amendment.
I remember some of the expert testimony presenting versions of the source code as all kinds of speech (someone even wrote a song I think) to make the point that code should be protected, but in the end they still lost the overall case.
It's one thing to classify code as speech, it's another thing to give it complete protection from censorship or criminalization in any scenario.
However, they figured out that First Amendment protected their free speech to the extent that they were allowed to publish human readable listings of their source code in the book, even though a floppy disk was right out.
So just for that book, they invented a machine readable easy-to-scan "paper floppy disk" system that printed hex checksums of each line in the left column (which coincidentally looked enough like line numbers that it flew under the radar unnoticed), so you could scan and OCR the source code and checksums from the book, then validate it against the checksums to correct all the scanning errors.
> "Cracking DES" has been published only in print because US export controls on encryption make it a crime to publish such information on the Internet, but the book is designed to be easy to scan into computers. (EFF is also sponsoring a lawsuit by Professor Daniel Bernstein to overturn the law and regulations that make Internet publication of such research results illegal. The case now rests with the Ninth Circuit Court of Appeals.) [2]
[1] https://w2.eff.org/Privacy/Crypto/Crypto_misc/DESCracker
A quick Google search confirms: not only would he have used crypto, he did use crypto:
> Jefferson had used ciphers before with official as well as unofficial correspondence; letters to James Madison, John Adams, James Monroe, Robert Livingston, among others include communication in cipher. It was a way to keep "matters merely personal to ourselves" as well as a way to "have at hand a mask for whatever may need it."
https://www.monticello.org/site/jefferson/jeffersons-cipher-...
Oh the irony.
That's the entire unique selling proposition of this American business (and a direct quote from their website), and it was a bald-faced lie. The DOJ didn't "destroy" this business; it revealed it for the sham it was. It could have continued operating long after DOJ remanded its keys; it was no less secure after than it was before.
The nuance I'm trying to get to here - is that the fundamental security flaw / backdoor is already present on the iPhone5C, the FBI is just trying to utilize it. Something as simple as a mandatory hardware-enforced increasing timeout would have made brute-forcing the passcode prohibitively expensive. (50 ms, 100 ms, 250 ms, 500 ms, 1sec, 2sec, 5 sec, 10 sec, 30 sec, 1min, etc...)
You can read on pg. 15 [0], for example, that Lavabit informed the FBI that it had the capability to obtain the information the FBI wanted.
Also, read page 100. Levison wanted to give the FBI the information as long as he was compensated for it.
[0] Court documents: http://www.documentcloud.org/documents/801182-redacted-plead...
The whole thing is worth a read but here's the gist
"Unlike the design of most secure servers, which are ciphertext in and ciphertext out, this is the inverse: plaintext in and plaintext out. The server stores your password for authentication, uses that same password for an encryption key, and promises not to look at either the incoming plaintext, the password itself, or the outgoing plaintext.
The ciphertext, key, and password are all stored on the server using a mechanism that is solely within the server’s control and which the client has no ability to verify. There is no way to ever prove or disprove whether any encryption was ever happening at all, and whether it was or not makes little difference... The operator can at any time stop averting their eyes, an attacker who compromises the server can log the password a user transmits, and an attacker who can intercept communication to the server can obtain the password as well as the plaintext email."
The model Lavabit used, is the same security model 99% of cloud services use even today.
The same model that iCloud, Google, and other use, all of which have control over the encrytion stored on their servers, all of which will turn over data (not shut down like lavabit did) when asked by the government to turn over said data.
Apple has never, and will likely never refuse to turn over data stored on their servers.
Seems to be an all out assault by the 'leadership' of a lot of western countries at the moment.
Could you legally reveal the target of an active phone wiretap? Intercepting email metadata for a specific person under investigation seems like a reasonable thing for law enforcement to attempt. Is his problem with it the action, or the idea of a secretive court allowing this?
The other issue is having to turn over encryption keys. This is much more of a grey area, and I can see why he would shut down rather than set that precedent. This is why if you want your data safe you should have the keys.
Citation needed.
Ignorance is bliss. Personally I'd rather be informed, that way when I do have the power to exert a little influence (such as in the voting booth) I'm more likely to make a decision that will steer away from more mess. Even so that almost always feels like decisions between various grades of bad rather than something good.
- John Stuart Mill
- Thomas Nagle paraphrased :)
A casual Google search says that "happy" == "feeling or showing pleasure or contentment".
The more informed you are, the more problems you will see and the less content you will be with the state of things. Problems aren't particularly conducive to happiness.
That said, ignorance is not necessarily bliss. It is better to be informed and be able to protect oneself from possible problems than it is to continue to pretend everything is fine and fall victim to eventual problems.
But more seriously, if you correlate happiness with ignorance and pass that off as something you don't have the power to change, that is a mistake. Happiness and your attitude towards things is something you can work on.
Intelligence, "smartness", and ignorance are all orthogonal.
Even very intelligent and very smart people can approach an issue with extreme bias and blatantly ignore (get it ;) news, facts, etc. that contradicts that bias.
I would argue that William Dembski[1] is both smart and intelligent, but I would also call him ignorant.
[Edit: my point being that people who choose to ignore the things that contradict their bias are happier as a result of their ignorance]
> I too am very smart.
is a reference to the subreddit at https://www.reddit.com/r/iamverysmart which points out people describing themselves as very smart, often in ironic ways. I realize now that it may have looked like I was actually making a claim about my own intelligence; I was not.
I read a comment somewhere (I think it was here, or perhaps another site) that Snowden was to HN what the SCO case was to Slashdot back in the day. That is - times were happier until it seemed like politics took over.
I'm not trying to knock either site. What I'm trying to get at is that there's a certain amount of group-think (group-angst in this case?) and if you immerse yourself exclusively in that, you start taking on that view. This 'existential angst' (I really can't think of a better term, though I know this isn't wholly adequate for what I'm trying to describe) is contagious.
HN became my daily news source when I finally got tired of Slashdot's political bent. After Snowden, HN has taken on a somewhat similar flavor. Don't get me wrong - I agree with a lot of it. I also know that sometimes I just have to step away from it, for my own happiness.
It's not about willful ignorance - it's about picking your battles and guarding your own interpretation and mood against the thoughts and mood of the group.
It just makes me sad... There's so much good that could come from computers, but our own governments just want to use them to spy on people. :-(
As far as I can see, they delivered on their promise.
Then, there was Lavabit founder acting snobby talkinv about how he used same security as banks. What might that be? HSM's for keys, link encryption, and per user policies? No, one SSL key protecting everyone like a generic website. Ohhh....
Definitely foresight on my part when I avoided that and similar services. Not to mention I thought they'd 0-day the servers. Still not sure why they didnt. You dont need US government in your threat profile to know top notch hackers like Chinese, Russians, and Israelis might target you to see who you're hiding with "bank style" security.
Note: I protect my Hacker News posts with bank-grade security. I require a login, name, and HTTPS on all posts. I feel safer already.
They did not create a secure communications platform. Any email sent to a user would be delivered plaintext (SMTP), and nothing stopped Lavabit from intercepting that info other than them saying so.
This is why (afaik) Silent Circle stopped offering their "secure" email system, because Lavabit made it clear that such a service is not really secure.
As a side note, Snowden also used Cryptocat so the fact he used Lavabit isn't necessarily a positive endorsement.
I have no idea about how Lavabit operated but that's the service I would offer.
With SSL only on the incoming port then interception is in the hands of the sender (modulo errors in SSL).