Lavabit Founder Says He Had ‘Obligation’ to Shut Service
bits.blogs.nytimes.com
bits.blogs.nytimes.com
http://www.democracynow.org/2013/8/13/exclusive_owner_of_sno...
Edit: Tried it on private mode and I couldn't see it either. No clue as to why.
> LADAR LEVISON: Well, just to add one thing to Greenwald’s comments, I mean, there’s information that I can’t even share with my lawyer, let alone with the American public.
Of course, if you engage in a criminal conspiracy with your lawyer, it's breakable(sorry Walter White). So they could claim espionage. But the catch 22 is proving it it if the only evidence is itself covered by said privilege.
"…prohibits you…from disclosing this letter, other than to…an attorney to obtain legal advice or legal assistance with respect to this letter.""
Source: http://upload.wikimedia.org/wikipedia/commons/9/91/EFF-IA_Na...
I can't see a reasonable way of establishing bona fides other than creating a strong implication/inference of "national security".
(My wife is a federal attorney, and it is disappointing how warped "the government's" perspectives are on rights and what is reasonable.)
"On March 9, 2006 the USA PATRIOT Improvement and Reauthorization Act was signed into law... Other amendments included that the recipient of an NSL was allowed to explicitly inform their attorney about the request" [1]
Scary stuff. It wouldn't surprise me if there's still some things, like implementation details, that you're compelled to keep secret from your attorney.
Whether or not that would stand up in court is another issue.
Edit: It's not entirely clear to me whether or not this was an actual prohibition on consulting with an attorney, or whether the NSL is worded sufficiently vaguely to make most people believe that's the case. Some case notes from Doe/ACLU v. Ashcroft make me believe it's the latter:
"Because neither the statute, nor an NSL, nor the FBI agents dealing with the recipient say as much, all but the most mettlesome and undaunted NSL recipients would consider themselves effectively barred from consulting an attorney or anyone else who might advise them otherwise, as well as bound to absolute silence about the very existence of the NSL." [2]
[1]: http://en.wikipedia.org/wiki/National_security_letter#Histor...
https://www.youtube.com/watch?v=-6xsv4azzpc
It does seem like NSL's are fundamentally unconstitutional, but I think every person needs to prove it now in Court, so if you get one, you should contest it.
"Lavabit had complied with 'narrowly tailored' court orders for user information on at least two dozen occasions in the past"
In other words Lavabit is not any better than Hushmail. Lavabit did not base its security on cryptography, it based on it trusting the people who worked for the company. Cryptography was just a side show, just like with Hushmail, because Lavabit could get the plaintexts whenever someone working there wanted (or whenever they were compelled to do so by a government, criminal organization, etc.).
BTW it's a really nice article, gives a nice personal side to the whole story.
http://ia600908.us.archive.org/9/items/gov.uscourts.mdd.2362...
Take a quick look at attachment B and you'll see that Lavabit was asked to provide the plaintext message bodies and attachments of emails sent by the user. This was not a demand for metadata, it was a demand for messages, and it was a demand that Lavabit complied with.
This is really not any different from Hushmail.
Of course Lavabit would not be the one brute forcing the passwords. That is not the point. The point is that the security of Lavabit is a matter of the user's password, and only in the best case where the user does not log in.
Ultimately Lavabit's security is a matter of the trustworthiness of Lavabit's employees, not the size of your key; it is marginally related to the strength of your password, but only under very specific circumstances. The fact that cryptography is being used somewhere in the system is a distraction. If instead of the US government showing up with a court order it had been a Chinese spy sending business secrets back to the Chinese government, would you still be defending Lavabit?
From what I see, they were ordered to provide all messages, records etc. stored on that account and related logfiles. It does not specifically say "plaintext", so Lavabit might have provided them with the encrypted e-mails and no logs (if they had none) and still be in compliance with the warrant (IANAL!). You cannot possibly be forced to provide something you do not have, right?
It is true that the subpoena asked for it, but a response to a subpoena that supplies what can be supplied and explains why the rest can't be supplied would not trigger another court docket entry unless the government didn't believe the explanation.
Because a subpoena is filed before the government actually contacts the witness, the government typically asks for everything it could possibly get or want.
In the US when it comes to subpoenas from civil or criminal courts, you only need to produce "books, papers, documents, data, or other objects" in your possession. The passwords were not in Lavabit's possession at the time it received the subpoena. Furthermore, subpoenas can be quashed if they are " unreasonable or oppressive" (see e.g. FRCrimP 17c). Asking a witness to write custom code in order to capture a user's password is a textbook example of an unreasonable request.
The rules for national security requests on the other hand are entirely different. 50 USC 1805(c)(2) requires the recipient of an electronic surveillance order to:
"(B) that, upon the request of the applicant, a specified communication or other common carrier, landlord, custodian, or other specified person, or in circumstances where the Court finds, based upon specific facts provided in the application, that the actions of the target of the application may have the effect of thwarting the identification of a specified person, such other persons, furnish the applicant forthwith all information, facilities, or technical assistance necessary to accomplish the electronic surveillance in such a manner as will protect its secrecy and produce a minimum of interference with the services that such carrier, landlord, custodian, or other person is providing that target of electronic surveillance;"
There's always a way to access the data. Cloud-based email is...cloud-based...which means that it's susceptible to man-in-the-middle and other forms of attack.
It's possible that the government was asking Lavabit to modify its systems such that the encrypted data guarantee would no longer be real, and then they demanded that he hide that fact.
I'm honestly not sure what to think about that. Should private data storage be permitted? Is there a difference between your private data in the cloud and your private data on a system at your home?
Who is arguing that? In this case, the issue is not about whether the government has probable cause. The issue is that any system that allows Lavabit to respond to a warrant can be used for mass surveillance, industrial espionage, etc. This conversation happened 20 years ago when people were arguing about key escrow. Almost nobody argues that the police should not be able to investigate crime; the argument is that backdoors are a massive vulnerability that leave innocent people, for whom the police have no warrant (or no "specific" warrant), at risk.
"Cloud-based email is...cloud-based...which means that it's susceptible to man-in-the-middle and other forms of attack."
The problem is not that the mail service is run by a third party. The problem is that encryption, decryption, key storage, and even key generation are being performed by a third party. I send encrypted mail through GMail all the time -- and Google is not able to decrypt those messages, even if they are presented with a warrant. While it may be problematic for the police to face such a situation, it would be problematic for me if criminals and spies could read my emails, and at the end of the crypto wars Congress determined that the need for good civilian crpytography vastly outweighed the government's needs to enforce laws and spy on other countries.
It is also important to remember that the police can still get messages that are encrypted/decrypted offline, they just have to work a bit harder for it. For example:
http://yro.slashdot.org/story/00/12/06/0255234/fbi-bugs-keyb...
The phrase "user information" is vague; it could include timestamps of all requests from a particular IP, for example. Given that he was willing to shut down his sole source of income on principle, I'm willing to believe that he had reasonable crypto in place to protect user data at rest.
Cryptography was just a side show, just like with
Hushmail, because Lavabit could get the plaintexts
whenever someone working there wanted (or whenever they
were compelled to do so by a government, criminal
organization, etc.).
Assuming good faith and a reasonable storage implementation, it is possible that Lavabit is not capable of providing plaintext messages on demand. I heard somewhere that messages were stored with a key derived from the user's password; if true, then a warrant for johndoe@lavabit.com might not be fulfillable until after the next successful login from johndoe@.Sure, but this warrant makes it pretty clear that the government was seeking message bodies, attachments, etc.:
http://ia600908.us.archive.org/9/items/gov.uscourts.mdd.2362...
"I heard somewhere that messages were stored with a key derived from the user's password; if true, then a warrant for johndoe@lavabit.com might not be fulfillable until after the next successful login from johndoe@."
...or to try brute forcing the password offline, which has a reasonable probability of working. Either way, it is not any different than the situation with Hushmail, and I would put both squarely in the "snake oil" category.
You have an awfully high standard of what you define as "snake oil" cryptography. If a brute force effort to derive the secret key constitutes snake oil, I have bad news for you regarding the state of crypto.
That being said, brute forcing a password is not the same thing as brute forcing a secret key. The distribution of passwords that people can remember is not even remotely uniform, and the distribution of passwords that people actually use is even more heavily biased.
Compare to GnuPG: the attacker needs access to your computer before he can even attempt to brute force your password or try to capture it.
You have not established that that warrant was for accounts of the second type.
You have not established that the contents of the DVD were readable by the authorities.
You have not established that the type of person who would have a Lavabit account would be the type of person who would choose a password which has "a reasonable probability" of being brute-forced in under a decade.
Why do you assume he's a lying bastard like the people at hushmail?
This was maybe a year or two ago. Sorry I don't recall enough, or have time to look this up. It may have been a lower court decision, subject to appeal.
This is really the point that bothers me - if the NSL type of thing is now going to extend to removing the right of server operators to decide what code will or won't run, then this campaign against citizens being able to communicate privately shifts from "design a non-tappable service" to more like a whack-a-mole situation with only transitory, small scale possibilities of private communication being available.
Edit: also this: https://news.ycombinator.com/item?id=6208631
For one thing, Ladar is the only person at Lavabit with access to the servers or hosting environment. Absolutely no one could access the plain text version of anything (password or email contents) without the password to an account, because all data for a specific user is encrypted using a key that is stored as an encrypted string in the database, without the account password the key cannot be decrypted.
Now, it would be possible for him to have installed software to intercept the password for a specific user when they authenticate, I have no idea if he ever had to do that. I do know that he's obligated by law to comply with court orders, you can't just refuse to cooperate if federal officials give you a warrant, if you don't cooperate they will throw you in jail until you change your mind. Those rules apply to every American company, not just Lavabit.
1. Allow a hacker to read your messages by attacking the mail server?
2. Allow a spy to read your messages by gaining employment with the service provider?
3. Comply with a broad, non-specific warrant?
2. N-part keys go along way for this. No one employee has the ability to do the things for warrant compliance. Yes still gamable, but so is any system. See 1.
3. Shut down when a non specific warrant is received. Have a big red button that kills everything. Make the system so that it deletes everything if more than N warrant accesses occur in M time units. In the worse case, passive agressive compliance that causes big outages, unintentional security leaks, and so on (while implementing the removal of BRB and N/M scheme) would go a long way in making the paranoid move on before following the world.
Secret sharing makes sense, but not in the context of a system like Lavabit. Where secret sharing makes sense is in identity based encryption, which is similar to Lavabit in that keys are generated by a trusted authority, but is different in that the authority does not store keys or decrypt messages. Threshold IBE is useful in settings where there are multiple key generation authorities, which must jointly compute secret keys from their shares of the master secret.
Finally, I would not rely on anyone to shut their service down in the name of fighting an overly broad warrant. First, whether or not a warrant is too broad is a matter of opinion, and the service operator's opinion may differ from my own. Second and more disturbing, there is no guarantee that the service operator can legally shut the service down when such a warrant is received. As I said elsewhere, Lavabit's users are lucky that the founder was willing to take a stand like this; it is not something I would expect.
While cited as an 'encrypted' email service, it apparently operated as a normal (web)mail server by default.
Uh, what? This could almost be the story satirized by this passage from 1911:
"A certain German art expert, who had obtained from the municipality of Bergamo permission to inspect the famous masterpiece, declared it to be a spurious Pincini... The editor of an Italian art journal refuted the contentions of the German expert and undertook to prove that his private life did not conform to any modern standard of decency. The whole of Italy and Germany were drawn into the dispute, and the rest of Europe was soon involved in the quarrel. There were stormy scenes in the Spanish Parliament, and the University of Copenhagen bestowed a gold medal on the German expert (afterwards sending a commission to examine his proofs on the spot), while two Polish schoolboys in Paris committed suicide to show what THEY thought of the matter."
-- Saki, "The Background" (http://ebooks.adelaide.edu.au/s/saki/clovis/chapter6.html)
They're nothing alike. Suppose Silent Circle sent an email to all its users announcing that they would destroy the data on the server in 7 days. It's a good bet the government has accounts on most privacy-advocating web services, simply to keep tabs. That gives the government 7 days to try to get a FISA warrant, or if they think they can get away with it, unilaterally issue a NSL.
They would only be able to subpoena a few of the email accounts (or maybe a lot, but certainly not all), but that still breaks the privacy model many people assume given its advertisement as "secure" webmail.
Silent Circle didn't want to take the chance, and your hyperbolic parallel notwithstanding, they had good reason to do what they did.
I was assuming that:
a) Lavabit can't access its users' email, so any subpoenas are ineffective at getting at emails stored in their servers.
b) However, the feds would force them to snoop on decrypted data for specific accounts as it is served back to the user. This would only give access to what the user happens to read after the order goes into effect.
c) They received a new order that was a lot more invasive, perhaps to snoop on all plaintext data as it left their servers.
d) They suspended operations before any such snooping could occur.
If all this is true, any other operation can follow the same steps. If the feds ask for too much, we suspend operations immediately, no 7 days. But they wouldn't need to preemptively suspend before the feds come knocking. Is there something wrong with my reasoning? Were you making different assumptions?
Now I dont know if the NSA attempted that with Lavabit, or if Lavabit willfully ignored that demand, etc but the government does have that legal power.
"In the name of the general welfare, to protect the people's security, to achieve full equality and total stability, it is decreed for the duration of the national emergency that:
...
Point Two. All industrial, commercial, manufacturing and business establishments of any nature whatsoever shall henceforth remain in operation, and the owners of such establishments shall not quit nor leave nor retire, nor close, sell or transfer their business, under penalty of the nationalization of their establishment and of any and all of their property.
..." [1]
https://en.wikipedia.org/wiki/Thirteenth_Amendment_to_the_Un...
The problem with that is you know your service is going to be used by criminals, child pornography, organized crime, terrorists etc. So if you start this service you know you're going to have to comply with government requests for that data. It seems disingenuous to complain about their requests as though you didn't expect them and that they wouldn't e reasonable. And I think he's saying that in his own way when you get into the details: "Yep, I supported the narrowly defined ones but the broadly defined ones are the straw that broke the camels back"
It's a power grab. Pure and simple. Those who control this system can easily find dirt on their political/corporate opponents, while being completely immune.
They might stop some occasional clueless idiot terrorists or CP distributors, but that's not the end goal, that's just the political theater.
You really think terrorists don't properly encrypt their conversations?
You really think high-level criminals don't properly encrypt their conversations?
Think again.
Funny story about that:
http://www.theregister.co.uk/2006/04/19/mafia_don_clueless_c...
http://www.telegraph.co.uk/finance/newsbysector/banksandfina...
> Hi Guys, We got a big position in 3m libor for the next 3 days. Can we please keep the libor fixing at 5.39 for the next few days. It would really help.
(I actually think there are high-level criminals among terrorists, mafiosi, Wall St., and even computer programmers. But of course the existence of such high-level criminals isn't an excuse for a government to abandon the rule of law and violate its constitution...)
High-level criminals otoh are most certainly savvy enough to not communicate important information through unencrypted channels.
This requires one to believe and accept the official threat level. I don't.
How about the different between narrowly-defined detention and wholesale just-in-case detention of everyone?
The two are directly analogous, in that scope makes all the difference in both cases. It's entirely possible to support detention of reasonably suspected criminals, and at the same time oppose formation of mass concentration camps. Nothing disingenuous about that.
> The problem with that is you know your service is going to be used by criminals, child pornography, organized crime, terrorists etc.
Thats a huge stretch and abuse of logic IMHO. Don't build roads because criminals and terrorists will drive on them. There will be also UPS/FedEx couriers delivering printed child pornography driving those roads. So better, setup checkpoint and unmanned vehicle x-ray type scanners and set them up every where on highways.
More insane: don't open a barber shop, because if you have hairy guy robbing bank next door, he can get a haircut at your place and cops will have hard time recognizing him.
I don't think every one and each of Lavabit 1,500 paid customers were terrorist. I understand and respect people willingness to have a safe and secure email, as Constitution says you should feel save and secure in your own skin.
> So if you start this service you know you're going to have to comply with government requests for that data.
We don't know what really happened. Knowing how feds work just a little bit, I wouldn't be suprised if owners were intimidated via FBI/CIA/DEA/IRS and plenty other Government Organisations. I wouldn't be suprised if owners, their families and their friends would fall under heavy scrutiny and deep IRS audits. There is really soo many things Feds can do not to break the law, technically, and still harass $hit out of you and your family.
If they fall on each gov request, next we will have that barber share his info, just because feds want to. You know, terrorists are humans; they do get haircut sometimes too.
Just thought those two sentences were funny being right next to each other.
Let's be honest here, though: The percentage of people using his email service for illegal reasons is much higher than the percentage of people using roads for the same illegal reasons. It's the same problem that Pastebin faces,[0] and it's the reason paste.pocoo.org shut down.[1] Services that advertise complete privacy and anonymity get swamped with people who want to hide illegal activity.
[0]: http://www.tgdaily.com/security-features/62490-pastebin-to-p...
I think people forget that freedom includes risk.
PS: I'll say what has been said again, Lavabit was so close to being wildly successful, it's a shame that an insecure govt leadership decided to squash a thriving venture. Though it was a likely conclusion because of centralized ownership.