BTW it's a really nice article, gives a nice personal side to the whole story.
BTW it's a really nice article, gives a nice personal side to the whole story.
http://ia600908.us.archive.org/9/items/gov.uscourts.mdd.2362...
Take a quick look at attachment B and you'll see that Lavabit was asked to provide the plaintext message bodies and attachments of emails sent by the user. This was not a demand for metadata, it was a demand for messages, and it was a demand that Lavabit complied with.
This is really not any different from Hushmail.
Of course Lavabit would not be the one brute forcing the passwords. That is not the point. The point is that the security of Lavabit is a matter of the user's password, and only in the best case where the user does not log in.
Ultimately Lavabit's security is a matter of the trustworthiness of Lavabit's employees, not the size of your key; it is marginally related to the strength of your password, but only under very specific circumstances. The fact that cryptography is being used somewhere in the system is a distraction. If instead of the US government showing up with a court order it had been a Chinese spy sending business secrets back to the Chinese government, would you still be defending Lavabit?
From what I see, they were ordered to provide all messages, records etc. stored on that account and related logfiles. It does not specifically say "plaintext", so Lavabit might have provided them with the encrypted e-mails and no logs (if they had none) and still be in compliance with the warrant (IANAL!). You cannot possibly be forced to provide something you do not have, right?
It is true that the subpoena asked for it, but a response to a subpoena that supplies what can be supplied and explains why the rest can't be supplied would not trigger another court docket entry unless the government didn't believe the explanation.
Because a subpoena is filed before the government actually contacts the witness, the government typically asks for everything it could possibly get or want.
In the US when it comes to subpoenas from civil or criminal courts, you only need to produce "books, papers, documents, data, or other objects" in your possession. The passwords were not in Lavabit's possession at the time it received the subpoena. Furthermore, subpoenas can be quashed if they are " unreasonable or oppressive" (see e.g. FRCrimP 17c). Asking a witness to write custom code in order to capture a user's password is a textbook example of an unreasonable request.
The rules for national security requests on the other hand are entirely different. 50 USC 1805(c)(2) requires the recipient of an electronic surveillance order to:
"(B) that, upon the request of the applicant, a specified communication or other common carrier, landlord, custodian, or other specified person, or in circumstances where the Court finds, based upon specific facts provided in the application, that the actions of the target of the application may have the effect of thwarting the identification of a specified person, such other persons, furnish the applicant forthwith all information, facilities, or technical assistance necessary to accomplish the electronic surveillance in such a manner as will protect its secrecy and produce a minimum of interference with the services that such carrier, landlord, custodian, or other person is providing that target of electronic surveillance;"
There's always a way to access the data. Cloud-based email is...cloud-based...which means that it's susceptible to man-in-the-middle and other forms of attack.
It's possible that the government was asking Lavabit to modify its systems such that the encrypted data guarantee would no longer be real, and then they demanded that he hide that fact.
I'm honestly not sure what to think about that. Should private data storage be permitted? Is there a difference between your private data in the cloud and your private data on a system at your home?
Who is arguing that? In this case, the issue is not about whether the government has probable cause. The issue is that any system that allows Lavabit to respond to a warrant can be used for mass surveillance, industrial espionage, etc. This conversation happened 20 years ago when people were arguing about key escrow. Almost nobody argues that the police should not be able to investigate crime; the argument is that backdoors are a massive vulnerability that leave innocent people, for whom the police have no warrant (or no "specific" warrant), at risk.
"Cloud-based email is...cloud-based...which means that it's susceptible to man-in-the-middle and other forms of attack."
The problem is not that the mail service is run by a third party. The problem is that encryption, decryption, key storage, and even key generation are being performed by a third party. I send encrypted mail through GMail all the time -- and Google is not able to decrypt those messages, even if they are presented with a warrant. While it may be problematic for the police to face such a situation, it would be problematic for me if criminals and spies could read my emails, and at the end of the crypto wars Congress determined that the need for good civilian crpytography vastly outweighed the government's needs to enforce laws and spy on other countries.
It is also important to remember that the police can still get messages that are encrypted/decrypted offline, they just have to work a bit harder for it. For example:
http://yro.slashdot.org/story/00/12/06/0255234/fbi-bugs-keyb...