Lavabit Defied FBI Demands to Turn Over Crypto Keys, Documents Show
wired.com
wired.com
EDIT: Since I posted the link 30 minutes ago, there is roughly $1200 more in fund and I'm guessing that it's mostly from HN. So keep it up.
$29,341 Raised of the $40,000 goal.
Then, I thought about what might happen if I don't.
But, if everyone donates without regard of consequences then there will be none. So just donate!
Although there is a very long way to go, America currently seems to be on path towards East Germany or China style surveillance.
”Every man should know that his conversations, his correspondence, and his personal life are private.“ - Lyndon B. Johnson
But even professions that have confidentiality baked into their core (clergy, shrinks, doctors)* can be compelled to provide info to law enforcement. In some cases, they are legally required to report illegal conduct.
*EDIT: not attorneys (for the most part)
[1] http://en.wikipedia.org/wiki/Attorney%E2%80%93client_privile...
EDIT: It kind of sounds like this is a grey area for attorney-client privilege[1]. I'm sure someone could successfully argue that privilege does not apply here because a) "LawyerBit" is not acting primarily as an attorney b) Email being email, the communications are disclosed to third parties
[1] http://en.wikipedia.org/wiki/Attorney%E2%80%93client_privile...
Or even constructed such that the lawyer was central to all communication.
So client A contacts the lawyer to advise client B of X. The lawyer dutifully complies (perhaps in an automated fashion).
Whenever Client A wishes to contact another party who is not a client of the lawyer, the lawyer is given a client lead from Client A. The lawyer emails (the only time when mail goes to 3rd parties) the party, inviting him to go on his retainer so he can advise him on Client A.
While such a system would have to be automated, the system could delete any evidence of this automation, or at least plausibly deny specific instances of the automation.
Thus, all involved could argue the lawyer was manually involved every step of the way in the process, which only ever occurred on the lawyer's system, and the client systems of his clients.
Then the lawyer couldn't delete the systems like Lavabit did because the government would have confiscated them as evidence of the conspiracy.
At that point, however, the 5th Amendment should apply, because the server provides evidence of a conspiracy the lawyer took part in, providing the encryption keys would also be providing evidence of the conspiracy; requiring the lawyer to testify against himself.
Some judges have tortured the 5th Amendment worse than this, so it's not entirely foolproof. Still, it's unlikely other lawyers would take this sort of abuse standing down, nor would the general public.
So even the most extreme legal logic I can think of would be unable to penetrate this arrangement, providing the computer security and encryption was all top-notch. Disclaimer: IANAL, though I'd be willing to be the IT employee for any legal firm that wanted to construct such a system.
You are doubtlessly right, though still fun to think about.
The law is (thankfully) not like code, and you can't always make a clever hack around the letter of it. When lawyers can, well, that' why they get paid well.
In a lot of states, for example, you can compel an attorney to testify about future or ongoing crimes, but not completed crimes someone is seeking legal advice for.
As an example, this is covered in california evidence code as section 956:
http://www.leginfo.ca.gov/cgi-bin/displaycode?section=evid&g...
"956. There is no privilege under this article if the services of the lawyer were sought or obtained to enable or aid anyone to commit or plan to commit a crime or a fraud."
1) Select an amount (I picked $25 as a test) 2) Advance to 'Step 2' 3) Go back to Step 1 4) Pick an amount again 5) Go to 'Step 2' 6) Fill out the form in detail 7) You'll be unable to hit the 'Continue' button
Edit:
Repeatable on other fundraiser pages.
I'll send the same via email.
John Gruber at Daring Fireball has been doing a lot of work to encourage people to donate. I think the latest uptick has been the fireball effect at work.
I find that limitation to "American" (surely meaning US american) people an incredibly embarrassing and nationalist call to action and it alone made me instantly close the tab.
Unfortunately, the Constitution of the United States of America, the sacred document that Mr. Levison was attempting to preserve, does not guarantee that right to every human being -- only Americans.
I look at it at a first step. Once we've "restored" the Constitution and managed to guarantee the right to privacy for those covered by it, only then can we start to "expand" that to include every human being.
I have many friends from all around the world and I believe 100% that all of us should be afforded that same right to privacy that the Constitution gives me, but we've got to start somewhere...
(Disclosure: I'm an American and I have and do donate to the EFF, EPIC, the Tor Project, and I happily gave to Mr. Levison's defense fund immediately after it was announced a few weeks ago.)
Like I said in the thread [0] linking to this crowdfunding campaign, I'm normally I'm hesitant to post one word comments like that, but in this case showing your donation breaks conformity behavior in large anonymous groups like the innocent bystander effect.
It looks like there is a new $96000 goal... someone else will have to do their share to pitch in.
"particularly describing the place to be searched, and the persons or things to be seized"
Clearly this is a violation of the 4th Amendment as such a key would give them the ability to conduct unfettered and "unparticular" searches. A more targeted, and constitutionally legal, approach would have been to order lavabit to use, but not disclose, the private key to decrypt specific emails from specific people. Given that the police know the public key, they could verify that lavabit had supplied correct decryptions.
Are there any older physical parallels to this? What happens if the police, in the process of securing a lawful warrant, require access to a physical master key or combination or etc. which would open a great deal more than access to the suspect's belongings?
When lavabit refused to comply,the FBI got more aggressive. Which seems like exactly what would happen. Think about it. What if the FBI subpoenaed financial records from a Bank who refuses to open the safe they were in. Well, the US Marshals are going to show up at the bank with a court order,break open the vault, and get access to all the records and take the one they want. It's not an unreasonable search provided there are checks that they only get the one record they are looking. In fact, arguably the Bank breached it's duty to it's customers by forcing the US Marshals to go through all their records rather than the Bank doing it self.
Obviously, it's not so clear in this case since Lavabit apparently finally did offer to hand over some data, but it is along those lines.
A commenter on that story makes a good point: Forget for a moment that the user they were looking for was Snowden. If the FBI had been looking for info for a case against a serial killer or a child porn ring, would we still hold Lavabit as heroes for not following the court order?
Of course they knew who they were looking for - it was necessary for that to be disclosed in order for the government to even demand the information in the first place. That's what a warrant is.
For as much was wrong with the government's request, it's first request was at least reasonable: specific knowledge on Edward Snowden. The inherent architecture of Lavabit rendered this request unreasonable, and things escalated from there.
Sure enough, the court documents and transcripts clearly have "target" followed by blacked out spaces just wide enough for Snowden, spoken by both lawyers and Mr. Levison. This happens dozens of times throughout the recently unsealed documents.
That's why the FBI changed tack and asked them to turn over the SSL private keys - because that was information that Lavabit already had, and the FBI could use those keys to record the information they wanted for themselves.
I would, because it's impossible to forget for a moment about Snowden. The context cannot be ignored; this is about Snowden. It's better to let 1,000 guilty men go free than 1 innocent man behind bars. As far as I'm concerned Snowden did the right thing and if protecting other criminals is the only way to ensure Snowden's protection... so be it. To quote Armin from Attack on Titans: "If you aren't willing to sacrifice anything, you can't change anything". In this case, sacrificing the chance to punish the guilty is worthy of protecting the innocent.
Oddly enough, this is why I have issues with the way in which people now protest against unjust laws.
The effectiveness of civil disobedience comes from putting authorities in a position where they must enforce an unjust law to the letter, thus demonstrating to the general public the injustice of the law itself and rallying support to change the law.
This means that civil disobedience effectively requires the person engaging in it to suffer the consequences of disobedience. If a law is unjust, but violators who attempt to demonstrate this can simply walk away relatively unscathed, then it's a lot more difficult to make the case to the public at large that the law is unjust. After all, that guy jumped up and down on the law, and got away with it! How bad could it really be?
But it seems that what we have now is a generation of people who are willing to take the step of declaring the law unjust, and willing to take the step of breaking it to make a point, but unwilling to suffer the consequences which would demonstrate the injustice to the public. Which accomplishes little.
When Lavabit first shut down, they claimed that they have no problem complying with individual court orders, but refused to be complicit in crimes against humanity. Perhaps they protected Snowden to enable him to publicize those crimes, and that if the target was a serial killer, Lavabit would have complied.
Furthermore, contempt of court should come with the ability to renounce your citizenship and be deported as a political refugee. In fact, that should be the punishment if fines don't work, not jail. Contempt of court is simply a statement that "Previously I lived in this country and supported its laws, but I've committed no crime and am now asked to support some aspect of this nation's laws that I don't agree with. I am now choosing to reject those laws as my own, even if that means that I will be deprived of the right to live in this nation." I really don't understand how jail time eventually become the punishment for rejecting laws but having committed no crime.
That being said, anyone who is in jeopardy of having to give up their citizenship should have due process in a court of law before being forced to do so.
It's not Snowden, it's a "criminal."
This kind of logic screams for Godwin. Or to be more precise, Milgram.
I find the sense of entitlement the FBI had quite disturbing. Perhaps it is technically true, but they clearly had an attitude not just that they were legally authorized to access such information, but that nobody should be allowed to stop them having it, and any personal cost involved or moral objection is not part of the equation. For me the two do not connect that way - I am entitled to buy a house but nobody is required to help me do it, and if I don't have the money, I'm screwed. It doesn't allow me to murder the guy down the street so that I can take his money to buy the house I want.
The question is, is the FBI allowed to recruit any civilian to do anything they think is necessary to get at some information they are authorised to acquire? Can they go to your grandmother and tell her to prostitute herself if that will help them? At what point does technical ability to accomplish something render you at the mercy of the state to do whatever they tell you? It is one thing to demand someone actively stop obstructing something. But to demand they actively assist goes a step further. The notion of conscientious objection has been accepted and even honoured and respected, even in times of war.
I don't know where this line is. But I know I'm very uncomfortable with the attitude that law enforcement showed in this case.
If Snowden showed that some people in government were violating the Constitution, and other people in government were trying to suppress his evidence, would that not mean that the people trying to suppress the evidence are complicit with the violators?
Even if these people didn't swear an oath to protect and defend the Constitution, it is still the law, and they are still bound to obey it.
So, what's the penalty for helping someone violate the US Constitution? And who enforces that?
Basically, people should stick to the law; dealing drugs or soliciting paid sex are both crimes, no matter who you do it to/with.
No it isn't. The government isn't entitled to jack shit. They can demand whatever they want, and they may be able to take it through force, or threat of force, in 99.99999999% of cases, but if the request is bogus, it's bogus, and an individual certainly has the right to take a moral stand and say "no, fuck off".
Now, that individual will probably have their name drug through the mud, be bankrupted, and wind up spending the rest of their life at Gitmo, but they can say "no" if it's important enough to them.
Some people are willing to die for causes they believe in, so it's not such a stretch to think that somebody, somewhere, would tell the govt. to fuck off in a case like this.
Your claim here appears to be that the government has only power, not authority (i.e. power + some sort of legitimacy or moral right to use that power). Is that your position? If so, under what, if any conditions do you believe the use of power against other people is legitimate?
Self defense. I hold basically the same position as Bastiat, in thinking that government can only legitimately be considered the "collective extension to our individual right to self defense".
http://www.emaildiscussions.com/showpost.php?p=558661&postco...
I apologize; it was not my intent to mislead (though it appears that I did so inadvertently). I was told that the outage was related to maintenance regarding the storage system
from one of the Lavabit admins.
How illegible? I'm really curious about this part.
We already know he was basically giving them the middle finger by printing it AND printing it very small. He would clearly need to do something extra odd to make it do this.
He might have done some less efficient encoding, like Base-16.
But still very much illegible.
He could have been "helpful" and provided ancillary information along with the keys.
The intelligence community has put us in such a bad spot that anyone who actually tries not to do something unethical, which should really be the default, is now exceptional and lauded.
Lavabit stood up, and that's admirable. That it's this admirable is a really bad sign.
He could have easily quietly given them the key (if he had it?), and then live the rest of his life with success and guilt.
Very, very few people would throw themselves in front of a bus the size of the US government to save an honest stranger. Those people are worthy of calling heroes.
That's exactly my point. This is not a situation he should have been in. In our current political environment, absolutely, his actions were heroic. But all he did was what he should have done. That the potential consequences for that are so horrifying is what makes this entire situation incredibly wrong.
And even so, it still doesn't change the fact that it would have turned all their business claims into giant lies, possibly even exposing them to suits for false advertising, etc.
That is a meaningless distinction. It is the difference between having to type a large number of characters (not even that large -- how hard is it to capture a password?), or a small number of characters. Lavabit, as designed, could access any user's email the moment that user logged in. That is obvious to anyone who understands what encryption is. It is an inherent vulnerability in every system that does what Lavabit/Hushmail/etc. do.
"And even so, it still doesn't change the fact that it would have turned all their business claims into giant lies, possibly even exposing them to suits for false advertising, etc."
If Lavabit advertised itself as an email service that cannot read your email, then that suit could have happened regardless, because the claim is untrue. If, on the other hand, it was advertised as a service that will not read your email and that protects your email while it is stored, that is different and would not have been affected by their cooperation with the FBI's demands.
The 'not complying' is only a side effect, and is more so tantamount to a refusal to do work for the government in opposition to lavabit's own business promises. I'm not sure the government in any instance has a right to compel work to meet their specified ends.
Imagine a mail service that operated solely as a Tor hidden service and required all users to use PGP --- for instance, by checking the contents of mail messages to ensure they were encoding them, and rejecting them if they weren't. That's a service that might reasonably make a promise not to cooperate with a court order.
Lavabit didn't have that system and instead had to make a difference promise: that they would shutter the enterprise before cooperating with a court. And so they did.
There are costs of doing business and one of the costs is the ability to comply with lawful court orders. You are completely wrong about the government lacking the means to compel compliance.
Edit: To tone that down a bit, "Moral Mazes" by Robert Jackall is an excellent although academic work on the ways in which corporate and government ethics differ from commonly espoused personal ethics. I find it a valuable key to trying to understand attitudes toward conscientious leakers such as Snowden. I am implying a value judgment, but realize the details are complex.
Generally: I think that when the core promise of your business is that you'll do everything you can to resist incursions on user privacy, then yes, it should be pretty common for those promises to be scrutinized.
I'm sure it's that too, but I've currently got it checked out as an interlibrary loan serving as my bedtime reading, and I'm finding it really insightful. But perhaps this is because I'm starting from a point of bewilderment as to what motivates most people to act as they do.
> a more intellectually credible way of saying "the whole system is out of order!"
But the miracle is that rather than being out of order, the system mostly works, and tends to keep working. What I like about the book is that it strives to explain the situation from the inside as a mostly coherent belief system, rather than critiquing it from outside as untenable.
At best Lavabit only ever provided security between logins i.e. when the data is "at rest." Any claims of security beyond that are, to be polite, overstated.
Their expectations of others reflect poorly on themselves.
Hence the need to develop systems for which the first "no" is the only "no": "no, we don't have the client-side encryption keys, and there's no way for us to give them to you, nor is there any way for you to surreptitiously insert them into the Open Source client software without being noticed, nor are we obligated to accept your patches introducing security holes which will effectively destroy our entire business/project credibility".
It needs to be more difficult to use your project as a tool for surveillance than it is to personally compromise a specific end-user system.
(That's not to say we shouldn't pursue legislative solutions eliminating the requests in the first place: we need to fight surveillance capabilities on both fronts, legal and technical.)
And, to really make it secure, you need to go outside of the smtp world, because all smtp has some amount of meta-data that gets transmitted in the envelope. And that meta-data can be just as damning as the contents of the messages.
I don't expect there to really ever be a truly secure email service, unfortunately.
http://s3.documentcloud.org/documents/801182/redacted-pleadi...
"shall furnish agents from the Federal Bureau of Investigation, forthwith , all information, facilities, and technical assistance necessary to accomplish the installation and use of the pen/trap device."
Let's not beat around the bush. You're willfully missing the point. The lawfulness of the order is not at issue; the target of the order is. I would happily obey a lawful order to turn in a fugitive rapist hiding in my basement; I would not willingly obey a lawful order from the same authority to turn over an escaped slave, even if I lived in a slave-holding nation.
If you don't think that Snowden should have broken the law to inform the public of massive, unsupervised, hidden government surveillance and lies about same, that's fine. But say so, don't go making disingenuous sidewise arguments and thinking you're sly. Yes, Levison disobeyed a lawful order. Laws should be obeyed because they are just, not because they are laws.
A search warrant was signed by a court for federal agents to retrieve/collect evidence for a specific target. How is what the FBI (and prosecutors) demanded different than a normal wiretap?
edit: If the FBI's order could not be completed in a way that would NOT compromise ALL users, then of course Lavabit should have resisted. My question is based on the assumed validity of this statement in the OP:
> The July 16 order came after Texas-based Lavabit refused to circumvent its own security systems to comply with earlier orders intended to trace the Internet IP address of a particular Lavabit user.
The data the FBI wanted wouldn't have just unearthed Snowden's emails, but everything by every Lavabit user. And if you believe that information wouldn't have made its way to certain other 3 letter agencies...
Delivering the information this way could be construed as merely avoiding paper-costs while using formats the hide-bound government officers would be most familiar with (paper). It's somewhat facetious, but you can almost say it with a straight face, and a tech-illiterate judge might even accept it (especially if you did something just slightly more legible at 5 or 6 points).
It would be impossible for anyone to claim with a straight face they complied if they did as you described. Lavabit can claim they provided the keys in a fairly digestible format, and it bought them a few days worth of time.
Also, a single character at 4 pt surrounded by whitespace is much, much easier to decode.
Finally, most courts would charge you for delivering that much paper. For similar reasons, paying court fees in pennies is not accepted by all jurisdictions.
Lavabit even admitted, they already assisted investigators in the past for investigation on a specific user. Apparently that request was legal in the view of the Lavabit owner, so there should be something different here.
It sounds like he was incurring some significant fines as well, so he was left with the choice of undermining his entire business model, or closing down.
I was talking about that unclear first request above.
I'm hopeful it will be overturned at the 4th Circuit, rather than waiting for SCOTUS. There are so many ways to challenge it. The only way we'd be fucked would be if Ladar didn't have the money to appeal, but it's a super tempting case for anyone at EFF/ACLU/etc. Funding the appeal to the max would also be in the self interest of any cloud business in the USA.
Just like Jewel v. NSA was always destined to be a landmark case, and now will be, after the executive privilege crap got thrown out.
Did the HN ranking algorithm change or did I miss something?
Here the screenshot http://imgur.com/7Yh9XB2
So while it might not be broken in the way we usually expect crypto to be broken, it continues to be broken from a trustability point of view.
(in this case the wrench is metaphorical)
(Reminds me of a Howard Roark moment to be honest)
Unless I'm missing something?
As it was implemented, the only option they had was to demand Lavabit's private key, since they use the same SSL cert per user.