This wasn't untested water, either. The exact same thing happened to Hushmail for the exact same reason, and should have been evidence enough that the model isn't viable.
So I think we should definitely support Ladar as a person, but we also need to be careful not to confuse that with supporting Lavabit, which was a very real danger that should never be repeated again (again).
Could you clarify what you mean by "How was it a handwave if it actually worked?" Lavabit, like Hushmail, has had no problem giving up information to law enforcement in the past.
Ladar claimed that he had no way to access user emails. The hidden subtext of that, which was sort of hand-waved away, was that he had no such access with the code he had written, and that all that stood between your mail and his eyes was his own willingness to write that code. The entire security of Lavabit depends on Ladar and his principles.
These systems are entirely built on code, and code is malleable. If you have control over the code that gets executed at every point in the stack (which the operator of a web app certainly does), there's always room for the operator to change the code and therefore change the behavior to do anything, including log things that were previously considered secure.
> The entire security of Lavabit depends on Ladar and his principles.
That has always been true. If he was a less scrupulous individual, he could have run an off-the-shelf e-mail solution with 0 fancy security, but claimed that it was all secure on the backend in his marketing. You wouldn't know the difference, because you can't audit the source code.
Unless you have the access, time, and expertise to perform your own source audit, any claims of security are always implicitly built upon a foundation of trust that the operator is doing what it claims.
Which is exactly why nobody should have believed Ladar's claims in the first place. He trumpeted the fact that he had not yet developed any wiretapping capability and tried to distract everyone from the hard reality of "encrypted webmail."
This is why real security and privacy require end-to-end encryption.
The trust model has to include the device/OS/browser/etc that you're accessing the device on as well as all code and keys (including WOT servers, GPG keys, and the webmail code itself, or, if locally installed, all binary packages, updates, etc).
Which I think is the point is really that in the face of a government who can compel, e.g.,
* an OS vendor to install a backdoor in their software, * a microprocessor vendor to critically weaken the Random Number Generator, * the author and BDFL of a key operating system kernel to use said RNG, * a distribution to include compromised or even unsigned packages, * a mobile carrier who will allow random hardware on their network that can sniff, MITM, and inject evil data, * a mobile phone manufacturer who will install CarrierIQ, * (heavens!) a user/customer who visits an app store and installs an application with either a trojan attached or one that is directly a trojan,..
In other words, no amount of end-to-end crypto will save us if we're attacked at each end and in the middle by people who will stop at literally NOTHING (jail) just to get at the data. This is why Schneier wrote "The Government has betrayed the Internet."
http://www.theguardian.com/commentisfree/2013/sep/05/governm...
Encryption is no panacea when you're dealing with someone who controls both ends and the middle. :( To put this on Lavabit is poor form, IMO. This is one end who stood up and fought and paid a huge price.
Which is why, as I have said elsewhere, webmail is the problem here; more generally, you cannot have security or privacy as a service.
As for the government pushing back doors into products, that is at least upping the ante. It is harder to sneak back doors into software that people are actually using, especially software that is widely used, than it is to sneak a back door onto a server than only a handful of people can inspect. It is also harder to sneak in a back door when there are many, separately maintained implementations of a common protocol; you are forced to try to sneak a back door into an abstract description, which a lot of experts will be reviewing (see e.g. DUAL_EC_DBRG; the backdoor was discovered within a year of the PRNG being publicized).
There are also limits to what sort of back doors can be put at a lower level. Suppose you sneak a back door into my CPU, but I am running software that was developed after you developed your back door. You can make a straightforward computability argument that in general, your back door will be rendered useless by unexpected changes to software, particularly sweeping changes to it.
In any case, my point is not that encryption is a panacea, but rather that webmail is, by its nature, insecure. There was no way that Lavabit's security could have ever been more than just a handwave.
This is it in a nutshell.
If you're going to use an appeal to authority, then Bruce Schneier is not the way to go. He's a cryptologist but he does make many unfounded claims.
I remember this happening. Since whoever runs Hushmail didn't go to the press and his blog and make a big scene after being approached by the feds (both for the US and Canada, mind you, since Hushmail's a canadian company). There's a reason why Hushmail was targeted, it was at the time the best way to figure out who's shipping large quantities of drugs everywhere. In the same year, Hushmail and eGold became compromised and Bush passed a law stating police can open your mail in USPS if they think you're a terrorist (previously they needed a warrant which by the time they obtained one you'd already have your package). Coincidentally, this was I believe around the time Silk Road started up. :)
So, Hushmail was involved in the pre-Silk Road days of internet drug trafficking, and I'm pretty sure that is not the position they wanted to be in. We'll never know if Hushmail was "forced" to give up users' information, but I would say that even if they didn't want to, they pretty much would have no other choice other than shutting their doors.
He could have complied with one of the several valid court orders that requested he give the FBI data on a specific account but stopped short if installing FBI code or devices on his system or handing over the keys. Had he done so, it would have stop there.
Instead, it escalated to the point where he actually was forced to expose all his users. Anyone who has transcripts of those connections (e.g the NSA), can now read them, get the passwords, and decrypt any mail they got form the server. It seems like a boneheaded move unless his only goal was to protect Snowden at all costs.
He rightly observed that those leaked keys would then get into the hands of God-only-knows-who.
From the newyorker article : "On June 10th, the government secured an order from the Eastern District of Virginia. The order, issued under the Stored Communications Act, required Lavabit to turn over to the F.B.I. retrospective information about one account, widely presumed to be that of Snowden. (The name of the target remains redacted, and Levison could not divulge it.) The order directed Lavabit to surrender names and addresses, Internet Protocol and Media Access Control addresses, the volume of each and every data transfer, the duration of every “session,” and the “source and destination” of all communications associated with the account. It also forbade Levison and Lavabit from discussing the matter with anyone. "
Sometime after his initial refusal and then offer to comply with some caveats that the fed's interpreted as stalling:
"Prior to the hearing on July 16th, the U.S. Attorney filed a motion for civil contempt, requesting that Levison be fined a thousand dollars for every day that he refused to comply with the pen-register order. EARLIER IN THE DAY, Hilton issued a search-and-seizure warrant, authorizing law enforcement to seize from Lavabit “all information necessary to decrypt communications sent to or from [the account], including encryption keys and SSL keys,” and “all information necessary to decrypt data stored in or otherwise associated with [the account].” (emphasis mine)
[O]http://www.wired.com/threatlevel/2013/10/lavabit_unsealed/
The stated use of these two things was to get information concerning a single person, but they never wanted just that information. On page 100, Levison states that he can manage to get the information the FBI is looking for, without providing the FBI with Lavabit's encryption keys. Someone (AUSA[censored]) says that the proposed solution does not satisfy the subpoenas and court orders, because it would not provide real-time access to the data.
---
In your linked documents,Exhibit 1 is the original June 10th order. Attachment A of it(page 4 of the PDF) details what he was order to hand over. It does not mention SSL keys at all. Instead it asks for a bunch of meta-data. In fact, it explicitly doesn't even cover communication contents. It also doesn't specify how Lavabit has to execute the order, just that it must provide the data.
This was the order Lavabit apparently initially refused.
Can you point to the first point they demanded the SSL keys? The stuff on page 100 looks like it pertains to the July 16th order. Which is, again, considerably after the June 10th order that originally asked for the data and after Lavabit refused that order. Also, totally inline with narrative of events as I presented it.
Regardin pen-registers: a pen-register can be done in software and is typically done by the service provider, not the government. The term is an anacranism dating back to telgraphs. It doesn't necessarly mean government hardware or software[0]. Hence the discussion page 99 of the pdf about "implementing the pen-trap device" in section d. So that's not blanket access
The June 28th order ("pen register/trap and trace order", page 7) is the one he started refusing, then tried to negotiate on later. I think the order "that Lavabit shall furnish agents from the Federal Bureau of Investigation, forthwith, all information, facilities, and technical assistance necessary to accomplish the installation and use of the pen/trap device" includes keys implicitly. The June 28th Order Compelling Compliance Forthwith (to the earlier order on the same day) notes, "To the extent any information, facilities, or technical assistance are under the control of Lavabit are needed to provide the FBI with the unencrypted data, Lavabit shall provide such information, facilities, or technical assistance forthwith."
The first explicit order referring to keys seems to be the July 16th search warrant, specifically Attachment B on page 36. According to page 98, FBI agents discussed encryption keys with Levison as early as June 28th.
See my response above. https://news.ycombinator.com/edit?id=6517845
Minimally, he gave them an "illegible copy." in 4 point font.Assuming its the actual key, I'm sure the FBI or NSA can OCR that. Even if parts of it are screwed up, SSL private keys actually have a fair amount of structure in them(at least enough to recover from someone writer "FUCK A DUCK" over and over again over part of one [0]) and even if say half the bits of the key give are illegible totally, the rest give you more than enough to factor it.
[0]http://crypto.2012.rump.cr.yp.to/87d4905b6d2fbc6ad2389debb73...
Sure, if we ignore the existence of things like PGP, S/MIME, smart cards, and the dozens of other ways we can have secure email without relying on some trusted third party like this.
"this technology was not meant to deal with the oppressive government that can compel any company to reveal any information"
Then it was not meant to deal with the evil hacker who takes control of the server and grabs valuable information.
"As soon as Ladar..."
There's the handwave. The security of the system depends not on technology, math, or physical laws, but on the whims of just one man. What if Ladar was less principled?
Sure, if we ignore the existence of things like PGP,
S/MIME, smart cards, and the dozens of other ways we can
have secure email without relying on some trusted third
party like this.
As I understand it Snowden was using Lavabit to communicate with journalists who didn't themselves have/use/understand PGP. Lavabit is technology you can use even if no-one else uses it.How do PGP and S/MIME solve the bootstrapping problem, where no-one uses them because no-one uses them?
Basically, the problem is that PGP and S/MIME as they exist today are (and I shudder to say it) too security conscious. The reality is that most users are not going to take the time to maintain their public keys, to verify others' public keys, etc., nor are most users going to spend the time to get their keys verified by a CA. We need a "lite" PGP client that is less obnoxious about using untrusted keys, and basically a "newbie" PGP that is more vulnerable to active MITM attacks (which are actually much harder to pull off than one might expect). It would also be nice if public keys could be easily published via QR codes, so that someone can literally hand their public key to another person.
The worst thing we can do is lie to people about the security they receive e.g. telling them things like "Lavabit is set up so that nobody but you can read your email!"
Bookmarking reply
While someone might have their business cards replaced, it's a lot easier just to send a different key to someone.
A QR code can have ~4000 chars of a-z and ~3000 Latin1 iirc
so with my limited gpg knowledge that handles my public key quite happily.
would be interested on the business card front though
Assuming that "private key" is a typo (you download public keys), you can just check the fingerprint of the key against the fingerprint you were given. That is easily automated.
>>> Then it was not meant to deal with the evil hacker who takes control of the server and grabs valuable information.
Indeed, it is not. If the hacker gets full control of your mailserver, at least your envelope information is completely compromised.
>>> The security of the system depends not on technology, math, or physical laws, but on the whims of just one man
This is completely false. Security depended on adversary not having full access to the Lavabit servers, not on Ladar's "whim". As soon as Ladar realized there's no possibility of legally providing it in the US, he closed the service. Assuming your adversary doesn't have full access to your service is kind of a precondition of using the service as means of security. That's like using lock is assuming the adversary does not have the key, if he does, the lock is useless as a security measure. As soon as Lavabit became essentially useless for the purpose it was created, it was shut down.
This is a strawman, because Lavabit never did anything to protect headers. What you are missing is that Lavabit could respond to a demand for plaintext, if Ladar were willing to do so; on the other hand, Google cannot give anyone access to the plaintexts of PGP encrypted messages that I send through their servers because of technical barriers. That is the point of doing your encryption locally, and that is why security and privacy are not a service.
"Indeed, it is not. If the hacker gets full control of your mailserver, at least your envelope information is completely compromised."
Except that with Lavabit, an attacker could also get all your message bodies.
"Security depended on adversary not having full access to the Lavabit servers, not on Ladar's "whim"."
Let's put it this way: if you were involved in a lawsuit against Ladar, would you trust your communications with your lawyer to Lavabit? Of course not, because Ladar could have modified the code at any time and without alerting his users at all to read any plaintext that he wanted to read. If he had been willing to cooperate with the government, he could have and nobody would have a clue.
"Assuming your adversary doesn't have full access to your service is kind of a precondition of using the service as means of security."
In other words, security is not something you can get as a service. The entire model is fundamentally and fatally broken.
"That's like using lock is assuming the adversary does not have the key, if he does, the lock is useless as a security measure"
No, it is like storing your key with the bartender at your favorite night club and assuming that he will not allow your adversaries to use it.
"As soon as Lavabit became essentially useless for the purpose it was created, it was shut down."
It was shut down because Ladar chose to shut it down rather than capitulate. He could have chosen to keep it going while the government eavesdropped on it instead. That means that, as I said, security boiled down to Ladar and his principles. That is why PGP and S/MIME provide you with better security: mathematics are not subject to the choices that human beings make, and with PGP, S/MIME, etc. your security is a matter of mathematics.
Since SSL keys are mentioned, I assume SSL was used in communication. This means the claim that Lavabit did nothing to protect headers is false.
>>> Except that with Lavabit, an attacker could also get all your message bodies.
This is true, however body of the message may contain encrypted information, which is useless to observer. Envelope information can not be encrypted in a way that is not readable by the mail server, that's the point of the mail server.
>>> The entire model is fundamentally and fatally broken.
That is kind of what I was saying - that current technology of the email can not do what Lavabit tried to do if the adversary can do what the courts said it can do. I'm not sure what you're disagreeing with here.
>>> He could have chosen to keep it going while the government eavesdropped on it instead.
That would be a betrayal of his user's trust, since any claim about what his service does would be necessarily false and he would become a liar if he ever claimed his server allows to communicate securely. I agree that this boils down to one's principles. I think a principle of "don't lie to your customers" is a good one to have.
>>> That is why PGP and S/MIME provide you with better security
No they do not, unless you can establish a peer-to-peer channel with your other party. In which case you're not using email anymore. Neither PGP nor S/MIME can prevent adversary from collecting envelope information in emails, and unability to do this is what made Lavabit impossible to continue.
>>> mathematics are not subject to the choices that human beings make,
You seem to be either genuinely confused about how email works and what running a secure email server involves, or trying to say something else than you're actually saying, or not making any sense. There are no "choices" that allow you to create secure email server in situation in which Lavabit found itself.
That is like saying that GMail is protecting the privacy of your headers, because GMail uses SSL.
"This is true, however body of the message may contain encrypted information, which is useless to observer"
Except that in the case of Lavabit, that encryption was just a side show since all the cryptographic operations were performed on the server.
"current technology of the email can not do what Lavabit tried to do if the adversary can do what the courts said it can do"
Except that someone who encrypts their message bodies before sending the message i.e. performing cryptographic operations locally leaves the server unable to fulfill demands for plaintexts.
">>> That is why PGP and S/MIME provide you with better security
No they do not, unless you can establish a peer-to-peer channel with your other party. In which case you're not using email anymore."
Really, you think I am not using email anymore if I am running my own personal mail server? It is also false to claim that one must have a peer-to-peer system to protect header information, or that PGP on its own is not enough. You could broadcast an encrypted message via Usenet. You could use anonymous remailers (e.g. "Type I" remailers, which use PGP). In all these cases, however, you need to perform your cryptographic operations locally.
"There are no "choices" that allow you to create secure email server in situation in which Lavabit found itself."
Sure there are: Ladar could have sold smartcards instead of selling cryptography as a service. There, one design decision that could have given his users meaningful security while still maintaining the convenience of webmail. To boost security even more, those smartcards could be coupled with a thumb drive that includes the necessary client software, so that Lavabit could not pull a Hushmail on its users.
It does. Unlike Lavabit, though, there is ample reason to assume they invalidate this protection by granting governmental adversaries access to the information stored on their servers - the thing that Lavabit refused to do, at least on mass scale.
>>> since all the cryptographic operations were performed on the server.
I don't see what precludes you from sending emails already encrypted. Security has layers. You are not limited to using just one.
>>> leaves the server unable to fulfill demands for plaintexts.
You forgot to read the part of my answer where I use the word "envelope".
>>> Really, you think I am not using email anymore if I am running my own personal mail server?
It is irrelevant what you personally are doing - it is relevant what Lavabit was trying to do. They were trying to provide certain service - for people that - like, I assume, most of Guardian journalists - are not technically advanced enough to run a secure mail server on their personal computer and set up everything else in a way that allows it to accept email from the internet. This proved impossible, thus Lavabit is not with us anymore. That was my whole point.
>>> Ladar could have sold smartcards instead of selling cryptography as a service.
He could also have sold hotdogs and Carribean timeshares, how that's related to the topic? He was trying to create a secure email as a service - for those that can not create the same by themselves, which in 99.999% of the population of email users. Not provide solution for completely different problem such as key exchange and creating VPNs and other stuff.
The system did serve sider encryption and decryption. Lavabit has, in the past, complied with court orders for data. They have access to the data. This is the fundamental problem with Lavabit.
It's rather unclear why they didn't comply with the initial court order in this case which was just for data on Snowden's account, but it's clear they could have complied (though maybe not as quickly as the Fed's wanted) and that they have in the past.
So, if you are contemplating using Lavabit II, keep in mind that sooner or latter it will get a lawful court order for data from whatever jurisdiction it's in. Either it will comply with it --- in which case it's street cred is worthless --- or it will refuse with the same apparent "fuck the police" bravado everyone likes , leading to the same set of escalations that happened here. The end of that is either/all of 1) the service failing because of computer seizure/the founder being held in contempt so he can't maintain it 2) Him caving and handing over keys again or 3) him shutting down the service to prevent 2.
None of these are good. If the court order is targeted at you, there is a decent chance your data is handed over. If it's not, there is a decent chance your data is still handed over or the service goes under.
Oh, and lastly, if your worried about the NSA's dragnet surveillance, they can just hack a foreign server.
Don't rely on non-end-to-end secure systems.
So you're typing this on OpenBSD? Sure, because that's secure.
Your RPM's are signed, so you're pretty sure they're safe?
Or you're using Funtoo or Arch and compiling from source? Have you read all that source? Even if you did, did you UNDERSTAND it all?
Are you using an Intel Ivy-Bridge or later processor with RdRand?
Are you using a phone?
Do you log into your webmail from one or more locations? How about email?
Do you trust SSL certificates? which ones?
And now... are all of those one other person that you're writing to that actually also uses GPG exercising the same caution? :)
I'm just saying... if you want to know that you're not being sniffed, you have to simply make it impossibly expensive to do so, which probably means get on a plane, meet and hand the person a note, and then burn it, and then scatter the ashes to the seven winds.
Then worry about the metadata of your flight, time, license plate readers, traffic and surveillance cameras.
The basic problem is that allowing this continued, blatant destruction of the 4th Amendment threatens the entire Bill of Rights which ultimately threatens the very foundation of our government and the rule of law.
Legal power, jail, and bullets trump crypto.
If true this is utterly despicable by the government. Alas, I'm not surprised.
I'd appreciate a clearer explanation of this, but last time I read about it, it really did seem like the loss of the contract was out of revenge, and that his prosecution would never have happened had he caved to the requests which he felt were unconscionable.
Isnt it funny to hear that a public company would not have been able to do something when it is about something good for its consumers and ultimately its country and citizens, but when it is something extremely bad like compliance, obedience and evilness then they suddenly can and are free to do it.
There is nothing stopping Google, Facebook or Microsoft to act as Lavabit did. Nothing at all except for their own cowardice, malicious intents and disregard for laws and their costumers.
It is like Obama, when it comes to do something good then his hands are tied, when it comes to break laws and shit on constitution to extend mass surveillance or to wage war and drone kill civilians then his hands are not tied.
Now, lets hear some more excuses for the way the most successful tech-companies have acted, their hands were tied, they would face huge repercussions, they didnt know better, they only meant to comply with law and so on.
The truth is, they dont have democracy in interest, or their consumers best in interest, in fact you as consumer and user for their services and these companies are diametrically opposed and for your best you should consider them enemies.
Try being CEO of Google, Facebook, or Microsoft, and suddenly deciding to close the entire business, and see how far you get before being removed.
It is enough if you threaten to shut down the business to make it known to the G-men that you wont play (the totalitarian) ball. We stopped SOPA/PIPA just with a partial blackout.
But these companies didnt make a squeek. They are accomplices.
Yeah, but not if it's an empty gesture that doesn't change anything. Any CEO of Google both wouldn't be able to shut it down rather than comply, and would be removed for trying. It would accomplish nothing.
The first thing it does is piss off one very wealthy person, whoever this CEO is. The second thing it does is piss off all of their very connected, wealthy friends. The third thing it does is serve as an egregious example of abuse to the public at large.
Hmm. Wealthy, influential people with large public support? Nah, these are two things politicians don't concern themselves about.
But they don't have to get up to the CEO, they get the foreign sysadmin guy and tell him he cant tell his boss or his lawyer or he goes to jail and you got anything you want.
Emphasis re-arranged by me. May I remind you that Lavabit was shut down in reaction to actions taken by law enforcement, doing something that is almost certainly actually legal? "Regard for the law" here would seem to entail doing what they want. You appear to be simultaneously criticizing public companies for disregarding the law and not disregarding the law.
(I object to its legality, but that does not change its legality.)
The Fourth Amendment has a few things to say on this. I'd strongly advise you to actually read it -- it's only a few sentences -- and make your own determination on what you think it actually says.
The FISC, authorized under the FISA, goes back to the 70's and was in reaction to the crimes that Nixon committed. Meet the new boss, same as the old boss. Obama has taken that ball and run with it in a big way. Most transparent administration, ha.
And even then, the FISC was and is itself contradictory to the Bill of Rights, 14th Amendment, etc,....
Guess which law wins? Assuming the Supreme Court agrees (and there's no guarantee they would.)
So if you're ordered to do something awful, but you know that there is a higher law that trumps that law, you can simultaneously be disregarding "the law" whilst maintaining "regard" for the law.
The key is: which law?