Demands on Lavabit violated Fourth Amendment, lawyers say
theguardian.com
theguardian.com
I've heard people say, as you do, that "the masses" will never do such and such, and I agree. But in the past, I haven't really been willing to separate "the masses" into their own group. Instead, I've considered myself, and you, and others on HN, as part of "the masses".
Anyway, I wonder now if I'm wrong. Maybe we should think of the masses as if they are proles (85% of the population in 1984)? Are "the masses" actually just a large group of people who are—literally—no help whatsoever is securing and protecting a just and free society for themselves and others? And worse, completely unaware that they are no help?
Perhaps the masses should be ignored, since their opinions—when they have any—are politically powerless.
In my ideal society the majority has more respect for education and rationality and ergo they would have thought, "hm, maybe this PATRIOT Act and increased surveillance is exactly in line with the goals expressed by the terrorists."
Or they'd at least think, "what's going on with these congressional districts, some sort of Uzumaki?"
But what seems to be happening is that nobody is angry enough to even vote differently. So I'll probably move to Canada or something.
Lavabit intentionally structured their service such that there were only two ways to get at a criminal's email: obtain a copy of the suspect's private key or compromise the entire service. Lavabit was capable of reading the suspect's email, but only by slurping from the firehouse and reading everyone's email.
What Lavabit set up to be their greatest strength ("Nobody can read your email unless they somehow have our SSL key") turned into a terrible systemic weakness ("If the government want to exercise its legal right to obtain a warrant and read a suspect's email, then the only way it can do that is to get the key to everyone's email").
My personal real-world analogy is a safe deposit box that opens either with a key the suspect has or with a master key that opens everyone's lockbox. The bank would defintely be required to turn over the master key. The fact that the only key that opens the suspect's lockbox also opens every other customer's lockbox is a fault of the bank's own devising.
(Of course, who the suspect is in the investigation is irrelevant to everything else.)
This way there is some actual balance to this madness. If Google refuses to help track down Osama, then the government can announce this, and people will be outraged at Google. Snowden is a different matter, many people don't believe he did anything wrong, so it is hard to take the government's side of things.
Do you really think that if Google had access to OBL's whereabouts and wouldn't comply with court orders to provide the information, that the acceptable outcome would be the CIA whining about Google on TV?
If Google refuses to help track down Osama, then the
government can announce this, and people will be outraged
at Google. Snowden is a different matter, many people
don't believe he did anything wrong, so it is hard to
take the government's side of things.
Are you really suggesting that our laws should be based on public opinion?>The government shouldn't have the right...
to this:
>The US Government absolutely has the right...
You can't refute a normative claim with a positive claim.
----
>Are you really suggesting that our laws should be based on public opinion?
I think he's suggesting that violence (which ultimately backs state compulsion) is not an appropriate response to a non-violent act (declining to hand over keys).
I think he's suggesting that violence (which
ultimately backs state compulsion) is not an
appropriate response to a non-violent act
(declining to hand over keys).
I'm sure that's what he is saying, but it's an intellectually lazy claim.If you only look at the scope of the demand (hand over the keys or we will put you in jail), it may seem like an escalation of force by the government. The real normative claim being made is that contempt of court charges are unconstitutional. Which is patently absurd.
The threat of force exists because through contempt, 'non-violent' dissenters can enable further violence.
He already succeeded in destroying an icon of our economy and taking thousands of lives with it. Are you really suggesting that its acceptable for us to debase one of the basic human rights that are the foundation of this country in order to capture one man? This is exactly what is happening with Lavabit.
I don't think any law should be based on public opinion, but when the interpretation of a law is potentially unconstitutional, then that interpretation becomes a matter of public opinion that should be decided in the US Supreme Court.
This 'unconstitutional' demand from the FBI was Lababit's creation by being obstinate to begin with. Did they just expect the government to give up after Lavabit told them they couldn't access that data?
That ship has already sailed. Take a look at the Boston marathon bombing manhunt if you need any more evidence of how far 'out the window' your fundamental human rights can go, given the right circumstances.
the 4th amendment of the constitution makes it perfectly clear that the government can only receive a warrant when they can establish probable cause of criminal activity AND that the warrant is specific and particular. no blanket searches.
The government had a specific and particular warrant to a single account on the Lavabit service. Lavabit denied them access to that account. So the government requested broader access.
"In Smith v. Maryland, the Supreme Court held that a pen register is not a search because the "petitioner voluntarily conveyed numerical information to the telephone company." Since the defendant had disclosed the dialed numbers to the telephone company so they could connect his call, he did not have a reasonable expectation of privacy in the numbers he dialed. The court did not distinguish between disclosing the numbers to a human operator or just the automatic equipment used by the telephone company."
While I can see why lawyers and judges should care about that bit of information, I completely fail to see why the common man should. Bad precedents, destined to be overturned, are created all the time. Even the Supreme Court overturns its own "precedents".
So while I agree that info is not completely useless, it's not actually relevant to the question of what the common man should do, because that doesn't change: he should do what's right and just, regardless of the present position of the state.
Of course my interpretation could differ from established case history, or even with a technical legal reading of that particular clause, but there seems to be a logical argument there (whether or not there's a legal one).
If it had the same requirements as a search warrant, though, I can't say I register an objection.
Beyond that, saying that the government's recourse is to put out a press release that says, "So, we're trying to get into Osama's email, but Google won't let us," is the appropriate way to handle a secret criminal investigation, then I think we'll always disagree.
[1] You can argue this, but it should be noted that nobody on HN seems to have a problem with the subpoena power when it's say used to subpoena documents from say Enron's accountants.
If the government subpoenas an individual for their encryption key, because they have reason to suspect the individual for a crime, it is different than to subpoena an innocent, indirect 3rd party. To me, it's like saying "We don't have enough police to handle this crime. So here - you have to take this gun and help us find the criminal. If you refuse, we throw you in jail."
Any service on the Internet could be used by all types of people, for good and bad purposes, just like a hammer can be used to drive nails or kill someone. You don't throw a hammer manufacturer in jail when someone uses a hammer to kill someone. Lavabit is an innocent 3rd party in all of this, regardless of how their computer system was designed.
We take it for granted when it comes to a physical search so why should they have unsupervised access to everything for a digital one?
This is a very disingenuous way of phrasing this. A far more accurate way of phrasing this is: lavabit did not implement a feature that would allow you to compromise a specific user's emails. They simply implemented the most secure option. Of course you can compromise any user of a service by compromising the whole service. That is not something they did "intentionally", that is simply how the world works. If it were possible to make it completely impossible to compromise a user's emails, I'm sure they would have done so.
The most secure technological option is not always the most secure option. If you don't trust the government, then you have to choose one of 3 options:
1. Consider a system that's resilient against rubber-hose techniques (aka warrants and contempt of court). You'll probably want one where you are technologically incapable of seeing the plaintext. Perhaps offer your paying customers the option of using an open-source program or browser extension.
2. Consider a less technologically secure system where you have access to private keys so that you can fold on one client but not every one.
3. Consider never visiting that country again.
I'm not sure what other choices you really have. Obviously, we can all campaign for better privacy. We can support the EFF and the ACLU, as I do. But we have to work within the laws of our countries, or they'll come down very hard on us.
[1]After this incident, the only way I see Encryption as a Service as being sustainable is an open-source suite with consultation contracts.
Has anyone analyzed whether the government has the authority to compel you to help them impersonate you? From what I can tell, that's central to the private key issue.
[Edit: Yes, you can passively eavesdrop if you're not negotiating a TLS ciphersuite with forward secrecy. Added "automatically" to clarify.]
Is it the equivalent to using a subpoena to force a third party to produce the physical key to a safe in which the investigating authority believes evidence will be found.
If the law is certain the needed evidence is within the container, the lack of a physical key would not stop the attempt to collect that evidence.
I'm curious if there are cases of the police requiring a physical key that is in effect a skeleton key. Say, for instance, an apartment manager's master key that opens every door in the building. Having possession of that would mean the police would have access to every apartment in the building regardless of whether the search warrant allows for that or not. That would be similar to having the SSL key in this case, the authorities would have access to everything.
Now, in that case, imagine the police department had recently been shown to not be trustworthy enough to have access to a key that opens every door in the building. I think you could see the dilemma here.
The key itself is not evidence, contraband, fruits, or instrumentalities of crime, Lavabit argues, but is merely a way to get to evidence, contraband, fruits, or instrumentalities of crime. This is a clever argument pressing an undeveloped aspect of Fourth Amendment law, but I don’t think it ultimately works. It’s pretty standard for computer warrants to authorize the seizure of passwords, encryption codes, operating manuals, “and other information necessary to access the computer equipment, storage devices or data.” I haven’t seen a Fourth Amendment challenge to such provisions, but I would think they are okay because they involve instrumentalities of crime. That is, the password or encryption key is part of the tool used to commit the crime, so it is part of the instrumentality of crime and can properly be obtained in a search warrant.
Now, you may be able to demand that Lavibit hand over the user's password or encryption keys, if it is able to do so. Those could likely be considered instrumentalities of crime. But handing over Lavabit's own private keys goes beyond that, to something that Lavabit merely uses to keep it's communications private with all of its customers, the people under investigation and everyone else.
Asking for Lavabit's private key is like asking for the master key to let you into any room the building, when only one tenant is actually under investigation. It goes beyond what is necessary to investigate the actual case in question.
As for the instrumentality of the crime, even though it's Lavabit's SSL key the government's contention is that Snowden made use of it in his alleged crimes (by for example encrypting leaked data with the public half of the key for transmission to lavabit's web to email gateway, where it would ultimately be decrypted by lavabit using the private key, and then emailed to the a recipient.) Suppose a criminal rented a car and used it as a getaway vehicle and then returned it. The police could get access to the car for forensic evidence from the rental company, notwithstanding the fact that the car belonged to the rental company who was not accused of any crime.
His offer, made rather late in the game, was the equivilent of the super telling the police they couldn't enter the apartment, but that he (the super) would search it for them and pick up whatever they were asking for, if they were willing to pay him some money for his time.
That might be a reasonable offer, but I don't think there's anything in fourth amendment law, or the statutes, that require the police to take him up on it, rather than just insisting that they do the search themselves.
In my own reading of the case, the area of the government's actions that seemed the weakest was the applicability of the rationale for the probable-cause-less pen-trap and stored communication act requests (i.e. the third party doctrine from Smith v. Maryland) to email headers and usage logs from a service that held itself as not being able to access these things. In that circumstance it looks to me like the user does have a reasonable expectation of privacy in those (meta)data, and so a warrant issued upon probable cause should be necessary. However, this case also involved a grand jury subpoena. That's a whole other (troublesome) kettle of fish, one that frankly I'm not too familiar with.
Why?
When setting up a business, are you required to organize it in such a way that in the future, the government can come along and perform a certain kind of search/and/or seizure? It that your obligation, failing which all of your customers must suffer?
It's one thing to have a law that states the government can ask for things. But I haven't heard anybody argue that the law requires you to organize your affairs in such a way that you can comply with requests like this "cleanly."
> It's one thing to have a law that states the government can ask for things. But I haven't heard anybody argue that the law requires you to organize your affairs in such a way that you can comply with requests like this "cleanly."
Generally you don't have to set up your business in such a way as to comply with requests cleanly, though there are exceptions for certain telecom providers (not applicable here). But by the same token your inability to comply cleanly doesn't absolve you of the responsibility to comply.
So our landlord hypothetical the landlord certainly is allowed to use the same lock on every door, but he still has to turn over the key when it is demanded.
As for the collateral consequences to third parties the court will not assume that the government is going to abuse their access to search more than they are authorized to. That seems to be the biggest disconnect. The judge didn't think that the ability to decrpyt all the traffic was a pertinent harm because his order didn't allow the agents to look at it. Whether or not that's a reasonable assumption as a matter of fact is an empirical question, but it is certainly a reasonable, perhaps even compelled, one from a legal standpoint.
If the business is allowed to send its customers a form letter telling them that hey has given the master key to the government, I would understand the position that the interests of the other customers were reasonably safeguarded.
If, for example, one of them was discussing some business and then suspicious trading occurred, she might ask whether a government employee abused the master key and was doing some insider trading on the side.
But if the business is not allowed to tell the customers that their privacy has been compromised, I would not want to give the government the "benefit of the doubt" about their use or abuse of a master key.
Trust, but verify, as they say. How does one verify when these security letters are handed out like candy?
No you aren't required to, however, you are required to cooperate with legitimate searches/seizures even if the you have structured your business so that doing so inconveniences other customers unrelated to the target of the search/seizure.
You can't structure your business in such a way as to make narrow searches/seizures impossible without inconveniencing unrelated customers and then use that as an excuse not to cooperate with otherwise-legitimate searches and seizures.
You've got Fourth-Amendment-As-Defined-By-A-Government-Lawyer-In-A-Secret-Court rights. They're similar, except that Federal agencies can snoop the hell out of whatever you're doing.
You know, to keep our children safe from terrorists.
Funny, as the number is 10 times higher, als stated by the guardian itself in the linked post.
Not that it matters, 40.000 would be just as bad.
I was confused until I remembered my high school German class.
1. a.k.a. The Grauniad. www.grauniad.co.uk redirects to theguardian.com
This is the educational problem we face ('we' being people who have the particular libertarian bent that Ladar is showing with his actions here). The masses, on all sides of the political spectrum, do not understand just how truly special our constitution is, and how offended they should be that the current holders of office are trampling it underfoot in so many ways. The 4th amendment could be paraphrased as "if officers of the state don't have good reason to think you're guilty, they have no right to invade your person in any way".
If we were talking about a fluke whereby the FBI, in the process of intercepting Snowden's communications, mistakenly saw the SMTP traffic of an innocent user of lavabit, OK, mistakes happen. But that's not what's going on here. The FBI requested, and was granted by a federal judge, the ability to search people for whom it had no probable cause of criminal action. Ladar's side brings this up in hopes that the judge will understand that more narrow measures would be just as useful to the FBI, without violating anyone's 4th amendment rights (including Snowden's since he did break the law) and without destroying the core of his business.
At least for citizens of the US, if the government isn't prepared to arrest you and press charges against you, it's supposed to leave you the heck alone.
As far as I know, Edward Snowden has not been tried and convicted in any US jurisdiction that I am aware of. I typically do not like being pedantic, but I can say if I was on that jury I would be hard-pressed not to push for jury nullification (http://en.wikipedia.org/wiki/Jury_nullification).
If (another big IF) this case goes to the SCOTUS and they (after quite a bit of money) they support Ladar and all of us, then you can take it for granted that a new 'decision' will take place in a secret 'court' which 'reinterprets' the facts.
It's like the facts don't matter, only feelings.
[1] http://www.wired.com/threatlevel/2013/10/lavabit_unsealed/
Do you think Kerr is wrong, or that the legal precedent is?
How did you get the impression a "secret" court was involved?
Discerning the difference in meaning between "Demands on Lavabit violated Fourth Amendment, lawyers say" and "Demands on Lavabit violated Fourth Amendment" is not an onerous task.
Even the headline makes it clear.
It was a bit of an hectic morning and then I read this with the wrong mindset and so on...
Thanks for the feedback.