Lavabit gets new crypto key, gives users 72 hours to recover e-mails
arstechnica.com
arstechnica.com
Does this not mean that the NSA could patiently log all the traffic going in and out of the site over the next few days, then get a court order for this new SSL private key, then decrypt the traffic they collected?
I may have misunderstood, but doesn't that make this something of a trojan horse? Many users will login and try to download all their email, and for everyone who does, when the NSA (very likely) get a court order for the new SSL key, they'll have that large amount of private email everyone tried to copy from the site?
Presuming they've imaged the drives with their encrypted mail, all they'd have to do is a half-dozen line patch to the code to log the passwords to disk as they come in.
Then they can decrypt everyone's private keys, and decrypt everyone's mail, PFS or no.
Anyone sending their Lavabit password outside of their own home is simply asking for someone else to decrypt and read their email.
If I had been a Lavabit customer, I would see this cipher suite as him saying-without-saying that this service is suspect and is to be avoided at all costs.
Exactly my thoughts too.
At least this option gives the users that choice.
EDIT: And hope the relevant courts are not running during those 72 hours?
This doesn't make sense, he would have had forward secrecy on unless there was some reason not to do so (like he was compelled not to, or if he isn't even the one doing all this).
If not all connections used it, FBI / NSA are probably now in the position to decrypt earlier recordings of user sessions, thus recovering the passwords, email contents etc...
From reading the ssllabs report, it looks like even with the current setup, sessions by IE and Safari (also Android?) users can be recovered once the new key is obtained via court order.
No idea about before the warrant, but I don't see any good reason to think it changed it changed
The certificate isn't what control PFS, it's the allowed (and preferred) cipher suites.
You can enable PFS without changing your cert.
They only ordered him to disclose the old ssl key, maybe it doesn't apply to the new one?
I believe it now implements Forward Secrecy...
It's far more likely that Levison has been bullied into 72 hours of snooping to avoid contempt than that he's suddenly decided, months after shutting down, for no reason at all, to open up a window for users to grab their emails.
Interestingly, in both scenarios the activity will be very logged and the alphabets will get all your data, but absence of PFS is unrelated to this.
Occam's razor says he replaced the compromised ssl key (the one the court ordered him to hand over)
Ladar shut down his servers than accept snooping on all his users, I certainly doubt he just decided after all this fighting to just give up.
He could have done this a while ago, but he didn't.
He could have relaunched fully, under a new entity, but he didn't.
He chose NOW, to relaunch for only 72 hours. Why?
He's flying back from Brussels to DC tomorrow. Then back to Dallas on 20 Oct.
So he's in DC while the server is up.
source: personal communication (SMS)
The court records were just unseal on October 2nd.
>He could have done this a while ago, but he didn't.
Maybe he's been working on it since the 2nd?
>He could have relaunched fully, under a new entity, but he didn't.
Why would that change anything? This would only serve to hurt his existing customers.
>He chose NOW, to relaunch for only 72 hours. Why?
Again, maybe he's been working on it since the 2nd?
He could just let people download their data and decrypt it locally. Instead the site is prompting you for a password which it could freely capture.
What? If an active attacker is changing certificates on the fly, he's also surely able to change the values in the HTML content of the page.
This will add absolutely no security for the users, only false sense of security via complex-looking measures, and he should know this.
Maybe if he destroyed everything apart from the one user account they claim they want access to?
Destroying everything does indeed cause some pain, but it also sets a very definite upper bound on just how much pain is possible (especially for your customers).
Either that or there's an amount of incompetence here that should might as well amount to the same degree of stay away.
However, the server is probably not actively compromised, because if it was they could use PFS and still listen in. It is still required, however, that they'll need either to own this key pair being used at some point to listen in to the traffic.
But that would mean that they can likely change the key pair on the server but for some reason they can't enable PFS, even though once they have access to the server in production, PFS is useless... so... who knows on that part.
tl;dr: If they get the key pair later (even if years later through brute forcing or whatnot) and don't have access to the server, then PFS disabled is a bad thing. If they have control over the server or the server logs all the session keys and they receive these at some point in time, then PFS enabled is, of course, a useless thing. If they don't get the key pair at any point, then it's fine, but I'd consider that unlikely.
Edit: The proper way forward is to estimate the chance they will get the key, which might as well call at 50-50, multiply that by the losses you would incur where they to gain access to these emails (and that's likely to amount to $0 for the vast majority, sorry if I'm being presumptuous and devaluing privacy) and compare that to the losses incurred if you didn't have access to these emails. Counter-intuitively arising from that, for some it might even make sense to connect assuming that traffic is intercepted, to show that they are boring and are using Lavabit for very mundane reasons.
For a trap, it's pretty damn obvious. The form submits the user name and password in plain text over the "secured" connection--the one that doesn't support forward secrecy, operated by a provider who's already known to be compelled to disclose SSL private keys.
Further, I can't imagine Ladar willingly set this up. This means that not only can they compel Ladar to hand over his private SSL keys, but they can apparently compel him to take positive action to fuck over his users. <s> Talk about a free country! </s>
SSL protects an adversary from seeing what you're talking about, not who you're talking to.
Tor will prevent an adversary from seeing who you're talking to, but not (in itself) what you're talking about[0].
Here, the topic of concern is an adversary (in this case, the government) finding out what you're talking about, so Tor isn't relevant.
[0]Because the last step is unencrypted and sent in plain text, even though intermediate steps are encrypted.
now, you'll just wait what happens and be as surprised by the outcome as you've been with the surveillance revelations this year.
brave new world.