EFF Has Lavabit’s Back in Contempt of Court Appeal
eff.org
eff.org
I'm talking about service providers moving their operations to more privacy-friendly jurisdictions, and improving protocols with e.g. perfect forward secrecy to make this sort of attack impractical.
So everyone suffers under an adverse decision in this case:
The US economy suffers because businesses seriously concerned about privacy choose to locate elsewhere
Law enforcement suffers because those businesses are no longer reachable when they have a legitimate reason to obtain the communications of spies, terrorists, or plain old criminals, and get a narrow warrant that properly protects the privacy of innocent bystanders.
Individual liberty suffers because a precedent will make it easier for people who don't care about privacy and use domestic providers subject to these overbroad warrants to be caught up in a surveillance dragnet
That being said, Congress, not the courts, is the proper venue to address those practical arguments. Will anyone care outside of technophile bubbles like HN? Unfortunately, I think we all know the answer.
Seriously, that is one heck of a broad warrant, namely the private key used to decrypt all business records of all customers.
There was no warrant for the SSL keys; that was issued as a subpoena when Mr Levison stated that the data-in-transit was encrypted. The judge told him to disclose the keys that were protecting Mr Snowden's data.
That Mr Levison happened to use the same SSL certs for all paying customers isn't the fault of anyone but... him.
If you're hosting encrypted data that focuses on privacy while remaining law abiding, it's just sensible to maintain separate SSL keys so you avoid this very scenario. It's not as if it wasn't foreseeable.
If you have separate server certs per user (as suggested above), then you can tell which user is using the service.
If you have separate client certs per user, then you call tell which user is using the service.
The Lavabit response to the original order was not the best, IMHO. As he was in possession of the certs and private keys, he could have decrypted Snowdon's traffic himself, and handed it to the court.
Instead, he tried to hide behind a BS "it's encrypted" defence. The court called his bluff. He lost.
I would imagine him decrypting the data himself would cause problems in a chain-of-evidence type of way though.
Anyway, at least in the physical security industry, security isn't about preventing intrusions. It is about delaying it and limiting it until a sufficient response can be mobilized. Perfect security is impossible
How the guy chose to run his business and what the warrant was requesting are two different things.
Yes a warrant imposes certain restrictions on your business.
What you are describing does happen, but I fail to see how it would happen under a search warrant.
As for your destroying data being against the law if it is requested by the courts. You are correct, except that if your business model is to destroy data in a timely manner then you cannot be held in contempt for destroying data before it was requested. At that point it becomes something different as they have to request you no longer destroy that data so that they can collect it. I don't see how that request falls under a search warrant. I suppose it could happen if a judge likes being overly broad in search warrants (which could cause problems in the criminal case), but it seems unlikely that's how a typical search warrant would be executed.
Name me one large company using HTTPS, with separate SSL server certs for each user.
Just one. I'll wait.
If it wasn't a warrant, a single leak of the key would expose everyone's data.
Do you honestly think that it would make sense to set up a completely new domain for each and every user? Do you have any idea what a nightmare that would be to support? Do you think it would be cost effective to spend $50/year per user to implement such a system?
And do you really think that SSL has anything at all to do with the encryption used for storing data inside his system?
It might be a pain to manage, and you'd need to get your wildcard cert resigned for each private key, but that's just logistics.
Completely and totally unrealistic for an email provider. The support costs alone would bankrupt the company.
Anyways, I'm just pointing out that it is possible to provide per-user certificates.
He designed his system to have a single point of failure. The government then exploited that fact because it would allow them to get access to the data they want. This is Lavabits fault, not anyone elses.
Did you know that your bank uses the same exact approach to SSL security? Did I just blow your mind?
Design a system where if the government wants access to one account, you have to give them access to everyones account to comply? Your fault.
And it's still not 100% clear that forcing a business to hand over their keys is even legal from a constitutional standpoint.
Also it is legal for the site to hand over their keys, it already happened. The only way it will become illegal is if the law somehow gets repealed.
There was no compromise anywhere, financial institutions use the same exact security strategy. An insecure system would be one that makes it easy for a 3rd party to intercept communications (via warrant or through a disgruntled employee or whatever), that is basically what you are suggesting.
I mean, on a technical level, you may be right, but the 4th Amendment is not something that protects only as long as the government does not exploit these technical details. See Kyllo v. United States.
So, no. The warrant the government obtained was not specifically for the data relating to Mr Snowden, but rather, was for the SSL keys.
That's not accurate. Lavabit offered to construct a backdoor for that particular user at well below cost. Instead the government demanded they destroy their business model by making all users insecure.
Imagine you run a hotel. The police are looking for a fugitive that's been known to check in occasionally. You offer to build a system that notifies the police if that user checks in. They refuse. Instead they demand you place a camera in each room.
Does the door to your house support multiple types of keys? Or is it designed to work with a single, specifically machined key? Can you open your front door with your car key? Why not?
SSL is what is used to protect communications between a client and the Lavabit endpoint. Once a request is inside the lavabit network other security measures are used. For example, each email message is signed using the account key for a given member, the account key is itself encrypted with the members password. The only way to decrypt a message is with the account key and the only way to decrypt the account key is with the member password. If you lose your password, your mail is gone forever. The feds had access to snowdens encrypted emails, but they had no way to decrypt them without his account password and the only way to do that is with snowdens personal password, which is why they wanted to sniff unencrypted traffic (to snag his password en route to the lavabit server). I've simplified a few things but this is a rough overview of how his system is designed.
No, you cannot have more than one SSL cert for a given hostname (and port combo). You can assign a unique hostname to each user. The "oh, no, SNI doesn't work with IE 6" problem shouldn't have been a major problem for lavabit.
Does the door to your house support multiple types of keys?
The door to my apartment building is opened by one key. Everybody in the building has a copy. The door to my apartment is opened by a different key. The shared key is not the key that protects my stuff.
I'm not sure you or the judge understands how SSL works. I would love to see them subpoena a bank for their SSL private key and see the reaction of the world.
It's probably a bad sign when the sane legal solution to avoid a rebellion (or worse) seems like fanciful wishful thinking.
edit: As other have said: Thank you, EFF!
The whole issue of making such a taboo topic is that it makes it hard for opposition to mobilize. However in the US we have other ways of doing that. Hyperpartisanship is something which has a remarkably similar effect while at the same time allowing us to say with a straight face that we are not a police state.....
In the UK such gerrymandering is taken very seriously because it's a fundamental attack on the integrity of the electoral system. People found guilty of it have had their political and personal lives ruined, and quite rightly too. But in the US it's standard practice. I don't think this is taken seriously enough.
"I grew so rich that I was sent
By a pocket borough into Parliament
I always voted my party's call
And I never thought of thinking for myself at all!
...
I thought so little, the rewarded me
By making me the ruler of the Queen's Navee!"
-- Arthur Sullivan, from "The HMS Pinnafore"
The scary thing is how well that verse describes American politics these days..... So maybe you are right....
(PS: Great job EFF!)
0: [pdf] http://cdn.arstechnica.net/wp-content/uploads/2013/10/gov.us...
For background, Lavabit filed their appeal a few weeks ago [0]. Ars covered it [1], and it was discussed here on HN [2] as well.
0: [pdf] http://cdn.arstechnica.net/wp-content/uploads/2013/10/gov.us...
1: http://arstechnica.com/tech-policy/2013/10/lavabits-appeal-w...