Judges Poised to Hand U.S. Spies the Keys to the Internet
wired.com
wired.com
There's also some information on the Kickstarter page: https://www.kickstarter.com/projects/ladar/lavabits-dark-mai...
If people running the company in question still hold US citizenship or keep money in the US, the US legal system can still reach them unless they never want to go home.
Reality is far from that I am afraid.
Seems a little far fetched but you never know.
a) Why does Wired, a tech pub who should know better, seem entirely ignorant of the existence of PFS cipher suites?
b) Why wasn't Lavabit using PFS? Then key compromise is mostly irrelevant as long as you're not incarcerated and can scream bloody murder.
He co-created Secure Drop with Aaron Swartz. If your memory doesn't go back that far, there was that cool article the other day about how a hacker reverse-engineered OKCupid. He's written stories that have put pedophiles in jail and exposed the FBI's use of malware on criminal suspects.
Someone else can defend Wired in toto these days, but, I will say it'd be hard to choose a less appropriate writer as proof for your first sentence.
And, yes, Poulsen was my former boss and editor.
The discussion starts at about 32:40. http://twit.tv/show/triangulation/125
2) Ladar has explained this. And even with PFS, if a service provider hands over SSL keys and gets hit with a gag order, perfect secrecy only helps in regards to past communications.
pFs provides resistance to previously passively recorded cipher texts being decrypted when the static secret key is disclosed. It does this by ensuring the session key exchange is protected by an ephemeral key; it is not possible to derive the session key from any static configuration, ie: rsa private key.
With the PFS ciphers, the static secret key provides server authentication; so you know your talking to the correct server or in this case FBI carnivore device. The mitm appliance can even support PFS between you and it so you wouldn't even know the difference!
I think a new crop of services that generate keys completely on the client and use servers as dumb, data-ignorant conduits between clients are going to be a lot more pervasive in the next 10 years. At least, that's what I'm betting on =].
Nice.
I was once a witness to a traffic accident, and had to go to court. The judge asked the defendant (whose inattention caused the accident) what happened, and his story wound up "and so the other guy was shaken up but not injured". The judge then gave a several minute harangue over his presumption in knowing what happened to the other guy.
Finally he asks the guy "how do you KNOW that he wasn't injured?". The guy replies, "I went to see him to apologize, and he TOLD ME that he wasn't injured."
Of course, the "told me" what second-hand so probably not admissible, but it sure didn't warrant the rant that the judge gave him.
Not always the case I'm sure but it has always made me rethink the idea of a Judge as an 'impartial' adjucator
The judge in the elevator with me quickly reached over me and pressed the "Door Close" button. This closed the doors, preventing the waiting people from getting on and the car continued to the next floor where he and I got off.
I'm not terribly surprised, given that judges are pretty used to being referred to (ridiculously enough) as "Your Honor", are they not? Or is that TV shit?
Also, hearsay can be admissible. In this case the "told me that he wasn't injured" would be allowed because statements by someone going against their own interest are allowed.
But you are right in that he probably should have been prepared for this as well. Its not unthinkable that judges would be adversarial to this sort of defense/line of thinking.
Of course, privacy obsessed clients can simply run their own email client off a USB stick with their own private keys.
But anyway, if the servers simply store keys which the clients themselves unlock via their passwords, and the server stores nothing, the NSA would have to either sabotage the hardware the clients use or else do rubberhose cryptanalysis.
</simplification, sorry if too much>
Open source is necessary (or nearly so) but not sufficient.
Even proprietary security companies have long practiced source provided (different from "open source") code for their key crypto engines. PGP comes to mind in this regard (the company, not the protocol).
But fully open source means you've got vastly more exposure of your crypto guts to examination.
For now.