Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I don't think so. He based his service on the premise that he didn't have the keys o the encryption, and I can imagine he was able to respond to the requests "this is what I have." Specifically, as the service customers paid for, he was able to give, for example, the name and the credit cards of the specific investigated customers if he billed them directly. But it is OK, there were narrow court orders, everybody is expected to get and respond to such. What happened now must be different. Otherwise, why would he decide to do what he did now?

BTW it's a really nice article, gives a nice personal side to the whole story.



Your theory is wrong. Here is the warrant Lavabit complied with:

http://ia600908.us.archive.org/9/items/gov.uscourts.mdd.2362...

Take a quick look at attachment B and you'll see that Lavabit was asked to provide the plaintext message bodies and attachments of emails sent by the user. This was not a demand for metadata, it was a demand for messages, and it was a demand that Lavabit complied with.


You have no basis to say that everything sought was produced.

It is true that the subpoena asked for it, but a response to a subpoena that supplies what can be supplied and explains why the rest can't be supplied would not trigger another court docket entry unless the government didn't believe the explanation.

Because a subpoena is filed before the government actually contacts the witness, the government typically asks for everything it could possibly get or want.


Why would the government believe a claim that Lavabit could not provide them with plaintexts? Hushmail did it, and Lavabit's architecture is not all that different. At best Lavabit could claim that the user had not logged in and thus they were unable to capture the user's password.


Hushmail is in Canada, I have no idea what the rules surrounding cooperating with the government are there.

In the US when it comes to subpoenas from civil or criminal courts, you only need to produce "books, papers, documents, data, or other objects" in your possession. The passwords were not in Lavabit's possession at the time it received the subpoena. Furthermore, subpoenas can be quashed if they are " unreasonable or oppressive" (see e.g. FRCrimP 17c). Asking a witness to write custom code in order to capture a user's password is a textbook example of an unreasonable request.

The rules for national security requests on the other hand are entirely different. 50 USC 1805(c)(2) requires the recipient of an electronic surveillance order to:

"(B) that, upon the request of the applicant, a specified communication or other common carrier, landlord, custodian, or other specified person, or in circumstances where the Court finds, based upon specific facts provided in the application, that the actions of the target of the application may have the effect of thwarting the identification of a specified person, such other persons, furnish the applicant forthwith all information, facilities, or technical assistance necessary to accomplish the electronic surveillance in such a manner as will protect its secrecy and produce a minimum of interference with the services that such carrier, landlord, custodian, or other person is providing that target of electronic surveillance;"


What the fuck, NSLs have taken down the first and fourth amendments and are turning towards the third.


No, at best they could say they don't have a system to capture people's passwords, and never betray their users by making one.


> Take a quick look at attachment B and you'll see that Lavabit was asked to provide the plaintext message bodies and attachments of emails sent by the user

From what I see, they were ordered to provide all messages, records etc. stored on that account and related logfiles. It does not specifically say "plaintext", so Lavabit might have provided them with the encrypted e-mails and no logs (if they had none) and still be in compliance with the warrant (IANAL!). You cannot possibly be forced to provide something you do not have, right?


Do we know the user was the one who paid for the service? I understood only those had the stored e-mails encrypted. Otherwise, free users had only clear text, and the e-mails in transit which happened after the order were also in clear before they were encrypted, so Lavabit simply had to provide such, for those they weren't able to say "we can't."


Lavabit could almost never claim to be unable to provide plaintexts. In the worst case they would only need to wait for the user to log in again, or perhaps to just brute force the user's password (this does actually work, even for seemingly hard-to-guess passwords).

This is really not any different from Hushmail.


Lavabit wouldn't be these that bruteforce the passwords. We all know who's in charge for such things. That they earlier provided what they had is to be expected, those were normal court orders, as you were able to prove by linking to them. What happend now must have been something significantly different to make the owner shutting down the company. The owner is not even allowed to say what, which is directly against the First amendment. That's really a huge issue. Please don't keep trying to distract from that by mixing up the normal court orders with what's going on now. Thanks in advance.


While there may be legal and policy differences between "normal" court orders and PRISM, the only technical difference is the scale. If Lavabit could respond to "normal" court orders, then they could have participated in PRISM. Lavabit's users are lucky that the company's founder took a stand for their privacy rights; he could have just gone the other way and kept a record of all their passwords / secret keys / etc.

Of course Lavabit would not be the one brute forcing the passwords. That is not the point. The point is that the security of Lavabit is a matter of the user's password, and only in the best case where the user does not log in.

Ultimately Lavabit's security is a matter of the trustworthiness of Lavabit's employees, not the size of your key; it is marginally related to the strength of your password, but only under very specific circumstances. The fact that cryptography is being used somewhere in the system is a distraction. If instead of the US government showing up with a court order it had been a Chinese spy sending business secrets back to the Chinese government, would you still be defending Lavabit?


Your entire argument comes down to "I don't think anyone but me can be right, and further I can't imagine any way this software could have been architected, therefore lavabit must be evil". Or something. It is very hard to follow your argument. You keep claiming various contradictory things....


Sorry, you are the one doing the distraction. Do read again what I've already written here, I'm leaving this discussion.


I don't care if the government asked for the data of one particular user, when investigating a serious crime and having probable cause. Did you read the documents you linked to? Are you saying that you don't believe that investigating authorities should ever be able to access the contents of an email account, even with probable cause?


If somebody sells me a service saying they can't provide that data, then I expect that data to not be provided. It's what I'm paying for, and it's the commitment they made to me.


Some argue that the government has no right to investigate the contents of an individual's email accounts, even with probable cause.

There's always a way to access the data. Cloud-based email is...cloud-based...which means that it's susceptible to man-in-the-middle and other forms of attack.

It's possible that the government was asking Lavabit to modify its systems such that the encrypted data guarantee would no longer be real, and then they demanded that he hide that fact.

I'm honestly not sure what to think about that. Should private data storage be permitted? Is there a difference between your private data in the cloud and your private data on a system at your home?


"Some argue that the government has no right to investigate the contents of an individual's email accounts, even with probable cause"

Who is arguing that? In this case, the issue is not about whether the government has probable cause. The issue is that any system that allows Lavabit to respond to a warrant can be used for mass surveillance, industrial espionage, etc. This conversation happened 20 years ago when people were arguing about key escrow. Almost nobody argues that the police should not be able to investigate crime; the argument is that backdoors are a massive vulnerability that leave innocent people, for whom the police have no warrant (or no "specific" warrant), at risk.

"Cloud-based email is...cloud-based...which means that it's susceptible to man-in-the-middle and other forms of attack."

The problem is not that the mail service is run by a third party. The problem is that encryption, decryption, key storage, and even key generation are being performed by a third party. I send encrypted mail through GMail all the time -- and Google is not able to decrypt those messages, even if they are presented with a warrant. While it may be problematic for the police to face such a situation, it would be problematic for me if criminals and spies could read my emails, and at the end of the crypto wars Congress determined that the need for good civilian crpytography vastly outweighed the government's needs to enforce laws and spy on other countries.

It is also important to remember that the police can still get messages that are encrypted/decrypted offline, they just have to work a bit harder for it. For example:

http://yro.slashdot.org/story/00/12/06/0255234/fbi-bugs-keyb...




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: