Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The fact the government wanted the SSL keys is obvious they wanted to get at all his customers, not just the one they were targeting.

Levison offered multiple times to write a specific script for the single user that would do what they wanted and at a minimal cost to the government - and they refused. A pretty clear indication they wanted unfettered access to his client base and his network.

Then you add in the lack of ANY oversight on either Lavabit's or the government's, and you have to praise him for what he did.



Do you really consider the judicial warrant system a lack of ANY oversight?

After Levison's lack of cooperation, could the investigators really trust Levison to hand over all the information?


Why should Levison trust a government who has proven to be untrustworthy when it comes to data collection? Levison didn't lie or mislead anyone, he even offered to get the data for them as long as it was targeted. The government has basically zero credibility in matters like this, and yet he was expected to trust them with no oversight (in the article, he was told there was no independent audit of their use of the data)?


What is this monolithic government you speak of? Are you saying that the FBI and the NSA are synonymous? I'm sure plenty of FBI investigators would take exception to an accusation like that.

I can play this game too. Dread Pirate Roberts used StackExchange, so therefore StackExchange users cannot be trusted to build websites that don't host drug deals and supposed hitmen.


Why the constant influx of throwaways?


After they had SSL keys and tap system, they won't need a warrant to access specific data - they could just look and see anything they want. Of course, some of it would probably be inadmissible in court, but who cares - they'd just use different evidence in the court or "parallel construct" it. If they already have the data, the warrant requirement is useless.


> Levison offered multiple times to write a specific script for the single user ... A pretty clear indication they wanted unfettered access to his client base and his network

i don't think this is the correct interpretation. in a court of laws, acquiring evidence is something procedural and governed by rules and regulations. having a third party (lavabit) acquire the evidence and then turn it over to the government is probably something that wouldn't pass muster in court due to chain of custody and other rules.

the government investigators had a particular target, and they needed to collect evidence that would be admissible in a court of law. its actually pretty tough to come up with a good alternative here for the government.


> i don't think this is the correct interpretation. in a court of laws, acquiring evidence is something procedural and governed by rules and regulations. having a third party (lavabit) acquire the evidence and then turn it over to the government is probably something that wouldn't pass muster in court due to chain of custody and other rules.

Search for "$" on this page: http://paranoia.dubfire.net/2009/12/8-million-reasons-for-re... It is very common for third party service providers to search records themselves on behalf of law enforcement, and law enforcement has historically trusted that and even compensated them.

It's the only way that really makes sense IMO. Can the FBI really bust down, say, Verizon's doors, seize all their hard drives, and correctly generate evidence based on systems that aren't theirs, and may in fact be unique among the phone systems of the entire world? Maybe an email system is simpler, but still.

Also, I think it's inappropriate to seize 400,000 users' data just to (ostensibly) get to one person. But I'm not a lawyer, maybe it is arguably legal.

P.S. Also see https://www.eff.org/files/filenode/social_network/Yahoo_SN_L... for all the things Yahoo does on behalf of LE.


On page 100 of the actual documents [1], the refusal was not based on chain-of-evidence concerns, but that by using the solution proposed by Levison, the FBI would not have real-time access to the data:

    The e-mail again confirmed that Lavabit is capable of providing the means for the FBI to 
    install the pen-trap device and obtain the requested information in an unencrypted form. 
    AUSA[censored] replied to Mr. Levison's e-mail that same day, explaining that the 
    proposal was inadequate because, among other things, it did not provide for real-time 
    transmission of results...
---

[1]: http://cryptome.org/2013/10/lavabit-orders.pdf


Great point. On page 46 it says Levison "would be able to collect the data required by the pen register and provide that data to the government after 60 days (the period of the pen register order)."

Then, "The prosecutors informed Mr. Levison that the pen register is a devise used to monitor ongoing email traffic on a realtime basis and providing the FBI with data after 60 days was not sufficient."

So, I am not sure what to think. After some research I couldn't tell whether "pen register" data is required to be real-time. The original order on page 7 doesn't seem to say "real time", but there could be some legalese or other laws that imply it.

Levison was clearly dragging his feet, but it seems sort of bizarre that they escalated their demands in response. Why not just get him charged with contempt and move from there? Since they played the "we can't trust him since he's been uncooperative" card, does this mean they would have trusted him if he complied immediately? What if he immediately turned over info and it didn't help their investigation or went counter to their preconceived notions -- would they have accused him of withholding some and demanded his private keys anyway?

There's weird things on both sides here. It sounds like Levison's actions on the whole are not very defensible though. :/


We still don't know everything that transpired here, but here's my interpretation of the article:

- The government is granted the right to snoop on Snowden's e-mail from a court. The court implores Lavabit to provide the technical expertise necessary to make this successful. - Lavabit replies that all traffic is encrypted, and that it would be a expensive to change that. Lavabit offers to make those changes so long as the government covers the costs of the change (in this case, one week of developer time). - The government balks at the prospect of paying for the change and tries to snoop themselves. They realize that the encrypted data they can snoop on themselves is worthless, and demand the ability to decrypt it themselves.

All of this seems to hinge on Lavabit's demand that it be paid to make the changes necessary to make the pen register effective. Presuming the government was willing to pay him (or he was willing to work for free), there would be a http://fbi.lavabit.com/snowden that mirrored all of Snowden's metadata and it would interoperate with the government's pen register. There would be no need to compromise everyone else's SSL key.

I'm not familiar with legal procedure, but how does that corrupt the chain of custody in a way that other solutions would not?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: