Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Suppose that Lavabit sold smart cards for end-to-end encryption, and as a service would store ciphertexts for you. The government shows up with a warrant, Lavabit says, "Sorry, we cannot comply because we cannot access secret keys or decrypt messages by some other means." What exactly does the government do after that?

The point is that Lavabit's architecture did not resist these kinds of demands at all. At best all Lavabit could do is protect your mail until you log in.



So here's a hypothetical for you. Suppose we build an architecture which you feel is more secure. Then the NSA people say "we have analyzed it, and there's a theoretical information leak. because that information leak exists you have to install our software which will exploit it. but if you'd designed your system better you would have been okay. also, incidentally, you're now legally forbidden from fixing this leak."

Then the legal obligations of the architecture are primary determined by the effectiveness of your security architecture; the existence of defects in the architecture which would preserve security in the absence of their exploitation is the thing matters to the court system.

That sounds tantamount to what you're proposing; is that really the sort of legal framework you think we have / should have? I personally think it's ridiculous, and I reject your justification and others which rely on a technical deficiency in Lavabit's implementation to endorse the legality and moral authority of the court's orders.


"Suppose we build an architecture which you feel is more secure. Then the NSA people say "we have analyzed it, and there's a theoretical information leak. because that information leak exists you have to install our software which will exploit it. but if you'd designed your system better you would have been okay. also, incidentally, you're now legally forbidden from fixing this leak.""

One of the features of a good security system is that there is no single party that can be compromised in a way that violates everyone's security. Basically, your example assumes that the system has a fundamentally risky design.

Even if you need a trusted party in your design, it should be the case that the party only has a limited ability to violate everyone's security. For example, consider an identity-based encryption system, which by its nature requires a trusted party to generate keys. Under the right circumstances, that party can delete the master secret key needed to generate keys; one can imagine setting things up so that the master secret is destroyed periodically, say once per month, so that only keys that were recently issued can be compromised if the authority is compromised (your identity under such a system might include some information about when your key was issued).

"I reject your justification and others which rely on a technical deficiency in Lavabit's implementation to endorse the legality and moral authority of the court's orders."

I think it would be fantastic to have a trustworthy government, but that is orthogonal to the issue here, because the security of a system like Lavabit is not limited to resisting court orders. Suppose the Lavabit have become as big as GMail i.e. big enough that the government might threaten an antitrust investigation if special favors were not performed. Suppose that a foreign government was trying to conduct industrial espionage against Lavabit's users, and surreptitiously installed eavesdropping software or equipment.

For that matter, suppose that you were personally involved in a lawsuit against Ladar. Would you communicate with your lawyer using Lavabit in that situation?

Also consider the reality that laws can change. It might take a massive terrorist attack to cause laws to change for the worse. Maybe a dictator will rise to power. Maybe people will just stop caring. Maybe it will be a combination of things, but the point is that building a system that relies on the law to protect users' rights is a fundamentally bad approach. It was not merely laws that stopped mass surveillance previously; when letters were sent primarily via the postal system, it was the lack of abundant and automatic copying that prevented mass surveillance. Laws are easy to change; widely deployed and widely used technologies are much harder to change (at least in ways that conform to the desires of politicians and governments).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: