3 ms·
A service that used a separate subdomain and SSL certificate per user could have avoided such a situation. Though this is an unreasonable burden for a service
by deepinsand 13y ago
A service that used a separate subdomain and SSL certificate per user could have avoided such a situation. Though this is an unreasonable burden for a service provider to bear for operating in the US.
- jlgaddis 13y agoHuh? You'd still have a private key per certificate. You might have one key for all of them or one key per cert, but you'd still have a private key for each of those certs. Unless I'm missing something?
- deepinsand 13y agoIf I read the article correctly, the Lavabit founder was unwilling to give up the private key because it would compromise all users, not just Snowden.
- jrockway 13y agoAnd giving up the SSL key for Snowden wouldn't give them anything useful, since he's probably not checking his US-based email anymore. (And SSL should be in perfect forward secrecy mode, so the private key can't be used to decrypt past sessions.)
- cbhl 13y agoThen the US could have simply moved up to asking for the private key to the wildcard certificate or certificate authority to do the requisite MITM.
- deepinsand 13y agoTrue, but presumably that would have been unconstitutional. As it was implemented, the only option they had was to demand Lavabit's private key, since they use the same SSL cert per user.