13 ms·
Lavabit SSL Cert Revoked
- deleted 13y ago[deleted]
- WestCoastJustin 13y agoCan someone weight in on what this means or why it is an issue?
- conductor 13y agoLadar Levison was forced to give Lavabit's SSL private key to the feds, so it is no more secure. That's why he (or GaDaddy, the issuer) revoked the certificate.
- miketucker 13y agoToday the owner, Ladar Levison, had to hand over the SSL certificates by court order. It marks the ending of a long battle in court, with unfortunately it ending in the govenment's favor. I'm assuming the post is just a hacker way of acknowledging the event. Related article: http://www.newyorker.com/online/blogs/elements/2013/10/how-lavabit-edward-snowden-email-service-melted-down.html http://www.newyorker.com/online/blogs/elements/2013/10/how-l...
- dedward 13y agoMore likely it's just the issuer doing what they need to do... it doens't matter that nobody will use it again anyway; from an issuer point of view, the certificate should no longer be valid. time to revoke it.
- mpyne 13y agoInteresting link, and much more informative than the other Lavabit news articles. It's a shame the government didn't work with Levison to either allow Levison to add the requested intercept himself (which, yes, would have required Uncle Sam to trust him) or to allow a third-party (or even a third party requested from both sides) to audit the proposed interception code. The judge is correct in stating that if Levison doesn't trust the government, then why should the government trust Levison, but Levison is clearly correct when he notes that giving up his SSL private keys would destroy the security of his whole infrastructure. The government would have been far better off by allowing a service like Lavabit to exist with the cooperation of an activist citizen than to force him to either harm all of his customers or shutdown the service. Somehow I don't think the D.A. here realized how serious many civil libertarians are. Props on Levison for trying to stick it out in the U.S. and make things better from within!
- quadlock 13y ago> The judge is correct in stating that if Levison doesn't trust the government, then why should the government trust Levison The judge is incorrect. The U.S. Government was designed to not completely trust itself. That's why there are checks and balances. Giving the FBI the private key lets them have unchecked access to data encrypted with it. It is wrong to asked to not be checked. [edited for format]
- Zoepfli 13y agoAlso, we have ample proof that the US Government cannot be trusted period. An entity that cannot be trusted can still reflect on itself, realize it has done lots of wrongs, and trust others that are reaching for higher standards.
- 13y ago
- stonemetal 13y agoIf lavabit returns to operation, or someone tries to pretend to be lavabit by using the cert then any visitor to the site would get a cert error until they get a new cert.
- orclev 13y agoTo my understanding this is what I would expect to happen. He handed over the cert to the FBI, so from a security standpoint it's useless now and should be considered compromised.
- enaeseth 13y agoWill having the private key allow the decryption of ciphertext that was previously intercepted (while the service was active) and stored? Lavabit was already shut down, so this revocation is equally useless for user security. :(
- bcoates 13y agoIf the connection was using a forward-secret key exchange (like DHE or ECDHE), then no. Unfortunately it's common not to and browsers don't do anything to warn people that they're using a low-security mode.
- Amadou 13y agoFWIW, just now I went looking for a firefox plugin that reports (in a human-friendly way) whether or not the SSL connection for a page is using perfect forward secrecy (PFS). I found "Calomel SSL Validation," which I am about to install. The PFS reporting only works with Firefox 25 and up. https://addons.mozilla.org/en-US/firefox/addon/calomel-ssl-validation/ https://addons.mozilla.org/en-US/firefox/addon/calomel-ssl-v...
- ihsw 13y agoIt would be interesting to see it be re-instated at the behest of the FBI.
- jevinskie 13y agoIt would be pointless, everyone knows by now that it is burned.
- recursive 13y agoPerhaps there is some automated robot that uses it that doesn't follow the news headlines.
- michaelmior 13y agoHopefully if such a robot really cares about security, it is checking for revoked certificates. Although this is admittedly a pain to set up.
- bcoates 13y agoThey'd have to go after GoDaddy to do that: $ curl http://crl.godaddy.com/gds1-64.crl | > openssl crl -text -noout -inform DER | > grep -A 6 2771FD5D73A8BB Serial Number: 2771FD5D73A8BB Revocation Date: Oct 3 22:57:44 2013 GMT CRL entry extensions: X509v3 CRL Reason Code: Key Compromise Invalidity Date: Feb 16 07:00:00 2012 GMT
- deleted 13y ago[deleted]
- jpinkerton88 13y agoThat's awesome that the certificate authority is being proactive.
- Fzzr 13y agoIs it clear that's the case? Or is it possible that this was upon request from Levison?
- jpinkerton88 13y agogood question. not sure
- maxk42 13y agoOr from the FBI
- alextingle 13y agoAnd this is exactly why perfect forward secrecy is so important.
- anologwintermut 13y agoDid he actually use forward secure SSL cipher suites for everything?
- jtdowney 13y agoThe site currently negotiates for DHE-RSA-AES256-SHA, which is forward secure.
- anologwintermut 13y agoRight. But if you connect with a browser that doesn't support that? And what about SMTP connections?
- jamesaguilar 13y agoPresumably if you care about security you are using a browser that does PFS and have personally verified that it is working.
- anologwintermut 13y agoIf you cared about security and knew enough to check that, you probably knew enough not to trust server side crypto and were using PGP or S/MIME on top of it or using OTR instead of email for secure conversations. That aside, this still leaves the very important question of SMTP traffic.
- sillysaurus2 13y agoYou mean browsers actually fall back to non-perfect-forward-secrecy? They even have the option of doing that? That's interesting if true. Ideally it should be enforced by the server, and if the browser can't support it, then the browser can't see the webpage.
- powertower 13y agoCan this be classified as - http://en.wikipedia.org/wiki/Obstruction_of_justice http://en.wikipedia.org/wiki/Obstruction_of_justice ? That is, I'm sure he understands that this action might be interfering with an investigation, and that it's reasonable to believe it was a willful act on his part. Can you get into trouble for doing something like this?
- koudi 13y agoNo. This does not affect their ability to use it. This certificate is simply no longer trusted by other parties (rightfully, because it was compromised). As matter of fact, this may not even be his doing.
- powertower 13y agoWhat if the 3rd party the FBI wanted to intercept via this Cert has now been 1) notified that there is a problem and 2) can no longer be intercepted (unless their browser does no CRL or OCSP checks on the domain's cert)?
- koudi 13y agoInteresting point. AFAIK they requested the key to decrypt previous communications. From security point of view, his move makes perfect sense. If FBI wanted to decrypt future communications, they would probably have specified that in their request. Then he would indeed break court order and could be hold responsible. On the other hand, it would be hard to prove any actual obstruction, since the service was shut down and all users notified about this whole situation.
- orblivion 13y agoWho would make future secure communications with Lavabit at this point? Certainly not Edward Snowden.
- chris_mahan 13y agoFollowing that line of reasoning down the slimy slippery slope, developing better encryption systems could be construed as obstruction of justice, no?
- deleted 13y ago[deleted]
- spindritf 13y agoI cannot ignore this warning in Firefox 24 from official repository on Ubuntu 13.04. Actually, I cannot ignore outdated certificates, or those with unknown OCSP status (for example freshly issued certs) either. Was there some change in Firefox's security model or is it my config? It's rather annoying.
- briansmith 13y agoFirefox treats an explicit "unknown" OCSP status as equivalent to being revoked, except we don't cache the "unknown" status. Firefox doesn't allow the user to override "revoked." The thinking behind our cert error override strategy is that cert error overrides are intended mostly to allow the user to fix something that is probably supposed to work, but a revocation is a very explicit signal that the certificate isn't supposed to work. Also, ensure Options -> Advanced -> Certificates -> Validation -> When an OCSP server connection fails, treat the certificate as invalid is unchecked.
- spindritf 13y agoThanks for answering. Yes, I have it unchecked. Is there some about:config magic or "kamikaze mode" that I could enable that would allow me to ignore at least outdated certs? Last night I locked myself out of my own website. The old cert expired and the OCSP server didn't know about the new one yet.
- conductor 13y agoYou can disable querying OCSP servers by setting the "security.OCSP.enabled" to false. This adds some privacy (otherwise OCSP servers can know and collect what SSL enabled sites you visit). Combined with the Certificate Patrol add-on [0] (to track certificate changes) this must be pretty secure, except when a certificate is being revoked you will not know about it automatically. [0] - http://patrol.psyced.org http://patrol.psyced.org
- newman314 13y ago
- deleted 13y ago[deleted]
- rebelidealist 13y agoConsider donating to https://rally.org/lavabit https://rally.org/lavabit. Lavabit needs at least 250k to continue fighting in the supreme court. See his last update on the rally page.
- interstitial 13y agoAnd our contribution becomes part of our "permanent record" with the NSA? So glad I'm a US citizen and need not fear about such things.
- scott_karana 13y agoThat just sounds like fearmongering. I can't see any way that helping to fund someone's court case can be considering a crime, even if he were completely in the wrong. I strongly suspect that there are favourable legal precedents, even.
- kyboren 13y agoNon-citizens can be turned away at the US border for any reason, or no reason at all. Considering that a person's ability to travel to the US is so professionally important in this industry (for conferences, business meetings, etc.), I do not believe this is fearmongering. Remember the case of the man refused entry after a misinterpreted Tweet about 'destroying America'? [1] It seems clear NSA surveillance informs CBP's entry decisions in at least some cases. Credit card payments are surely surveilled by NSA, so this actually sounds like a pretty well-grounded fear. [1]: http://www.nbclosangeles.com/news/local/British-Tourists-Denied-US-Entry-Twitter-Comments-Customs-Border-Protection-138364904.html http://www.nbclosangeles.com/news/local/British-Tourists-Den...
- PeterisP 13y agoIf such donations really cause problems at borders, then it will be a sign that the place is FUBAR and you (and everyone else) should avoid traveling there.
- l33tbro 13y agoI'm so sick of being sickened. I hate that this is becoming the norm and we can't do anything about it. I hate to spit cliches, but is this where my tax dollars go? For me, govt and internet should almost be like church and state. Where is the data around foiled terrorist plots? I just can't stomach the obtuse logic that we need to pay our taxes to employ these virtual minders. This is not what the internet is about. It just seems so incredibly difficult to mobilise and take action against this shit ... Btw, Ladar ... you've been incredible in all of this (tips Stetson)
- thangalin 13y agoI have mocked-up a system for policy creation. The project is open; please contribute your thoughts. People say "it has flaws" but never explain the flaws, nor how to address them. https://bitbucket.org/djarvis/world-politics/ https://bitbucket.org/djarvis/world-politics/ Would greatly appreciate constructive criticism. The system serves to educate everyone (openly and transparently) on implications of existing and upcoming policies. If the idea intrigues you, check out what other people are doing along the same lines: https://bitbucket.org/djarvis/world-politics/wiki/Related%20Links https://bitbucket.org/djarvis/world-politics/wiki/Related%20... Rather than getting to the point where citizens have to "mobilize against" the current government, we should be seeking to self-govern in such a way that mobilization is not necessary.
- Buttons840 13y agoI like the ideas you present. Does this site exist? If not, what existing sites do you think are closest to your vision?
- thangalin 13y agoThe site I have mocked-up does not exist. I want to work on it, but it does not pay, and I need to eat. :-) I am working on a side-project (yes, a start-up) that will provide the income I need to work full-time on the World Politics idea. The closest idea is probably: https://canada.yrpri.org/ https://canada.yrpri.org/ It has a number of issues, though.
- deleted 13y ago[deleted]
- tomphoolery 13y agoWell this is annoying.
- robmcm1982 13y agoThey are still down today.
- schrodinger 13y agoSafari on my iPhone is capable of accessing it with no warning. Anyone else seeing this?
- chmars 13y agoConfirmed.
- thefreeman 13y agosame with chrome on my android
- 7402 13y agoI wondered why Safari (running on an older OS X 10.6 system) didn't report the certificate as revoked, although Firefox on the same system did. The answer appears to be as described here: http://www.intego.com/mac-security-blog/protect-safari-from-fraudulent-digital-certificates/ http://www.intego.com/mac-security-blog/protect-safari-from-... After setting the proper options in Keychain Access, Safari reported the revocation correctly.
- pkteison 13y agoFYI, this was enabled by default in Lion (10.7.2).
- brian_cloutier 13y agoLavabit has revealed something incredibly important. The US Government has no problem with seizing your private keys. It claims the right to impersonate you without your permission. It no longer matters which system you use, Sovereign Keys, PGP web-of-trust, traditional PKI, they're all the same. Services based in the US can be MITM'd without leaving any traces. If this is allowed to continue uncontested there will no be no way to stay secure online. The only solution is a partial solution, to create decentralized services. This, at least, will require the government to seize the private keys of each individual they want to track.
- dobbsbob 13y agoThe only way to stop this is to dismantle the police state. We have no chance of keeping up with their anti-privacy arms race
- kordless 13y agoLet's replace them with an app while they are in halt mode.
- anologwintermut 13y agoThe government already got to seize private keys when they got search warrants and ceased servers. I'd imagine this is the case in all of Western Europe.
- xyzzyz 13y agoYes, but they weren't able to use them for MITM attacks, as seizing servers either equaled to shutting down a service, or allowed service operator to change the keys, so seized keys were useless. Now they feel they have right to obtain the private keys for you, and impose a gag order, so that you cannot change the compromised key. I doubt that significant amount (if any) of western European countries are able to force you to keep using compromised private key, and keep you silent about this using a gag order.
- joe_the_user 13y ago
- general_failure 13y agoAndroid 4.3 cm shows page with no problems. CRL not working?
- drivebyacct2 13y agoConfirmed. https://lh6.googleusercontent.com/-6emYmxfdYQI/UlSXCljXjTI/AAAAAAAAV5g/P6oTMjpavjs/w497-h883-no/13+-+1 https://lh6.googleusercontent.com/-6emYmxfdYQI/UlSXCljXjTI/A...
- chimeracoder 13y agoSame thing for me, in both Chrome and the default browser. This is troubling.
- flux_w42 13y agoHere to with 2.3.7-CM. If you explicitly check the certificate it even says: "This certificate is valid" with a reassuring green check mark. Seems legit ... These things really makes me pull out my hair.
- anologwintermut 13y agoAnyone using Safari or IE apparently isn't getting a forward secure connection to https://Lavabit.com https://Lavabit.com . They end up with TLS_RSA_WITH_AES_256_CBC_SHA according to SSLLabs[0]. Since things escalated to the point where Lavabit had to hand over it's key rather than the data on one account the FBI obtained an initial court order for [1], anyone with a transcript of those sessions and access to the key can read them. The resulting cipher suites: IE 6 / XP No FS * SSL 3 TLS_RSA_WITH_3DES_EDE_CBC_SHA (0xa) No FS 168 IE 7 / Vista TLS 1.0 TLS_RSA_WITH_AES_256_CBC_SHA (0x35) No FS 256 IE 8 / XP No FS * TLS 1.0 TLS_RSA_WITH_3DES_EDE_CBC_SHA (0xa) No FS 168 IE 8-10 / Win 7 TLS 1.0 TLS_RSA_WITH_AES_256_CBC_SHA (0x35) No FS 256 IE 11 / Win 8.1 TLS 1.0 TLS_RSA_WITH_AES_256_CBC_SHA (0x35) No FS 256 Safari 5.1.9 / OS X 10.6.8 TLS 1.0 TLS_RSA_WITH_AES_256_CBC_SHA (0x35) No FS 256 Safari 6 / iOS 6.0.1 TLS 1.0 TLS_RSA_WITH_AES_256_CBC_SHA (0x35) No FS 256 Safari 6.0.4 / OS X 10.8.4 TLS 1.0 TLS_RSA_WITH_AES_256_CBC_SHA (0x35) No FS 256 Safari 7 / OS X 10.9 TLS 1.0 TLS_RSA_WITH_AES_256_CBC_SHA (0x35) No FS 256 [0]https://www.ssllabs.com/ssltest/analyze.html?d=https%3A%2F%2Flavabit.com https://www.ssllabs.com/ssltest/analyze.html?d=https%3A%2F%2... [1]http://www.wired.com/threatlevel/2013/10/lavabit_unsealed/ http://www.wired.com/threatlevel/2013/10/lavabit_unsealed/
- rektide 13y agoAlmost on display: heavy-handed web-browsers that won't let us visit a site, for our own good.
- bcoates 13y agoUnfortunately the way cookies, etc. work it's nontrivial for a browser to just visit a site that's offering a compromised certificate without undermining past and future security. A revoked certificate being offered doesn't have any innocent explanations, you would want to use a specialized tool not a general-purpose web browser to analyze it.
- tonyplee 13y agoThe rebel's force is weaken. Feel the power of the Empire. :-)
- lettergram 13y agoI've read quite a few complaints about the government on this post. My suggestion is to simply do something. You have (a) the ability to vote, so stop voting in Republicans OR Democrats (both equally as bad) OR even run yourselves. (b) send a letter to your representative, they occasionally will read the mail, plus you at least can vent your frustration at someone who CAN do something.
- deleted 13y ago[deleted]
- MustBeAShill 13y agoOr run for office yourself. I would vote for a centrist candidate that offered a bill that declared email as sacrosanct as a telephone call or postal mail.
- balabaster 13y agoThe only issue with running yourself is that you need enough funding to generate more propaganda and PR than the cartel you're up against... and you forget that lobbyists run your country anyway. Don't delude yourself into thinking that your vote actually means anything. That "democracy" you think you live in is theatre designed to make you feel cosy and warm, just like the TSA does when they "protect" your air travel. It's all just a sham to keep you and everyone else from rocking the boat too much.
- deleted 13y ago[deleted]
- huslage 13y agoThis is not new people! We've known for many years that MiTM was "normal" in surveillance circles. We've been saying for years that CAs are probably compromised as well. Why does it take some "revelation" to make people PAY ATTENTION? This is not a technical issue. It's a rights issue. Solving it by technical means only kicks the can down the road by an exceedingly small amount of time. Fix the system first.
- MustBeAShill 13y agoIsn't the fact the cert was revoked showing that the CA system works? The FBI would love for it to be still chained back to a valid CA. You were only seconds away from calling folks "sheeple", weren't you ;)
- zmmmmm 13y agoSo I wonder, if he has been banned from revealing that he has handed over the key, does revoking it count as such a revelation? At this point, the authorities have Streisand'ed their own case - anybody they were interested in would have stopped using Lavabit months ago. So they seem to be pursuing it out of pure belligerence at this point.
- beedogs 13y agowhich isn't all that surprising. The feds act like spoiled children when they don't get their way.
- SCAQTony 13y agoThis is both chilling and depressing. The only reason why the general public is barely phased or even cares about this nonsense is that they don't even understand what a SSL Cert is or what it means to have it taken away.
- interstitial 13y agoI'm sure this comment will be buried, but I sleep better at night knowing HN can still get its panties in a wad over tramplings of freedom and the abuse of the system -- long after the main stream media has lost interest. The young and old hackers reading these posts will no doubt start spending frontal lobe CPU cycles on solutions that will find their agile way into the public sphere in months, not years.
- balabaster 13y agoAm I reading into this right? The court declared he must hand over the private key to the SSL encryption on his server so the government could do as they wished with the traffic... and then Levison revoked the key, thus making it useless to everyone?
- scintill76 13y agoHe shut down the site, so unless they've been capturing all the encrypted data and the sessions didn't have forward secrecy, the key was already useless.
- jervisfm 13y agoWhen I viewed this page running Chrome (Version 30.0.1599.88 beta) on a ChromeOS device I did not get any warnings. Interestingly, when I used chrome on my Win8 PC (version 29.0.1547.76 m), I did see the warning pop up. Doing some quick searching online revealed that chrome does not appear to do online revocation checks any longer by default[1]. You can still manually turn it back on with the "Check for server certificate revocation"[2] option which is what I did. [1] - http://www.macworld.com/article/1165273/google_chrome_will_no_longer_check_for_revoked_ssl_certificates_online.html http://www.macworld.com/article/1165273/google_chrome_will_n... [2] - chrome://settings/search#revocation
- deleted 13y ago[deleted]
- malandrew 13y agoThe lavabit case highlights something interesting that we need. We need that not only individuals have privacy, but that businesses have privacy of who their users are. The same way we provide anonymity to users through centralized means, is there not a way to provide a way for service provider to have a sufficient level of opaqueness of who their customers are. You can't subpeona Service Provider A if you don't know whether Person of Interest X is using the services of A, B, C, or D, etc.