7 ms·
GoDaddy Pulls Lavabit's Security Creds Because the FBI Got Its Encryption Keys
- venus 13y ago> “[W]e’re compelled by industry policies to revoke certs when we become aware that the private key has been communicated to a 3rd-party and thus could be used by that party to intercept and decrypt communications” This raises an interesting possibility of civil disobedience. Imagine if there was a site hosted in, say, russia, which received tip-offs from NSL recipients about these SSL seizures. And imagine they then informed the SSL issuers, who would revoke the certs, rendering the old ones useless and forcing the FBI back into court, with no-one to point a finger at. I suppose the FBI would just request an order for all future certs as well.
- shubb 13y agoWell, the finger is pointing at the NSL recipients. They are supposed to be the only people that know about the order, so they carry the can if it gets leaked.
- venus 13y agoThere'd be a lot of people inside the FBI with knowledge. Proving it was an NSL recipient, let alone nailing down which one, would be difficult if not impossible in court. Snowden's leaked a whole lot more than any NSL recipient ever did...
- tankenmate 13y agoIn that case you could use flapping certificates as a dead man's switch.
- malandrew 13y agoflapping certificates?
- tankenmate 13y agoIf the certificate keeps changing, regardless of whether it is valid and/or expired, then it is an indicator that not all is well.
- hnha 13y agoalready discussed at https://news.ycombinator.com/item?id=6517553 https://news.ycombinator.com/item?id=6517553 no need for a Forbes link of all.things.
- crb 13y agoI found it interesting that GoDaddy revoked the certificate - previously, I had assumed Levison did it himself.
- annnnd 13y agoGood point - linked article missed that (crucial IMHO) piece of data.
- Shivetya 13y agoI am curious if the FBI could step in and prevent GoDaddy from taking this action. Secret courts do not seem to have realistic limits. In this context, can SSL be trusted?
- deleted 13y ago[deleted]
- p4bl0 13y agoWell, now that the certificate has been revoked, it's too late for the FBI to do anything: either users saw that the certificate has been revoked, or they didn't yet but if a new certificate is installed they will see that it's a new one with a different fingerprint (at least their browser should warn them of that).
- msumpter 13y agoI don't think it's entirely clear that GoDaddy revoked the certificate on their own. Their statement was they were made aware, it's unclear if they became aware based on news coverage, or Levison made them aware of the key compromise. I'm not entirely convinced GoDaddy would want to insert itself voluntarily into a federal court case based on news reports. But I do think they would revoke a certificate if Levison reported the key compromised as standard procedure. I can see threats of obstruction charges being thrown at GoDaddy for interfering with the investigation.
- michaelfeathers 13y agoMaybe ditching one's certs can become the new warrant canary.
- betterunix 13y agoI have wondered what the legal implication of revoking certificates after complying with a court order to turn over private keys would be. I assume that the court would hole you in contempt for doing so, but IANAL.
- Daniel_Newby 13y agoThis is why competent people use write-only key modules with aggressive tamper-detection and self-destruct capabilities.
- forgotAgain 13y agoThanks to Lavabit’s design, Levison could not simply offer a tap of a particular user’s communications if that user had paid for a secure, encrypted account. That line really bothered me. The government demanded access to all user's data and this line places the responsibility for that onto Lavabit. The government wants all of our data, all of the time. They are the responsible party not Lavabit.
- rtpg 13y agoWhile the government might want all of our data, the NSL in question (at least according to the New Yorker piece ) requested only the data on one user(presumably Snowden). Levison was unwilling to put the software into place to tap into this single person's communcation. There was a warrant, but he wanted to charge $3.5k for the effort. I don't know how I feel about that. In any case the Judge then said to just hand over the SSL keys so that they could do it "the old fashioned way" (listening to everything on the line). Anyways, the point is that the original intent was not to get everyone's data, yet this is the point everyone keeps on parroting. The original intent was always to specifically get this single user's information, not some sort of power play by the FBI. Maybe things changed down the line but I feel like none of us are in a position to know that (although who knows, Mulder might spend his time trolling HN)
- uxp 13y ago> There was a warrant, but he wanted to charge $3.5k for the effort. I don't know how I feel about that. How would you feel if the police/FBI came to you with a warrant that requested all video footage from outside your home so they could spy on your neighbor's comings and goings. Oh, and by the way, you don't have a security camera system, and they aren't going to reimburse you to install one. If you do not produce video evidence, you are then disobeying the warrant and are in contempt of court. Lavabit's system was not designed to listen in to one persons communications. It would cost money to implement that system. He requested he be compensated for his effort ($3500 is a piddly amount of money anyways), and they came back and said that was too much effort, so they'll take the entire thing. Back to the analogy, should the cops/FBI be able to possess your home in order to spy on your neighbor because you don't have a security system installed?
- paulschreiber 13y agoPeople still use GoDaddy?
- wmeredith 13y agoGoDaddy gets a lot of nerd hate (for good reason). However, they also market a lot which = mainstream dollars. They're the number one domain registrar with 32% of the market. The second largest is Enom with 8%. Source: http://www.webhosting.info/registrars/top-registrars/global/ http://www.webhosting.info/registrars/top-registrars/global/
- alexwright 13y agoI still use GoDaddy for a couple of names because they support DNSSEC DS records. I'd like to move them out, but my other providers don't even have a roadmap to implement DS/DNSSEC.
- benjarrell 13y agoPrice is why, for a 2 year wildcard certificate: GoDaddy is $180 per year Comodo is $428 per year DigiCert is $535 per year
- corford 13y agoThey're $170 with Namecheap
- codereflection 13y agoI think it also has to do with a lot people who are registering domains don't know any better.
- tsaoutourpants 13y agoI think the revocation misses the point: "if" the NSA has been logging all the traffic from Lavabit for the last 6 months, they can now use the SSL key to decrypt all the data they've stored. It's not just about future communications, but about decrypting the past.
- Daniel_Newby 13y agoI will repeat my previous comment: Perfect forward secrecy, bitches. If you use a protocol that supports perfect forward secrecy, and you ought to, then the private key is used only to authenticate the ephemeral session key, not to encrypt it. Compromise of the private key does not allow previous sessions to be decrypted. (Compromise does allow impersonation, though, which is why you need pre-distributed certificate revocations.)
- tsaoutourpants 13y agoI agree. But like virtually any site of which I am aware, Lavabit didn't force PFS. It's browser-negotiated. The "funny" thing is that there's a good chance that any one user might have been using PFS, so it's less likely that they can get a specific user's data (Snowden) and more likely that they can get a random sampling of other, non-target users' data.
- malandrew 13y agoBut does pfs protect meta data as well?
- some1else 13y agoThe site is down due to Lavabit's decision. GoDaddy pulling it's certificate is just a PR move. GoDaddy supported SOPA, which is very much in line with what NSA demanded of Lavabit.
- haroldp 13y agoAt the risk of saying anything nice about GoDaddy, this seems like it was the right move. Known compromised keys should be revoked. This key was clearly compromised. Now what other Microsoft/Skype/Yahoo/etc keys can we demonstrate were also handed over to the government?
- deleted 13y ago[deleted]
- nivla 13y agoWhat? Why would you give them your private key in the first place? You only need to sent in your public key to have it signed. The only two scenarios I can imagine is if they had generated both the public and private key for you or if they had offered to backup it up.
- bsullivan01 13y agoKnowing that the FBI has Lavabit’s keys, GoDaddy shuttered its secure site. Next: Getting a judge to forbid GoDaddy etc from revoking the certificates. Interesting times we live, a parallel reality is created