4 ms·
The new certificate does not offer Forward Secrecy https://www.ssllabs.com/ssltest/analyze.html?d=liberty.lavabit.com https://www.ssllabs.com/ssltest/analyze.ht
by robhu 13y ago
The new certificate does not offer Forward Secrecy https://www.ssllabs.com/ssltest/analyze.html?d=liberty.lavabit.com https://www.ssllabs.com/ssltest/analyze.html?d=liberty.lavab...
Does this not mean that the NSA could patiently log all the traffic going in and out of the site over the next few days, then get a court order for this new SSL private key, then decrypt the traffic they collected?
I may have misunderstood, but doesn't that make this something of a trojan horse? Many users will login and try to download all their email, and for everyone who does, when the NSA (very likely) get a court order for the new SSL key, they'll have that large amount of private email everyone tried to copy from the site?
- koenigdavidmj 13y agoDestroy the key immediately after the 72 hours? EDIT: And hope the relevant courts are not running during those 72 hours?
- gentoomenpls 13y agoMaybe weasel wording on the warrant? They only ordered him to disclose the old ssl key, maybe it doesn't apply to the new one?
- robhu 13y agoPerhaps... but does it not seem rather a little odd that someone so knowledgeable about security who had Forward Secrecy on before would now /accidentally/ get a new certificate without it? This doesn't make sense, he would have had forward secrecy on unless there was some reason not to do so (like he was compelled not to, or if he isn't even the one doing all this).
- ge0rg 13y agoThis is something that striked me as missing in the Lavabit key warrant discussion: was Forward Secrecy merely an option on the server before the shutdown, or was it enforced on all connections, regardless of client support? If not all connections used it, FBI / NSA are probably now in the position to decrypt earlier recordings of user sessions, thus recovering the passwords, email contents etc... From reading the ssllabs report, it looks like even with the current setup, sessions by IE and Safari (also Android?) users can be recovered once the new key is obtained via court order.
- anologwintermut 13y agoBefore they came back up, I ran SSL labs test on their site. It did support forward security for some browsers. Now it supports none. No idea about before the warrant, but I don't see any good reason to think it changed it changed https://news.ycombinator.com/item?id=6518430 https://news.ycombinator.com/item?id=6518430
- eli 13y agoIf he intended to give the government access to your email, wouldn't there be much easier to implement and harder to detect ways of accomplishing it than a wonky cipher suite setting?
- bennyg 13y agoWhy not cover all of the bases?
- mikeash 13y agoThis is probably wandering too far into conspiracy territory, but what if he's being forced to do it but doesn't want to, and this is his way of obeying badly?
- sgentle 13y agoI don't think that's at all too far into conspiracy territory. Keep in mind that him being forced to do something and obeying badly (because he couldn't talk publicly about it) is a pretty precise description of the events leading up to the shutdown.
- JshWright 13y ago> get a new certificate without it? The certificate isn't what control PFS, it's the allowed (and preferred) cipher suites. You can enable PFS without changing your cert.
- edwintorok 13y agoNitpick: it is not the certificate that offers Forward Secrecy or not, it is the server's SSL cipher-suite settings.
- sneak 13y agoForward secrecy in this instance does not matter one bit. Presuming they've imaged the drives with their encrypted mail, all they'd have to do is a half-dozen line patch to the code to log the passwords to disk as they come in. Then they can decrypt everyone's private keys, and decrypt everyone's mail, PFS or no. Anyone sending their Lavabit password outside of their own home is simply asking for someone else to decrypt and read their email. If I had been a Lavabit customer, I would see this cipher suite as him saying-without-saying that this service is suspect and is to be avoided at all costs.
- switch007 13y ago> ... I would see this cipher suite as him saying-without-saying that this service is suspect and is to be avoided at all costs. Exactly my thoughts too.
- XorNot 13y agoOr you know, he could just publish that the key is not secure. There's no hidden messages here, I would put more money on Lavabit screwing up.
- grey-area 13y agoThe majority of lavabit users probably joined on principle and would not be harmed by the NSA having their secrets at present. For those users the convenience of getting hold of all their mail (if they didn't have a local backup) might be worth the tradeoff of having to change their password and risk the NSA recording/decrypting their data on lavabit. Others could simply not access the data if they want to leave it encrypted. At least this option gives the users that choice.
- gentoomenpls 13y agoCould you revisit the link you posted? I believe it now implements Forward Secrecy...