3 ms·
Perhaps... but does it not seem rather a little odd that someone so knowledgeable about security who had Forward Secrecy on before would now /accidentally/ get
by robhu 13y ago
Perhaps... but does it not seem rather a little odd that someone so knowledgeable about security who had Forward Secrecy on before would now /accidentally/ get a new certificate without it?
This doesn't make sense, he would have had forward secrecy on unless there was some reason not to do so (like he was compelled not to, or if he isn't even the one doing all this).
- ge0rg 13y agoThis is something that striked me as missing in the Lavabit key warrant discussion: was Forward Secrecy merely an option on the server before the shutdown, or was it enforced on all connections, regardless of client support? If not all connections used it, FBI / NSA are probably now in the position to decrypt earlier recordings of user sessions, thus recovering the passwords, email contents etc... From reading the ssllabs report, it looks like even with the current setup, sessions by IE and Safari (also Android?) users can be recovered once the new key is obtained via court order.
- anologwintermut 13y agoBefore they came back up, I ran SSL labs test on their site. It did support forward security for some browsers. Now it supports none. No idea about before the warrant, but I don't see any good reason to think it changed it changed https://news.ycombinator.com/item?id=6518430 https://news.ycombinator.com/item?id=6518430
- eli 13y agoIf he intended to give the government access to your email, wouldn't there be much easier to implement and harder to detect ways of accomplishing it than a wonky cipher suite setting?
- bennyg 13y agoWhy not cover all of the bases?
- mikeash 13y agoThis is probably wandering too far into conspiracy territory, but what if he's being forced to do it but doesn't want to, and this is his way of obeying badly?
- sgentle 13y agoI don't think that's at all too far into conspiracy territory. Keep in mind that him being forced to do something and obeying badly (because he couldn't talk publicly about it) is a pretty precise description of the events leading up to the shutdown.
- JshWright 13y ago> get a new certificate without it? The certificate isn't what control PFS, it's the allowed (and preferred) cipher suites. You can enable PFS without changing your cert.