4 ms·
It's fairly obvious that you have no clue how SSL actually works. Do you honestly think that it would make sense to set up a completely new domain for each and
by MagicWishMonkey 13y ago
It's fairly obvious that you have no clue how SSL actually works.
Do you honestly think that it would make sense to set up a completely new domain for each and every user? Do you have any idea what a nightmare that would be to support? Do you think it would be cost effective to spend $50/year per user to implement such a system?
And do you really think that SSL has anything at all to do with the encryption used for storing data inside his system?
- MichaelGG 13y agoActually you could implement it rather easily using a wildcard cert and a CA provider that provides unlimited signings (like DigiCert). The user goes to "https://myuser.whatever.com" https://myuser.whatever.com", and you use SNI to select the private key. It might be a pain to manage, and you'd need to get your wildcard cert resigned for each private key, but that's just logistics.
- MagicWishMonkey 13y agoIt would be a nightmare to manage, and you would have to explain to all 400k of your customers how connect to the smtp/imap endpoint for that particular user. Completely and totally unrealistic for an email provider. The support costs alone would bankrupt the company.
- MichaelGG 13y agoReally? Server: <username>.provider.com. Anyways, I'm just pointing out that it is possible to provide per-user certificates.
- jlgreco 13y agoThat would cause any particular user to leak what user on the site they were. In other words, if I connect with https to lavabit normally, anyone watching my connection knows I went to lavabit, but don't know what account I am associated with. If I have to hit a subdomain specific to my user, then they know.
- res0nat0r 13y agoSad that the parent is being down voted for being 100% correct. He designed his system to have a single point of failure. The government then exploited that fact because it would allow them to get access to the data they want. This is Lavabits fault, not anyone elses.
- MagicWishMonkey 13y agoSo you're saying lavabit is at fault for using SSL exactly how it was designed to be used? Did you know that your bank uses the same exact approach to SSL security? Did I just blow your mind?
- res0nat0r 13y agoYes, yes and no. Design a system where if the government wants access to one account, you have to give them access to everyones account to comply? Your fault.
- MagicWishMonkey 13y agoNo one designs systems like that because, up until now, the threat of having the feds confiscate your private SSL keys was unthinkable for those of us who don't wear tinfoil hats. And it's still not 100% clear that forcing a business to hand over their keys is even legal from a constitutional standpoint.
- res0nat0r 13y agoThe site wasn't designed to be 100% secure most likely due to it being overly complex and burdensome on the end user, thus reducing uptake. So a comprise was made and that is why it was designed the way it was...thus leading to a subpoena for the entire site since Lavabit didn't comply with handing over a specific users data. Also it is legal for the site to hand over their keys, it already happened. The only way it will become illegal is if the law somehow gets repealed.
- pekk 13y agoIt's obvious that your straw man has no clue how SSL works. Why should the disclosure of one SSL key compromise all users of your service?
- MagicWishMonkey 13y agoBecause an SSL certificate is linked to a specific domain. It has nothing at all to do with user accounts. Creating a custom domain for each and every user is totally nonsensical from both a business and technical standpoint.
- pekk 13y agoGod did not say "Lavabit must only use SSL and cannot use any other measures to fulfill its understood and contractual obligations with customers". That is ridiculous.