3 ms·
So you're saying lavabit is at fault for using SSL exactly how it was designed to be used? Did you know that your bank uses the same exact approach to SSL secu
by MagicWishMonkey 13y ago
So you're saying lavabit is at fault for using SSL exactly how it was designed to be used?
Did you know that your bank uses the same exact approach to SSL security? Did I just blow your mind?
- res0nat0r 13y agoYes, yes and no. Design a system where if the government wants access to one account, you have to give them access to everyones account to comply? Your fault.
- MagicWishMonkey 13y agoNo one designs systems like that because, up until now, the threat of having the feds confiscate your private SSL keys was unthinkable for those of us who don't wear tinfoil hats. And it's still not 100% clear that forcing a business to hand over their keys is even legal from a constitutional standpoint.
- res0nat0r 13y agoThe site wasn't designed to be 100% secure most likely due to it being overly complex and burdensome on the end user, thus reducing uptake. So a comprise was made and that is why it was designed the way it was...thus leading to a subpoena for the entire site since Lavabit didn't comply with handing over a specific users data. Also it is legal for the site to hand over their keys, it already happened. The only way it will become illegal is if the law somehow gets repealed.
- MagicWishMonkey 13y agoWhat? The site WAS designed to be 100% secure, which is why the government demanded he hand over his private keys. There was no compromise anywhere, financial institutions use the same exact security strategy. An insecure system would be one that makes it easy for a 3rd party to intercept communications (via warrant or through a disgruntled employee or whatever), that is basically what you are suggesting.
- tedunangst 13y agoFinancial institutions haven't promised to keep your info secret from the government when served with a warrant.
- tedunangst 13y agoPerhaps the problem is believing that using SSL exactly as designed is the right solution. Somehow tarsnap manages to keep my data safe without relying solely on SSL.