3 ms·
The "shitty security" you are referring to is the defacto SSL standard implementation. The same implementation used by your bank, fortune 500 corporations, and
by MagicWishMonkey 13y ago
The "shitty security" you are referring to is the defacto SSL standard implementation. The same implementation used by your bank, fortune 500 corporations, and the federal government.
- alexkus 13y agoI'm guessing the GP was referring to the fact that Levison didn't update Lavabit to prefer ciphers that provide perfect forward security. Here is his own admission on the subject:- " When I was designing the Lavabit encrypted storage feature in 2004, it simply wasn’t possible for an attacker to intercept and decipher a large number of SSL connections in real time. This assumption was presumed true even if an attacker managed to gain access to the SSL private key. The situation has obviously changed. Network tools now decipher SSL connections efficiently, and servers are fast enough to make this attack a reality. A theoretical weakness became practical. I missed that development. More importantly, I failed to update the Lavabit SSL configuration to prefer ciphers that provided perfect forward secrecy. " Source: http://arstechnica.com/security/2013/11/op-ed-lavabits-founder-responds-to-cryptographers-criticism/ http://arstechnica.com/security/2013/11/op-ed-lavabits-found...
- MagicWishMonkey 13y agoHe misspoke: http://www.reddit.com/r/IAmA/comments/1qetvk/i_am_ladar_levison_owner_and_operator_of_lavabit/cdcnh5v http://www.reddit.com/r/IAmA/comments/1qetvk/i_am_ladar_levi... I agree that he should have been more pro-active with PFS, but he did not consider a national security request to surrender his SSL keys as a legitimate threat. He's somewhat paranoid but he doesn't wear a tinfoil hat or anything.
- res0nat0r 13y agoThese comments sound like the guy is getting a pass for his screwup, and the only reason why is because the government is the one doing the subpoenaing. If the situation was reversed everyone where would be cheering at how incompetent and idiotic the government is. It should be owned up that he designed his system with a weak spot, and that weak spot was obviously used to legally subpoena the data the government wanted access to.
- res0nat0r 13y agoMy bank has never claimed anywhere that my banking records are totally secure and that they would never have a chance of being turned over to the Feds if there was an investigation.