4 ms·
> It is more than possible to build services that thwart the kinds of orders Levison received. Perhaps, but unless there is appropriate and firm pushback again
by enlashok 12y ago
> It is more than possible to build services that thwart the kinds of orders Levison received.
Perhaps, but unless there is appropriate and firm pushback against further legislative creep, mass surveillance, and abuses of process, etc then those other services are at risk of getting stamped out as well.
Levison is not a saint, but he doesn't have to be.
- tptacek 12y agoIf Levison was the only person doing this, my complaint might be less relevant. But he's not; he's at the vanguard of a trend, and is our best cautionary tale about what happens when people chase that trend.
- jacquesm 12y agoMaybe that's where you hit the wrong note then. Most of your writing here seems to be directed at Levinson particularly, not in the general sense as a cautionary tale aimed at the potential users of such a service.
- tptacek 12y agoI don't understand. Levison did something objectionable. Who am I supposed to direct my complaint at? Are you suggesting that I should instead reserve my complaints for the users of these services? That empirically does not work; there are millions of users, and none of them research the tools they use to communicate privately.
- jacquesm 12y agoLevinson did something stupid (possibly maliciously stupid, I'm not qualified to judge), the users did not do due diligence on the claims made by the service and from the looks of it Levinson is paying a price. But that ship has sailed. He fucked up, he tried hard to limit the damage and as far as I can see he's been punished just about enough. So if you're upfront about using this as a cautionary tale then that would start with either educating users of such services or with pointing out similarities between Levinson's flawed approach and other offers of services like that. Further dumping on Levison is pointless, it's like kicking a guy that is already down. Compare this with Karin Spaink taking on scientology knowing full well that that would bring down a lot of trouble, but doing society a great service in warning people of the dangers of that particular organization. For users of Lavabit any kind of warning is a bit late and I think they have learned their lesson (or at least, I would hope they did). Snake oil peddlers have been making money for years, the farmaceuticals or the broken-crypto ones look all the same from where I'm standing, they are playing with people's lives. But the ones that get caught are as far as I'm concerned neutralized, it's the ones that remain that deserve our attention, and their users as well.
- tptacek 12y agoWhat does "due diligence" by laypeople for crypto providers look like? I don't understand where you're going with this.
- jacquesm 12y agoIf you buy a climbing harness because you're going to go mountain climbing and you can't tell a good one from a piece of junk then maybe you shouldn't be climbing on mountains, no matter what the maker of the product claims. In the end, the responsibility for your life is yours and you can't outsource that. So looking over the product you buy is a minimum requirement for things that your life depends on, just going on claims absent independent verification of those claims is for want of a better word, terribly stupid. By analogy, if you're say, some technically adept guy that decides to screw over the NSA just using a service because it claims to be secure is probably not a good idea. In cases like that you either do it yourself or you assume that you are taking a risk. I can't really see Snowden, working for the NSA as a layperson in this context, just as I can't see a mountaineer as a layperson when it comes to evaluating mountaineering gear. Case in point, I worked on some pretty high structures in the gray past and I've rejected multiple 'definitely good' safety harnesses and clamps simply because they did not pass my personal standard for quality of such important gear. If I had chosen to continue and used them, and something would have happened to me because of the device failing then I would have partly blamed myself. If crypto is of life saving importance to you then you have to know at least enough to evaluate the service and if you can't do that then either you knowingly take a risk or you should probably not be doing what you plan on doing. My personal take on anything internet related is that since I can't predict the near future (let alone the far one) I assume that anything stored on my computers will become public one day. I suppose that even the most secure implementation available to us today is only one bug away from being wide open after all. Call me pessimistic. One last thing about lavabit, I can see at least one very obvious way in which lavabit could have been broken that would not require Levinson's cooperation at all (but would have required a lot more foresight on the part of the NSA). In a way it is reassuring that Levinson was able to do that he did, that lowers my estimate of the NSA being able to record and store at will considerably. After all, if they can't even afford to tap the ingoing and outgoing traffic of a service that offers secure email then either they are not very good in their target selection or their resources are spent on more interesting targets and so 'little fish' like Snowden can get away with their deeds. I'm pretty sure that that hole is now plugged and I would hope that the users of similar services now know that as soon as you hit 'send' your secret is no longer.