TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Lavabit SSL Cert Revoked

420 pointsby jamboover 11 years ago

25 comments

brian_cloutierover 11 years ago
Lavabit has revealed something incredibly important.<p>The US Government has no problem with seizing your <i>private keys</i>. It claims the right to impersonate you without your permission.<p>It no longer matters which system you use, Sovereign Keys, PGP web-of-trust, traditional PKI, they&#x27;re all the same. Services based in the US can be MITM&#x27;d without leaving any traces.<p>If this is allowed to continue uncontested there will no be no way to stay secure online. The <i>only</i> solution is a partial solution, to create decentralized services. This, at least, will require the government to seize the private keys of each individual they want to track.
评论 #6518990 未加载
评论 #6518609 未加载
评论 #6518514 未加载
评论 #6518811 未加载
评论 #6518661 未加载
评论 #6519261 未加载
评论 #6519831 未加载
l33tbroover 11 years ago
I&#x27;m so sick of being sickened. I hate that this is becoming the norm and we can&#x27;t do anything about it. I hate to spit cliches, but is this where my tax dollars go?<p>For me, govt and internet should almost be like church and state. Where is the data around foiled terrorist plots? I just can&#x27;t stomach the obtuse logic that we need to pay our taxes to employ these virtual minders. This is not what the internet is about. It just seems so incredibly difficult to mobilise and take action against this shit ...<p>Btw, Ladar ... you&#x27;ve been incredible in all of this (tips Stetson)
评论 #6518562 未加载
评论 #6518237 未加载
评论 #6518788 未加载
评论 #6522266 未加载
评论 #6518824 未加载
orclevover 11 years ago
To my understanding this is what I would expect to happen. He handed over the cert to the FBI, so from a security standpoint it&#x27;s useless now and should be considered compromised.
评论 #6517972 未加载
评论 #6519209 未加载
anologwintermutover 11 years ago
Anyone using Safari or IE apparently isn&#x27;t getting a forward secure connection to <a href="https://Lavabit.com" rel="nofollow">https:&#x2F;&#x2F;Lavabit.com</a> . They end up with TLS_RSA_WITH_AES_256_CBC_SHA according to SSLLabs[0].<p>Since things escalated to the point where Lavabit had to hand over it&#x27;s key rather than the data on one account the FBI obtained an initial court order for [1], anyone with a transcript of those sessions and access to the key can read them.<p>The resulting cipher suites:<p>IE 6 &#x2F; XP No FS * SSL 3 TLS_RSA_WITH_3DES_EDE_CBC_SHA (0xa) No FS 168<p>IE 7 &#x2F; Vista TLS 1.0 TLS_RSA_WITH_AES_256_CBC_SHA (0x35) No FS 256<p>IE 8 &#x2F; XP No FS * TLS 1.0 TLS_RSA_WITH_3DES_EDE_CBC_SHA (0xa) No FS 168<p>IE 8-10 &#x2F; Win 7 TLS 1.0 TLS_RSA_WITH_AES_256_CBC_SHA (0x35) No FS 256<p>IE 11 &#x2F; Win 8.1 TLS 1.0 TLS_RSA_WITH_AES_256_CBC_SHA (0x35) No FS 256<p>Safari 5.1.9 &#x2F; OS X 10.6.8 TLS 1.0 TLS_RSA_WITH_AES_256_CBC_SHA (0x35) No FS 256<p>Safari 6 &#x2F; iOS 6.0.1 TLS 1.0 TLS_RSA_WITH_AES_256_CBC_SHA (0x35) No FS 256<p>Safari 6.0.4 &#x2F; OS X 10.8.4 TLS 1.0 TLS_RSA_WITH_AES_256_CBC_SHA (0x35) No FS 256<p>Safari 7 &#x2F; OS X 10.9 TLS 1.0 TLS_RSA_WITH_AES_256_CBC_SHA (0x35) No FS 256<p>[0]<a href="https://www.ssllabs.com/ssltest/analyze.html?d=https%3A%2F%2Flavabit.com" rel="nofollow">https:&#x2F;&#x2F;www.ssllabs.com&#x2F;ssltest&#x2F;analyze.html?d=https%3A%2F%2...</a> [1]<a href="http://www.wired.com/threatlevel/2013/10/lavabit_unsealed/" rel="nofollow">http:&#x2F;&#x2F;www.wired.com&#x2F;threatlevel&#x2F;2013&#x2F;10&#x2F;lavabit_unsealed&#x2F;</a>
rebelidealistover 11 years ago
Consider donating to <a href="https://rally.org/lavabit" rel="nofollow">https:&#x2F;&#x2F;rally.org&#x2F;lavabit</a>. Lavabit needs at least 250k to continue fighting in the supreme court.<p>See his last update on the rally page.
评论 #6518103 未加载
评论 #6518270 未加载
alextingleover 11 years ago
And this is exactly why perfect forward secrecy is so important.
评论 #6517937 未加载
lettergramover 11 years ago
I&#x27;ve read quite a few complaints about the government on this post. My suggestion is to simply do something. You have (a) the ability to vote, so stop voting in Republicans OR Democrats (both equally as bad) OR even run yourselves. (b) send a letter to your representative, they occasionally will read the mail, plus you at least can vent your frustration at someone who CAN do something.
评论 #6519270 未加载
评论 #6519049 未加载
powertowerover 11 years ago
Can this be classified as - <a href="http://en.wikipedia.org/wiki/Obstruction_of_justice" rel="nofollow">http:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Obstruction_of_justice</a> ?<p>That is, I&#x27;m sure he understands that this action might be interfering with an investigation, and that it&#x27;s reasonable to believe it was a willful act on his part.<p>Can you get into trouble for doing something like this?
评论 #6517941 未加载
评论 #6517946 未加载
7402over 11 years ago
I wondered why Safari (running on an older OS X 10.6 system) didn&#x27;t report the certificate as revoked, although Firefox on the same system did.<p>The answer appears to be as described here: <a href="http://www.intego.com/mac-security-blog/protect-safari-from-fraudulent-digital-certificates/" rel="nofollow">http:&#x2F;&#x2F;www.intego.com&#x2F;mac-security-blog&#x2F;protect-safari-from-...</a><p>After setting the proper options in Keychain Access, Safari reported the revocation correctly.
评论 #6518404 未加载
WestCoastJustinover 11 years ago
Can someone weight in on what this means or why it is an issue?
评论 #6517811 未加载
评论 #6517805 未加载
评论 #6518019 未加载
zmmmmmover 11 years ago
So I wonder, if he has been banned from revealing that he has handed over the key, does revoking it count as such a revelation?<p>At this point, the authorities have Streisand&#x27;ed their own case - anybody they were interested in would have stopped using Lavabit months ago. So they seem to be pursuing it out of pure belligerence at this point.
评论 #6519641 未加载
jpinkerton88over 11 years ago
That&#x27;s awesome that the certificate authority is being proactive.
评论 #6517872 未加载
ihswover 11 years ago
It would be interesting to see it be re-instated at the behest of the FBI.
评论 #6517964 未加载
评论 #6517899 未加载
评论 #6518467 未加载
huslageover 11 years ago
This is not new people! We&#x27;ve known for many years that MiTM was &quot;normal&quot; in surveillance circles. We&#x27;ve been saying for years that CAs are probably compromised as well. Why does it take some &quot;revelation&quot; to make people PAY ATTENTION?<p>This is not a technical issue. It&#x27;s a rights issue. Solving it by technical means only kicks the can down the road by an exceedingly small amount of time. Fix the system first.
评论 #6519063 未加载
schrodingerover 11 years ago
Safari on my iPhone is capable of accessing it with no warning. Anyone else seeing this?
评论 #6519217 未加载
评论 #6518572 未加载
interstitialover 11 years ago
I&#x27;m sure this comment will be buried, but I sleep better at night knowing HN can still get its panties in a wad over tramplings of freedom and the abuse of the system -- long after the main stream media has lost interest. The young and old hackers reading these posts will no doubt start spending frontal lobe CPU cycles on solutions that will find their agile way into the public sphere in months, not years.
spindritfover 11 years ago
I cannot ignore this warning in Firefox 24 from official repository on Ubuntu 13.04. Actually, I cannot ignore outdated certificates, or those with unknown OCSP status (for example freshly issued certs) either.<p>Was there some change in Firefox&#x27;s security model or is it my config? It&#x27;s rather annoying.
评论 #6518012 未加载
评论 #6518226 未加载
jervisfmover 11 years ago
When I viewed this page running Chrome (Version 30.0.1599.88 beta) on a ChromeOS device I did not get any warnings.<p>Interestingly, when I used chrome on my Win8 PC (version 29.0.1547.76 m), I did see the warning pop up.<p>Doing some quick searching online revealed that chrome does not appear to do online revocation checks any longer by default[1]. You can still manually turn it back on with the &quot;Check for server certificate revocation&quot;[2] option which is what I did.<p>[1] - <a href="http://www.macworld.com/article/1165273/google_chrome_will_no_longer_check_for_revoked_ssl_certificates_online.html" rel="nofollow">http:&#x2F;&#x2F;www.macworld.com&#x2F;article&#x2F;1165273&#x2F;google_chrome_will_n...</a><p>[2] - chrome:&#x2F;&#x2F;settings&#x2F;search#revocation
rektideover 11 years ago
Almost on display: heavy-handed web-browsers that won&#x27;t let us visit a site, for our own good.
评论 #6518737 未加载
balabasterover 11 years ago
Am I reading into this right? The court declared he must hand over the private key to the SSL encryption on his server so the government could do as they wished with the traffic... and then Levison revoked the key, thus making it useless to everyone?
评论 #6520129 未加载
SCAQTonyover 11 years ago
This is both chilling and depressing. The only reason why the general public is barely phased or even cares about this nonsense is that they don&#x27;t even understand what a SSL Cert is or what it means to have it taken away.
malandrewover 11 years ago
The lavabit case highlights something interesting that we need. We need that not only individuals have privacy, but that businesses have privacy of who their users are. The same way we provide anonymity to users through centralized means, is there not a way to provide a way for service provider to have a sufficient level of opaqueness of who their customers are. You can&#x27;t subpeona Service Provider A if you don&#x27;t know whether Person of Interest X is using the services of A, B, C, or D, etc.
评论 #6519769 未加载
general_failureover 11 years ago
Android 4.3 cm shows page with no problems. CRL not working?
评论 #6520007 未加载
评论 #6519113 未加载
评论 #6518579 未加载
tonypleeover 11 years ago
The rebel&#x27;s force is weaken. Feel the power of the Empire.<p>:-)
tomphooleryover 11 years ago
Well this is annoying.
评论 #6521129 未加载