TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

GoDaddy Pulls Lavabit's Security Creds Because the FBI Got Its Encryption Keys

95 pointsby bcnover 11 years ago

8 comments

tsaoutourpantsover 11 years ago
I think the revocation misses the point: "if" the NSA has been logging all the traffic from Lavabit for the last 6 months, they can now use the SSL key to decrypt all the data they've stored. It's not just about future communications, but about decrypting the past.
评论 #6528170 未加载
venusover 11 years ago
&gt; “[W]e’re compelled by industry policies to revoke certs when we become aware that the private key has been communicated to a 3rd-party and thus could be used by that party to intercept and decrypt communications”<p>This raises an interesting possibility of civil disobedience. Imagine if there was a site hosted in, say, russia, which received tip-offs from NSL recipients about these SSL seizures. And imagine they then informed the SSL issuers, who would revoke the certs, rendering the old ones useless and forcing the FBI back into court, with no-one to point a finger at.<p>I suppose the FBI would just request an order for all future certs as well.
评论 #6527247 未加载
评论 #6527828 未加载
michaelfeathersover 11 years ago
Maybe ditching one&#x27;s certs can become the new warrant canary.
评论 #6528064 未加载
hnhaover 11 years ago
already discussed at <a href="https://news.ycombinator.com/item?id=6517553" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=6517553</a><p>no need for a Forbes link of all.things.
评论 #6526782 未加载
forgotAgainover 11 years ago
<i>Thanks to Lavabit’s design, Levison could not simply offer a tap of a particular user’s communications if that user had paid for a secure, encrypted account.</i><p>That line really bothered me. The government demanded access to all user&#x27;s data and this line places the responsibility for that onto Lavabit. The government wants all of our data, all of the time. They are the responsible party not Lavabit.
评论 #6527614 未加载
评论 #6527630 未加载
评论 #6528079 未加载
paulschreiberover 11 years ago
People still use GoDaddy?
评论 #6527874 未加载
评论 #6527945 未加载
评论 #6528520 未加载
some1elseover 11 years ago
The site is down due to Lavabit&#x27;s decision. GoDaddy pulling it&#x27;s certificate is just a PR move. GoDaddy supported SOPA, which is very much in line with what NSA demanded of Lavabit.
评论 #6528856 未加载
bsullivan01over 11 years ago
<i>Knowing that the FBI has Lavabit’s keys, GoDaddy shuttered its secure site.</i><p>Next: Getting a judge to forbid GoDaddy etc from revoking the certificates.<p>Interesting times we live, a parallel reality is created