Lavabit Case Unsealed: FBI Demands Companies Secretly Turn Over Crypto Keys
jest3r writes "Lavabit won a victory in court and were able to get the secret court order [which led to the site's closure] unsealed. The ACLU's Chris Soghoian called it the nuclear option: The court order revealed the FBI demanded Lavabit turn over their root SSL certificate, something that would allow them to monitor the traffic of every user of the service. Lavabit offered an alternative method to tap into the single user in question but the FBI wasn't interested. Lavabit could either comply or shut down. As such, no U.S. company that relies on SSL encryption can be trusted with sensitive data. Everything from Google to Facebook to Skype to your bank account is only encrypted by SSL keys, and if the FBI can force Lavabit to hand over their SSL key or face shutdown, they can do it to anyone."
Understandable that he shut down.
The USA is ruled by evil bastards that have no respect for the citizens.
Time to revolt is now.
I don't see why they would want the SSL key, when presumably they have easy access to the data on the servers under the laughable "due process" already in place. Why would they want to intercept the traffic when they could just read it off the server?
This posting is provided 'AS IS' without warranty of any kind, implied or otherwise.
How is this legal? How do you get a warrant that broad? Are fishing expeditions now allowed by law enforcement?
In all fairness their first request was horseshit. The idea that the metadata of email even encrypted email is not protected is already so outlandish as to be nearly unbelievable. We now know we live in a police state.
This judge is either willingly part of this bullshit or the most naive SOB that ever lived when he believed the FBI would only take the information the warrant allowed. If you give them the ability to get more they will take more.
Umm in a police state Lavabit would have never existed in the first place.
We are in one of those times where the US government is over-reaching their powers under the Constitution. It isn't the first time.
Time to wake up folks. The price of freedom is eternal vigilance.
How is a user who just reads considered "abusive" to Slashdot? Treat Tor like any other open proxy, giving it read-only access.
the US gets the press, but every country is doing as much as they can (and are able to) with the money and network taps they have in place.
this is human nature. the dark side of human nature.
at least its out in the open, now. what we do with it, as a species, is up to us. do we put our data thieves (ie, the government) behind bars or do we just say 'I have nothing to hide!' and let them continue along with their abuse and theft of our privacy?
there is no country that won't do this, no matter what they say. so stop thinking its the big bad old USA. its everyone, everywhere, who CAN do it. companies includes (your corp firewall and your corp provided laptop probably has built-in certs from the company)
--
"It is now safe to switch off your computer."
there is no country that won't do this, no matter what they say. so stop thinking its the big bad old USA. its everyone, everywhere, who CAN do it.
Qualitatively, yes you're probably right. Quantitatively, not so much. It's like the military. Every country, or almost, has one. But only the USofA spends about as much on "defense" as the rest of the planet put together.
PS Capitals, used with some restraint, go a long way to making heads and tails out of a sentence.
Gosh, thanks. That must be why the other ships call me Meatfucker -- GCU Grey Area (Eccentric)
Basically, the government can force you to do anything it wants, and there's nothing you can do about it. Strange, I remember hearing about some document that spelled out certain limitations on the governments powers, and certain rights that people had, but I must have misremembered.
Because I'd prefer my employer not to know my /. UID?
Never ask "why do you want privacy"; that's always a stupid question. Privacy is simply an integral part of the two prime human goals: liberty and dignity.
This is a fundamental mindset change that's needed in developers! We've learned to write software that uses the least possible privilege, as the core of security. We need to learn to write software that offers the most possible privacy, as the core of human rights.
Socialism: a lie told by totalitarians and believed by fools.
I live in Ireland. I can pretty much guarantee you of three things.
1) The state lacks the expertise to snoop on any communications.
2) The state lacks the legal clout to force anyone to turn over their encryption keys.
3) The government would likely not survive the closure of an IT SME such as Lavabit -- and loss of associated jobs -- which resulted from direct government interference in that company's ability to operate in Ireland.
The rules that apply to the US government do not apply to every government. Some governments lack the skills, laws, and nerve to pull off what the White House/NSA is doing to US internet companies right now. More governments simply lack the money to pay for so extensive a network of surveillance and control.
That can includes more than simply being ABLE to do it. It includes being EMPOWERED to do it, being PERMITTED by the people to do it, and to being able to AFFORD to do it. Right now the US government is able, empowered, but only just about permitted and certainly not able to afford to continue to finance a spying program of this magnitude.
The Soviet Union exhausted both its finances and legitimacy in trying to keep its populace under control. Hopefully the US will not have to go through as painful a breakup in order to reverse its present trend.
May the Maths Be with you!