Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is something that striked me as missing in the Lavabit key warrant discussion: was Forward Secrecy merely an option on the server before the shutdown, or was it enforced on all connections, regardless of client support?

If not all connections used it, FBI / NSA are probably now in the position to decrypt earlier recordings of user sessions, thus recovering the passwords, email contents etc...

From reading the ssllabs report, it looks like even with the current setup, sessions by IE and Safari (also Android?) users can be recovered once the new key is obtained via court order.



Before they came back up, I ran SSL labs test on their site. It did support forward security for some browsers. Now it supports none.

No idea about before the warrant, but I don't see any good reason to think it changed it changed

https://news.ycombinator.com/item?id=6518430




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: