Hacker Newsnew | past | comments | ask | show | jobs | submit | anon10191's commentslogin

But how far could they go? Could they compel GnuPG authors to secretly weaken GPG, along with a gag order?

I know that seems like it's taking it to the logical extreme, but if they can compel web service authors to alter their apps to insert exploits (assuming that's what happened), why couldn't they compel open source desktop app authors to do the same?

The only difference being that the GPG authors would have to be really sneaky to avoid code review. Possibly with "help" from the NSA.


You should look closer at what this type of orders actually compel a service to do. In the lavabit case, my theory is that it went as follows:

- The FBI compels lavabit through a FISA warrant/NSA to produce Snowden's emails/data/etc.

- This data is encrypted, so lavabit cannot comply immediately. However, on logging in, Snowden provides lavabit with his password so that they can decrypt the emails.

- Since lavabit then has the password and access to the emails, they are now required to hand that over to the government. They may need to add some code to store the password, but that is not a fundamental change to the system; it is merely a way of intercepting the data they are sent and required to hand over to the government.

So [I think that] the government does not order lavabit to make changes, it orders it to produce evidence. Such an order would not make much sense when aimed at the GPG authors.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: