Hacker News new | ask | show | jobs
by maqp 2319 days ago
Lavabit also sent the private keys from their servers to clients using TLS that utilized RSA for key exchange. Levison was to put it into a word, a fool, for letting that happen. Once he had to submit the private RSA-key for the certificate, FBI could decrypt every past session, and every private key of every user. IMO he'd have to put a hell of a lot of effort if I'm ever going to look at his creations again.
1 comments

It was a deeply irresponsible service for Levison to be selling to people.