Jump to content

VPN Provider Shuts Down After Lavabit Case Undermines Security


NelsonG

Recommended Posts

[url="http://torrentfreak.com/images/cameraspy.jpg"][img]http://torrentfreak.com/images/cameraspy.jpg[/img][/url]As the revelations of Edward Snowden roll [url="https://www.google.com/#q=edward+snowden&tbm=nws"]on and on[/url] the notion that individuals in the United States, or indeed citizens of any country, have any real online privacy is being continually undermined.

As a result, interest in anonymity services such as Tor and [url="http://torrentfreak.com/vpn-services-that-take-your-anonymity-seriously-2013-edition-130302/"]VPNs[/url] has increased as even regular Internet users balk at the idea of being monitored.

While there are hundreds of providers to choose from, one particular US-based company has decided that the current environment on home soil makes it impossible to offer an effective consumer-focused service.

“With immediate effect as of this notice, [url="https://cryptoseal.com"]CryptoSeal Privacy[/url], our consumer VPN service, is terminated. All cryptographic keys used in the operation of the service have been zerofilled, and while no logs were produced (by design) during operation of the service, all records created incidental to the operation of the service have been deleted to the best of our ability,” the company said in a statement.

While it’s not unusual for a provider to leave the marketplace, CryptoSeal says that the ground has recently shifted beneath its feet, meaning that the legal basis on which the company was founded can no longer be relied upon.

“Essentially, the service was created and operated under a certain understanding of current US law, and that understanding may not currently be valid. As we are a US company and comply fully with US law, but wish to protect the privacy of our users, it is impossible for us to continue offering the CryptoSeal Privacy consumer VPN product,” the company says.

The problem, CryptoSeal says, relates back to the recent Lavabit case. The now-shuttered email service used by Edward Snowden closed down in August, with founder Ladar Levison saying that he had been “forced to make a difficult decision: to become complicit in crimes against the American people or walk away from nearly 10 years of hard work by shutting down Lavabit.”

[url="http://torrentfreak.com/images/lavabit.jpg"][img]http://torrentfreak.com/images/lavabit.jpg[/img][/url]Lavabit had been targeted by U.S. authorities but rather than compromise the privacy of his users, Levison decided to close the service down instead. He is currently tied up in a legal battle with U.S. authorities and it’s a document from this case that has caused CryptoSeal to shut down its consumer service.

“The Lavabit case, with [url="https://www.documentcloud.org/documents/801182-redacted-pleadings-exhibits-1-23.html"]filings[/url] released by Kevin Poulsen of Wired.com reveals a Government theory that if a pen register order is made on a provider, and the provider’s systems do not readily facilitate full monitoring of pen register information and delivery to the Government in realtime, the Government can compel production of cryptographic keys via a warrant to support a government-provided pen trap device,” CryptoSeal state.

A pen register is a device originally created in the 1800′s for recording telegraph signals on paper but more recently the term has been used to describe devices that can monitor telephone lines and Internet communications. Since VPN communications are encrypted, CryptoSeal believes that the only way it would be able to comply with a pen register order would be to do the unthinkable – hand over its encryption keys.

“Our system does not support recording any of the information commonly requested in a pen register order, and it would be technically infeasible for us to add this in a prompt manner. The consequence, being forced to turn over cryptographic keys to our entire system on the strength of a pen register order, is unreasonable in our opinion, and likely unconstitutional, but until this matter is settled, we are unable to proceed with our service,” the company informs.

While encouraging customers to [url="https://rally.org/lavabit"]donate[/url] to Lavabit’s defense fund, CryptoSeal says it is currently investigating whether it will be able to provide a consumer VPN service in the future without compromising user privacy. The company signs off with the following call.

“For anyone operating a VPN, mail, or other communications provider in the US, we believe it would be prudent to evaluate whether a pen register order could be used to compel you to divulge SSL keys protecting message contents, and if so, to take appropriate action,” CryptoSeal concludes.

Source: [url="http://torrentfreak.com/vpn-provider-shuts-down-after-lavabit-case-undermines-security-131022/"]VPN Provider Shuts Down After Lavabit Case Undermines Security[/url]

[url="http://feed.torrentfreak.com/~ff/Torrentfreak?a=aNOWQvWBQek:fCzN9PPd8o4:yIl2AUoC8zA"][img]http://feeds.feedburner.com/~ff/Torrentfreak?d=yIl2AUoC8zA[/img]</img>[/url] [url="http://feed.torrentfreak.com/~ff/Torrentfreak?a=aNOWQvWBQek:fCzN9PPd8o4:D7DqB2pKExk"][img]http://feeds.feedburner.com/~ff/Torrentfreak?i=aNOWQvWBQek:fCzN9PPd8o4:D7DqB2pKExk[/img]</img>[/url][img]http://feeds.feedburner.com/~r/Torrentfreak/~4/aNOWQvWBQek[/img]

[url=http://feed.torrentfreak.com/~r/Torrentfreak/~3/aNOWQvWBQek/]View the full article[/url]

Link to comment
Share on other sites

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Our picks

    • Wait, Burning Man is going online-only? What does that even look like?
      You could have been forgiven for missing the announcement that actual physical Burning Man has been canceled for this year, if not next. Firstly, the nonprofit Burning Man organization, known affectionately to insiders as the Borg, posted it after 5 p.m. PT Friday. That, even in the COVID-19 era, is the traditional time to push out news when you don't want much media attention. 
      But secondly, you may have missed its cancellation because the Borg is being careful not to use the C-word. The announcement was neutrally titled "The Burning Man Multiverse in 2020." Even as it offers refunds to early ticket buyers, considers layoffs and other belt-tightening measures, and can't even commit to a physical event in 2021, the Borg is making lemonade by focusing on an online-only version of Black Rock City this coming August.    Read more...
      More about Burning Man, Tech, Web Culture, and Live EventsView the full article
      • 0 replies
    • Post in What Are You Listening To?
      Post in What Are You Listening To?
    • Post in What Are You Listening To?
      Post in What Are You Listening To?
    • Post in What Are You Listening To?
      Post in What Are You Listening To?
    • Post in What Are You Listening To?
      Post in What Are You Listening To?
×
×
  • Create New...