Civil Liberties  
comments_image Comments

Lavabit Founder Refused FBI Order to Hand Over Email Encryption Keys

Unsealed documents show Ladar Levison, now subject of government gag order, refused requests to 'defeat its own system'

Photo Credit:


The email service used by whistleblower  Edward Snowden refused FBI requests to "defeat its own system," according to newly unsealed court documents.

The founder of Lavabit, Ladar Levison, repeatedly pushed back against demands by the authorities to hand over the encryption keys to his system, frustrating federal investigators who were trying to track Snowden's communications, the documents show.

Snowden called a press conference on 12 July at Moscow's international airport, using a Lavabit address. The court documents show the FBI was already targeting the secure email service before the invite was sent.

Levison is now subject to a government gag order and has appealed against the search warrants and subpoenas demanding access to his service. He closed Lavabit in August saying he did not want to be "complicit in crimes against the American people".

The court documents, unsealed on Wednesday, give the clearest picture yet of the Lavabit case. The documents, filed in the eastern district court of Virginia, are redacted and do not mention Snowden by name. But they do say the target of the FBI is under investigation for violations of the espionage act and theft of government property – the charges that have been filed against NSA whistleblower Snowden.

On 28 June the court authorised the FBI to install a "pen register trap and trace device" on all electronic communications being sent from the redacted email address, believed to be Snowden's. A pen register would allow the FBI to record all the "metadata" from the account including the e-mail "from" and "to" lines and the IP addresses used to access the mailbox.

Levison said that the client had enabled encryption on his email and that he could not access the email. "The representative of Lavabit indicated that Lavabit had the technical capability to decrypt the information, but that Lavabit did not want to 'defeat [its] own system,'" the government complained.

In July, the authorities obtained a search warrant demanding Lavabit hand over any encryption keys and SSL keys that protected the site. Levison was threatened with criminal contempt – which could have potentially put him in jail – if he did not comply. Such a move would have given the government access to all of Lavabit users' information.

In an interview with The Guardian in August, Levison said he had complied with government requests for information relating to individual account holders in the past. It appears that he was once again prepared to cooperate in this case. However the government now wanted greater access.

In a court hearing on July 16 before senior US district court judge Claude Hilton, US prosecutor James Trump said Levison should be fined $1,000 a day unless he complied with the order to hand over the encryption keys.

Levison asked for the court records to be unsealed. "I believe it's important for the industry and the people to understand what the government is requesting by demanding that I turn over these encryption keys for the entire service," he said.

Trump objected, saying Levison was trying to "invite industry in and litigate as a surrogate for him the issue of whether the encryption keys are part and parcel of the pen register order."

Levison went to court to fight the demand on August 1. "The privacy of … Lavabit's users are at stake," Lavabit attorney Jesse Binnall told Hilton in a closed-door hearing. "We're not simply speaking of the target of this investigation. We're talking about over 400,000 individuals and entities that are users of Lavabit who use this service because they believe their communications are secure. By handing over the keys, the encryption keys in this case, they necessarily become less secure."

See more stories tagged with: