GitHub's 2015 Transparency Report
github.com
github.com
> "we are not even allowed to say if we've received zero of these reports—we can only report information about these types of requests in broad ranges"
Interesting. What are they really telling us with that range? Could they not get away with saying "1–249"?
Edit: Nevermind. The document they cite[0] clears it up.
[0] https://www.justice.gov/iso/opa/resources/422201412716042240...
Hence warrant canaries: they basically consist of creating a strong expectation of a (permitted) negative statement, such that its absence will be noticed. So far it's believed that you can't be compelled to maintain a no-longer-accurate canary against your will.
edit: Wait, I see what you're referring to. [citation needed], because as far as I know warrant canaries remain legal.
Last I heard canaries were still going strong, although they're generally limited to one bit (letters: yes or no?) rather than any more detail.
The reason why warrant canaries are binary is that once an NSL has been issued, the case law that the parent commenter linked comes into play: companies may only indicate in buckets how many they have received (0-249, 250-499, etc). So you couldn't have your warrant canary say "I have never received more than 3 NSLs" then "I have never received more than 5 NSLs" etc.
- We have not received any requests in Q1 of 2016.
- We have not received more than 50 requests in Q1 of 2016.
- We have not received more than 100 requests in Q1 of 2016.
Assume he had a scheme that just said the following:
We have received no NSL letters in Jan 2016 We have received no NSL letters in Feb 2016 We have received between 0 and 249 NSL letters in March 2016 We have received no NSL letters in Apr 2016
The only reason the canary "works" is as a binary option - if you say "We have never received an NSL" up until you receive one, the government cannot compel you to continue including that line in your report, because that would be compelled speech which is legally difficult and (as far as anyone knows) hasn't been attempted. But anything you say beyond that related to the quantity or existence of NSLs is subject to the linked guidelines. In other words, they cannot force you to continue including a paragraph (the canary) in your report, but they CAN regulate anything you do choose to include in your report.
[1]: https://www.justice.gov/iso/opa/resources/422201412716042240...
Edit: NSL letter, ATM machine, blah
So even if before I received any letter I'd tried to be clever and just said: "No NSL letters in March, No NSL letters in April.... etc.", if I ended up receiving one during that time period at all, all of those WOULD HAVE to collapse to "We have received 0-249 letters in the first semester of 2016 (or 2016 altogether)"
Sort of. There's also a required 6 month delay. So if you received an NSL today, but had "No NSLs in Jan" , "No NSLs in Feb", "No NSLs in Mar", etc, you would need to remove all those and could not report the 0-249 number until 2017.
You are saying nothing at all. Just adding/removing images on a page called /canary/
IANAL, but I'd be interested how the above would be illegal.
People tend to assume the court system is like a machine when it's very human at its core. A judge isn't going to say "well you technically didn't reveal any info so you're kosher," a judge is going to be pissed that you decided to low-key defy his/her order.
There are countless loopholes in various legal systems across the world that "get a pass". It's often a matter of finding the right loopholes.
One example is gambling in Japan. Illegal. But if you play at a pachinko slot for a chance to win some tokens you can go next door and there is a business that will buy the tokens from you! It really is convenient someone is willing to buy these otherwise useless tokens. :)
I'm sure if I put some thought into it I could find a few more loopholes that are a "wink and a nod" away of being illegal. Of course, my suggestion might be too blatant and the company would be dragged to the courts. But even a single canary could still warrant being dragged to court over.
It would seem that it's perhaps illegal to say anything once you've gotten at least one of them, and they tell you that you can't do this anymore right?
> a provider may report aggregate data in the following separate categories:
> The total number of all national security process received ... in the following bands: 0-249 and thereafter in bands of 250
[0] https://www.justice.gov/iso/opa/resources/422201412716042240...
* fine-grained categorisation large bulk, separately reports on numbers of NSLs, customer affected by NSLs, content FISA, customers affected by content FISA, non-content FISA and customers affected by non-content FISA in bands of 1000 (for each category) starting from 0-999 inclusive
* coarse-grained categorisation finer bulk, report only the aggregate number of FISA and NSL orders and the number of customers affected by that aggregate, but do so in bands of 250 (starting from 0-249 inclusive)
So "0-249" means "between 0 and 249", they're not allowed to be more precise at this point
[0] https://www.justice.gov/iso/opa/resources/422201412716042240...
That didn't exactly clear it up for me. Would you mind saying how that clears it up? Does it really mean 1-249 after all?
I suspect they would not be using the 0–249 band if they were not gagged by a previous order. My uninformed interpretation is that they have received an NSL or FISA order, but not necessarily in 2015. So the 2015 number might be zero after all.
Maybe someone more informed could confirm or debunk this interpretation.
http://www.wyden.senate.gov/news/press-releases/wyden-places...
Contact your Senator/Representative if you don't want that to happen. Even though a similar amendment failed in the Senate last week, it was a close call.
Also, next there they are supposed to vote on the renewal of the FISA Amendments Act, and I'm sure they'll try to further expand their spying powers some more then, too.
If you search for cse131 you'll find a bunch of repos still up.
This kind of whack-a-mole is typical of DMCA and requires a lot of resources to manage.
To be really tested, it'd have to go to court.
I noticed when searching a lot of solutions were still up for this course, so maybe the solutions alone are OK, and it's only the base code being DMCAed. That said, there is a lot of base code still up too, so it's likely that this person just hasn't come around on their whack-a-mole cycle yet.
For example, the cs225 course provides an image processing library, and you need it for the assignment, so if you put the library in the repo they DMCA'd.
Similarly, many courses give you a framework of code. If you filled in the framework they would DMCA.
They did this a bit, but there was a pretty massive back lash. I don't think they are doing it atm
In fact, I'd argue that in the case of the solutions being shared publicly, at least everyone can benefit equally instead of only those who are part of the clique doing the sharing.
The only real answer is to either write new assignments each year, OR, simply assume that all students will have the solutions to the assignments.
A good way to tell if students are really doing the homework is to have a 10 minute homework quiz in class where the students answer a question very similar to a homework problem. Those who have truly done the homework will be done quickly and those who haven't will struggle mightily.
the budget / resources doesn't exist for that
After a while they would eventually stop looking up solutions and just ask their peers for some advice/code review. My job became surprisingly easy when I started treating students like adults.
When a law is clearly unethical, don't work so hard to abide by it.
https://www.eff.org/deeplinks/2016/04/disappointing-ruling-n...
http://thehill.com/policy/technology/278448-judge-dismisses-...
https://github.com/github/gov-takedowns/tree/master/Russia/2...
Your assumption was also my own until reading here.