Germany's biggest Bitcoin exchange surrenders user data to the police
reddit.com
reddit.com
Would you risk having your servers seized for someone you know committed a crime? If you do, you make it very easy for competitors to shut you down.
edit: I'm assuming they don't blindly trust the police, but can verify the transactions to the drug site themselves. If that's not the case, making the police get a warrant would be the right thing to do.
"Gives us the data on these 8 people, or we'll get a warrant for it."
vs.
"Gives us the data on these 8 people, or we'll get a warrant to confiscate all your servers, computers, laptops, and phones."
And getting a warrant is not as large a barrier as people like to believe: https://www.popehat.com/2014/07/15/warrants-bulwark-of-liber...
Is a bit over 20k drug related warrants over 10 years really that much for the country the size of USA with such a drug problem and such an axe to grind with drugs users (war on drugs, private prisons, blacks with crack and teens with weed being juicy targets to boost statistics, etc.)?
Or 1300 warrants and 600 extensions in one fiscal year for a 'black bag job search' across all circuits?
If they say "we'll get a warrant anyway", just response "okay, so get the warrant and come back and I'll give you the data". Then at least it's up to a judge to decide where giving out data is warranted, and not up to an oridinary policeman and sysadmin.
All the time? Really?
A warrant possibly means that they go out of business, because the servers are physically seized. If you tell me you'd risk that for a stranger who you can tell probably committed a crime, I don't believe you.
Why would the police be interested in destroying a legitimate business just because they want data for 8 users?
They can just as well get the warrant and then get the data the same way they did now.
Lavabit comes to mind. I'm sure there are other examples too.
Probably not because of one user, but when the cases pile up there's a good chance it'll raise questions about the legitimacy of their service.
When you earn your money by running said service, you are likely going to want to avoid that.
That's a very very slippery slope. It is the job of the police to not look into data not related with the case, not yours.
Surrendering the info would be giving the police more power if anything since, they now can come and get data from anyone without a warrant (how do you even know that this account is dealing drugs other that "the police came looking for him"?).
Take a look at the transaction history. If there are transactions with known drug site wallets, give them the data they are asking for. Otherwise, request they get a warrant.
If you are going to cooperate, I think that's the most reasonable way to go about it.
Bitcoin exchanges are seen as dodgy anyway and they don't have a lobby to fight for them, so showing some way of cooperation while keeping everyone's (legal) interests in mind might be a good idea.
Not necessarily. A acquaintance of mine at an ISP always did that when police came knocking for "illegale pirating" allegations. His standard response was: Get a warrant or else I would commit a criminal offence (what he would have done).
Nearly never police came back with a warrant. And in the spare cases they did come back he did provide the data (if it was still available) and never did any equipment get seized.
Your friend is also a saint with cojones the size of cannon balls for doing that too.
In Poland the "take it all" strategy seems to be the default one, at least for private devices. There was once a case related to one Polish movie being shared on torrents that ended in 40 thousand confiscated PCs. The law firm hired by the movie studio gave the prosecution a list of 40 thousand IPs they said were pirating their client's movie. The prosecution gave a blanket warrant and the police got the people data from the ISPs, confiscated the computers and gave the law firm copy of the personal data so they could offer the 'pirates' a few hundred zloty settlements to not press charges.
C.f. frivolous DMCA on YouTube reviews and this case: https://news.ycombinator.com/item?id=14904149
So much for warrants when it comes to allegations of piracy.
Polish link for the 40k PCs case for anyone interested: https://www.dobreprogramy.pl/Juz-40-tys.-polskich-internauto...
Once you start selectively give out user data, you are basically giving out warrants yourself and acting as a judge.
Now what's morally ambiguous is then deciding to reveal that data to others, and if you did it indiscriminately for all customers I'd be against it. But on a small scale, I don't think it's so wrong.
Do you actually know though? Or is it really just an educated guess?
> why not cooperate and make it easier for everyone?
Because violating privacy isn't supposed to be easy. Those laws exist for a reason.
If it's that easy to get a warrant, why didn't they just go ahead and get the warrant?
Which means bitcoin.de doesn't care about following the law in the first place.
Not a surprise for a company trying to make money off of a pyramid scheme currency.
> The protection of our unscrupulous customers and their bitcoins is more important to us than the protection of the data of offenders.
Another interesseting thing:
> We only issue data from customers to investigating authorities if they can inquire in writing in specific cases and can demonstrate a legitimate interest in specific criminal offenses. This has always been the case from our point of view.
Big question here: So they've done it several times?
We've already seen local cops in Sweden and Denmark track drug dealers through bitcoin. They must have had the cooperation of exchanges and banks to make that happen.
So I expect exchanges to cooperate on the same level that banks cooperate with police.
Say my DigitalOcean VPS hosted in Germany provides a service X which can be subverted for illegal purposes. Will the police have to me to ask for data or can they go to DO and demand access to the data without my knowledge?
Is this meant to imply that the legal situation is very different in the Netherlands/France, or that you encrypt everything because it's the same as in Germany?
I assume that if you want to search/seize somebodies property then you have get a warrant made out the the legal owner of the property. (Obviously you don't have to get a warrant if the owner voluntarily hands out the data...) In your example DO is the legal owner of the server your VPS runs on. I can't see why DO would be required to tell you about it.
I don't know how the owners of data centers play into this. I guess if you have somebody else's property in your possession and the cops have a warrant then you have to hand it to them.
Keep in mind that the actual data on the VPS may be protected by all sorts of privacy laws if, e.g., you run a mail server on it.
Edit: I forgot to mention that the location of the server and the jurisdiction the legal owner is under also play a large role. Also don't forget which jurisdiction you're under. Nobody cares that you've rented a server from a russian company located on the dark side of the moon. In this case they'll probably make the warrant out to you rather than the legal owner. And you'll have to comply.
I'm just asking, not challenging what you're saying.
I don't know what happens when a landlord hides weapons or something under the floorboards and then rents the place to somebody. Say the people renting the place are on vacation and the police has a warrant (made out to the landlord in this example). Maybe they can go in with the landlord (and, at least in Germany, they also need an independent witness) but are only allowed to search the actual property and not the stuff in it (because the landlord doesn't own the stuff). I don't know. But this kind of renting is well covered by laws (including lots of laws protecting the renters).
"Renting" a VPS (webspace would be a better example) probably isn't defined by any laws. It feels more like user data connected to a (paid) software service. Renting a dedicated server is a different story.