GitHub suspends Tornado Cash developer account
twitter.com
twitter.com
He is writing fin-tech FOSS, but because that software and the space it targets is not fully under US gov control, his well-being and entire future is now at risk.
This is not the freedom the US keeps talking about. It is tyranny.
Vitalik himself used tornado cash for private transactions. Do you think that Vitalik openly launders money?
Who can tell? Isn't that the point of Tornado Cash?
Authoritarian governments should really start hanging around on HN, they would love the sentiment here...
The point is that you can't know. That's the purpose of a money laundering operation.
I think maybe a better analogy would have been to use VPN rather than SSL. Because SSL doesn't obscure the source and destination, just the contents of the message.
Wrong. You can in fact know, because it has auditing tools which allow one to disclose transactions exactly for AML reasons.
At least put in some research before you engage in a discussion where it becomes apparent that you clearly lack the knowledge to participate in a fruitful discussion. Making factually incorrect statements like yours as if they were facts is misleading a lot of people.
Usually the person making that claim is incapable of making any substantial argument, and that's their crutch at stopping any more criticism of their position.
>Usually the person making that claim is incapable of making any substantial argument, and that's their crutch at stopping any more criticism of their position.
In this case this is describing you tho, on top of you spreading clear cut misinformation.
Or more corporate, you don't want your competitors to know details of your next project.
There are groups who think property rights are inane and tyrannical. One way to ignore those laws is breaking and entering. Is it only a good thing when it conveniently aligns with what you consider inane and tyrannical?
What is your position? That tools primarily intended to break any law are inherently suspect and it's good to ban them?
I think a tool's primary use is important. And that's nuanced, and subjective.
Let's take guns for example. Guns are regulated in most western countries, some more heavily than others. Gun advocates often cite needing them to hunt animals or to defend themselves from predatory animals in rural environments. Sometimes they also cite using them to defend themselves against other humans. Mostly though guns seem to be used for self harm and to shoot others.
In a more tyrannical setting, guns could be used for revolution and to overthrow oppressors. I assume you're OK with things like banning assault rifles for civilian use in your country even though that use case is a possibility elsewhere in the world?
When Tornado Cash's primary uses are speculation, tax evasion, and money laundering in a country like the US -- I don't disagree that it should be banned or heavily regulated even if in some specific setting it could possibly be used for other purposes.
A lot of folks in the west very loudly cite Tornado Cash (and other things in the crypto space) as a means for oppressed peoples to bypass government control. I wonder if they're not similar to the people who want to own an AK-47 because they sometimes like to hunt ducks or want to protect themselves from home invasions.
" I don't disagree that it should be banned or heavily regulated even if in some specific setting it could possibly be used for other purposes." - but wouldn't that apply to everything? It is obvious that a typical govt would try to clamp down on things that are a threat to itself, be it guns on anonymous defi.
The question is (1) how much do you trust the current government / an average government on Earth / support whatever the current laws / average laws are in the first place, (2) how much do you trust the government / laws to not deteriorate in future (e.g. abortion ban with financial punishment for violators, Canadian trucker style, how about that?), (3) is the government less or more likely to deteriorate when checks on it are removed?
I personally think that's the point of privacy. To protect people from the government. Otherwise it easily becomes a tyranny if they have a full control and visibility over the citizens.
Cash is much safer because the risk is only at the time of transfer.
How you send the cash, btw? By mail? How do you ensure that post office is not going to learn who is the sender of the envelope with cash?
Re: cash - if you think about the problems I listed, you can see how it’s better in each case, all stemming back from not creating a permanent public ledger of potentially risky activities.
The simplest way to understand this is that money from crime is tracked so that investigators can follow it to the bad guys. We have laws that financial providers have to keep records so we can find the bad guys. A tool whose explicit exclusive purpose is to obfuscate bad guys money will not satisfy the legal requirements of operating financial services in the US. No one should be surprised by this.
"China has financial laws. Enforcing those laws is not tyranny" to justify an incredible government over-reach into what any one in the world may publish, and how any one in the world may encrypt their digital financial transactions.
>>The simplest way to understand this is that money from crime is tracked so that investigators can follow it to the bad guys.
While there is abundant evidence that these laws impose massive costs on law-abiding citizens and companies, there is little to no evidence that they are effective at reducing crime:
https://www.tandfonline.com/doi/full/10.1080/25741292.2020.1...
They do support the burgeoning regulatory compliance industry though.
Which seems unlikely in his case as he is based out of Russia.
US can and will restrict his access to US persons/assets (incl. vice versa).
[0] https://twitter.com/w_y_x/status/1556716055296294914?s=21&t=...
[1] https://twitter.com/bantg/status/1556721709931175937?s=21&t=...
“U.S. Treasury Sanctions Virtual Currency Mixer Tornado Cash” https://news.ycombinator.com/item?id=32386189
Specifically:
> all property and interests in property of the entity above, Tornado Cash, that is in the United States or in the possession or control of U.S. persons is blocked and must be reported to OFAC.
I don't have a strong opinion on whether tornado cash should be allowed to exist, but it's obvious that it violates US law.
Similarly if you distribute OSS viruses don't act shocked if people want to harass you over it - distributing viruses is illegal in some places
I am not, and neither are the authors of Tornado Cash. There is legitimate purposes to use privacy-preserving services. As long as I file my taxes correctly, I should be able to use them as I wish.
> but it's obvious that it violates US law
Since they got added to the SDN list, it's obvious yes. But before that, why it is obvious? Again, as long as I file my taxes correctly with the IRS, there shouldn't be a problem with using services like this.
these are the same people that will be SHOCKED when something they use, love, or do is ruled illegal or "obvious" violation of US Law,
Maybe a decade ago when I worked at a game studio our IT department got mad at me for being connected to a torrent tracker. What was the tracker for? Patches for one of our games, because the updater used BT.
I have a feeling in this instance your bias is in favor of allowing bittorrent to exist because you have a personal use for that technology that is not illegal, and you do not have a personal use for the Tornado Cash technology, thus you have no ability to see legal uses for that tech.
I have found it to be an exceedingly rare trait for people to be able to externalize, and understand other people's worldviews. If they personally do not need, desire, or have a use for X, then they have no problems with the government clamping down, regulating or banning it. Never coming to the wider understanding that the government may (and likely will) turn it gaze to them.
Plenty of legitimate software can be used for nefarious things (and sometimes the legitimate code is indistinguishable from malicious code, e.g. remote viewers).
We should probably focus on the people and the actions those people take, rather than code itself, or we might end up in a bit of a pickle. Ban encryption because it's used in ransomware. Ban tech-support software like TeamViewer or QuickAssist because it is used in scams.
The vast majority of OSS software does not have this hazard and it does everyone a disservice to pretend that the situation is identical. There are a bunch of other things OSS maintainers should be worrying about before US sanctions.
Maybe you don't know exactly what "money laundering" is. That you want to hide whatever you are doing doesn't mean that what you're doing is illegal, which is a prerequisite for something to be "money laundering". Just like E2E doesn't exists solely for hiding criminals doing criminal things.
I'm not sure if you understood my comment. I don't care about the authors and whether or not they were sanctioned. My point was about the code itself. If we started to force GH and the like to remove any code that has been used in an illegal activity, there's going to be very little code left on GH.
Just think of malware analysis or feeding malware to the machine-learning monster.
In the end, it's just information and can be interpreted in a myriad of ways and for all kinds of purposes, including the good ol' simple satisfaction of intellectual curiosity. But many people in this thread seem to have a zero bit mind. By that I mean that they have a single bit dichotomy good(allow)/bad(ban) world that invariably has the value "bad(ban)".
Beside the fact that GH is a private company that maybe doesn't want to be associated with some stuff.
I am not talking about what GH is at liberty to do; clearly they can do whatever they want. I’m asking about what they’re legally bound to do as a result of these sanctions. I find the precedent here more fascinating and troublesome (as an open source author myself) than the instance of the code in question.
So I guess a good question is: should it be illegal to tell people how to launder money? I would say no because I think laws should regulate behavior not speech.
I think for example that people should be able to make arguments why punching a Nazi should not be illegal, say, and maybe the best way to do it. But punching is clearly illegal, and threatening a Nazi directly should also be illegal.
However with abortion, some states that have made abortion illegal are trying to make it illegal to talk about where to get abortions, or how an abortion is performed. So if that is deemed legal by SCOTUS, then expect all kinds of laws to restrict speech in that manner.
Now everybody gets to learn that the United States regulatory policy machine will lean very hard on anything that'll threaten it's ability to flex soft power against its opponents.
>What even is GH required to do in response to this sanction, or are they just being overly cautious since we’re in uncharted waters?
Letter of the law is don't do financial transactions with those addresses.
The quiet part is: this technology is now associated with being a channel for money laundering, and will open up any parties hosting or making it available a potential subject of accessory to wire fraud/money laundering charges. As a publically funded company, I assure you, the legal, risk, and compliance departments are now erecting 100 foot poles between the company and this project.
You see, big business and government have a bit of an incestuous relationship. The bigger the market actor, the easier it is for the government to apply sufficient pressure where the easy way out is for said large actor to just "stop associating with that thing".
This is why OFAC is aptly named. You end up on it, and you basically fall out of the economy. The last sound you hear is the subject in question going O, FAC-<signal lost>.
Oh, actually, no, slight exaggeration, the truth is far more chilling.
You see, financial institutions will still process deposits. They just stop allowing withdrawals, turning the business relationship into a one-way trap for funds.
In theory, it may be possible to get off the OFAC list if you end up on it, however, financial institutions are instructed not to inform customers that they are sanctioned if asked. You're only told that a technical error precludes them from completing the transaction. If you mistakenly show up on OFAC, (like by sharing a name with someone who is on it), there are ways to get off of it by providing proof you are not the individual in question. In fact, most times, if you reach out, the service personnel you get are trained to get as much personal info as possible to try to determine whether or not you are actually the individual targeted by OFAC.
Companies will generally dig into it, and resolve it while playing coy. In this case though, it looks like businesses are taking the message to heart and just noping out of supporting it.
I'm not sure what you mean by "restricted," but publishing open source encryption software on the internet only requires that the BIS be notified. No review or approval is required.
https://en.wikipedia.org/wiki/Export_of_cryptography_from_th...
er...the US government infringes on free speech all the time
?
you mean after Phil Zimmerman spent years in court, and then published a physical book of the source code?
and the US government then sucessfully restricted export of actual software with above 56-bit keys for years[1]? to the extent that Debian and OpenBSD did all their opensource crypto work outside the US to avoid trouble?
and they still explicitly ban export to "rogue states" and "terrorist organisations" in 2022[2]?
things have improved since the 90s but it's still not unencumbered by the US government and the changes mostly happened to make US tech companies more competitive, not due to a desire to free anyone's speech.
[1]: https://en.wikipedia.org/wiki/Export_of_cryptography_from_th... [2]: https://en.wikipedia.org/wiki/Export_of_cryptography_from_th...
https://en.wikipedia.org/wiki/Bernstein_v._United_States
From your link: "the BIS must be notified before open-source cryptographic software is made publicly available on the Internet, though no review is required."
https://en.wikipedia.org/wiki/Export_of_cryptography_from_th...
> Militarized encryption equipment, TEMPEST-approved electronics, custom cryptographic software, and even cryptographic consulting services still require an export license.
However:
> the BIS must be notified before open-source cryptographic software is made publicly available on the Internet, though no review is required.
So you're free to publish open source cryptographic software on the internet, you just have to let them know you're doing it. Bernstein vs US is the reason for that.
Is GitHub sanctioning just the accounts that they consider to be directly associated with the sanctioned organization, or, are they also sanctioning the upload of that open source code by unassociated third parties?
Since code is copyrightable, is this a first amendment violation?
https://en.wikipedia.org/wiki/Bernstein_v._United_States
There is a long history of "the land of the free" carving out exceptions from freedom.
The group that was focused in the take down requests was "Tsunami Democràtic", which you can find some background information about here: https://en.wikipedia.org/wiki/Democratic_Tsunami
However Tornado Cash came with a compliance tool that allows you to disclose your transactions to third parties and prove they are clean. Similar with Monero, ZCash.
You have an invoice or receipt or bill to show. And the government could go ask the person who wrote said invoice/receipt/bill to confirm its legitimacy.
The governance you are referring to is some auxiliary support stuff, like anonymity mining.
Edit: also idk where you're seeing the governance component in that flow you linked, there doesn't appear to be one...
Information wants to be free! ACAB! Eat the police!
For any project that is self-hosting, like Tor which allows criminals, scammers and money launderers to access the internet and the 'dark web' and bypass sanctions with high anonymity and are self-hosting at [0]. Perhaps the FBI should 'take them down' immediately?
What are they waiting for then?
Judging by what's happening right now, if I'd live in the US, I'd definitely be concerned right now. I hope I'm not gonna be put on a list of sanctions just because I chose to publish my software as MIT and some criminal happens to use it.
Plenty of people use services like that to move funds from their cold wallet to their hot one, in order to not make visible to the public how much funds they have. Again, as long as you properly file taxes, this should not be a issue.
And yeah, some people do work on privacy-preserving services that can and will be used for bad purposes. Anything involving E2E encryption is usually made for privacy reasons, is this bad enough for you to say the same thing about it? What about things that can be used to skirt copyright like youtube-dl, do they deserve the same treatment?
Isn't that literally what money laundering is?
> As long as you file your taxes correctly, it wouldn't be illegal to use services like Tornado Cash.
IIRC, money laundering businesses pay their taxes too (e.g. the Breaking Bad car wash pretended the drug profits came from washing cars, and paid taxes those "car washing" profits).
If the funds you're shielding via something like Tornado were legitimately earned by you, it's your right to do whatever you want to protect your privacy (as long as you report the proper tax paperwork to the government, otherwise it can turn into tax evasion).
It seems that regulators can change their position at any time. See the recent example PredictIt.
Steganography makes fools out of infotyrants.
I hope you weren't part of the 'criminals' crying about youtube-dl being suspended by GitHub in 2020: [0].
So GNOME [1], WireGuard [2], The Linux Kernel [3], Mozilla [4] and ReactOS [5] and Tor Project [6] are all 'criminals' for self hosting their own projects on their own servers rather than being forced to host it on GitHub?
Surely they all know that GitHub can take their repositories down for any reason. If they all announced that they are going all in on GitHub, what is the whole point of supporting 'free software' in the first place?
[0] https://news.ycombinator.com/item?id=24872911
It's the same as asking "why do people need E2E encrypted chat," because they want to and there's nothing wrong with them not wanting you to read their chats, that's why.
The question was what other use the tool had. "Private transactions" are 100% isomorphic to money laundering, the only difference is the words you use to explain it.
In fact, "private transactions" are, in fact illegal. You're not allowed to do that in the industrialized world. It's true that small-value cash transactions are de facto private, in the sense that the government decides to look the other way and focus its laundering enforcement on larger players.
But no, that ship sailed decades ago. You're not allowed to have private transactions, because if you have them then the criminals will, and we as a society have made a bargain to give them up to reduce crime and corruption.
https://www.law.cornell.edu/wex/money_laundering
It's not just "private transactions."
https://en.wikipedia.org/wiki/Bank_Secrecy_Act
If you know a specific provision of any law that does prohibit such transactions, please post a link.
Where exactly do you expect to get that "large sum of cash" except from a bank? (Or conversely, what is the recipient expected to do with it except deposit it?) You're right that the enforcement of the law focuses on the entities (banks and other financial actors) who manage large transactions. If you had an "individual" doing that sort of thing regularly[1], you should absolutely expect to seem them regulated under AML statues.
What you want you can't have. You don't have it now. You won't have it in the crypto future. We've decided to make what you want illegal, and no amount of arguing on HN is going to change that.
[1] Like, for example, an operator of a money laundering tool on the ethereum network.
There are people who occasionally sell expensive things for cash, and people who keep a lot of cash in safes. My claim is that those activities are legal. You have not provided a statute or regulation saying it's illegal.
(There's no way for me to reference a statute for my claim, because we write laws saying what's prohibited, not what's allowed.)
There are not, not in practice. And to the extent there are they they do so by converting that cash to traceable assets in banks subject to know-your-customer rules who are able to attest to the validity of those transactions. To the extent that you have private entities doing very large, regular cash transactions that are not visible to AML regulators, that practice is not presumptively legal (nor common, except for literal criminals). You know this. I know you know this. Just ask a lawyer if you think you could get away with that. You can't.
Hiding behind a "if this and this and this were true then you could evade AML rules" as a technicality (effectively: that there are edge cases not covered under existing statutes) is not arguing for the legality of the kind of pervasive laundering enabled by a crypto mixer, and you know it.
But I'll quit since it's clear you're not going to reference any sort of law saying this is illegal.
This is just a digital form of that.
Or is that also an illegal/illegitimate use now?
That argument doesn't work. In fact yes, the government understands that printed money is untrackable and we have extensive tools to deal with that, up to and including the formal sanction of entities that try to evade these controls.
This viewpoint issue is not limited to financial legibility of course. We do know that the underground economy, because data is only reported by authorities, is inflated or deflated for political purposes, further muddling any potential estimations. Oh, and plenty of what the IRS wish to do is just that - wishful, and only when it's convenient for the other party. You can try to regulate cash transactions domestically in a more heavy handed manner, but you're mostly going to affect those least able to afford it to begin with, and the costs involved may not be worth the effort. Oh, and US currency is commonly used abroad, including in place of native currencies in some countries. When it comes to cash, there are only estimates as to how much the government can reasonably regulate the transacting of, and the government's policies have undermined efforts to do so even when they could. Not everyone is in the cohort that posts on HN.
Now we need to keep local backups of every library we use, just in case.