[0] https://twitter.com/w_y_x/status/1556716055296294914?s=21&t=...
[1] https://twitter.com/bantg/status/1556721709931175937?s=21&t=...
[0] https://twitter.com/w_y_x/status/1556716055296294914?s=21&t=...
[1] https://twitter.com/bantg/status/1556721709931175937?s=21&t=...
“U.S. Treasury Sanctions Virtual Currency Mixer Tornado Cash” https://news.ycombinator.com/item?id=32386189
Specifically:
> all property and interests in property of the entity above, Tornado Cash, that is in the United States or in the possession or control of U.S. persons is blocked and must be reported to OFAC.
Beside the fact that GH is a private company that maybe doesn't want to be associated with some stuff.
I am not talking about what GH is at liberty to do; clearly they can do whatever they want. I’m asking about what they’re legally bound to do as a result of these sanctions. I find the precedent here more fascinating and troublesome (as an open source author myself) than the instance of the code in question.
So I guess a good question is: should it be illegal to tell people how to launder money? I would say no because I think laws should regulate behavior not speech.
I think for example that people should be able to make arguments why punching a Nazi should not be illegal, say, and maybe the best way to do it. But punching is clearly illegal, and threatening a Nazi directly should also be illegal.
However with abortion, some states that have made abortion illegal are trying to make it illegal to talk about where to get abortions, or how an abortion is performed. So if that is deemed legal by SCOTUS, then expect all kinds of laws to restrict speech in that manner.
Now everybody gets to learn that the United States regulatory policy machine will lean very hard on anything that'll threaten it's ability to flex soft power against its opponents.
>What even is GH required to do in response to this sanction, or are they just being overly cautious since we’re in uncharted waters?
Letter of the law is don't do financial transactions with those addresses.
The quiet part is: this technology is now associated with being a channel for money laundering, and will open up any parties hosting or making it available a potential subject of accessory to wire fraud/money laundering charges. As a publically funded company, I assure you, the legal, risk, and compliance departments are now erecting 100 foot poles between the company and this project.
You see, big business and government have a bit of an incestuous relationship. The bigger the market actor, the easier it is for the government to apply sufficient pressure where the easy way out is for said large actor to just "stop associating with that thing".
This is why OFAC is aptly named. You end up on it, and you basically fall out of the economy. The last sound you hear is the subject in question going O, FAC-<signal lost>.
Oh, actually, no, slight exaggeration, the truth is far more chilling.
You see, financial institutions will still process deposits. They just stop allowing withdrawals, turning the business relationship into a one-way trap for funds.
In theory, it may be possible to get off the OFAC list if you end up on it, however, financial institutions are instructed not to inform customers that they are sanctioned if asked. You're only told that a technical error precludes them from completing the transaction. If you mistakenly show up on OFAC, (like by sharing a name with someone who is on it), there are ways to get off of it by providing proof you are not the individual in question. In fact, most times, if you reach out, the service personnel you get are trained to get as much personal info as possible to try to determine whether or not you are actually the individual targeted by OFAC.
Companies will generally dig into it, and resolve it while playing coy. In this case though, it looks like businesses are taking the message to heart and just noping out of supporting it.
I'm not sure what you mean by "restricted," but publishing open source encryption software on the internet only requires that the BIS be notified. No review or approval is required.
https://en.wikipedia.org/wiki/Export_of_cryptography_from_th...
er...the US government infringes on free speech all the time
?
you mean after Phil Zimmerman spent years in court, and then published a physical book of the source code?
and the US government then sucessfully restricted export of actual software with above 56-bit keys for years[1]? to the extent that Debian and OpenBSD did all their opensource crypto work outside the US to avoid trouble?
and they still explicitly ban export to "rogue states" and "terrorist organisations" in 2022[2]?
things have improved since the 90s but it's still not unencumbered by the US government and the changes mostly happened to make US tech companies more competitive, not due to a desire to free anyone's speech.
[1]: https://en.wikipedia.org/wiki/Export_of_cryptography_from_th... [2]: https://en.wikipedia.org/wiki/Export_of_cryptography_from_th...
https://en.wikipedia.org/wiki/Bernstein_v._United_States
From your link: "the BIS must be notified before open-source cryptographic software is made publicly available on the Internet, though no review is required."
https://en.wikipedia.org/wiki/Export_of_cryptography_from_th...
> Militarized encryption equipment, TEMPEST-approved electronics, custom cryptographic software, and even cryptographic consulting services still require an export license.
However:
> the BIS must be notified before open-source cryptographic software is made publicly available on the Internet, though no review is required.
So you're free to publish open source cryptographic software on the internet, you just have to let them know you're doing it. Bernstein vs US is the reason for that.
Is GitHub sanctioning just the accounts that they consider to be directly associated with the sanctioned organization, or, are they also sanctioning the upload of that open source code by unassociated third parties?
I don't have a strong opinion on whether tornado cash should be allowed to exist, but it's obvious that it violates US law.
Similarly if you distribute OSS viruses don't act shocked if people want to harass you over it - distributing viruses is illegal in some places
I am not, and neither are the authors of Tornado Cash. There is legitimate purposes to use privacy-preserving services. As long as I file my taxes correctly, I should be able to use them as I wish.
> but it's obvious that it violates US law
Since they got added to the SDN list, it's obvious yes. But before that, why it is obvious? Again, as long as I file my taxes correctly with the IRS, there shouldn't be a problem with using services like this.
these are the same people that will be SHOCKED when something they use, love, or do is ruled illegal or "obvious" violation of US Law,
Maybe a decade ago when I worked at a game studio our IT department got mad at me for being connected to a torrent tracker. What was the tracker for? Patches for one of our games, because the updater used BT.
I have a feeling in this instance your bias is in favor of allowing bittorrent to exist because you have a personal use for that technology that is not illegal, and you do not have a personal use for the Tornado Cash technology, thus you have no ability to see legal uses for that tech.
I have found it to be an exceedingly rare trait for people to be able to externalize, and understand other people's worldviews. If they personally do not need, desire, or have a use for X, then they have no problems with the government clamping down, regulating or banning it. Never coming to the wider understanding that the government may (and likely will) turn it gaze to them.
Plenty of legitimate software can be used for nefarious things (and sometimes the legitimate code is indistinguishable from malicious code, e.g. remote viewers).
We should probably focus on the people and the actions those people take, rather than code itself, or we might end up in a bit of a pickle. Ban encryption because it's used in ransomware. Ban tech-support software like TeamViewer or QuickAssist because it is used in scams.
The vast majority of OSS software does not have this hazard and it does everyone a disservice to pretend that the situation is identical. There are a bunch of other things OSS maintainers should be worrying about before US sanctions.
Maybe you don't know exactly what "money laundering" is. That you want to hide whatever you are doing doesn't mean that what you're doing is illegal, which is a prerequisite for something to be "money laundering". Just like E2E doesn't exists solely for hiding criminals doing criminal things.
I'm not sure if you understood my comment. I don't care about the authors and whether or not they were sanctioned. My point was about the code itself. If we started to force GH and the like to remove any code that has been used in an illegal activity, there's going to be very little code left on GH.
Just think of malware analysis or feeding malware to the machine-learning monster.
In the end, it's just information and can be interpreted in a myriad of ways and for all kinds of purposes, including the good ol' simple satisfaction of intellectual curiosity. But many people in this thread seem to have a zero bit mind. By that I mean that they have a single bit dichotomy good(allow)/bad(ban) world that invariably has the value "bad(ban)".
Since code is copyrightable, is this a first amendment violation?
The group that was focused in the take down requests was "Tsunami Democràtic", which you can find some background information about here: https://en.wikipedia.org/wiki/Democratic_Tsunami
https://en.wikipedia.org/wiki/Bernstein_v._United_States
There is a long history of "the land of the free" carving out exceptions from freedom.