Sanctioned project's contributors must be deleted from the server - where is that written in the list of things Microsoft has to do since you went out of your way calling everyone on the reply train ignorant?
Sanctioned project's contributors must be deleted from the server - where is that written in the list of things Microsoft has to do since you went out of your way calling everyone on the reply train ignorant?
This is quite simply not how a sanctions regime works. The US government does not make a list of all the sanctioned persons’ assets, then start going after those in court.
Instead, it goes the other way: any company with a US nexus watches those sanction lists carefully. When someone is listed they look at their internal records for hits and denies them service. So no one told Microsoft anything; they self-enforced a sanction that applies to everyone in the US. And I mean everyone: if an individual knowingly violates these sanctions they’re breaking federal law - it’s not just companies.
So when you contribute code to an open source project, you generally do so under an open source license. All of them generally contain something akin to the following:
IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE
LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES
(this particular excerpt is from the BSD license)I can understand taking action against the people who run the code. I can even understand taking action against people who were hired to contribute. But why kick some random open source contributor in the guts? What did they do wrong?
Are there open source licenses that protect the contributors from such unforeseeable damage? Or are we to watch our step from now on as open source contributors?
The argument probably is that they assisted a sanctioned entity by providing a contribution i.e. service to it. Quoting US Treasury "These prohibitions include the making of any contribution or provision of funds, goods, or services by, to, or for the benefit of any blocked person and the receipt of any contribution or provision of funds, goods, or services from any such person."
However, the major factual question is whether they did violate any sanctions since the contributions generally were made before the sanctions were in effect - it's not that Github had to do it, but that they chose to be safe rather than sorry (in order to ensure that Github themselves don't violate the sanctions) and if they aren't absolutely sure they blocked people. [edit: apparently not everyone, some contributors are not blocked, so they apparently did some review before choosing whom to block]
The key issue is that any collateral damage is considered acceptable, but any false negatives are absolutely not. If Github leaves even one actual agent of TornadoCash unblocked, Github has committed a crime, if they block a hundred unrelated accounts, that doesn't violate anything.
> Are there open source licenses that protect the contributors from such unforeseeable damage?
No, a contract or license can't absolve you from this prohibition if it applies to you.
> Or are we to watch our step from now on as open source contributors?
Yes, but not "from now on" but since before open source existed. There are entities you are not allowed to contribute to, and it's your responsibility to know and check who you are dealing with.
Even though “better 100 guilty persons should escape than that one innocent person should suffer”. Not that this was ever uncontroversial, but how did it ever go so wrong, that the very problems of government that modern laws sought to correct are gleefully recreated using private companies as enforcement proxies?
I’m not trying to directly argue that they shouldn’t, though (as long as we allow that there is no moral principle that a non-natural person’s rights follow a natural one’s). I’m saying that it’s generally accepted to be a good thing that a (branch of) government can’t directly take away your livelihood without a good reason, and if you think the reason was not good there are reasonably unbiased ways to have your disagreement considered. For the most part, this applies to a government doing it by prohibiting a private party to deal with you. On the other hand, if the same state of affairs is reached by that government merely making it potentially very expensive for a private party to deal with you, somehow none of these standards apply anymore (or maybe they nominally do but nobody’s ever succeeded at enforcing them, which amounts to the same thing). That is what gives me the chills here.
OFAC sanctions can be appealed.
And what if they did so before the sanctions? Is the US so happy to retroactively punish people who literally did nothing wrong?
What on earth did people think a tumbler like Tornado Cash was going to be used for and by?
There's nothing sinister about privacy. It would be a logical fallacy to assume that just because sinister things happen in private that privacy itself is sinister.
Totally agree. One damning aspect of Tornado is we know it was used to launder money. Criminals used it. This was publicly reported and certainly known to the Tornado team.
If you know your product is being used by criminals to do crime and you respond by shrugging your shoulders, I’m not sure what the expected outcome is supposed to be other than getting dinged.
You are aware that criminals use all the same thing as you an me right? They use toothbrush too... should Coldgate not shrug their shoulders? Sure they don't commit crime with them, but they do use them. Want something they use to commit crime? Guns to kill, cars to evade, bags to carry the money, etc... what should all theses companies do? Let's go even closer, about privacy, what about balaclava manufacturer, it's the default thing considered for banks robbers, yet they still sell them!
I don't have all the details in this case, my guess is that Tornado Cash were aware that it was used by theses countries and could have stopped theses specific accounts (it would keep going for sure without their knowledge using alternative accounts obviously, just like many of theses countries still are able to get Windows illegally, but at least they would no longer be aware of theses accounts). In that case it does makes sense and I agree with the direct sanction of Tornado Cash. I would still disagree with the blanket sanction over the open source contributors, as they might have contributed without knowing it was used by sanctioned country.
Writing all that made me think of a question: do you believe contributor to Windows should be sanctioned too knowing that Windows is used in some of the sanctioned countries?
No contributors have been sanctioned. Three leaders had their GitHub accounts deleted, from what I can tell, and are trying to misrepresent that as a threat to everyone who ever touched the project.
Otherwise you end up in situations like this where innocent people are going to get screwed over because they utilized a tool that criminals utilized. This isn't fair or just by any standard and I personally don't accept the collateral damage as worthy.
This doesn't even begin to touch on the vast majority of laundering that happens in fiat across international banks . That would take a while just to list all the infractions that are constantly happening, yet those entities are still not only operating in the free market, but they have federal insurance and backing.
Hiding illegal gains.
> crime happened before the laundering and that's what we should be preventing
Covering up a murder is a crime because we don’t want people helping murderers cover up.
> like this where innocent people are going to get screwed over because they utilized a tool that criminals utilized
People who used Tornado Cash aren’t getting screwed. Even the developers aren’t. They aren’t personally sanctioned. Their work, which has been used to launder money, is.
Third parties, like Microsoft, are choosing not to associate with them. (The developers who knew about the laundering, e.g. through the public announcements law enforcement made, and kept working on it are far from innocent.)
> doesn't even begin to touch on the vast majority of laundering that happens in fiat across international banks
Yes, there are other crimes.
People laundering money through banks get sanctioned and jailed. When banks make a habit of laundering money, they too get sanctioned. There is ample historical record of all of this.
Incorrect, as per sanctions putting the onus on private entities to get things right, circle has blacklisted any USDC address that has been owned by the tornado cash protocol, which means anyone using tornado cash for legit purposes will lose every dollar they had in USDC. I'm really not sure how you came to the conclusion innocent people weren't getting screwed here, but it's irrefutable that they are, unless of course your definition of guilty is someone that used tornado cash, which would be a silly definition. I've used mixers plenty for completely legit reasons. I don't want people knowing how much crypto I have and I don't want to manage tons of addresses so when I transact in open ledgers I have at times had people pay me via mixers to hide the addresses I own and thus hide how much crypto I own from people doing business with me. All completely white market business dealing with buying/selling electronics too, for that matter.
> People laundering money through banks get sanctioned and jailed. When banks make a habit of laundering money, they too get sanctioned. There is ample historical record of all of this.
Incorrect, they pay fines that rarely even cover the profits they made to begin with.
Wasn’t aware of that. Fair enough. Innocent people will get harmed.
That said, innocent users whose USDC was frozen haven’t lost their money. They’ll have to show they weren’t laundering money. When they do, they should be able get it unfrozen. If that doesn’t work they can pursue legal remedies, though the law in all of this is obviously undeveloped. We are in dire need of stablecoin legislation; something to add might be controlled redemption for users the issuer no longer wishes to associate with.
Their situation is analogous to getting money stuck at PayPal. If you don’t want to take that risk, don’t use PayPal. If you don’t want to run the risk of your stablecoin getting stuck, don’t use mixers. Particularly after they’ve been publicly identified for laundering money.
People have been talking about all of this for years. It was continuously shouted down, or claimed to be impossible because blockchains are above the law or something. I get that there was a lot of noise above that signal. But like, it’s North Korea. On the balance of harms, of course this is what happens. There was never another endgame. The wheels of justice just turn slower than bullshitters spin yarn.
I hope you're right, but the process to make this happen will be painful and slow and the damages will not be compensated I suspect.
> If you don’t want to run the risk of your stablecoin getting stuck, don’t use mixers. Particularly after they’ve been publicly identified for laundering money.
Following this logic, should people stop using HSBC or any of the top international mega-banks? We're talking about banks that didn't "accidentally" let money laundering happen. They actively facilitated it. HSBC specifically laundered money for one of the most violent cartels in the world and not a soul went to jail.
Bit of a rant, but my point is that exactly where should people keep their money that is safe from being caught up in laundering? Such a place doesn't exist as far as I'm aware.
Practically speaking? HSBC laundered $881 million in 2012 – but they had trillions of dollars of assets under custody. They may have to pay a big fine, but your ability to get at your money will not be impacted.
And even if you deposited your money into your account at "Money Laundering Bank N.A." where everyone but you was a specially designated national, you still have legal recourse to those funds backed by decades of case law. That same case law might help you if you keep money from a mixer in stablecoin that becomes frozen, but it's going to get way hairier.
Nothing wrong with writing code. Code is speech, that's settled law. But the Tornado Cash team wasn't just publishing. They were building a tool. Semenov styled himself as a co-founder and the group advertised open positions on its website.
It doesn’t. Tornado was used to launder money. That’s all that matters.
My guess is the only people in real legal jeopardy are those who kept working on it after its involvement in laundering was exposed. (I’m assuming they weren’t in on the laundering.) For GitHub, figuring out who those people are is impossible. So they’re being cautious and cutting ties more broadly.
There is a creep problem to sanctions. Some companies in Russia are banned. Suddenly everyone from Cyprus is under extra scrutiny, since you don’t want to be the dupe they used to launder their money. Tornado and its developers were those dupes. But it has been illegal to help North Koreans launder money since before Tornado was founded. It remained illegal when it became known North Korea used Tornado to launder money. Anyone going into money services knows, or is negligent in not knowing, that these laws apply to them. It’s tough to have sympathy for anyone who kept ties. Particularly when the punishment, so far, is simply ostracism.
The US didn't mandate deletion of their Github account. The US isn't punishing them – you can tell because they didn't put them explicitly on the SDN list.
Microsoft made the choice to remove their accounts. Their compliance team likely looked and said "$ we make from these devs < $$$ we'd pay to our lawyers to simply decide if we should keep them on our platform."
This person can be totally oblivious to the illegal stuff that's happening behind the scenes. After all they were just trying to prove that they actually have experience with cryptocurrency code to potential future employers.
It also can be some random security researcher who is preventing open source developers from shipping vulnerable code. I know for a fact that Github themselves employ such people that send security-related patches from time to time to open-source projects.
You can work up more examples -- my point is that people who definitely have nothing to do with any illegal activity whatsoever could exist in the list of contributors of these repositories.
It's nice that they didn't just nuke the whole contributors list, but it's still a bit unsettling.
> it's your responsibility to know and check who you are dealing with.
What can I say, duly noted.
Sometimes you just have to assume that everyone's operating in good faith.
But, you can’t just put anything in one of these agreements; the law overrides anything you might state in a contract.
Furthermore, software licenses govern the use of your code by other people. It doesn’t govern your use of the GitHub service.
Your use of GitHub is governed by the GitHub ToS. Under that agreement, they can terminate service for any reason they want. They can cancel your account if they wake up grumpy on a Tuesday and just feel like it. Or, they can terminate service because they don’t want to touch anything that might be sanctioned with a 10 foot pole.
From the Twitter thread it appears that the devs whose accounts were nuked were core contributors to a sanctioned entity. That feels fairly sensible & what a company who wants to comply with sanctions would do.
They wilfully contributed to the upkeep of a money laundering service. They should be thankful losing their GitHub account is the extent of the fallout, take it as a lesson that code can cause real harm, and act more judiciously in future when it comes to contributing labour to suspect projects.
Privacy is not illegal.
Just because you find a use for a technology doesn't make the technology good. Nuclear weapons are a highly effective alternative to insect repellent, but that does not justify the general purpose use of nuclear weapons for repelling insects.
It's like saying the local brothel can't be shut down because the building could potentially be used to teach the word of the lord while the employees aren't otherwise busy. The exclusive purpose of the brothel's existence is enabling trafficking and sex work, and the benefit of any potential imaginary supplementary uses are grossly outweighed by the benefit to society of closing it down.
Privacy as such is not illegal, but that does not mean that government may not prohibit certain specific ways of achieving privacy.
There are a variety of sanctions mechanisms. Tornado didn’t have to be controlled by North Korea (it isn’t), just used by them to fall afoul of U.S. law.
The state has the power to levy taxes and prevent transactions with entities that it considers harmful (OFAC is effectively this); this is the state taking steps to do so, while GitHub is deciding that people who are attempting to evade those laws are outside the risk profile of "who we want to provide services to".
I hear the US government actually supports this method.
Cryptocurrency enthusiasts like to think that just because their transactions are done inefficiently on a blockchain, banking laws don't apply to them. Of course they apply. The only difference is their transactions are more expensive.
Operating an illegal money transmitter that demonstrates no capability/intent to actively filter OFAC specified sanction targets, however, is.
And no, things like monero and zcash aren't a working solution to this problem either, that's a whole different discussion though.
Things like the Bank Secrecy Act are only there to guarantee a level of secrecy/protection from other customers. Law enforcement, government, and third party service providers are not counted there realistically. If you want financial privacy, you keep your own books. By that same token though, you don't get to act surprised when the authorities come a knocking with a warrant to crack open your books when they find out you made a poor decision of people to work/transact with.
Surely you accept that illegal trade happens through cash and even through banks, so you will agree that there is some level at which you cannot ban an entire system.
[0] FBI/CIA/etc
If you are affected you could take this to court, and might even be able to convince them that the law went too far in incentivizing GitHub to delete your account. It seems very unlikely, but with a good lawyer courts can do weird things. If you do pull this off, then that would change court precedent, and when combined with a few dozen other cases eventually make it so courts will not accept deleting all accounts as a useful to to prove attempting to comply with the law. (Let me be clear, I doubt you could win this case, but it is theoretically possible so I offer it for completeness sake)
This matters a great deal when it comes to OFAC sanctions. The value of sanctions isn't "OFAC chasing down people on the SDN list", it comes from companies following federal law and blocking transactions that legally need to be blocked. And OFAC recognizes this – just look at their enforcement actions[0] and you can see examples where companies that build internal compliance programs and self-disclose violations come out with limited to no penalty[1], whereas companies that skirt compliance regimes place themselves at much more risk[2].
[0]: https://home.treasury.gov/policy-issues/financial-sanctions/...
[1]: https://home.treasury.gov/system/files/126/20220721_midfirst...
[2]: https://home.treasury.gov/system/files/126/20201020_berkshir...
So you have to figure out for yourself if exercising your right to free speech is worth having the government blowup your life for the time it takes to “prove your innocence“. Because, I can assure you, they don’t care even a little bit about violating your constitutional rights if it gets in the way of whatever witch-hunt they are currently on. It’s the court’s job to sort those details out.
The novelty here is that prople are being forced to realize how destructive getting sanctioned is due to bearing witness to the power of the network effects involved. This was inevitable, no matter which way you cut it.
As far as I can tell, the executive branch was not mandated to delete anyone who contribted to/was a "member" of the github tornado dev group.
It did exactly that.
These companies got that list, their legal, risk, and compliance departments got in a huddle, and they laid out an action plan to try to get ahead of the regulatory action, while minimizing any risk of contamination or liability.
The government did not tell them to do that. Note, this is by design. The government telling them to would be unconstitutional. Rather, they acted in their own way, which to them rang as reasonable.
That is how it rolls. Is it fair? No. Is it right? Arguably not. Is it concerning? Hell yes.
It is what it is though.
> Sanctions Implications
> These prohibitions include the making of any contribution or provision of funds, goods, or services by, to, or for the benefit of any blocked person and the receipt of any contribution or provision of funds, goods, or services from any such person.
One interesting and under-appreciated fact about OFAC: they take an, ahem, expansive view of where US law applies.
CSE TransTel was a company based in Singapore who was sanctioned in 2017[0]. They had a bank account with a Singapore bank. TransTel did business with Iran, in violation of US sanctions. But neither the company nor the bank were in the US; how did OFAC make that fly?
Because TransTel did transactions with a US dollar account, OFAC argued the settlements of that account caused banks inside the US to incidentally violate sanctions. Essentially the presence of US dollars created a nexus and allowed OFAC to enforce US sanctions against what would appear to be an entirely foreign entity.
Any wonder MS is treading lightly?
[0]: https://home.treasury.gov/system/files/126/20170727_transtel...
https://home.treasury.gov/policy-issues/financial-sanctions/...
https://home.treasury.gov/system/files/126/virtual_currency_...
They are setting a precedent that any forks or similar implementations of this protocol will also be sanctioned.
A comparison would be sanctioning the Matrix protocol because it facilitates end-to-end encrypted communication for terrorists.
It's basically an HTTPS layer. You roll up some set denomination of ETH or whatever into a zero knowledge note, which can then be treated like cash. Anyone who has the private key can generate a request to send the note somewhere else, and there's nothing linking the creator of the note to the spender of the note.
Never once has it been marketed towards criminals, or have any of the team made any indication that it was build for criminal purposes. It appears it was actually in heavy use for three years or so before Lazarus apparently used it for the first time, which is why the sanctions were slapped on it. Fuck Lazarus, but also the idea that anything tech they use becomes illegal is insanity.
In short, if you are not concealing the source of your funds to conceal a crime being committed, you are not guilty of money-laundering. It's that simple. KYC laws apply to banks and corporations, not individuals and not protocols and not code.
Privacy is not against the law, and neither is deploying a privacy tool that happens to be used by criminals. The comparison to matrix is surprisingly apt here. I have no doubt that criminal activity is facilitated by matrix, but the idea that they are responsible for that is ridiculous.
I would tell you to just look at the Tornado Cash code yourself to verify this, but alas...
Onion routing does, sure.
Ethically I find that area very much a double-edged sword. It's great for privacy and people evading speech-hostile regimes, but it does also enable trading and propagation of CSAM etc. It's why I've never run a Tor or Freenet (does that still exist?) node, I don't want to support that stuff with my resources.
No, it just encrypts between the ends, hence it being called "End to End Encryption". You're going beyond that if you're talking about hiding the fact that the origin and destination are talking to each other at all.
> If Alice and Bob and John and Piper are all communicating with pseudonymous names in a Matrix room, you do not know who is talking to who or what they are talking about.
Maybe so, but in other E2EE products the fact of communication is not obscured to someone who has access to the traffic. E2EE just means there isn't a server in the middle that decrypts everything before relaying, or any sort of master key they could use to do that with.
Matrix looks like a great system, but it's not the only E2EE product, nor does it define the term.
1. You are using and supporting the same protocol that they are also using. As the application grows and improves because more people are using and supporting it, the criminals are also being helped.
2. You are creating cover. The more people that use Tor and Matrix, the more secure it becomes for all users within the network.
If you and a criminal are both using the same Matrix server, neither you nor the host would know. Your plain text messages are going into the protocol, getting mixed and encrypted, and then spit out the other end.
The express purpose of an end to end encrypted chat protocol is to provide privacy. If users of it engage in criminal behavior that does not mean the express purpose of the protocol is also criminal.
You cannot launder money, though. This is forbidden regardless of which method you use (crypto, art, car washes, etc). These sanctions are saying "we consider this specific use of this specific algorithm to be illegal, so if you interact with it via these wallets you will be sanctioned too". But they are not saying "this algorithm is illegal".
Even then, the algorithm and Tornado are not the same thing. It seems unlikely you can use Tornado itself for this purpose, even if the algorithm itself is useful.
The press release specifically calls out a lack of efforts to block known bad actors and illegal funds from using their system:
> Despite public assurances otherwise, Tornado Cash has repeatedly failed to impose effective controls designed to stop it from laundering funds for malicious cyber actors on a regular basis and without basic measures to address its risks.
So you probably can provide a mixing service if you can find ways to reasonably limit money laundering on it. This would probably be antithetical to the decentralization principles built into Tornado, but might allow continued legal operations.
This is just "deleting people because sanctions need to be severe and hurtful".
It's pretty cut and dry.
They'd no longer be allowed to contribute to the project, but does someone having contributed in the past mean the sanction on the project extends to their person? Github themselves provided hosting to the project.
Sanctions work because they are virulent.