I'm sure the judge will be thrilled to have to listen to arguments about the with the nuances of dev, ops, devops and a distributed platform such as that which executes Ethereum's smart contracts.
I'm sure the judge will be thrilled to have to listen to arguments about the with the nuances of dev, ops, devops and a distributed platform such as that which executes Ethereum's smart contracts.
It's more like being arrested for developing a Bittorrent client
Nearly every time someone gets arrested for developing software they where also advertising and in some cases outright advising people on how to get away with illegal shit using their software.
Like here: https://www.investopedia.com/stock-analysis/2013/investing-n...
While they do get blamed, the Netherlands doesn't seem to care all that much. They seem very selective with how they react to supposed money laundering
https://www.reuters.com/article/us-ing-groep-settlement-mone...
https://www.dw.com/en/how-ing-bank-in-poland-helped-russians...
> ING’s Chief Executive Ralph Hamers said no individual at the bank was found to be responsible for the failures
Closed source means it is easy to hide whose fault it was, and then all you can do is fine the company since you can't arrest everyone. This is also why companies are so keen on deleting old message logs etc, to avoid leaders going to prison.
They have less control than you may think.
Any ethereum miners (or proof-of-stake validators) who block some class of transactions immediately become vulnerable to denial of service attacks.
This came up back in 2016 with the DAO hack on ethereum[1]. Some ethereum miners considered blocking transactions that moved the stolen funds, but then realized that this was infeasible: if you block such transactions, then the DAO hacker can spam you with them. Such spam on ethereum is usually prevented by requiring the sender to spend money on each transaction (ie pay gas fees). But that fee is only charged when the transaction is included in a block -- if you refuse to include it, then the spammer pays nothing. The kicker is that, by Rice's theorem, there is no way in general to distinguish "malicious" transactions from non-malicious ones (for _any_ definition of "malicious") short of just executing them to see what they do.
So if you as an ethereum miner (or validator) try to block certain transactions, you can be forced to do unbounded amounts of work for free, ie DoS'd.
[1] https://hackingdistributed.com/2016/07/05/eth-is-more-resili...
It’s just a program that runs and guesses a bunch of salts that hopefully result in a hash that meets some particular parameters (e.g. starts with 5 zeros). You want to be the first to guess correctly so you win the reward for that block, so any sort of investigation doesn’t make sense. From what data was stored on-chain in that block and whether it may be problematic (or even what the data represents), to which contracts were involved (and whether they have criminal ties), it’s just not reasonable for any miner to take responsibility for the block chain operating as expected.
I think this is the core issue with the block chain, is that society has always expected there to be some moral agent that you could hold responsible. Except in cases of natural disasters, you can normally blame someone.
But with blockchains, it’s a lot harder to place blame on someone, or link a physical person to the online identity.
Similarly with the 2008 GFC, everything was abstract enough that almost nobody got in trouble for a situation that was most certainly man-made, but hard to place the blame. At least then, though, the government had some amount of control over the banks and also relied on them to return society to normal.
Through the government’s eyes, block chain doesn’t appear necessary for society to operate and is very difficult to regulate, so I’m sure their tolerance is a lot lower for blockchains when financial crimes crop up from it.
Yes and no. It depends on what you mean by “validating”.
If your objective is to restrict the types of transactions that end up in the blocks you yourself create, you can recompile geth with a custom mempool implementation, and use that custom mempool to inspect the data of any pending transaction you want. This is how MEV works.
In other words, it is 100% possible for a technically-competent miner to only create new blocks that exclude blacklisted accounts, or that restrict transactions according to any number of criteria.
On the other hand, once a new block has already been mined and propagated to the network, there is nothing that a single miner can do to stop it.
If you start rejecting otherwise-valid blocks because they include blacklisted transactions, you will only fork yourself from the network. The rest of the miners will keep on building on top of the block you wanted to drop.
Is it reasonable for the postal service to examine every single piece of mail to check if it is illegal?
It's forbidden to send money through mail in many places. When you go to the post office to send money, the post office verifies your identity, the payment method, the sanctions list, etc and keeps the records for the authorities.
If you decide to violate the rules and send cash in a letter, the postal service allows the authorities to access the raw packages and full information, and full access to it, whether to use cash sniffing dogs (they really exist), etc.
Also, a fundamental difference with crypto exchanges:
Whether you send large amount of cash for criminal activity via the postal service or whether you send a large amount of books the postal service isn't going to benefit more, so they don't have to encourage criminal activity.
Similar to people using paper money or end-to-end encryption really. Nobody needs military-grade encryption or anonymous currency unless they're trying to hide something.
Say I sell software, or SaaS. Then I may need military-grade encryption because I need to sell, a few potential customers (may) need that, and I need to keep my costs down so supplying the latest and greatest cipher to everyone is the right default. It may waste a bit of CPU but it saves the time of the sales and support people, and human time is expensive.
Say I'm going to buy something tomorrow, and I don't like SPoFs. There's a card in my wallet, or maybe two, but if the card reader in the shop is down, that's a SPoF unless I also carry some cash.
What a useless, puerile argument
"Doing nothing" isn't reasonable though, and the people has decided. Calling the people's arguments puerile or useless makes no difference.
Imagine the scenario wherein potential "illegal" crypto is mixed through another service. How would you expect Tornado to verify that without straight-up blocking specific services through transaction patterns?
If the network is completely p2p, they really aren't.
OTOH, it seems foolish to develop/run a p2p network and publish your real name along with it. It's asking for trouble.
This would be similar to the developer of the encrypted phones that everyone defended initially until it became known that he flew to other countries to train drug dealers how to use the phones.
In this crypto business, it is not enough to just build the system and expect people to magically know that it's for them and how to use it - 50% of the work is selling and training people on the system.
This is all speculation based on previous similar cases.
Whereas, for a crypto network, the more funds flows in, the better for the operators and eventually for the developers (who gets paid by node operators via increased coin value or donations). The less compliance or questions asked, or the more anonymity = the more shady flows.
They do today. Back in 2001, flying was a lot different. For starters, there was no such thing as an armoured door between the flight deck and the passenger compartment, mostly because such a door is heavy and costs extra fuel.
That's one big difference between those whose products can be used for both good and bad who do not get in legal trouble over the bad use and those that do. There's some threshold for a given type of produce of tolerable bad use. When they product is approaching or exceeding that they make changes to lower it, or if it can't be fixed abandon the product.
> Please respond to the strongest plausible interpretation of what someone says, not a weaker one that's easier to criticize. Assume good faith
The person's core argument was obviously that "airlines do what they can to keep people safe rather than financially benefiting from criminal activity" which distinguishes Tornado from airlines and web browser developers.
As an aside, it was less important to prevent hijacking before 2001 because the end result of most hijackings before then was that nobody got hurt if pilots complied, so there would be no reason to place a cockpit door. That strategy obviously changed after 9/11.
I don't think the behavior and results of airplane hijackings pre 9/11 fall into common knowledge, even on hacker news. That's a pretty niche, specific collection of 20+ year old historical facts.
Those doors are not heavy. It's not a flying tank. Removal of printed in-flight seatback magazines would offset the weight. Until 9/11, flight deck door procedures were lax.
(and banks do all they can to avoid fraud, yes yes yes)
> It is suspected that persons behind this organisation have made large-scale profits from these transactions.
I’m sure a judge can look at more concrete evidence in the form of financial gains.
This is SOP for the bulk of nonviolent crimes in the US.
Anonymizing spending on it’s own is not a crime. Clearly the line is crossed if the developer is promoting the use of the software for illegal purposes. I’m only vaguely familiar with Tornado cash, was that the case? If not, how do we as a society/community draw the line on determining a developers intentions?
If a company releases software that is used nefariously, there are very common legal actions to hold them accountable. For example, Facebook has extensive legal obligations to meet to do with behaviour on their platform.
I am not arguing that tornado cash should be illegal (or that encryption should be illegal) rather I am arguing that people are responsible for the software they have created.
If I commit a crime, my intent is absolutely a part of the equation when determining legal action. Why should it be any different with software?
If you wish to argue that the right to privacy is so great that it exceeds any risk of criminal activity, and thus the developers of tornado cash were doing something for the greater good, so be it (that’s probably the position I would take) but it doesn’t absolve them of responsibility.
Taken to the extreme, if I build a piece of software that can save the lives of murder victims by killing the murderer: I am responsible for the killing of (intended) murderers. We might decide that the activity is justified, that the software is operating for the greater good and is therefore permissible, but that doesn’t change my responsibility.
So, is your answer to the asked question yes, the developers of Metasploit should be arrested and jailed?
How about the developers of Bitlocker? It's used to encrypt illegal content, impeding police discovery efforts. Every person who developed a file-sharing website should probably also be arrested. Lots of illegal/pirated/etc. content out there.
The point being that almost every software on the planet can potentially used for malicious and illegal activities. Seems like if we indefinitely held developers responsible for what other people do with their software, the smart person would never develop any software.
Every other industry deals with this challenge — why should software be any different?
You said:
>If a company releases software that is used nefariously, there are very common legal actions to hold them accountable
If you believe that, it follows that you believe that every developer of encryption algorithms should be "held accountable" (be it jail, or "responsible without prison", etc.) because other people use encryption to hide illegal activity. Developers of internet protocols should be accountable for the actions other people take on the internet, because lots of illegal things happen on the internet.
Metasploit, Kali, 7-zip, FileZilla, Word/Excel, Putty, OpenVPN... Should I go on? All of these are used for nefarious things all the time. Are you really suggesting that the developers of these should be responsible for the nefarious things that their users do? If not jail, what responsibility are you suggesting?
>Every other industry deals with this challenge — why should software be any different?
Most other industries have protections against this type of liability, not responsibilities. See knives, guns, planes, cars, etc. Unless their is gross negligence, which isn't just "it was used nefariously", the maker of X is generally not responsible for what some user of X does with X.
Edit for clarification:
You can argue about purpose-built nefarious software, sure. If I develop ransomware, and advertise it as ransomware, and there's no legitimate use other than ransoming... I should probably be held responsible for the ransomware attacks that occur using that tool (at least, I accept that argument). The problem with applying this to all software is that most everything that is used nefariously was originally designed for and used for legitimate uses. When that's the case, the person who committed the crime with the legitimate tool should be held responsible, not the maker of the legitimate tool.
If you knowingly build software that can be used for money laundering and make no effort to prevent money laundering then, if software was treated like other industries, you’d absolutely expect to be held liable.
You've retreated back to money laundering, but that is not what you originally were talking about.
You were pretty clear that you were talking about any software which is used nefariously. Which I pointed out that pretty much any software can be used nefariously (e.g. ssh, browsers, hosting software, etc.), but you keep avoiding that.
A web browser can be used to access a banking website through which you might engage in money laundering, sure, but that’s very different to a piece of software that can be used to hide the origin of funds.
The difference is like a kitchen utensil manufacturer vs. a gun manufacturer. A kitchen knife can be used to kill, a gun can be used to kill, but we hold gun manufacturers and kitchen utensil manufacturers to different standards because intent is an important aspect.
Your argument is predicated on the idea that intent doesn’t matter, but intent does matter, intent is a significant component of criminal law.
>If a company releases software that is used nefariously, there are very common legal actions to hold them accountable
There is no mention of intent. Just that if a software is used nefariously, the creators of that software should be legally accountable.
You later talk about your intent, when you commit a crime, but that's very different. I agree that if someone commits a crime with X software, their intent should be considered. What I don't agree with is holding Tatu Ylönen accountable for someone else's nefarious use of ssh.
Money laundering laws very much disagree with this.
Since crypto currencies, nearly by definition, don't care about country borders and the mixers don't trace the amount put in by each user, they almost certainly allow you to circumvent money laundering registration requirements. It's even worse if they frame the mixer as financial institution, in which case it directly violates its reporting requirements.
Where do they?
The developer of Tornado Cash is not responsible for who uses it and for which reasons, just are knife makers are not responsible for murders.
Not a valid comparison.
Courts and law have long held the completely reasonable position that if the main intent of a product is not to commit crime, that those using it for a crime are held responsible, not the producer.
Conversely, if a product is designed to facilitate crime, or is used significantly more for crime than not, then the liability starts to shift to the producer (as well as the users).
This is the latter case. If the courts show that the producers knew the product was used for crime and added features to assist that on purpose, then they should be held liable.
According the to article, 14% of money moved through the mixer was of criminal origin. If any bank did that, they'd rightfully get hammered by the law (and they do, for vastly smaller ratios of criminal activity).
There are laws about facilitating criminal money laundering.
How is privacy not a legitimate use case?
> According the to article, 14% of money moved through the mixer was of criminal origin.
I’m pretty sure the majority of duffel bags sold in cartel controlled areas of Mexico are used to transport drugs or drug money, that doesn’t mean selling them should be a crime.
I'm pretty sure that's not true. 1-1 we tied :)
And again , not equivalent. If local duffel bag makers knew duffel bags were used significantly for crime, and added features to facilitate crime, and ignored laws requiring tracking criminals (which is what money processors have to follow), then the duffel bag maker would be criminally liable.
In the cast at hand, the company processes the transactions for criminals. That is vastly different than selling a duffel bag. And it runs afoul of criminal money laundering laws that all processors have to follow, and for good reason.
This is why the courts are the place to hash such stuff out - internet opinions are vastly inferior to people performing investigations using evidence.
get off your high horse, use of tornado cash is quite common among crypto natives, otherwise it's like broadcasting your pepsi purchases on instagram
Given the high data protection requirements warranted by operating a financial service, users could be reasonable sure that their Pepsi purchase remains private.
Of course such measures would run counter the intended use of Tornado cash, including money laundering, but that is their problem and no one's else.
But there's definitely legitimate uses for Tornado Cash. The same way there's legitimate uses for cash.
14% of funds, yeah, not 14% of users... Big difference.
Yep, it shows an incredible quantity of money laundering through the service.
I'm sure that isn't true. Most people anywhere in Mexico are civilians not involved in the drug trade.
A textile mill producer who gets an order for 5000 duffle bags likely has no vision in mind for the use of the bag beyond "sell to N stores at X price for profit". The storeowner who buys the duffle bag likely also has no criminal motive and instead just wants to sell inventory at profit.
Tornado Cash devs will be scrutinized to understand their main goals, and their communications/advertising strategies, likely as well as any correspondences will be considered for this determination.
You're stating this as if it's fact when it's really not. Tornado Cash was certainly not designed with the intent of criminal activity, but for privacy - and as for "significantly more for crime than not", I've not seen any actual evidence for this, only evidence to the contrary. People claim it's mostly used for crime, but those are purely conjecture, at least the ones I've seen are.
Again, claims of privacy is not enough magic to make them free from legal requirements for money laundering laws. Privacy claims do not make banks immune from money laundering. Privacy claims do not make anyone free from meeting legal requirements.
>those are purely conjecture
The above states ~1/7 of all money flowing through can be tied to criminal behavior. If true, that's an astounding ratio that would rightfully put a bank out of business and key players in prison.
Unless the service was redeployed (unlikely) or operating behind a proxy contract, it wouldn't have been possible to add new features.
Only if you made and advertised a "human killing knife", so in this case I have no idea how this software was advertised by the devs and community.
I think the intention is important in this case, what was the purpose and who benefited the most , if 99% of knives are used for bad things then you would probably have some ideas about that issues.
The charge isn't the anonymization of the money, it's specifically the concealment of money produced by criminal activity, and whether or not that's something that is allowed based on NL law is really the question, as is the motive of the developer/service providers.
This next part is from a US perspective, but remember that there are multiple aspects to law besides just the actual act. There has to be a motive as well.
The reason as I understand it that knife/gun manufacturers aren't really held responsible is because (arguably) their goal is not for persons to commit illegal acts.† Thus the illegal act is an exception and independent of the intention of why the product is produced, and there is not a motivation to empower illegal activity from the manufacturers.
With Tornado cash, it becomes a bit murkier I think and I suppose this is why it's being sent for examination as opposed to outright finding the person guilty. I would imagine what the judge wants to find out are things like:
1. Who was the primary audience/user for Tornado Cash (TC)? Not generalized, but who was actually using it?
2. Were there communications between the team behind TC and other entities that can be identified or no?
3. Did the TC team have awareness of who their main customers were and where the coins mainly came from?
4. Was there any campaigning by the TC team that can be found which shows they were specifically catering to people doing illegal activities?
5. Likely, a court and FIOD would want to investigate if any regional activity can be tied to Tornado Cash††, and if a known sanction region was utilizing the service, were actions taken to prevent this.
I understand that the goals of cryptocoins and the goals of Governments are opposed by design, and likely there will be constant conflicts like this for a long time with cryptocoins and governments; one wants to circumvent monetary rule, the other imposes the monetary rule. I have no personal judgement on TC or cryptocoins, but the court decisions will be interesting to read.
† - I do realize that this line blurs a lot depending on the type of knife being sold, and even worse with gun manufacturers. Unironically, the Borat movies (I forget which one) show this pretty well when Borat asks which gun is best for "stopping Jews", and the gun owner doesn't blink. Gun manufacturers I would suggest walk a fine line in their advertising, as do proponents of gun rights. I know responsible gun owners so I'm not here to case a wide net on all things gun related, but my take on a lot of weapons advertising is that it sells a violence fantasy.
†† I'm not as familiar with ETH or even how probable it is that they can find who used a service, but it's something that the teams will try to figure out. Whether or not this is a good idea long term is not the point I want to make, it's more that I think this is something governments will be interested in. Very likely, there is a vested from these governments in ensuring specific sanctioned countries cannot use cryptocoins to circumvent sanctions. I don't really agree with this ultimately, but it is important to understand the entire thought process beyond just "governments hate cryptocoins".
In finance, you are required to maintain the chain of provenance in an unobfuscated form. If you can't, or won't, your license to operate is revoked. If you didn't have one in the first place, you're already in hot water. You cannot play in the sandbox anymore. That's the civil side. Just like not being willing to help with airline emergency exit doors probibits you from taking up that row of seats.
Second, if you are connected to willful facilitation of criminal activity, that's when the fangs really come out, because the criminal with the technical expertise to facilitate is a much rarer thing, and the perfect subject for being made an example of ad a warning to others.
This is why I have repeatedly told anyone who'd listen. Peer-2-Peer payment technologies without control/auditing paired with them will never be tolerated once they are widely known about. Hell, things like World of Warcraft Gold or game currencies have been used as money laundering vehicles long before blockchain, and even they got law enforcement scrutiny from time to time.
Do not publish that which you don't want to eventually run the chance of being held responsible for.
The stated goals of TC was privacy. Privacy is not a crime.