Decentralized storage company Storj removed their warrant canary
storj.io
storj.io
Data on Storj is by default end-to-end encrypted with keys only the data owner controls (with optional support for sharing features). Only the data owner can decide who to share the keys with and who can see the data. Put another way, Storj can’t access data without the data owner sharing keys and access!
However, if the owner shares the encryption keys and provides access to others, it can be further distributed by others. Storj does not allow illegal content per our terms of use and conditions. If someone has stored potentially illegal content and shared it with others, law enforcement may seek to obtain information by way of a subpoena, warrant, or other legal process. As you probably know since you're reading this thread, often such inquiries are confidential and the recipients may be prohibited from disclosing their existence.
If you're interested in our encryption and security design decisions, there are a lot more details over at https://www.storj.io/disclosures. Glad you're all paying such detailed attention!
Of course it’s a different business model, and I can’t vouch for PIA actually standing by those commitments. And I empathize with wanting to use best in class tooling to optimize your site experience. But prioritization of privacy, and commitments to minimizing log retention, are things you should consider revising to the extent you are legally able to do so. Don’t feel you need to respond here, of course, to that point!
Yes, that is exactly the kind of thing you're supposed to be taking a stand against and resisting.
In fact, warrants like this are not "often" confidential - that is an aberration and an abomination - and a relatively recent one.
We - all of us - should publicly oppose these measures and work to resist them.
EDIT:
I think I have misunderstood - the HN title is incorrect/misleading.
Storj did not remove their warrant canary, they failed to update it.
Interesting ...
And doing this does not change the law, so nothing changes.
I think there are more well spent time ways to improve freedom etc around the world and where you live
I of course understand what you mean, but I don't feel like excusing my self for pointing out logical or factual flaws.
I can say that while this is essentially a security discussion and not a dinner party conversation, I am nice to talk to :).
He directly acknowledges that this post is about the canary disappearing and doesn’t immediately explain why. If the canary vanished due to a script failing or a person forgetting to update it he would have loudly and clearly stated that they have not been served and the reason why the canary was not updated.
Those facts, imo, HIGHLY suggest they have been served with a secret warrant.
[1] https://www.eff.org/deeplinks/2016/05/canary-watch-one-year-...
[2] https://web.archive.org/web/20210712025824/https://canarywat...
In NSLs, you are not allowed to reveal the existence of the request. Removing the warrant canary reveals the existence of the NSL.
Sometimes courts also prohibit you from revealing that you gave away user account information to the police.
In theory, using the (incorrect) logic of the canary warrant, you could publish a list of all user IDs and say "The police never requested the user information for these IDs below:", but this seems very gimmicky in front of a judge.
At the end of the day, a company that is actually subjected to NSL wishes has very little reasons to remove a canary warrant.
1) They cannot be sued for lying in their canary warrant as this was a properly formed court request.
2) It is good marketing for them.
3) They risk significant criminal charges for no benefits.
They really have no incentive to do so.
Disclaimer: IANAL
Trying to logic bomb your way out of this is just asking for a summary judgement against you. It doesn't matter if it's not logically consistent, most rulings aren't! They will simply ignore this argument.
The counter to the "compelled speech" argument is that the government is not the one that forced you to start doing warrant canaries! You started doing warrant canaries, the gov't wouldn't ask for a remedy of you putting up continued canaries. You put the onus on lying on yourself, and if you don't do it you'll just be charged with revealing the facts.
Government demanding you to compel speech is not what would happen.
And no, most rulings are, in fact, logically consistent.
If we take the inverse, and we are talking about prior constraint, I have a really hard time imagining courts not siding with the executive. There are so many more controversial things the courts side with on law enforcement, "do not tell people who we are investigating" feels like such an easy win (and honestly much more acceptable to the general public than anything).
I feel like there's some fundamental argument here about negligence. In what way is the government responsible for you making a promise you can't keep to your customers?
But... ultimately there's no "real" answer except what the case looks like when it gets in front of judges and how they feel about it. And I will admit arguing it's not compelled speech takes a hell of a lot more effort (even if I believe it's true!).
NSL are already on shaky legal ground in the first place with a good part of the court looking for ways to curb them. Which is why when push comes to shove the government often drops challenges to their authority instead of allowing it to get up to the Supreme Court.
They, like common thugs, exist because of the threat and the fact that most people lack the resources to fight them so they just give in
Parents aren't bound by the US constitution.
Not saying something is one thing, saying something false is something else.
It boggles my mind. "Why do I have to comply with this order?" "Because not complying with a legitimate authority is breaking the law." "Can you really use an argument based on the sanctity of the law to justify ordering me to break the law?"
Prior restraint is the government forcing you to _not_ say something.
Compelled speech is the opposite, forcing you _to_ say something.
Both have a high bar to meet, and meeting one does not mean you that you meet the other. In the case of compelled speech, I don't believe a US court has ever ordered someone to lie, which is what would be required here.
Tomorrow, the government is asking you to capture messages of some users that are planning a terrorist attack.
By default your app is not capturing these messages, but technically you could do it with a specific update. The lawyers already challenged the decision, they confirmed the request cannot be avoided.
You end up pushing a backdoor targeting specific users ("a law enforcement custom update").
Court is explicitly asking you to not disclose the existence of this special update.
As a business owner, why would you reveal it ?
You'll go to jail (or struggle in court at least) for few years, have a horrible reputation and end up poor because your company is going to lose all its user base :/
This sounds like an insane decision.
The users, upon learning you got backdoored are going to go away, because the competitors "Telegram", "WhatsApp", etc, they will not have removed their canary or they will simply not have claimed anything :)
Perhaps on paper the law cannot force you, but if you don't comply you are cutting the branch you are sitting on.
The alternative is just to leave the warrant canary and live happily after.
Perhaps you even made the world better after all and actually prevented an attack.
But, pretending that's not the case:
> As a business owner, why would you reveal it ?
Because you have principles? Backed up with at least a little bit of spine?
> You'll go to jail (or struggle in court at least) for few years, have a horrible reputation and end up poor because your company is going to lose all its user base ?
It's not clear that you would go to jail. You can simply shutdown[1]. For those that actually care about privacy, your reputation would only increase.
[1] https://www.theguardian.com/technology/2013/aug/08/lavabit-e...
- Don't create a platform where arbitrary changes can be made
- Don't use a platform which can make arbitrary changes that decrease privacy
Blockchain-based OSS regularly gets negative comments here on HN, but they do implement such workarounds (personally I think xx Network is well-protected), as do non-blockchain based Open Source projects. The problem for the latter is no funding for devs and independent, decentralized infrastructure.
Another alternative would be to implement Binary Transparency, and make the app only download updates whose hashes appear in an independently-run jurisdictionally-decentralized append-only log. (Rolling out such a change might take too long to help the target of the current NSL, but it would protect future users, and announcing such a feature would itself be sending quite an important message).
I suppose if your business relies on keeping its source code secret, then you could just put an "if userName == the_target_mentioned_in_the_NSL" branch into the code, so that all your users receive the same update, but hopefully someone out there would be able to reverse engineer that code (perhaps after an anonymous tip-off).
Perhaps the government would be willing to pay for a software engineer to obfuscate the code enough that this malicious branch won't be detected in time, but I think that would put selective pressure on software companies to not distribute obfuscated binaries.
We compel speech in companies all the time. We force them to disclose ingredients and add labels to their products. We force them to hand over financial information and employee records. Forcing them to lie is something I haven't seen though.
I don't see how the government could be stopped from forcing a company to hand over their encryption keys and just continuing to publish the canary on the company's website themselves though.
The government could force the handover of encryption keys, with the caveat that if a set of keys controlled by the provider can compromise your security, it's a trash system.
Forcing the existing canary to remain would be straightforward as well.
Compelling false speech, i.e., continuing to publish a time-based canary, is a huge leap from either of those things.
There is a fairly reasonable argument one could make for doing so:
- The company's value is tied to its reputation for securing its users' data
- An NSL or similar would risk their users' security and the company's reputation
- This will affect the value of the enterprise and therefore the existence of an NSL ought to be disclosed to investors
However at the meta-level, this would be a substantial escalation since an order to continue publishing a canary is no longer just compelled lying, but compelled securities fraud, effectively pitting one branch of government (the national security apparatus) with another (the SEC).
It's always felt like engineers thinking they're outsmarting a much more mature legal system with humans built-in to slap away foolish gotchas.
The EFF seems to think warrant canaries would work, though, but under the premise that you can say "I've received some number of national security letters", just not "I've received this precise number of NSLs." That's an _entirely_ different line of thinking than every advocation of warrant canaries I've read.
And then the engineers, unsatisfied with the messy world of human intervention, create a system without humans, where the "code is the contract" (ethereum). Then rapidly abandon that tenet at the first inconvenience and return to human discretion (DAO fork).
Other than, you know, doing the entire thing they are designed to do. Some people do, in fact, care about civil liberties.
I don't like this ...
If you're publishing a warrant canary, updating it should be a manual process that a human is involved in.
The whole point of the headlines and the baseball/basketball scores is to prove that the messaged weren't pre-generated and pre-signed in advance.
What's the difference between pre-signing a stack of future canaries vs. script-generating them as time goes by ? Either way, you're muddying the negative-statement aspect of it ...
https://www.rsync.net/resources/notices/canary.txt
We discussed it a bit more at length a few years ago:
https://twitter.com/rsyncnet/status/1387090538273206274
"What hasn't gone away are the nondisclosure provisions of National Security Letters that were amended by the USA FREEDOM ACT of 2015 and the 9th Circuit Court of Appeals' ruling that "the nondisclosure requirement does not run afoul of the First Amendment."
...
"... and so we will continue. We will also continue to mirror internationally to CH and HK. A false, or coerced, publication will require cooperation across multiple continents, languages and legal regimes - all in seven days or less since we publish every Monday morning ..."
[1]: https://web.archive.org/web/20141027143819/https://github.co...
No, I don't think there's been an example of that happening, but perhaps we would expect that if the government wanted to bring such a case, they would use a secret court, or an NSL, which would likely result in the warrant canary being added back to the site before anyone noticed. (An injunction against removing the canary could even be included in the initial secret warrant).
In the US the government can take over parts of your facility, and that could mean installing whatever equipment they want or even setting up camp and running ongoing operations on location. They'd have no problem updating the canary of a company who refused to keep doing it themselves.
I doubt most business owners would risk losing everything on top of prison time though. The best we can probably hope for is that they'd decide to simply close shop like these guys did: https://www.eff.org/deeplinks/2013/08/lavabit-encrypted-emai...
> The Fifth Amendment to the United States Constitution protects witnesses from being forced to incriminate themselves
Although, with Storj, the signatures didn't expire, so in the event that the government did setup operations, they could have just continued using one of the older signatures. (And only would have been unable to create new ones on request)
[1] https://web.archive.org/web/20221021050048/https://www.storj...
[2] https://en.wikipedia.org/wiki/Key_disclosure_law#United_Stat...
I hadn't seen the old one, just the empty one they have published now. It was a lot more specific than other comments suggested!
> Although, with Storj, the signatures didn't expire, so in the event that the government did setup operations, they could have just continued using one of the older signatures. (And only would have been unable to create new ones on request)
that's my guess. they could either compel the company to turn over the keys or they could get them themselves from wherever they are stored/used.
Of course such an important passphrase shouldn't only exist in the head of one person, and instead should be distributed between multiple members of the company (so perhaps the HSM could require N of M passphrases to unlock the master secret, using Shamir's Secret Sharing), which means creating a very complicated on-going criminal conspiracy, with new hires forced to further the crime in unique and creative ways, so that their individually-chosen passphrases can't be guessed.
Removing the canary could potentially be classified as an illegal disclosure of the government request, so uh, criminal charges on that front. Of course that assumes that the secondary case isn’t also classified I guess.
Refusing to add a new canary past the expiration date has the same effect, but is only done through inaction.
I am not a lawyer, but my understanding is that this is the stated legal opinion of the lawyers at the EFF.
But if you had a script doing so, which is likely the case, you would have to modify it or direct it to stop updating, which would be a violation again.
I don’t think it’ll be that cut and dry as others have stated articulately.
> The government can't compel your speech
That’s not true. The United States government can compel your speech, albeit in very limited cases.
>- a declaration that, up to that point, no warrants have been served, nor have any searches or seizures taken place
>- a cut and paste headline from a major news source, establishing date
>Special note should be taken if these messages ever cease being updated, or are removed from this page.
>The current message is here:
...and then it goes blank.
The warrant canary exists because disclosing such warrants is illegal and carries some penalty. I imagine the federal government would bring a case to apply that penalty, and the courts would have to decide whether "removing a canary" === "illegally disclosing a secret subpoena." If so they can freely apply the penalty, and the penalty will carry legal precedent for being applicable to warrant canaries, and it will have a chilling effect on sites that wish to use one.
If i smoked every day, and chose to stop smoking, but the act of me stopping smoking is a signal to some third party that is deemed illegal, can the gov't compel the continuation of smoking?
In this case, information got removed, which is not illegal because the information removed is not required by law.
This distinction, from my understanding, is important for legal reasons.
I haven't caught up with them, did they ever decentralize the coordinator or whatever
would it even be about the data uploaded?
there are so many free options I’m over this
1. The native Storj "uplink" command. Using this interface, a Go utility called uplink is run on the local client machine. It contacts a Satellite Node (the non-decentralized aspect of Storj) to retrieve a list of Storage Nodes that will accept the upload, then the file is split up and encrypted by the local uplink client code and sent to Storage Nodes recommended by the Satellite Node. In this case, the Satellite Node knows about the various pieces making up a file, the Storage Nodes have encrypted pieces of the file (but do not know how they relate to each other), and neither the Satellite Node nor the Storage Nodes could reconstruct the original file, even if working together, because the encryption key is stored on the local client machine only.
2. There is an S3 Gateway that gives Storj an S3-compatible interface. To use this, a Storj user would register a user account on the S3 Gateway, giving them an access key (login name) and secret key (password). When files are uploaded using the S3 Gateway, the access key and secret key are used to validate that the user has access to the specified bucket but there is no encryption happening. When data is received on the S3 Gateway, the Gateway uses the uplink technology to send split and encrypt the file and send the pieces to Storage Nodes. When a file is retrieved using the S3 Gateway, the Gateway does the reverse and sends the original, unencrypted file back to the S3 client.
Storj customers using the Storj network with the native Storj uplink client should have nothing to worry about as long as their local Storj key isn't disclosed.
For Storj customers using the S3 Gateway, it seems to me that by using data stored on the S3 Gateway, authorities could reconstruct files that were uploaded.
For HashBackup (I'm the author), both interfaces are supported, though the S3 interface is recommended. Since HashBackup encrypts everything locally before doing any uploads, backups stored on Storj using either interface cannot be reconstructed without a copy of the HB backup key, which is only stored on the local client machine, is not part of the backup data, and is never uploaded anywhere.
For our hosted S3 Gateway (called the Gateway MT), we have more details about how it works on this page: https://www.storj.io/disclosures, in the section titled "Encryption for Gateway MT"
The summary is that while the S3 gateway does have temporary access to unencrypted data during transit by protocol necessity, the S3 gateway does not keep the keys necessary to do this outside of the context of a request.
HashBackup is also great!
The precedent supports that to some degree, but it's really not clear.
The government probably can NOT compel you to re-sign and update an expired canary, at least according to the lawyers at the EFF.
In the decades before 9/11 the US government had the decency to lie to the American public about it. They told us that America was so great because it would never do those kinds of things. Those types of activities were held up as examples of horrible atrocities communist nations subjected their citizens to.
Even as evidence came up from time to time showing that the US government didn't always live up to those ideals they continued to be expressed as what this country stood for. Post 9/11 that was no longer the case. This might be a more honest American government, but I can't help feeling like we've lost something.
The TSA is the result of a brief moment of unity where we decided we feared someone else more than each other. Eliminating it might save money and simplify travel, but it won't touch the fear and ignorance.
Whatever optimism we had died during Vietnam, if not long before that.
The Patriot Act was a renamed law (several laws actually) that the the FBI/CIA/NSA had been trying to get passed for decades, it was a wish list for them that was rubber stamped shredding what little protections left in the constitution
https://www.eff.org/deeplinks/2020/04/yes-section-215-expire...