PyPI Was Subpoenaed
blog.pypi.org
blog.pypi.org
That's suspiciously specific. Sounds to me like they also received some other subpoenas they aren't allowed to talk about.
I would if the sequence was such that the receipt of eachbof thr subsequebt ones delayed writeup of the overall incident in the interest of completeness or because there was some relationship between them
> the subpoenas from March and April 2023 don't have a gag order. Why mention those months specifically if in the other months they didn't receive any?
Because you are doing an aggregate writeup of a series of events and you want to convey when they occurred and why you are able to do a detailed writeup.
Such subpoenas are clandestine surveillance of citizens by their state. The problem with such types of surveillance in particular is the lack of accountability.
How does the ethical use of this prolematic tool get ascertained? Where and how is the democratic oversight implemented? How is misuse treated and prevented?
often there's posts on HN about how the UK and all other Western European countries are totalitarian because they don't have unrestricted free speech
but then apparently the police (FBI) can restrict the free speech of Americans without any court involvement at all?
I really don't understand
My understanding is that the FBI or other non-judicial body cannot unilaterally issue a gag order. Subpoenas and gag orders related to them are granted by judges.
(Which isn't to say that the relationship between the judicial branch and law enforcement bodies is always pure and equal)
People engage in childish fantasies featuring themselves in imaginary subversive behavior.
It's unresolvable cognitive dissonance leading to repressing and reinterpreting the cause.
seems pretty clear to me, at least for gag orders
less so for the other stuff you mentioned (could you argue pirated Disney movies are speech? probably not)
> That if any person shall write, print, utter. Or publish, or shall cause or procure to be written, printed, uttered or published, or shall knowingly and willingly assist or aid in writing, printing, uttering or publishing any false, scandalous and malicious writing or writings against the government of the United States, or either house of the Congress of the United States, or the President of the United States, with intent to defame the said government, or either house of the said Congress, or the said President, or to bring them. or either of them, into contempt or disrepute; or to excite against them, or either or any of them, the hatred of the good people of the United States, or to excite any unlawful combinations therein, for opposing or resisting any law of the United States, or any act of the President of the United States, done in pursuance of any such law, or of the powers in him vested by the constitution of the United States, or to resist, oppose, or defeat any such law or act, or to aid, encourage or abet any hostile designs of any foreign nation against the United States, their people or government, then such person, being thereof convicted before any court of the United States having jurisdiction thereof, shall be punished by a fine not exceeding two thousand dollars, and by imprisonment not exceeding two years.
Welcome to America. Our laws contradict each other and its all about politics. The Supreme Court figures out where the line is drawn and what is, or isn't, legal according to the Constitution.
With regards to 1st Amendment, the limit is drawn today at Libel, Slander, "Fire in a Crowded Theater", pornography, and many other restrictions upon "free speech". Gag orders included.
That one's apparently a myth.
https://reason.com/2022/10/27/yes-you-can-yell-fire-in-a-cro...
I'm more inclined to believe Supreme Court Justice Alito over a Libertarian website. Especially because a sitting Supreme Court Justice literally will preside over the case and make a decision based on their own ethics/process/whatever.
An entire article that starts off with "BTW: Supreme Court Justice is wrong on subject" is... well... that's not how this works. The Supreme Court justice literally defines (or at least, is 1/9th of the definition) of our country's legal interpretation.
If the Supreme Court says "Obamacare is a tax", then its a tax. No if, and, or buts about it. It can be as ridiculous or contrived an argument they want, its the purview of the Supreme Court. They are the final say on any of these legal matters.
And unless "reason.com" (or any other libertarian source) somehow manages to get the ear of the other Supreme Court Justices to believe their argument, I think I can safely ignore their article there.
But they know that. I'm guessing they're just trying to clickbait readers and make somewhat sketchy arguments for more clicks + plant more articles that are aligned to libertarian values (as is the point of reason.com).
2. Schenck vs United States was largely overturned by Brandenburg vs Ohio, but this aside was still non-jurisprudential.
3. I am unfamiliar with Justice Alito’s opinion on the matter and you didn’t cite it, so with no context I will only temporarily defer to you for the purpose of saying this: SCOTUS makes jurisprudence through the rulings and opinions they hand down when they take a majority vote in conference, draft opinions and sign on to them. One Justice does not make jurisprudence over a statement which itself was never jurisprudential.
Reason wears their ideological stripes on their sleeves, but this is still essentially a myth that doesn’t die and a fuller explanation of it isn’t a matter of ideology.
You still shouldn’t falsely shout fire in a crowded theater, as people will die. You also shouldn’t pretend a fire isn’t there or part of the show either as people will also die. Basically, if there’s a fire in a theater you’re in, just be glad for modern building and fire codes.
This here is the evolving nature of the court that I want to highlight most of all however.
In 1919, the Supreme Court believed one thing. Later, in 1969, half-a-century later, it believed another thing and overturned the earlier ruling.
As an organization, the Supreme Court tends to try to be consistent. But its not always true, and certainly in these days where we've had a dramatic change in the makeup of the court + filled it with young justices, we're going to see a big change in how the court writes opinions in the years, and decades, to come.
-----------
Laws are written. Constitutional Amendments are written. A few years ago, the 4th Amendment protected a woman's right to privacy and therefore Abortion. That's no longer true today. Etc. etc. Just a modern quickie example about how changing opinions can change our understanding of long-standing laws (or Constitutional Amendments) from the 1700s.
Generally speaking, the Supreme Court is trying to do what's right for our court system. To have laws interpreted consistently over time, and across the country.
> A few years ago, the 4th Amendment protected a woman's right to privacy and therefore Abortion.
Due process clause of the 14th amendment actually was the citation under the portions of Roe v Wade not overturned by Planned Parenthood v Casey prior to them both being overturned in Dobbs. The due process clause is often used to read into law from the bench things which are not written into law by Congress or the States under the doctrine of substantive due process, and the issue with that doctrine comes down to: if Congress didn’t say it, and the States didn’t agree to it (Constitution), then is it really actually Federal law? So far the answer seems to be: temporarily yes, and on shaky ground until either Congress addresses it or a future court does. That a court can overturn its own precedents is why if we wish for them to stick, you write them into statute.
Going back to the First Amendment, most of the seeming contradictions in our free speech law really are addressed in the first 5 words of the First Amendment: “Congress shall make no law”. Courts are not Congress, and our Judiciaries have habits and traditions that predate the Constitution and are rooted specifically in the English common law, especially among the States which is why you can be found civilly liable for defamation in most States, and then the standard is high and the extent to which it is applicable is curtailed more with the First Amendment than it would be without it.
It's not just Reason or Libertarians saying that the old "fire in a crowded theater" trope is nonsense:
https://www.popehat.com/2012/09/19/three-generations-of-a-ha...
> An entire article that starts off with "BTW: Supreme Court Justice is wrong on subject" is... well... that's not how this works. The Supreme Court justice literally defines (or at least, is 1/9th of the definition) of our country's legal interpretation.
No, a majority of the current Supreme Court is what defines jurisprudence on a subject.
There are crazy (and non-crazy) minority opinions all the time that don't amount to anything. A later Supreme Court can even repudiate an earlier one.
So it's true that this could change someday, and maybe Alito would even be in the majority then, but until and unless that happens, the "fire in a crowded theater" example is still dicta from an old case that's not good law.
I still don't really understand
in the UK: Parliament has unlimited power and people talk quite a bit about formal constitutions being a good model to be followed
it seems a bit sad the attempt to protect the population against government using a formal constitution doesn't seem to work in reality (even when the wording is as clear as day)
Whose definition?
Answer: The Supreme Court decides the definition of things. Its only unconstitutional if the Supreme Court says so.
That's how the USA can get away with... I dunno... the Office of Censorship in 1941. (https://en.wikipedia.org/wiki/Office_of_Censorship). Definitions change, not only due to different members on the Supreme Court, but also due to different circumstances (WW2 meant that the Supreme Court was willing to ignore the obvious incursion into the 1st Amendment, at least temporarily)
EDIT: I always forget that it was actually the Office of War Information that did the Hollywood Censorship thing (https://en.wikipedia.org/wiki/United_States_Office_of_War_In...), rather than the Office of Censorship.
I guess that's the underlying problem
I'm not sure how you fix it really, though not having direct political appointees as top judges might be a good start
(maybe put an LLM in charge of a supreme court? I kid, I kid)
De facto means in fact. Given that the king does no governing no, he is not, in fact, the ruler. You may be looking for de jure, though I question even that.
If he tried, people would say no. If he insisted, he'd get tossed out on his ear.
No, and it never was. That was an obiter dictum that didn’t accurately reflect the state of the law in the decision in which it appeared, and the actual holding in that case itself (now regarded as an intense intrusion on core political speech) is no longer operative.
It's a catchy turn of phrase that gets stuck in the mind, but it was also an rhetorical device neither in a decision that has since been substantively overruled, not an actual example of an existing limit on free speech.
You can't say "Hobbit" in your own stories. But you can say "Halfling", and that's how people tend to get around that problem. Blonde Thor is Disney/Marvel (Historical Thor was a redhead IIRC, so Blonde Thor is Disney/Marvel Trademark), etc. etc. Plenty of restrictions on Free Speech in practice.
You can, though.
You can't use it to market your stories or other products, and there's some manners of use innthr body of a book that might run some risk of liability for dilution or tarnishment, but...
If you want to use copyrighted characters and it's not fair use, then no.
Unlike those other countries, the US Constitution never contained such an explicit clause, but the Supreme Court has always read it as if it did. The Supreme Court feels quite justified in doing that, because if you go back and look at the debates in Congress and the state legislatures over the proposal and ratification of the Bill of Rights, it is clear that its proponents always intended it to be interpreted as if such an "exception clause" existed, even though (for whatever reason) they chose to leave it as implicit rather than explicitly putting it in the text.
Doesn't seem to healthy for any nation that is supposedly democratic?
> often there's posts on HN about how the UK and all other Western European countries are totalitarian because they don't have unrestricted free speech
I haven't seen these posts. Do you have an example handy?
here's one from earlier in the week: https://news.ycombinator.com/item?id=36000459
they're pretty common, here's another one: https://news.ycombinator.com/item?id=35617773
> often there's posts on HN about how the UK and all other Western European countries are totalitarian because they don't have unrestricted free speech
I don't see that in the comments you cite - nothing related to totaliterianism, unrestricted free speech, or comparison to the US. The comments just look like critiques of some laws related to speech, similar to critiques of US laws. Maybe I misunderstand.
edit:
https://news.ycombinator.com/item?id=28651811
https://news.ycombinator.com/item?id=28523358 (this entire comment section, probably: https://news.ycombinator.com/item?id=28522599)
Something like 95% of criminal cases are resolved with plea deals and not trials, and legal representation from public defenders has very limited resources.
Cash bail results in many people imprisoned without trial: After arrest, the court requires bail. Poor people can't afford it, so they are jailed until trial, which can be over a year. The impacts go beyond the (very serious) loss of freedom: They lose jobs, their family loses income, dependents (children, elderly) lose caregivers.
Judges now, don't need or required to use cash bails, they choose to, they can release people without cash bail now. either into the person's own recognizance, or even into the care of others.
If a judge doesn't feel the person is likely to return to their following court date, and they can't leverage financial burden as a means to insure it, they are likely just to forego the process and hold them.
Source: https://calmatters.org/justice/2021/03/waiting-for-justice/
I'm not sure whether that's good or bad. I guess it depends on what you are accused of.
If you choose to plead the fifth, the prosecution is absolutely forbidden from bringing that up the courtroom, much less using it to insinuate your guilt.
Any lawyer in the US will tell you not to speak to the police or prosecutor. At all.
The point is: this case was televised to millions and he STILL questioned it.
It really doesn't, at least in a court of law. Although if the police are interrogating you, they will almost certainly try to convince you that it does.
I don't think you're ever required to any answer any questions from the police, whether avoiding self-incrimination or otherwise. You're only required to answer a question in court, and even then only if the answer wouldn't be self-incriminating (or a few other narrow exceptions I think; the concept of the court not being allowed to compel someone to testify against their spouse is a common trope in media, although I'm honestly not certain how accurate it's portrayed). You also aren't required to take the stand when accused of a crime; while you can choose to do so, you're also free to just have your lawyer make your case via the questioning of witnesses instead of having to answer questions directly yourself.
That said, my understanding is that you're _not_ allowed to plead the 5th if the answer wouldn't actually be self-incriminating, so it's a weird thing where you're only allowed to not answer a question by essentially stipulating that you _did_ do something illegal that would be disclosed if you answered truthfully. If they can prove you weren't actually avoiding answering due to self-incrimination but plead the 5th anyways, I'm pretty sure you can be charged with contempt of court. Having never been on a criminal jury, I can't say I know exactly how it would play out in deliberations, but it's hard for me to imagine that it doesn't affect things at all; even if a jury isn't technically allowed to consider it an admission of guilt, from a legal perspective pleading the 5th seems pretty explicitly either a non-legally-admissible admission of guilt or a crime of contempt of court in itself, so I don't see how the law isn't basically forcing the jury to conclude that you've committed a crime one way or another. The question would then boil down to which of the two crimes the jury thought you had committed (the one you were accused of or contempt of court), and while they're not supposed to be deciding the question of the latter, it seems likely that the jury's view will be tainted by this.
Of course, all of this only applies if you did actually commit a crime; if you genuinely didn't commit any crimes, you wouldn't be lying under oath when stating that instead of pleading the 5th. The jury still might think you did commit the crime though and are just doubling down on lying under oath to try to hide that, though.
Honest question, like blibble, I don't really understand it either?
Congress shall make no law respecting an establishment of religion, or prohibiting the free exercise thereof; or abridging the freedom of speech, or of the press; or the right of the people peaceably to assemble, and to petition the Government for a redress of grievances.
The key phrase "or abridging the freedom of speech, or of the press".As far as I know, this kind of language is absent from other Western nations. For example, Canada jails people for criticizing those of Islamic persuasion. [0] Note, the article doesn't record what the accused actually said. Here's a wikipedia overview of hate speech laws by country [1], though it is wikipedia, so take it with a grain of salt. Here's a somewhat relevant piece from Reason that takes an anti-hate-speech stance [2] where the author details the unconstitutionality of hate speech laws.
"Free speech" as we understand it in the US is unique in the world.
As far as the restrictions at state and federal level, these are considered unconstitutional, and you'll see a large number of them struck down in various courts across the country. Those in power definitely seek to expand their powers and fortunately we have a law that allows the citizenry to push back against that.
[0] https://www.cbc.ca/news/canada/hamilton/muslim-hate-1.614516...
[1] https://en.wikipedia.org/wiki/Hate_speech_laws_by_country
[2] https://reason.com/2021/05/20/teen-arrested-under-connecticu...
E.g. german constitution is quite similar:
``` Article 5 [Freedom of expression, arts and sciences]
(1) Every person shall have the right freely to express and disseminate his opinions in speech, writing and pictures and to inform himself without hindrance from generally accessible sources. Freedom of the press and freedom of reporting by means of broadcasts and films shall be guaranteed. There shall be no censorship.
(2) These rights shall find their limits in the provisions of general laws, in provisions for the protection of young persons and in the right to personal honour.
(3) Arts and sciences, research and teaching shall be free. The freedom of teaching shall not release any person from allegiance to the constitution. ```
(2) notes that there _are_ limits, but if I understood the concept of gag orders and also wolverine876's answer correct, thats the same for the US:
``` Civil rights, including those in the First Amendment, are not absolute. Regarding speech, you also can't harass people, threaten them, defraud them, incite violence, ```
In comparison, Nazi symbols are protected hate speech in the US. [2]
The US has tried to ban political parties in the past but eventually courts find that sort of thing unconstitutional. [3]
[1] https://en.wikipedia.org/wiki/Strafgesetzbuch_section_86a
[2] https://en.wikipedia.org/wiki/Bans_on_Nazi_symbols#United_St...
[3] https://en.wikipedia.org/wiki/Communist_Control_Act_of_1954
When you free speech is restricted still seems pretty arbitrary to me [shrug].
They're a response to being sued. If a lawsuit is clearly bogus, you can get it thrown out extremely quickly and the other side usually has to pay your attorneys.
Not all states have them and not all states that have them, have good ones.
Anti-SLAPP suits are filed by the person who said the thing. And yes some states have good anti-slapp protections but that means the rest of Americans don’t enjoy that freedom.
> As far as I know, this kind of language is absent from other Western nations. For example, Canada jails people for criticizing those of Islamic persuasion.
The US is not unique in having constitutional protections of free speech. For example part of the Canadian constitution is the "Canadian Charter of Rights and Freedoms", which forms part of the Constitution Act 1982. Section 2 of which says "Everyone has the following fundamental freedoms: (a) freedom of conscience and religion; (b) freedom of thought, belief, opinion and expression, including freedom of the press and other media of communication;" – that's essentially saying the same thing as the US First Amendment.
In Europe, article 9 of the European Convention on Human Rights (ECHR) protects "Freedom of thought, conscience and religion". The Convention is quasi-constitutional in nature – while it is an international treaty whose members are in theory free to leave at any time, in practice quitting it is impossible for many European countries–membership in the ECHR is a requirement for EU membership, so no EU country is going to get away with denouncing it. And many national constitutions have equivalent provisions, such as articles 4 and 5 of the Basic Law of Germany.
One difference – the text of the US constitution doesn't contain any exceptions to the 1st Amendment, whereas the Canadian constitution, the ECHR, Germany's Basic Law, etc, explicitly state that freedom of speech/etc can be subject to limitations. However, in practice, even though the US constitution never explicitly says that the 1st Amendment has exceptions, the Supreme Court has always held that it does, although the scope of these exceptions has varied due to the evolving opinions of the Supreme Court – for the first century of the US's existence, SCOTUS allowed sweeping exceptions to the 1st Amendment; in the 20th century, it narrowed the allowed exceptions significantly, and developed some highly complex case law on which exceptions are allowed.
The real difference is actually nothing to do with the text itself, it is all about case law – since the 20th century, SCOTUS has been very strict in only allowing quite limited exceptions to the 1st Amendment. Courts in Canada, Europe, etc, have always been much more liberal in allowing exceptions to the right of free speech. Now, possibly the difference between a text which provides no explicit exceptions versus a text which does may have influenced that, but I don't think it was decisive. It was not historically inevitable that SCOTUS would start interpreting the 1st Amendment much more strictly in the 20th century, if different justices had been appointed, it easily could have decided to stick with its 19th century case law which allowed greater exceptions to it. Conversely, even though Canadian/European/etc texts explicitly mention exceptions, their courts could have chosen to interpret those explicit exceptions far more narrowly, producing a result much closer to that of the US, if they had wished to do so.
Canadian law on is nowhere near as protective as the US. Defamation has a much lower standard there.
Defamation with public figures in the US is next to impossible to win. That's not true in Canada.
However, there is one interesting difference – under Australia's uniform national defamation law (adopted in 2005), corporations cannot sue for defamation. (There is an exception for small businesses, with less than 10 employees.) So, the recent Dominion vs Fox News lawsuit would have been impossible in Australia.
It is a very powerful tool to shut up adversaries and it is extremely harmful for real opinions and real free speech.
But they may also have no hate towards other ethnicities or desire their deaths. If pressed, they might even say that their vision of a "pure" society isn't worth the deaths of minorities that would come about if they tried to implement it.
I think too often we confuse the stereotypical example with the definition. The stereotypical white supremacist hates minorities, but the definition itself doesn't require it (I know of no surveys that would tell us what proportion of white supremacists match the stereotype).
My whole point is that you (and many others) are using a new definition of "hate" which doesn't match the old one. "Hate" used to be an emotion, a feeling, a dislike of something and a wish to see it destroyed.
One can feel superior to something without having any dislike of it or a wish to see it destroyed. I consider myself superior in many respects to the rocks in my back garden, but I neither dislike them nor wish them destroyed.
A supremacist may consider themselves smarter or prettier or taller than some other group, but that does not necessarily mean they want to destroy the other group.
Any left-wing should be allowed, any right-wing stuff should be denied.
Few exceptions exist on the western side, Spain is probably the most remarkable case. Reason why you wouldn't often hear much about what happens there, unless it is something negative to bash the right-wing people there.
It comes across as very dishonest.
There are people who genuinely think the Holocaust was exaggerated or didn't happen at any substantial scale who bear no ill will to Jews, seeing it simply as a question of historical fact of limited relevance to the modern day.
I would really recommend doing a cursory, bare-minimum reading of the associated Wikipedia page [0] and citations. Plenty of historians revise the events surrounding the Holocaust to provide less biased and more nuanced information. Very different from taking an assumption as fact (the holocaust did not happen) and working backwards from that.
Why not just say "we ban speech that says the Holocaust didn't happen"? Why get it classified as hate and then because somehow hate is censorable get it autocensored? It seems somehow disingenuous.
The only reason people deny it is because of anti-semitism.
What does the word "hateful" mean? The old meaning is "full of the emotion of hate". Someone who thinks the Holocaust wasn't real could in theory have no strong feelings about it and think it has no relevance to their lives.
It is not required by definition that Holocaust denial is hateful (using traditional definition of the word "hate"). Nor is it required by human psychology (for example, you could have someone who read an unfortunate sampling of books as a child and took "disbelieve anything the victors of a war say about their enemies" as gospel and never got educated on the details).
"I don't hate them! I just think they got a bit worked up over a few arrests. They're too sensitive. I don't blame them for it, but when you deal with them you've got to remember they can be prone to distorting the truth."
Come _on_
A court found him guilty for "groepsbelediging", insulting a part of society, which is a crime. He did not get a punishment.
That's the only example that comes to my mind of something that the courts found not allowed in the Netherlands.
Earlier it was listed "..you also can't harass people, threaten them, defraud them, incite violence, distribute copyrighted information.."
So where are these exceptions innumerated? Just purely from a technical point of view, why can defrauding be made illegal, but hate speech can not?
It actually seems the number of exceptions is quite limited - so I never understood why they were not spelled out explicitly (like in an subsequent constitutional amendment for instance). It seems to undermine the authority of the bill of rights. The original text makes no provision for exceptions...
Yelling "fire" in a crowded theater, for example [0]. Another comment in this thread talks about the "clear and present danger" doctrine that came from the case. That case was followed by the Brandenburg v. Ohio [2] case in 1969, which instituted the current methodology used for determining what is "allowed" speech. That rule/methodology is called the "imminent lawless action" rule.
[0] https://supreme.justia.com/cases/federal/us/249/47/
[1] https://en.wikipedia.org/wiki/Shouting_fire_in_a_crowded_the...
First, every court of appeal can strike down a law as unconstitutional. The Supreme Court is only special in that there is no further appeal.
Second, case law absolutely determines the interpretation of each text, and each court is mildly bound by its own precendent (via stare decisis), and completely bound by the precedent of superior courts.
Third, there is no tension between these facts and people being judged individually and being equal before the law. The law must (in principle) be applied equally to everyone.
Any federal court, not just the courts of appeal.
You can be charged with a crime if you knowingly, falsely yell "fire!" in a crowded theater and someone gets hurt as a result.
The case you linked is not actually a ruling on whether you can do this.
In reality, the phrase was an analogy used to justify the conviction of a man who committed the heinous crime of… making and distributing leaflets opposing the draft in World War I. So for all the high minded rhetoric in the First Amendment, it may not provide all that much protection if your speech inconveniences the government sufficiently.
One might also be tempted to draw inferences from the fact that Schenk, the man whose speech was considered not worth protecting, was a socialist pacifist, while Brandenburg, whose free speech was considered more worthy of protection, was a KKK leader promoting violence against Blacks and Jews. In the US, protecting the civil rights of Nazis has become a litmus test of civic virtue across the political spectrum. Unfortunately, that protection is extended far less vigorously and consistently to other political views.
https://en.wikipedia.org/wiki/Schenck_v._United_States
https://en.wikipedia.org/wiki/Brandenburg_v._Ohio
https://en.wikipedia.org/wiki/National_Socialist_Party_of_Am...
In the case of fraud, it’s not the speech itself, it’s the part where someone gives you money (or other consideration) under some agreement or understanding, and doesn’t actually get what was promised. There’s nothing intrinsically wrong with what you promised, it’s your failure to deliver.
Threatening people? The illegal part is not that you used words at them specifically, it’s that you caused them to credibly fear for their life and safety. You could just as well do that without words, just standing outside their place with a baseball bat making menacing gestures. Harassment similarly may use words, but the objectionable part is often subjecting them to your words or actions or presence directly, to cause distress, instead of leaving them alone in peace.
“Hate speech” as a problem generally is about the content of the speech itself. You might wish to convince people that others in a group are bad and worthy of being considered bad. Your audience is typically people like yourself, or third parties who you wish to sway, and if you are in a public place you are mostly not following around an individual to be hated, or telling them you are about to do them violence. (If you do, it may in fact be harassment or intimidation.)
In all the cases listed, the speech in question is being used to directly and (at least usually) intentionally harm or interfere with another person. I believe this is a case where looking to the Framers' intent rather than the strict wording of the amendment is worthwhile in determining how best to apply it. It seems obvious that they did not intend to make all forms of fraud and threats legal with no recourse (and I imagine there is some jurisprudence that cites specifics to this effect).
“Police say the man targeted people on social media and promoted hatred against them after an attack in London, Ont., in June, where four members of a family were killed.”
Does that sound like criticism to you? It reads like harassment to me.
Not even the historical claim holds, as constitutional protections for free speech in France and Sweden predate the American constitution.
> For example, Canada jails people for criticizing those of Islamic persuasion
He was arrested, presented to court, and acquited. Therefore he was not "jailed". Also: the charge was inciting/organising a hate crime, in the wake of a killing of a Muslim father and his 15-year old daughter, not "criticising those of Islamic persuasion".
Don't be a liar, it doesn't help your argument.
True, but we don't know what the man actually said. So whether the charge was true or not remains solely decided by those policing speech.
> He was arrested, presented to court, and acquited.
Thank you for pointing this out. I should have been more careful in my reading of the source material.
This is what the guy was charged with violating (as per https://hamiltonpolice.on.ca/news/hamilton-police-charge-mal... )
Framing it as "Canada jails people for criticizing those of Islamic persuasion" is disingenuous, as if Canada specifically has laws about some specific religion or faith.
^1 In 1990 we got a law called the Bill of Rights Act which included freedom of expression.
Edit: added ^1
This is more about private property rights, is it not? You can sing loudly in a park until local ordinances (noise, curfew) kick in.
The "movie theater" example I'm familiar with is that you can't scream "fire" in a crowded place.
the fire one is basically anything that incites panic can get you into legal hot water, and if there are injuries or death as a result some form of manslaughter charges probably because ultimately you were responsible.
good point
Free speech means you can express and advocate for any view point, not that you can make any sounds with your mouth in any context.
For example, someone could not express the viewpoint that 'thebigwinning sexually assaulted coworkers and stole money at their last job'. It would slander you (an exception to free speech that I omitted in the GP) and you would be entitled to damages.
Nor could someone express to an angry crowd the viewpoint that 'the bigwinning should be assaulted', nor could someone selling cryptocurrency express the viewpoint that 'cryptocurrency is a safe, stable investment for unsophisticated investors', etc.
> sing loadly in a movie theatre.
Perfect example. Inappropriately making sounds with your mouth, not holding an illegal belief.
> express to an angry crowd the viewpoint
The issue is the context of the angry crowd, not the content of beliefs. Do you believe the US will penalize me for believing crypto currency is safe and stating that publically?
> thebigwinning sexually assaulted coworkers and stole money at their last job'
They are indeed allowed to believe that. They can't be taken to jail for holding that view of me. Now if they tried to get me fired with false evidence that would be a problem. If they caused damage to my business reputation without evidence that could result in civil damages.
We are talking about speech, not thought - expression, not belief. You said "you can express and advocate for any view point", not that 'you can believe any viewpoint'.
Yes, all speech depends on context. The significance of speech is its impact on other people; it is communication. You can say whatever you want in the shower.
So the First Amendment is basically just the demo. And other western countries, oft criticized, just didn't have as nice a demo as that, but offer more or less the same features and gameplay.
It's nice to say "all speech should be free!" in theory but then, when faced with a situation where a mob boss says "please go kill that person" or ringleader whips up a mob into a riot. Should a judge just say "well, he was just exercising his First Amendment rights!" and ensure no consequences befall that person?
A person enters my home and says things I find offensive. Should the First Amendment prevent me from removing that person from my home for that reason?
I decide to leak trade secrets of my employer for profit. Should the First Amendment protect me from being fired and sued for this?
With the mob boss example, wouldn't the charge be something like conspiracy to commit murder rather than prosecuting the instruction itself? i.e. saying the words is not in itself illegal, but the intention to conspire to get the person to commit crime on your behalf is the illegal part and the instruction is evidence.
Absolutely, it is. However, I interpreted the comment I replied to as suggesting the First Amendment is not sufficient free speech protection.
Isn't that covered by actual murder (or conspiracy to commit murder if it isn't seen through) charges, unrelated to free speech?
>A person enters my home and says things I find offensive. Should the First Amendment prevent me from removing that person from my home for that reason?
Isn't that covered by the right to invite (or throw out) whatever guest you want at your home? You have the same right even if they don't say things you find offensive, heck, even if they just tell you pleasant things...
>I decide to leak trade secrets of my employer for profit. Should the First Amendment protect me from being fired and sued for this?
Isn't that covered by copyright law (or similar)?
The point wasn't "practical limits to free speech" regarding a "mob hit" request or some non-existant and never argued obligation to let people in your house if they speak lest you prevent them from expression (?), but how more abstract (or open to interpretation) restrictions can be used to effectively limit actual free speech.
Not to mention "private entities such as your employer can restrict your speech in many ways", like a not so uncommon case of you saying something they don't like on your (unrelated to work) personal social media, in which they can just fire you. Or the social medium itself can censor you.
Making the FA protections kind of moot, in a time when it isn't the government that has to do the censoring anymore, while the public just gathers on 3-4 tech behemoths platforms.
> Isn't that covered by the right to invite (or throw out) whatever guest you want at your home?
> Making the FA protections kind of moot, in a time when it isn't the government that has to do the censoring anymore, while the public just gathers on 3-4 tech behemoths platforms.
I don't understand your points. You're both mixing concerns and splitting them, seemingly at random.
Here's the Cliff Notes version:
The examples you brought up as arguments to why free speech can't be absolute (which I didn't argue for in the first place) are contrived and unrelated to free speech.
They are also already covered by existing laws, such as laws against conspiracy to commit murder, about the right of exclusion, etc. If anything I'm separating concerns, mixed up for no good reason.
As for my statement about FA, it's pointing how its protections are rendered moot, since they don't apply to private businesses and thus don't protect speech (the kind that matters, not mob hits) in places where the public discourse really happens nowadays. So, it's not "sufficient free speech protection" anymore.
I added it to further the discussion, what with FA being the very topic of this subthread, and not some randomly "mixed concern"...
The First Amendment supersedes law by determining whether it can be law at all, so whether it's covered by "law" is actually only half the story.
> The examples you brought up as arguments to why free speech can't be absolute
I started with deliberately stupid examples to make my point: Free Speech was always clearly limited, by necessity.
> it's pointing how its protections are rendered moot
That in itself is debatable. What evidence do you bring that this is somehow worse than it used to be? It used to be the case that, to get _any_ significant speech, you had to get your work published. Now you can just shoot it off on Twitter, Reddit, HN, take your pick.
Which is neither here, nor there. Conspiracy to commit murder, as per the "mob boss gives an order example" would always be illegal regarless of our "free speech" stance, and the First Amendment didn't come into play determining whether that "[could] be law at all".
It was rather the other way around: the First Amendment was drafted with the certainty that such a thing isn't about free speech and will always be illegal.
This isn’t really backing up your point that the First Amendment isn’t sufficiently protecting free speech.
Not great, but not terrible (jail).
Fun fact: Europe actually has better protections for free speech for employees. Even if you're a hardcore Nazi taking part in actual Nazi rallies, unless you're wearing company clothing or are a high-ranking corporate official, you can't get fired for that. And when you, say, contribute to an open source project in your non-work time on your own computer, your employer doesn't get any rights to that code.
Rights afforded by a state are restrictions on a state's power over its subjects. But as the state holds ultimate authority, the only way these rights are upheld in practice is through a system of self-imposed indirection and bureaucracy that mostly exists to limit the power of any one individual operating the state, rather than the state as a whole.
The First Amendment means whatever the state wants it to mean. The Supreme Court can make a case-specific ruling one way or another but it intentionally holds no direct power. A police officer can literally get away with killing you if they can construct a scenario that gives them sufficient justification to do so. The problem with intelligence agency is that by necessity they have less red tape holding them down and they're thus in practice far less limited in how much power they can wield.
States are authoritarian and oppressive by default. They're only held back by self-imposed limitations. But those limitations only exist at the behest of the states themselves. Try and openly plan to dismantle a state (using violence or not) and most states will abandon any pretense of freedom of speech in a second.
That's all true and should be true, but it's also possible to take these limitations too fare, and we have.
>threaten them
You absolutely can. It just has to be nonspecific. "Kill all lannisters" is fine. "Kill x lannisters in y mall at z time" is not. See : Brandenburg v Ohio, Schenk v US, Hess v Indiana.
>interfere with others' activities (sing loudly in a movie theater),
lmao what? You can absolutely do that. the theater will kick you out but you can absolutely not be arrested for it. what an absurd claim.
>you also can't harass people
You can absolutely do that, to a degree.
>distribute copyrighted information that isn't yours
Not really related to 1A
>Private entities such as your employer can restrict your speech in many ways.
That's not 1A. 1A specifically applies to the government.
I don't know if humans are able to ignore evidence they have heard outside of court. We are not good at only including one set of information when making judgements.
I agree that free speech has significant value and restrictions should only be put in place when required to uphold other rights.
I'm sure you're not alone in your opinion that a jury is able to ignore what they've heard about a case in the media. However you do disagree with the current judicial system of most developed nations. That doesn't necessarily make you wrong. I think there is merit to the argument you're making, I just am not convinced that people can ignore information like that.
https://juryanalyst.com/blog/the-power-of-media-coverage-how...
https://www.canlii.org/en/commentary/doc/2019CanLIIDocs2798#...
The information that so-and-so parties provided some information (without disclosure of that information) in response to a lawful request will usually not predudice a trial.
What gag orders are for is a) avoiding tipping off the subject of an active investigation b) avoiding general knowledge or disclosure of key sources of information and investigative methods used by law enforcement and c) concealing the general scale, nature and purpose of surveillance activities from the general public.
I agree, but the only time I think it's justified is when it's to protect the right to a fair trial.
@_sib_ra10
There is absolutely no consequences to anybody for this. If you're going to ask how US citizens tolerate such blatant abuse, and why they don't do something about it - that's a very good question. Please get back to me if you find any answer to it.
In such cases, a well written, clear law on freedom of speech only increases the distance between what people think they have, and what they actually have.
It took over 125 years before Supreme Courts started reinterpreting the First Amendment to apply to some government actions that weren't acts of Congress, but there are still tons of situations where regular people can restrict free speech. For example, in Frederick v. Morse, while the Olympic torch was running through some town in Alaska, a public high school student unfurled a banner that read "bong hits 4 Jesus". Despite this not being on school grounds and the student not going to school that day, the school suspended him explicitly because of the speech on his banner, but the SC said that's fine.
(Sidenote: I wouldn't look to the SC for coherent reasoning; the SC has been an absolute dumpster fire for all but the Warren court and parts of FDR's court. Hell, three current Justices (Roberts, Kavanaugh, and Coney-Barrett) worked on George W Bush's legal team in the democracy-negating Bush v. Gore case)
are you sure about this? As far as I understand "gag orders" can only come from a judge. Of course the FBI could request strongly that you not talk about something but I'm not sure it would hold legal weight.
Your examples are even weirder. How would such malfeasance justify clandestine observations? That is clearly disproportional, thus unethical.
Claiming governance structures were "baked into" institutions is pure hopium. Democratic oversight means, there must be transparency enabling you as a citizen to detect and react to misconduct, at least by proxy.
The "free press" isn't free to report and investigate such subpoenas, obviously.
This is why the majority of your fellow citizens disagree with you and are fine with the current state of affairs.
https://www.democratandchronicle.com/story/watchdog/2013/12/...
Three of my teenage friends were in his basement when the FBI kicked down the door and stormed in armed to the teeth.
Perhaps you’re fine letting thieves and murderers get the upper hand but the rest of us are not.
Consider yourself lucky that criminals haven’t had much of an impact on your life.
It is a trade-off. The downsides have been enumerated ad nauseam on hacker forums for decades and compared to the reality of organized crime comprise just a small percentage of the ill effects experienced in a relatively low corruption society like the United States.
This does not, of course, mean that the harms to certain individuals from organized crime aren't worse. But governing based on a small number of emotional anecdotes, and ignoring the broader harms being perpetrated to placate that vocal minority, is deeply irresponsible.
I don't see a difference between, say, a capo that orders a hit, and a member of congress who votes for a foreign 'police action' - save for that the congressmember has much, much higher numbers.
Same goes for a bank robber vs. a bank exec who gets a multimillion $ payout from bailout funds - we're impressed if the bank robber cracks a million - but it's like "that makes sense" when the exec walks away with eight figures of tax dollars.
I don't know anyone whose been killed by a mob hit, but I know soldiers who have lost their lives to bullshit foreign wars, and literally everyone who pays taxes lost money to the villains in 2008.
I believe criminals have had a huge impact on my life - they just all got there through 'legitimate' channels, which IMO makes no difference to whether I'm poorer or people are dead.
I can’t think of anyone I know who has been affected by holes in the ozone layer. Must be a fabricated government boogeyman designed to force me to buy an inferior fridge.
Law enforcement agencies have been quite effective in controlling them over the last few decades (that and they’ve been replaced by foreign drug cartels..). It was probably quite different back in the 60s or 70s
There are many [1] counties in California that come immediately to mind - but I digress.
I'll readily admit that things have changed - organized crime was indeed a much bigger problem in the past - but I might argue that even then the fault lay not with a lack of enforcement, but the existence of really, really dumb laws (prohibition). I might further argue that what organized crime is still problematic, is also a legislative rather than an enforcement issue (current prohibition, which we euphamize as the 'war on drugs').
Even if it's enforcement that's doing the work of eliminating the effects of organized crime on actual citizens - the potential for harm is way bigger from an organization with a monopoly on violence, a state mandate, and practically unlimited coffers.
1 - https://en.wikipedia.org/wiki/List_of_California_wildfires
Of course, the idea is that people are corruptible whereas laws are clear and neutral, but reality falls far short of this ideal. Any system can be gamed and ultimately captured; the more widely accountability is distributed, the less the probability of its timely application.
Kind of a shocking assumption to make. Over the past several decades it has become increasingly apparent how our governing structures have no inherent relationship with ethics.
The constitutional justification is the same one behind not being allowed to yell 'fire' in a crowded theatre if there is none, or not being able to go on TV and threaten the Judge overseeing your case - 'the constitution is not a suicide pact'. [https://en.wikipedia.org/wiki/The_Constitution_is_not_a_suic...]
As to if it is being abused? Guaranteed. Being prevented? Not effectively. Only the occasional leak of the abuse and corresponding consequences (if any) seem to be counteracting it, and even then not well.
Sunlight is the best disinfectant, and most of the national security apparatus is solidly in the dark, and has been for a long time.
I can't speak specifically to this case, but in general when asking a judge for the warrant they also provide compelling evidence that harm would come from disclosure. The judges weigh the rights of the targeted and other parties that would be subject to a gag order against the greater good.
To answer your last two questions, all gag orders eventually expire. It isn't a prohibition against the impacted party speaking out, just a delay. They can go directly to the judge or appeal to a higher court.
It’s exactly this “it’s totally fair, surely it’s not ridiculous” attitude that shows how the powers control the people.
Gag orders and secrecy agreements can definitely be indefinite and regularly are.
https://web.archive.org/web/20220809113138/https://cdt.org/i...
What democratic oversight? This is the United States we're talking about lol.
I never know how to interpret statements like this. The fourth amendment guarantees court oversight over search and seizures. A court signs off on every subpoena issued anywhere in the USA. Are you making this argument from the perspective of "I didn't know courts were involved" or "I don't view courts as sufficient oversight".
If it's the latter... what's your alternative? Eliminate gag orders (which is all this is) entirely? You realize that there's a lot of stuff that happens in courts that we all agree should not be public, both for privacy and law enforcement reasons. Why get upset over this one particular thing?
Via the judicial system
> Where and how is the democratic oversight implemented?
In congress
> How is misuse treated and prevented?
Through the judicial system and congress
> How does the ethical use of this prolematic tool get ascertained?
It probably doesn't get ascertained, sadly. I think the advantages for investigations that might occur if people communicate more strategically is not worth the risk of political procecussions, which I believe are on the rise for a while now.
The government is not preventing you from expressing your free thoughts and opinions. They are compelling you to not disclose the details of something you had no knowledge of before they asked you about it.
Nothing is stopping you from writing a blog post about how it is unfair to seek records of a potential criminal, but you cannot write about how it is unfair to seek the records of Bob Jones when you had no other reason to believe Bob was anything but a regular user.
source: https://durbin.ee/ as of Wed, May 24 at 1:45 PM PDT
It could be, it could also be that they were trying to communicate both the timing of the subpoena string and why they are able to talk about it, and there aren’t any others.
It's definitely unnatural to say again 'as allowed by the ones received in those months we already mentioned'.
A non-disclosure order probably does exist for other subpoenas.
PGP signatures—even though rarely used—would allow someone to verify that a signed package was not modified by PyPI after being uploaded by its original author.
Without any sort of signing mechanism, we have to trust the U.S. Government to never demand that PyPI insert a backdoor, via a National Security Letter, FISA court order, or other kangaroo court process. Good luck with that.
The existing PGP signing mechanism had usability issues and security footguns[1], but was better than nothing. It's a shame they didn't roll out a more usable and secure alternative before removing the existing functionality.
[0]: https://news.ycombinator.com/item?id=36044543
[1]: https://blog.yossarian.net/2023/05/21/PGP-signatures-on-PyPI...
The PGP signatures were removed, nominally because few people used them. ...but the timing of the removals is coincidental, no?
"You need to have a backdoor that lets us see who's downloading what packages and let us inject custom code to particular targets"
"That's technically impossible because of..."
"Here is a court order. Implementation is your problem. You're not allowed to tell anyone you even received a court order."
"...well, I guess signed packages have to go then..."
(:
I don't actually believe that, since PGP signing was frankly, barely used and really there's hardly any meaningful difference between a PGP you can't verify (which was most of them) and not having it; in fact the illusion of security is probably worse than not having it at all.
...but still. As you say. It sucks there's no meaningful replacement for it.
I haven't explicitly asked, but I would be very surprised if any of the other PyPI admins felt differently.
I've tried to dig around whether there's any history or potential of government stopping company from ceasing operation/resigning and honestly nothing came up that wasn't ww2 related. So, I think it's pretty safe to rule out PyPI from doing anything like this.
If you're looking for examples of what the NSL process is like, Nicholas Merrill's story[0] comes to mind.
Further, the fact that admins have this power—even if they'd never use it—makes them an attractive target for black hats. If backdooring packages was easier to detect, it'd be a less attractive option for those that might want to do so.
I'm still hopeful that they'll re-implement some sort of end-to-end signing mechanism, sooner rather than later. I trust PyPI and the people behind it, but I'd like to be able to verify.
But let's step back a moment and presume that they do have that ability to compel. The first step here is that none of the PyPI Administrators are the legal owners of PyPI, so such an order would not be sent to any of us, but rather to the PSF itself. The PSF would then be on the hook to either comply or fight said hypothetical order, but individual members of the administration team would not be, and would be free to quit. They may not be able to say why they've quit, but quitting AFAIK would be entirely possible.
The PSF, while not having Apple's war chest, does retain counsel for dealing with things like this, and I can say personally I'd spend myself broke before I'd be willing to do so.
We are going to be implementing signing, and I'm hoping we'll be able to make strong progress on that soon.
The other half (key retrieval and identity binding) was never provided, because PGP as an ecosystem made doing so intractable. It was not better than nothing, because it was nothing; anything you could have done with it can be done with your own sidecar signatures.
Being unable to verify your trusted identities in a PKI is one such “zero factor.” It makes the PKI strictly equivalent to (crappy) resource integrity at the best, which is when everything is signed. PGP on PyPI didn’t even manage to clear that hurdle; it was worse than nothing by virtue of advertising properties that it was incapable of providing. That too is a zero-able factor in a security design.
I suspect the source of your confusion comes from the idea of differential security, which is approximately "I don't need the best lock; I just need a better lock than the other guy". Again, note that this does not apply to cryptographic signing of packages. Note also that the question of whether or not your system actually is more secure than the other guy's is very much a binary distinction: it either is or it isn't. You can quantify this quite easily by counting vulnerabilities, or by analyzing the degree of access gained for each vulnerability that is encountered.
So yeah, it's one of the few things that tends to be all-or-nothing (up to some threat model, of course).
PGP can use the only known solution to the problem, which is letting several key servers be configured by the user to import keys (which can then be verified by checking the key fingerprint on another source which is "trusted", like the publisher's own website).
You can still import keys by physically exchanging trusted keys with others (so called Key Signing Party[2]) but that obviously cannot scale... or using any innovative method you come up with, but no one has found a bullet proof way to do this that's usable.
But saying PGP only solves half the problem is wrong. It solves one problem: that of how to verify a publisher's artifacts were not modified, which is valuable.
The next problem to solve is how to obtain and vet public keys from publishers. The solution could work somewhat like TLS certificates (with certificate authorities playing the role of trusted key servers) or using blockchain (perhaps a rare problem for which blockchain could actually be helpful) but both of these bring their own issues with them. If you know of a better solution, though, do bring it up instead of throwing the bathwater out with the "baby"!
Tracing back the code to a legal entity seems unnecessary in the majority of cases.
Without those two conditions, a signature is a digest produced by an untrusted party. For PyPI, that means that PGP signatures are no better than (and in some senses, worse) than PyPI's own digests, since PyPI at least is a currently trusted party.
Both are useful.
To the best of my knowledge, there has never been a successful decentralized PKI. Even the most successful uses of PGP are not decentralized; they're essentially private PKIs maintained by a small set of presumed trustworthy maintainers.
I agree that's not all that useful on a global scale - it essentially degrades to the current PKI setup then, because validating everything is expensive and doesn't need to be done by everyone every time to get nearly all of the benefit. But it is a significant difference for individuals making individual decisions.
PKI is indeed hard, but it’s not even remotely intractable. The Web PKI is a functioning PKI; yesterday’s thread explains how the codesigning scheme we’re building for PyPI is going to look very similar to the Web PKI.
At the ecosystem level, PGP was not providing resource integrity to PyPI: too many of the keys involved were weak, and only a tiny proportion of packages were even signed. Even if that proportion was 100%, PGP would have been the wrong tool for that job: PyPI already has transport and resource integrity via the right tools: TLS and digests. Using an untrusted signature for resource integrity is using the wrong tool for the job.
The original thread contains multiple references to Sigstore, which is the scheme we’re planning on building on for PyPI.
The confusion here comes from the confusion in the PyPI article about PGP. The article complained that many keys could not be found on keyservers as if that mattered.
The Debian web of trust is a good example of how this stuff actually works. Before you can submit packages to Debian you have to get an existing Debian developer to sign your PGP key. In Debian the trust flows downward from older developers to newer developers.
This is not how signing works in Debian at a technical level. At at technical level uploading to Debian requires them to add your key to a list of keys maintained by the archive administrators. As a matter of policy those administrators ask you to get your key signed by an existing Debian Developer, but at no point does their upload infrastructure check that or use the Web of Trust.
The requirement for having individual keys signed by Debian Developers just makes it easier for the archive administrators to decipher which keys they want to add to their root of trust. The upload system does not check those signatures at all, they do not need to exist in the slightest as far as the upload system is concerned.
There are some caveats:
* Avoid -9999 packages as you won't get any guarantee of authenticity of whatever will be obtained from the upstream repository, other than whatever trust you place in a X.509 certificate that in all likelihood is controlled by either Microsoft (GitHub) or otherwise accessible to Amazon, Google, etc by nature of common open source project hosting arrangements.
* When syncing your local repository, verify all changes since your last sync. This could be as simple as syncing to a point n-days ago, after which numerous developers you know have signed more recent commits on top (you at least know those developers have been impacted too if the whole repository was compromised and the compromise is now on the public record).
* You don't really know how many people are using the packages you care about, and thus how many other people across the world are also exposed to (and possibly reporting problems with) signatures that Gentoo developers have committed.
In addition to relying on existing sources such as the Gentoo Git repository, an additional way to build trust is setting up software "looking glass" tools in different jurisdictions to check that software downloaded from different carriers in different jurisdictions are all the same.
At least with these measures the attacker has to compromise everyone and make this compromise a public record, rather than just silently compromise one target.
This is my new favorite alternative to “vanned” (or “v&”)
Also note that the noun associated with being "vanned" would be a "party van", not just a "van".
To be vanned/V& is to have the glowies inside the party van take the vanned party away.
:/
In the US, subpoenas come from the Justice Department (either state or federal depending on the crime for which evidence is being sought). The court that issued the subpoena is on it, and the person or entity being served, has the right to see why some government agency felt it could aid in the uncovering of a crime that had already been committed. The person or entity then has the opportunity to challenge that in court prior to complying with it. This is sometimes informally called "quashing the subpoena." From my sister-in-law who is a defense attorney, the most common result of challenging a subpoena is to get what it asks for narrowed down to just what is plausibly responsive.
In the article, this response: As a result we are currently developing new data retention and disclosure policies. These policies will relate to our procedures for future government data requests, how and for what duration we store personally identifiable information such as user access records, and policies that make these explicit for our users and community. Is good practice for limiting what a subpoena can request (you can't give what you don't have).
At Blekko we logged access records in such a way that we could use PII for 48 hours and then it was deleted. The CTO, Greg Lindahl, is a huge privacy advocate and this sort of architecture made it possible to get information to improve our ranking and service without compromising people's privacy. In practice I don't think any agency could go from "we have a suspect" to "issue a subpoena" in 48 hrs so it was a useful way for us to stay out of the crosshairs. The most interesting event was the FBI asking for information on IP addresses that had accessed their honeypot CSAM site. That turned out to be some of the machines in the crawling cluster. Given that the site was outside the crawl "horizon" and didn't rank (very few sites linked to it) it didn't even make it into the cache for rank analysis. But in that case the turn around time was impressive. Of course that is because they were just using their own logs to generate subpoena requests.
Watch out for smaller jurisdictions that might have “you should have expected” laws that says your 48hr window is too short.
Had a jurisdiction said, "You should have expected ..." I expect our response would have been, "We have published what we retain, me meet conform to federal and state laws you knew ahead of time we wouldn't have more than 48 hrs worth."
That said, jurisdiction when it comes to the Internet is always kind of "weird". Did you use the web service in your house in Columbus OH, or did you use the web service on a server in a data center in California? Also as I recall our TOS also had a requirement that any legal action be brought in California but I don't think we ever tested that in court.
The NSA and SS can get quite testy about it and make you wish you were dealing with the FBI.
What usually happens is the large corporation lays out a case like "yt-dlp is responsible for billions in damages" and they press the DOJ to investigate and prosecute.
[https://archives.fbi.gov/archives/news/testimony/intellectua...]
There is an applicable federal criminal law.
> Introduced in the House as H.R. 2265 by Bob Goodlatte (R–VA) on July 25, 1997
> Committee consideration by United States House Committee on the Judiciary and United States Senate Committee on the Judiciary
> Passed the House on November 4, 1997
> Passed the Senate on November 13, 1997
> Signed into law by President Bill Clinton on December 16, 1997
Before that, it would involve something like literal film, which didn’t scale well, and was too expensive and difficult for a typical person to do at home. It still happened, but was VERY niche.
With VHS/VCRs, someone could spend a couple thousand dollars and make hundreds of bootleg copies of any blockbuster video out there from their garage, and it was easy to literally go to Blockbuster(tm) and get an copy to duplicate without being tracked. Easy money. Folks would sell them out of the back of (literally) vans, or through friends, or via flea markets, etc.
It’s still super prevalent in Asia, using DVD/Blu-ray’s.
In the US, it then eventually got applied to the internet, because it was even easier and more scalable using computers, and harder to track down the culprits.
It’s all about money in the end of course.
> "Records of all Python Package Index (PyPI) packages uploaded by..." given usernames
> "IP download logs of any Python Package Index (PyPI) packages uploaded by..." given usernames
I don't think they'd want a list of packages uploaded by a given user if they were after yt-dlp devs. They'd be asking for a list of maintainers of a given package.
You are wrong.
So they should promptly update their policies to a) stop logging so much, b) delete all past logs, and c) sharply limit the span of time until deletion of whatever logs they decide they really need to track for internal needs.
They should avoid logging, and rapidly rotate logs, to thwart future subpoenas from the total surveillance state.
I mean if DOJ is interested in PyPI logs the only reason I could think of, is if it was used as a supply chain vector into breaking in into other organizations.
I also checked PyPI repo and looking at it I don't think it is published, there are few that look like might be it, but looking at them, they feel like something that would install something nasty on your computer.
As a somebody who relies on PyPI for development, I want them to store all kinds of data that would discourage PyPI to be used for any shady purpose.
Also perhaps there's a better example than youtube-dl, as they really don't do anything illegal. Yes their github repo was taken by DMCA request but then it was reinstated back. The GitHub spin it that they are standing up for developers, but the DMCA was just frivolous. I guess, still good for them, because they could just take it down and do nothing.
For $REASONS they've decided Fastly should be the only official mirror. This makes it a one-stop shop for malicious governments.
PyPI still fully supports mirrors (though it is becoming increasingly hard to run a full mirror of PyPI, last I looked a full copy of PyPI is about 30TB).
The only thing we ever removed was designating any particular mirror as official and an auto discovery protocol that was quite frankly extremely insecure and slow. That worked by giving every single mirror that wanted to be an "official" mirror for auto discovery a subdomain of `pypi.python.org`, labeled {a-z}.pypi.python.org. A client would determine what mirrors were available by querying last.pypi.python.org, which was a CNAME pointing to the last letter that we had assigned, that would tell it how many mirrors there were, then they could work backwards from that letter. So if the CNAME pointed to c.pypi.python.org, the client would know that a, b, and c existed.
Immediately you should be able to see a few problems with this:
- It is grossly insecure. Subdomains of a domain can set cookies on the parent domain, depending on ~things~ they can also read cookies.
- It does not scale past having 26 mirrors.
- It does not support removing a mirror, there can be no gaps in the letters.
So we needed to remove that auto discovery mechanism, which raised the question of what, if anything, we should replace it with?
Well at the time we had only ever made it up to g.pypi.python.org. So there was only 7 total mirrors that ever asked to become an official mirror. To my knowledge we never reused a letter, if a mirror went away we would just point the mirror back at the main PyPI instance. I don't remember exactly, but my email references there being only 4 mirrors left.
From my memory at the time, most of those 4 mirrors were regularly hours or days behind PyPI, would regularly go offline, etc.
But again, we never stopped anyone from running a mirror, we just removed the auto discovery mechanism and required them get their own domain name. We even linked to a third party site that would index all of the servers and keep track of how "fresh" they were, and other stats (at least until that site went away).
Running a mirror of PyPI is a non trivial undertaking, and most people simply don't want to do that. We never had many mirrors of PyPI running, and as it turns out once we improved PyPI most people decided they simply didn't care to use a mirror and preferred to just use PyPI, but still to this day we support anyone to mirror us.
Debian managed to solve all of the concerns you listed, what makes PyPI unique?
Firstly, Debian's mirror network URLs allow a mirror operator to attack the base Debian.org site if they rely on cookies on debian.org (they may not, I'm not sure). Specifically the `ftp.<country>.debian.org` aliases cause this. On PyPI we did use cookies at the base url, so this was a non starter for us to keep.
The second thing here is that Debian and PyPI from a technical level about how mirrors are configured and hosted are generally similar. Meaning other than the above aliases, mirrors are expected to have their own domain and users are expected to configure apt or pip to point to a specific domain. Debian does have a command that will attempt to do that configuration for you to, to make it easier.
The third thing is that Debian's mirrors are as secure as the main repository is against attacks from a compromised mirror operator. This isn't the case in PyPI where you're forced to trust the mirror operator to serve you the correct packages. There is vestigal support for a scheme to support this in the mirroring PEP, but nothing ever really implemented it except the very old version of PyPI (none of the clients, etc). That scheme is also very insecure, so it doesn't really provide the security levels it was intended to.
The fourth thing is that a Debian mirror is easier to operate.
Packages on Debian don't live forever, as new versions are released old versions get removed, and as OS releases move into end of life, entire chunks of packages get rotated out. However on PyPI we don't have the concept of an OS release, or any sort of phasing out of old packages. All packages are valid for as long as the author makes them available. This means that the storage space to run a PyPI mirror (currently ~30TB) is a lot more than the storage space for a Debian mirror (~4TB).
On top of that the way apt and pip function are inherently different. Apt has users occasionally download the entire package set so that apt has a local copy of the metadata while pip asks the server for each package for the metadata (it does some light caching, but not a lot). This means that to discover what packages are available, apt might make one request a day while pip might make 100 requests for every invocation of pip. Packages on apt release a lot slower and less often than on pip. so many times people may not be needing to download more than a handful of packages, but people generally need to download a lot of packages from PyPI at a time.
I believe? the Debian mirroring protocol is rsync based, which is generally pretty reliable, while the PyPI mirroring protocol is a custom one which works, but it sometimes has a tendency to get "stuck" every few months and require operators to notice and fix themselves.
I suspect the differences between the strength of the mirror network is some combination of the two, but I suspect the the third and fourth things are the biggest differences, particularly when PyPI's CDN solved the problem in most users minds that would cause them to want to host or use a mirror.
Note that the blog post doesn't say they handed the entire database over to the feds. They received three warrants scoped to specific packages and returned only the data they had available that was associated with those packages.
An effective mitigation for abuse/spam is to increase its cost. One example is to require payment.
Suddenly getting hits at mydomain.com/[uuid]? At least you know somebody has looked at the data, or at the very least fed it through some processing tool that is extracting and visiting the URLs.
Why not to the users themselves? Have they been prohibited from doing so? (TFA does not say afaict)
I see an ambulance going lights-and-sirens behind me. I don't know they're on their way to or from a hospital, but I pull over because I have reason to believe they are.
We're a message board and we're thus optimized for drama over truth-seeking (it's just human nature). The truth of these kinds of events is usually not all that interesting. If it's something more dramatic, we'll hear more about it in the future. In, like, a sort of Bayesian sense, you can predict that any given subpoena or court order is going to be about a case nobody would bother sending warning signals about.
This is true. The result may be so boring local news wouldn’t even cover it. In some cases you have to find the investigating agency’s unremarkable press release and then dig for related court documents to even find out what happened.
PyPI would pretty much want to inform the users, but they probably simply can't (without getting into legal trouble).
"We have waited for the string of subpoenas to subside, though we were committed from the beginning to write and publish this post as a matter of transparency, and as allowed by the lack of a non-disclosure order associated with the subpoenas received in March and April 2023."Uhm, am I misunderstanding what you wrote, because that is definitely not true. Subpoenas require an officer of the court by definition (in the US anyway), which can be a judge, a court clerk, or even lawyers in some jurisdictions.
I'm sure the NDA stuff here is ironclad! I'm just curious what the mechanism is.
If they are acting as an officer of the court, which they’d need to be to sign off on a subpoena, I believe the answer is yes. The mechanism is called a “gag order”.
Same with wiretapping orders, or frankly a subpeona for pretty much anything from a third party.
That's not entirely true.
https://en.wikipedia.org/wiki/Administrative_subpoena
Local organizations have come up with equivalents, although there is less (no?) statutory support for that.
I left off the second part after the ellipses because it’s not relevant to the current discussion and because there’s constitutional challenges against them even when federally issued, as your link calls out. I didn’t want us to tangent off needlessly. The law is a messy place, lots to find and hate.
I've lost track of the number of "white hats" that contact us with extortion requests after they used some dependency confusion attack.
Presumably because there is some demand for compensation before disclosure?
There's an entire industry now of people that check known vulnerabilities (so they don't invent anything themselves) in software/packages and cross check this against outdated websites, at a very large scale.
They have no morals or security ethics, they barely even have knowledge, they just want to make money with the least amount of effort possible.
Don't ever pay them a cent. They're just as ruthless as spammers.
If there is an entire industry of people doing low effort work which then discovers vulnerabilities on a company's website that company should pay them, and probably fire some people they've already been paying for not putting in even that much effort to secure their own stuff.
Who is less ethical? The people reporting vulnerabilities and wanting to be paid for it or the companies who don't bother to invest in even basic security practices putting people's data at risk and allowing scammers and hackers to leverage those insecure systems to hurt others?
The vast majority of websites on the internet do not have a team behind them. That's exactly the reason why they lack maintenance.
So they're not intimidating well-funded companies, they're intimidating that nice guy that in 2003 build a website for the local bridge club. Volunteering his time and money to do so.
If it's easy, then more the danger, and more the reason to pay the white hats instead of getting robbed by black hats?
Besides 'dependecy confusion' is not typo-squatting at all. It is about having a public package that masks the name of a private package repo. The default behavior of pip is to then use the public repo, which can let outsiders who know internal package names totally take over those internal packages.
Which is the most important part.
Edit
I read 'chaps as saying there was an NDA on the subpoena, but apparently there wasn't, so this might just be flatly wrong.
>As a result we are currently developing new data retention and disclosure policies.
“I guess we don’t actually need that” should have been the idea from the start.
I'd say they followed "I guess we don't actually need that" approach reasonably well so far and good for them if they want to improve that even more.
On top of all of that, it's volunteer run and has been understaffed for basically it's entire life, so sitting down and figuring out a proper data retention policy that takes a holistic view of everything we have just never bubbled up.
In general I think we already do a pretty good job of collecting a minimal amount of data, and hopefully with proper policies we can do an even better job.
Never made sense to me. Terrorists and other very bad people usually aren't in the business of following laws so I don't know what crimes you'd prevent by weakening the rights of everyone else.
Surveillance does not reduce crime, tending to people's basics needs so that they don't need to commit crimes reduces crimes.
> the government read everything everyone wrote/texted/read
is this really a relevant analogy for this? And yes, I've heard of the mass surveillance via telco that we did find out (through Snowden) was happening, and do think it seriously crossed the line. I'm just wondering if this kind of case at issue has anything in common with that malfeasance at all.
Is it your belief that they lacked any probable cause and are actually trying to persecute those 5 people for some reason?
Rather than try to argue against a position I'm not fully understanding, I'd like to hear how you think police should solve crimes with a significant "cyber" component.
Let's say someone stole your identity and in the process they emailed all your financial documents to example.anon12345(at)gmail. If you contacted the police and the FBI subpoenaed Google to force them to give them the details of whatever they know about that accountholder, is that bad and hurting the rights of somebody, or is it protecting your rights?
Does it change based on the despicableness level of the crime suspected? From one count of copyright infringement of a Taco Bell commercial, to organized retail theft rings, to identity theft, to CSAM, to terrorism?
I'm not saying you're wrong, I'm just curious what the "We hate subpoena power" argument is so I can decide where I stand on it. I feel mildly like I'm not as bothered as you are, but I suspect I'm missing something.
Also, should "online" operate under different rules than offline? If the "feds" have probable cause that some guy is a drug kingpin and they break into his office and his safe to seize evidence, is that equally bad as forcing Google to open up his Gmail account for them?
Child porn and terrorism are the favorite subjects of politicians looking to enact a new law but idk if it's good to follow that thinking and use it as an example as opposed to a serial killer or something
While they are transparent the events happened, they are not transparent about which packages and what authors are being flagged, which is unfortunate.
Considering they are admitting they will always obey government commands, including regarding non-disclosure of actions to affected users, it is prudent to assume they are, in fact, not transparent about events; only about those events which the government has let them tell you about. Other events (e.g. National Security Letters) may or may not have occurred.
Subpoena = the court compels you to hand over the evidence we need.
You get shown the warrant to prove that they have permission, not to order you to comply.
I realize this comment is a little ambiguous: the order in the warrant case is an order by the court to the court's officers to perform an arrest, seizure, etc. It's not an order for you (the subject of the warrant) to comply.
Subpoenas can be issued by attorneys (including prosecuting attorneys) as part of the investigative and discovery processes.
Warrant = "Back up the van and haul it away"
The warrant is a command to a law enforcement officer, which allows the law enforcement officer to personally go and search and seize things (or people), while overriding some rights that would normally prevent this. Normally it is issued by a court. Generally there is no way to challenge a warrant to prevent its execution, because it is not disclosed to the target before it's executed (i.e., a law enforcement officer shows up with the warrant and begins executing it immediately, by force if necessary).
(Edit: I wrote above that it's risky to comply imperfectly with a subpoena and then argue in court that this was reasonable, but usually if a lawyer gives a professional opinion that the subpoena is invalid or overbroad for some reason, then the recipient of the subpoena won't be punished for following that advice. The lawyer may also attempt to negotiate directly with the issuer of the subpoena, for example by sending a letter explaining why the the subpoena appears to be invalid. The legal standards for issuance of subpoenas are also pretty broad. For civil litigation, which is not what DoJ is doing here, they are set out in https://www.law.cornell.edu/rules/frcp/rule_26; notably, they can be issued to third parties.)
This url does not exist. Was this response generated by an LLM?
No, its just that HN’s automatic linkification continues until it breaks on whitespace, so if you type punctuation (here, the “;”) after a link with no intervening space, it gets included in the URL.
Strip the semicolon and its fine:
But also I possibly shouldn't use civil litigation as the only example of subpoenas, again because this one arose in a different context.
This was the point where I was wondering if this is really about some malicious packages or something more along the lines of copyright infringement software.
From a 2021 article[1] about packages used to deliver malware "we have alerted PyPI about the existence of the malicious packages which promptly removed them. Based on data from pepy.tech, we estimate the malicious packages were downloaded about 30,000 times."
For comparison yt-dlp has tens of millions of total downloads and gets downloaded over 70,000 times every day [2]
[1] https://jfrog.com/blog/malicious-pypi-packages-stealing-cred...
Which means the subpoena would only be useful if the criminals made an opsec mistake. That is generally how most sophisticated criminals get caught, but here it feels like anyone inventive enough to try will probably also be prudent enough not to leave a trail.
> "IP download logs of any Python Package Index (PyPI) packages uploaded by..." given usernames
Do you feel the same way if the cops are receiving the IPs of everyone who downloaded yt-dlp? IP addresses and timestamps resolve to physical locations and oftentimes street addresses.
Even if they were, and the DOJ was going for a dragnet operation to go after tools that could potentially infringe terms of service of big corporations, they would go after every tool and every fork. Not just 1 package. But again, what court would allow such action and why?
If I was in the DOJ and was investigating a malicious package uploaded to PyPI, I would ask for the IP's of the downloaders to see if the uploaders dun goofed and downloaded their package shortly after uploading off VPN. Or to find out if any major corporations were impacted by downloading the malicious package and to inform them.
With PyPi hosting a ton of malicious packages and malware, certainly I am not morally opposed.
I reject the vibe that “law enforcement bad, freedom good, tear it all down.” It is not at all constructive or thoughtful. I fear that people are forgetting that everyone is really on the same side, that we do really want to prevent crimes, and fairly and equitably. It’s ok to want a more fair and equitable Justice system, but in my opinion the solution is not to attack every law enforcement action with emotionally charged language.
The problem gets a bit hairier when dealing with dependency chains, however.
…but why is that a goal for PyPi? As a publisher of packages, it’s a nice-to-have, but as an end user it’s kind of scary. I don’t want to use software packages published by anonymous and potentially unaccountable people. That’s probably why they have so many malicious packages.
Maybe you live in an oppressive regime who will imprison/murder you for publishing some code; ok, but that’s an outlier, and there are a lot of ways to get around that situation.
I just don’t see the benefit of privacy in this situation? Is it just to reduce the administrative overhead of collecting/verifying identity info? I’m genuinely curious to learn about a realistic use case that justifies the risks to all users.
I know you can self host your own package index, but very few users have the resources to do that.
I actually think the larger problem is Python's reliance on imperative code that executes at install time. Yeah you can use pip --download and extract it yourself, but folks rarely do that.
Yeah no way they haven't had other subpoenas then.
According to US news over the past 3-4 years, you can just ignore subpoenas, then get a contributor job on a cable news network. Bonus points, the more you flout the law as arrogantly as possible ;p
Presumably the 5 users in question were interesting in some way, not just random.
> I would think a bad actor who would register would spoof their ip and use burner accounts anyhow
Maybe, but they could find that out with the information. If there's a 10% chance each was sloppy or un-paranoid, there's a 40% chance they get at least one piece of real info.
The person might not have thought they were doing anything wrong. Some judge might have greenlit this for a piracy case against the five maintainaers of youtube_dl{c} or something silly.
In general, I think it usually goes poorly when programmers invent clever legal workarounds. The legal system isn't a computer program. It's guys with guns.
EDIT: One situation where the government cannot compel you to lie is if it violates your fifth amendment rights (self incrimination).
At the end of the day if uncle Sam demandeth, uncle Sam will haveth.
If a mom-and-pop shop or open source org, it's a faint hope at best.
I think that would be outside what can be done with a subpoena. It would require a court order.
https://www.theverge.com/2014/9/18/6409575/apple-warrant-can...
The problem with a warrant canary is there's too much doubt about why it disappeared. Did they actually receive a warrant, or is it just a decision from corporate to discontinue the practice?
The result is the same.
Surprised the doj didn’t issue any gag orders.
This is way overbroad. The fact that a judge granted this is very bad.
It's not hard at all, on the other hand, to imagine situations where this would be a reasonable request. Probably the most obvious would be if the packages contained material which was illegal to possess or distribute (like CSAM). Another would be if the packages were being used as part of a malware C&C operation -- knowing what IP addresses downloaded the packages would aid in determining the scope of the campaign.
either a small group of users, or one user with multi aliases wrote a nastyapp ?
Should one of the countries issue an order, the ones outside of its jurisdiction can openly disclose the information. Say if the US forces the US entity to not do something, the French one sees it and can warn all users.
In case anything happens with the content of the service, the detail of the changes would be made clear by someone outside the jurisdiction.
A typical example is TrueCrypt that, one day, changed their page to say to use something else instead of their product.
If the code was shared between several countries, the others could simply publish that this and that was changes out of band, and that it means that the code is now positively unsafe.
You are right. My comment was a bit offroad, I could have made that clearer (about how to deal with "data" (code, ...) in international context)
> I think it'd be quite hard construct that in a truly "safe" way.
For open source code it is easy - everyone sees teh chnages and why they've been promoted.
For closed source, having your source at a third party (or synchronized), build from only the identical code (between the two repositories), and enforce a two-eyes kind of code promotion (merge) will make it so that any change in the code that is not vetted by both parties (or multiple parties) will not get built.
I gave the example of Truecrypt that was unfortunately US-only and they had to revert to allusions in order to inform that it was tempered with.
https://www.developer-tech.com/news/2023/may/22/pypi-suspend...
Further, whatever they're investigating here is probably "important", for some definition of important, so they likely value the ability to lean on non-disclosure clauses etc.
I suspect it was more about going after software that was enabling piracy, those are often created by naive students who are not expecting the power of government to be unleashed on them.
Not really.
The vast majority of supply chain attacks in practice are idiots exploiting namespacing, bitflips, or typos on pypi/npm to drop miners or infostealers.
Yes, even the shit tier supply chain attacks count :)
Wow, I had zero idea how old Python is.
> The privacy of PyPI users is of utmost concern to PSF and the PyPI Administrators, and we are committed to protecting user data from disclosure whenever possible. In this case, however, PSF determined with the advice of counsel that our only course of action was to provide the requested data. I, as Director of Infrastructure of the Python Software Foundation, fulfilled the requests in consultation with PSF's counsel.
The first part of this section contradicts all of the rest. If user data privacy is of "utmost concern", then it is a concern above fulfilling legal obligations under US law. Plus, such supposed obligations must be staunchly fought before even considering whether or not to observe them. So, in fact, user data privacy is a minor concern for the Python Software Foundation, while swift prostration towards the US federal state is what's of utmost concern.
Of course, they almost admit it themselves. If we carefully read the second clause, they don't say "we're committed to protecting user data from disclosure", but - the "we're committed... when possible". So, they're saying that if they believe it isn't possible to protect, they have _no_ commitment to try their utmost to protect. i.e. when they see fit, user data protection is _not_ a concern at all. ... ok, ok, it is a public relations concern.
That said, I think we should be working towards a world where they're unnecessary. As a middle party to what ought to be a developer/developer trust relationship, they're attack surface that threatens depender sometimes and dependee other times.
Going peer-to-peer will be less convenient, but worth the investment in the long run.
Any information that can be subpoenae-ed can also be hacked away.
What if you operate from e.g. Iceland, Switzerland or even many EU states? Can a US Gov. agency still subpoena you?
It immediately reminded me, that PyPI content is really trash as it is because of all the squatting and pointless unfinished toy-projects, and whatever they are logging clearly doesn't help, but I think that big problem for PyPI is one seemingly minor detail: lack of namespaces (as in packagist.org of pkg.go.dev). It is not a solution for all sorts of malicious behaviour, of course, but it really makes things much easier. It doesn't solve typosquatting and such, but, honestly, neither does the current system, obviously. And at least it allows to keep the actual package names semantic. And which one of countless "*/time" libraries you wanna get you just kinda have to decide separately, using the number of starts on the github as a reference and carefully copy-pastying the id to your requirements.txt
The same issue I have with Cargo. I mean, really, isn't it obvious that making users compete for better project names just makes everything shit?
Edit
Even that is technically wrong; some DOJ subpoenas are apparently preauthorized by statute.
https://www.justice.gov/archive/olp/rpt_to_congress.htm
tl;dr: Everyone from the Appalachian Regional Commission on down can subpoena you without a court being involved. And of course Congress has inherent subpoena powers.
This is a step towards answering my noodly question earlier in the thread: authorization for NDAs and "gag orders" in subpoenas appears to be controlled by (varying) statutes.
Emphasis on the last part: or to the users themselves.
In other words: unless they actually let the users involved in spite of claiming the opposite, the whole article is complete posturing.
This is not the case if the subpoena is issued by the FISA court, otherwise known as "the court of no rejection."
Because they do, in regular federal courts.
> This is not the case if the subpoena is issued by the FISA court
The Foreign Intelligence Surveillance Court doesn’t (and courts in general don’t) issue subpoenas.
This sounds like a matter of technicality, no? Whatever you call it, what they issue has the effect of a subpoena that you can neither appeal nor speak about.
My point is not that this is what's going on here, but that the right to appeal is not generally a given.
No.
> Whatever you call it, what they issue has the effect of a subpoena that you can neither appeal nor speak about.
No, it doesn’t. FISC doesn’t generally issue orders that are subpoena-like that would be presented to people outside of government. It provides surveillance orders to the FBI under which they conduct surveillance and, should someone later question if maybe that surveillance was a criminal violation of the Foreign Intelligence Surveillance Act—which would also be the FBI—the FBI can show the FBI the paper from the FISC that says its okay and then the FBI will not arrest the FBI for criminal violations of FISA.
Or if someone somehow finds out they were surveilled and files civil charges, the paper serves a similar function.
Where they do (and this only, IIRC, occured under law that has now expired) issue orders that apply to external parties, those can be challenged directly in the FISC, appealed from the FISC to The Foreign Intelligence Surveillance Court of Review, and, from there, to the US Supreme Court. There is at least one such appeal to FISC-R by Yahoo! that has been published in redacted form.
In no case does FISC issue orders that would go to an outside party who would then have no means or forum to challenge them.
> submitted_from | IP Address
> PyPI retains records of critical user events including account creation, emails sent, email address changes, logins, and login failures. See this list for the comprehensive set of events recorded.
> ip_address_string | IP Address
Retaining IP addresses for over a decade doesn't sound GDPR-compliant.
Great respect for the response. Reevaluating data retention is a great move.
They point out that they are not subject to a gag order.
Oddly specific wording there. It would seem they have received additional subpoenas outside that timeframe which do have gag orders, and someone slipped up and failed to put the gag orders in these particular subpoenas.
Seems like the DOJ may be doing some long-term fishing for, what, software developers? First the DOJ came for the conservatives, and I said, "go get 'em!" because I wasn't a conservative; next the DOJ came for ____?
Step two: style yourself as an oppressed minority
Step three: defend any action, decision, or position as a persecuted martyr
Don’t lead with this.
> In this case, however, PSF determined with the advice of counsel that our only course of action was to provide the requested data.
If you’re going to say this.
I’m not judging their decision. Maybe not going to prison is a greater concern to them. It’s fine to just say that you thought it was best to comply because [lawyer reasons that you don’t have to disclose to anyone]/counsel.
EDIT: Or say “there are bad people out there and we trust the DOJ”. Whatever.
Also I don’t see how being light-hearted has anything to do with this submission, Thomas.
Other than possibly IP addresses, it seems like the only information they had available to disclose was close to the bare minimum needed to operate the service.
They can feel that way, and comply.
It's hard to keep those things separated. I would very much like the code submitted to PyPI be protected end-to-end by cryptographic signatures, when PyPI has either no resources, or no spine to stand up to a government. Any signatures, even PGP, which should be in place until someone provides better mechanism.