Ethereum Foundation removes their canary
github.com
github.com
* You're suddenly under governmental orders not to disclose X. You remove a canary that says not-X, effectively disclosing X, and this was obviously your exact and pre-meditated intent. You then have to find a lawyer who will help you argue to a judge and other officials that you're in the clear with this loophole.
* You have a canary that says not-X, as an assurance to some other party. X happens, but you're also told at the same time that the folk wisdom you heard on the Internet about canaries will not protect you. So you don't remove the canary. Now your canary is falsely assuring that other party, betraying whatever trust they put in you, perhaps to their detriment.
Although... I also don't see much use in them either, it seems everyone ends up complying with something eventually and so all canaries end up getting removed.
vs
Why didn’t you do this thing 2 weeks ago that you were under no legal obligation to do?
Seems like a significant and valid distinction even if what they communicate to the intended audience is largely the same.
“Largely the same” because in the second case it would be possible that forgetting, or some other obstacle to resigning occurred.
IMHO, that's kinda a weaselly trick, no matter how good the cause, and it might not stand up, not legally, nor in extra-legal practice.
And to my knowledge, warrant canaries haven't been tested in U.S. courts, so the zeroth (and possibly most common) scenario would just be that you remove the canary and nothing happens to you, and the canary works as intended.
Neither of your scenarios seem problematic:
"You then have to find a lawyer who will help you argue to a judge and other officials that you're in the clear with this loophole."
Presumably the same lawyer(s) you've already retained for the purpose of defending the canary (and other things). Defending the canary in court (under US 1A law regime) is the entire point.
Also note that in the de facto standard canary process[1] you don't remove the canary (as that would be a positive, intentional act of speech). You simply stop updating it.
"So you don't remove the canary."
Again, under no scenario do you remove the canary - you simply stop updating it.
[1] "Special note should be taken if these messages ever cease being updated, or are removed from this page."
I imagine that canary questions sometimes come up in non-publicly-disclosed legal proceedings, as well as in the occasional extra-legal practice.
If that actually does happen, and canaries ever failed to stand up in them, then how many lawyers would ever be in a position to hear about those failures, such that the lawyer could competently advise clients how to use canaries successfully?
Would the lawyer have to have been the veteran top litigator who handled the situations that reached the ear of the ACLU, or who previously worked on those situations on behalf of some facet of government?
Or is there sufficiently binding official assurance from government that canaries done a certain way are OK, no matter what happens in some non-public meeting?
(BTW, I really like your company. Though, as much as its canary looked like probably a signal of principled old-school Internet techie values, it also looked like potentially a bit of a magnet for trouble, in business it might attract, and in who it might antagonize. The tech choices there seem be heavy on minimizing risk of IT drama, but the canary seemed to flirt with drama.)
I think you assume that getting in contact with lawyers from the ACLU is much much harder than it is, either that or that the ACLU only gets involved in sufficiently high-profile cases but nonetheless false. If you're a company that deals with sensitive data and have a legitimate worry about getting NSLs you could probably get a meeting with the relevant legal/policy expert just by shooting them a polite email about it.
Experts in a particular niche field not wanting to talk about their passion, impossible challenge. "Wait, woah, you also care about this?! You wanna testify in the committee hearing for the bill our team is working on?"
My question was where would someone go to get counsel about canaries, from someone who knows how this actually works in practice, not only in the legal precedents that are public info. (After all, we are talking about situations involving gags.)
For example, I was guessing maybe there's someone at the ACLU who has heard of enough of the non-public to give good counsel. But asking.
Unstated, I was also wondering whether the folk wisdom that so many people repeat, and which some seem to rely upon, is informed by the expertise of the rare people in a position to know the full reality.
Even if it's true, it does sound like a stereotypical computer person's misunderstanding of how law works: "Aha! But this Constitutional interpretation says that government can't compel speech! Checkmate!" Hence, checking that.
The original idea was that on some regular cadence (say weekly), you actively post a (hopefully signed) message somewhere saying "I hereby attest that, as of <insert current date>, we have not received any warrants/subpeonas/etc and are not subject to any gag orders, etc. etc.". (eg, rsync.net's canary: https://www.rsync.net/resources/notices/canary.txt). You have to set it up so that someone has to actually go and do something for the updated canary to go up, so it's like a dead man's switch. If you ever stop posting those, that's the signal to users that something is up.
That approach is extremely robust legally. In the US at least, publicly posting a digitally signed message asserting something presumably important and valuable about your business that's knowingly a lie would be considered false advertising, wire fraud, etc. depending on the exact situation. The government has a lot of power to legally compel you to not do things that would otherwise be legal (eg, uttering the speech "we just got a subpeona for all of your data!"). What they absolutely cannot legally do is compel you to do something illegal. Eg, they can't make you commit wire fraud by actively lying to your customers about the services you provide. That's a very strong legal position and you wouldn't have a hard time getting a lawyer to back you up on it.
Basically, if your "canary" requires you to "take down" something, it's not a proper canary and, yeah, I wouldn't trust it to protect you from much.
https://www.eff.org/deeplinks/2014/04/warrant-canary-faq
https://www.eff.org/deeplinks/2016/05/canary-watch-one-year-...
this commit removes a section of the footer as we have received a vol…
…untary enquiry from a state authority that included a requirement for confidentiality
This is nothing like that, the commit message itself is literally disclosing the fact that they have received an enquiry.
On the other hand, they are calling on their allies in the SEC to reject the Ethereum ETF, while the SEC is using Ethereum's transition from Proof of Work to Proof of Stake — which reduced its energy consumption by 99.99% — as the legal justification to designate Ethereum a security and thereby severely reduce the market's access to it.
"US Congressional Group ‘Disturbed’ by Crypto Mining Energy Usage" https://www.coindesk.com/policy/2022/07/15/congressional-gro...
"Democrats to SEC: Don't approve spot Ethereum ETFs and any other crypto ETPs" https://www.theblock.co/post/282846/democrats-to-sec-just-sa...
"According to a person at a company who received a recent subpoena request, the SEC’s probe of the Swiss-based Ethereum Foundation began shortly after the blockchain’s shift to a new governance model known as “proof-of-stake” in September of 2022." https://fortune.com/crypto/2024/03/20/sec-gary-gensler-ether...
I wonder if the NSA should have a team that just goes around organisations that have warrant canaries and sends them baseless confidential messages, just enough to trigger the canary. The fact that they don't do this suggests they don't think canaries are much use.
That given, they are not going to "waste" their canary if it was a simple request for information. Best guess, this is the beginning of the end for Ethereum and they have been compromised just like Blockstream and BitcoinCore were previously.
It is best to assume that from now on Ethereum is no long a decentralized application but its development is being directed by a governmental agency, again, same as BitcoinCore.
Most important next step for Cryptocurrency is to make it development resistance. Every notable attack on crypo the last few years has not been hackers but developers like Greg Maxwell, Peter Todd and Adam Back who attack the code base out in the open, acting as useful idiots for three letter organizations. It seems ETH is next on the chopping block.
Seems like wild speculation.
> Of course, the whole point of a Doomsday Machine is lost, if you keep it a secret! Why didn't you tell the world, EH?
As proof, this is the only line returned when you search the text for the string "tell the". https://www3.nd.edu/~dlindley/handouts/DrS.htm
It's pretty annoying to work in a codebase that had no formmatter running so that I then have to make special adjustments to my editor to stop formatting on save for certain files.
So either have code formatting standards to start with which are automatically applied, or else accept PRs that have whitespace fixes and merge them promptly (I can accept splitting up the commits into formatting and non-formatting commits but even that is barrier to entry over people being able to submit changes to your software easily--every bit of fussiness is a tax on the submitter's time and will result in less submissions).
Otherwise, if the problem is that you have patches waiting to be merged for weeks that result in merge conflicts, that isn't solved by putting the patches together into a single patch: you just have a process that is going to make formatting changes impossible to clear without tons of extra work.
As for submitters, they need not put in this time: the maintainer or review team can trivially split the patch as this is literally close to hunk selection... it is so easy that I routinely do this as part of every single commit I have made even locally and even temporarily for as long as I can remember?
Regardless, I still don't understand: nothing you are saying makes it sound like the people in your scenario are actively making code changes to avoid having to make a formatting change--"a tactic to continually change code to get away from having a formatting change come in--which is what was claimed and what seemed so utterly confusing... I can't imagine someone saying "I'm going to change this logic few days as I hate formatting patches".
This is why when people think about submitting a change and they see their editor auto-formatting changed half the lines in the file with whitespace fixes, they get a bad feeling about how submitting anything to the project is going to go.
It makes every single commit as ugly as this one. In other words, instead of only some of your commits being full of formatting noise, all of them are, because touching any line causes rewrapping/reindentation of all the nearby lines.
Running a formatter on every single commit is dumb, unless you're an enormous company that doesn't release their software (i.e. Google and very few other companies).
If you ship your software, make the autoformatter part of the release process. Commit the reformat (to the trunk) right before each branch-off. It's a great compromise. Everything is autoformatted "in the limit" but the disruptive commits happen only once per release cycle. Formatting-only PRs get rejected with "please wait until the next release and/or teach the autoformatter to do whatever it is you want here"
Especially if the cleanup touches the same code you are semantically modifying you are basically forced into a bad dilemma of doing them in parallel (leading to a merge conflict with yourself yuck), or doing them in series which leads to the question of whether you should twiddle your thumbs while waiting for the first commit to get through review or whether you should do something else in the meantime risking forgetting the other commit.
That's why I don't think it's completely clear cut.
[0]: In 2019, Ethereum Foundation employee Virgil Griffith was arrested by the US government for presenting at a blockchain conference in North Korea. He would later plead guilty to one count of conspiring to violate the International Emergency Economic Powers Act in 2021. (https://en.wikipedia.org/wiki/Ethereum)
Green if it was tax organisation and yellow if is a criminal one
> this commit removes a section of the footer as we have received a voluntary enquiry from a state authority that included a requirement for confidentiality
Which... is just saying what happened? Point is to remove it without saying anything, as if you do, you'd break the "requirement for confidentiality" and put yourself at risk.
I agree that it is not a contract between equals, it is an action of law in government; like it or not it is the price of civilization. In the USA the basis of law has been worked out very well, in some cases. Of course there are abuses and no one is defending an abuse of the law. Humans are social and difficult. The answer lies in a system of review and an ability to change over time.
If it was CIA and they sent me: "Please give us all information on XYZ so that we can organize an assassination on them. This is voluntary and you don't have to give us that information. This is just pretty please."
I think I would kill my canary even if the request is technically voluntary and I wasn't compelled to give out any information. But that was a joke scenario because I couldn't come up with more realistic scenarios.
And then I guess if your threshold is too low, you'll kill your canary on something that might be a nothingburger.
So if you go ahead and say "I haven't be served a warrant by X group" on your website, the government can stop you from saying the contrary, but they can't force you to lie about it, so you are free to remove the canary since it is no longer true.
If the courts ever tried to retaliate against that, they'd run into a mountain of precedent that forbids compelled speech. They would have to argue that you are required to lie, rather than be allowed to retract a non-truth. That's not something the Constitution is going to allow.
If someone asks me "Have you been served a warrant with a gag order?" - I'm allowed to say "No", and lie about it if I want to. I am not allowed to say "Yes", per the gag order.
Now, if someone asks me: "have you been served a warrant with a gag order? Say no if the answer is no, but say nothing is the answer is yes". Now, I am allowed to say no, and allowed to say nothing, even though by saying nothing it directly contradicts the point of the gag order? Is it really the case that these gag orders are meaningless if someone just asks the question in the right manner?
I can't really buy that. I suspect canary warrants only "work" because they have never been tested in court yet.
But, I guess we won't really know until a warrant canary event makes its way to the courts.
>Now, if someone asks me: "have you been served a warrant with a gag order? Say no if the answer is no, but say nothing is the answer is yes". Now, I am allowed to say no, and allowed to say nothing, even though by saying nothing it directly contradicts the point of the gag order? Is it really the case that these gag orders are meaningless if someone just asks the question in the right manner?
It isn't about asking or answering questions. Let's say I light a fire in my firepit each morning that I haven't been served with a secret warrant. The day after I'm served, I simply don't light it. Anyone watching the firepit then knows that I've been served. Nobody is asking me anything, and I'm not saying anything. The government can compel you to stay silent due to a gag order, but they cannot compel you to trudge out every morning to light the firepit.
The "I didn't really talk about it, I just didn't NOT say I WASN'T talking about it" thing feels like a flimsy technicality. I think what's really protecting these canaries is that they're non-specific and one-time-only.
I don't think we're going to see many "I have not been gagged by the CIA on April 25, 2024" canaries going around, even though that technically uses the same loophole.
I'd be extremely skeptical of anything you read in this thread about contentious signing, dates or whateever. There are a lot of amateur lawyers with amateur opinions in here. If you are interested in ever using one, find a lawyer and check with them first.
But whatever the legal consensus is, I doubt a git commit that says "NSA wuz here" fits in with it.
https://github.com/ethereum/EIPs
Or the go-ethereum execution client (the most popular execution client):
The SEC sent subpoenas to companies seeking documents and financial records relating to their dealings with the Ethereum Foundation, the story said, citing companies that have received SEC subpoenas.
If I were to don my tinfoil hat, it seems possible to remove the canary with a boring incident for plausible deniability of a prior incident whose confidentiality is more strictly enforced.
The stricter gag order gets what it wants - non-disclosure of that particular gag order, the canary gets what it wants - removal after an incident.