Warrant Canary
en.wikipedia.org
en.wikipedia.org
Outside of spy fiction and conspiracy theories, I haven't seen any evidence that the government can legally force someone to lie (vs just a no comment) in order to cover up an NSL or FISA order.
Is there any evidence that they would able to force a company using a warrant canary to issue a fake one or respond with anything other than "no comment" to direct questions from the media?
http://www.buzzfeed.com/mattlynley/verizons-internal-memo-to...
On the other hand, if you're pre-arranged that you will simply fail to communicate something after a certain event then there is no doubt what statement has been made. A judge will see right through this if it's tried and probably impose contempt of court. If one were to try something like this it would be essential to broaden the scope enough that it couldn't be used to reference a specific gag order.
Edit: Ultimately, legality turns on the statutory language of the provision in the Patriot Act that obligates businesses not to disclose (anyone know what it is?). The approach as originally proposed by by Steven Schear (http://tech.groups.yahoo.com/group/cypherpunks-lne-archive/m...) was for the ISP to simply not answer a direct inquiry by a customer about whether or not a warrant has been served. The advantage of this approach is that it is far harder to provide evidence to the effect that not responding to the question in that context is a statement. The disadvantage is that a non-response might not provide certainty to the person who asked the question. Effectively, the more that a clear convention is formed around the "canary mechanism", the higher the risk that a court would hold conduct in association with the convention in breach of the statutory obligation not to disclose.
* "the omission is expressly made sufficient by the law defining the offense; or"
* "a duty to perform the omitted act is otherwise imposed by law (for example one must file a tax return)."
I don't know of any such law involving canaries.
[citation needed]
Has there been a case where the judge forced a civilian to lie?
The court can't compel you to lie. The court can compel you to not communicate about a gag order, and enforce that with contempt of court. So if you don't choose to "lie" (since again, we all understand the purpose of the communication is not as a factual statement but rather to signal whether a gag order is received) they can still hold you accountable for it.
getWarrantCurrentStatus(custID) // "No"/"No Comment"/"Yes"
getWarrantLastChangeDateTime(custID)
getWarrantPreviousStatus(custID)
getWarrantHistoricalStatus(custID, DateTime)
getWarrantResponseCurrentCount(custID, responseType) // accepts only "No Comment" or "Yes"
getWarrantResponseHistoricalCount(custID, DateTime, responseType)
// for all the above functions, a custID of 'MagicNumber' is the special customer ID of 'Anyone'.
Yes. The law generally isn't a binary automaton that can be "tricked" by a bit of clever catch-22 logic.
Your canary is a one-bit communications channel. Removing it or ceasing to update it constitutes flipping the bit. That, obviously, is communication.
http://torrentfreak.com/kim-dotcoms-gaming-lag-hints-spying-...
"Your honor, we went above and beyond the law, creating a special system for handling lawful surveillance requests by the FBI and NSA. Unfortunately, the expanding volume of surveillance requests has overwhelmed this system, resulting in unintentional increases in latency experienced by surveillance targets. Our technical support staff is developing a solution..."
If the client is asking why the transaction or payment is delayed while the authorities investigate then the regulated company cannot mention the real reason and have to try and make up a lie or explain that some other entity is responsible for the delay and they don't know the real reason.
This is true in the UK at least and I assume you can see how it relates to the Warrant Canary concept. I will add that the tipping off offence is backed up with the threat of jail time for staff and directors in a company.
If they leave it up, and the truth eventually comes out, could they be sued for misleading their shareholders?
If they take it down does that open them up to being sued by the government?
(aside: Sorry for the downvote, my finger slipped up :/)
Edit: typo
I wouldn't be surprised if this wasn't the case and yes, one part of the government makes you do it, and the other one sues you for it.
What the customer gets out of that lie is none of the concern of the ISP.
Maybe a better solution would be a system that generated an indicator with only a certain level of assurance that it is accurate, and have it err on the side of NOT giving false positives. This would have a built in level of deniability.
Of course, this all assumes that this disclosure even comes to the government's attention. But that's a calculated risk any canary-user will take.
The only play on the government's part at that point, as far as I can tell, would be to acknowledge that the NSL did exist in order to prove that he was lying. They likely would not do this though, as it defeats the purpose of the gag order.
http://www.wired.com/threatlevel/2013/03/nsl-found-unconstit...
To me, the notion that the second shouldn't be possible is common sense. I find it hard to express how little it surprises me that you do not share this perspective.
Not that I agree with gag orders attached to warrants, mind you. But saying that it's just "stopping a process running on my computer" not "communicating information" is just wrong from an information theoretic point of view. Lots of things can be used as a semaphore to communicate information. I bet in other contexts (say insider trading), you'd agree that it doesn't matter whether some CEO tipped off his buddy about insider information by carefully varying load on a server to modulate response times on a web page, thus communicating bits of information.
I do not doubt that they have constructed for themselves a legal scenario that allows them to command warrant canary operators to lie. On the contrary, I am suggesting that they have with all likelyhood done exactly that.
The situation is constructed by the canary operator; the legal situation, the justification for commanding the canary operator to lie, is not constructed by the canary operator. As much as they would like to be, the canary operator is not in a position to dictate how the laws are written and interpreted.
If the canary operator were in a position to construct the legal situation, then there would be no cause for concern. However they are not, and cannot be.
Ah, but what if the CEO is just taking a long time to reply to emails from friends, because he is very busy preparing for some huge business move -- is it insider trading if one of those friends sets up an options position that profits from increased volatility? This gets down to the difference between a side channel (inadvertent) and a covert channel (deliberate). The distinction does not matter from an information theoretic point of view; the same information is communicated in either case.
If the intent was to communicate, I don't see how the fact that it's a side channel is relevant.
Now that, that is genius.
You can't game your way around that.. the court will care about outcome, not method.
let's say it is a potentially very effective idea for CIVIL DISOBEDIENCE..
emphasis due to you kind of missing the point - arguing about the legality of such a thing is pure misdirection imho
As best as I can tell, that is disclosing information.
a) you are able to signal that you did, or b) they compel you to lie and you then can press a "free exercise of religion" defense (this is where the 'right participants' part comes in; you'd have to be able to ensure the only people with the power to update the canary are (1) people that the NSL cannot be hidden from and (2) members of a religion that forbids lying).
I don't think so. Generally, the way it works in the US court systems is you have to break the law before you can challenge it in court. This means that, regardless of the eventual decision, you would have already revealed the NSL (or removed the canary), and the question is where you allowed to.
Same as if you claimed that, per your faith, you "have to" wear a yarmulke all the time, but it turns out you only wear it in courthouses that prohibit it.
But if a person practices a religion imperfectly, to propose that their continued attempts to live by it are null and void? That's ludicrous. Moreover, it would also constitute the government telling you specifically how to practice your religion, which is to my mind even worse than forbidding it in the first place.
(EDIT: minor continuity fix)
Also, it is (somewhat) well established in law that you cannot be compelled to break the law. If you are a company, it is illegal to lie and say, for example, you have not received NSL`s.
It's one thing to demand secrecy of people who are willingly agreeing to keep secrets so they can be issued a clearance. It's something entirely else to give secrets to an unwilling recipient who never agreed to keep them, and threaten to destroy their lives if they don't.
c) "You have signaled that you received an NSL and are therefore in violation. It's your own damn fault you were forced to choose between lying and breaking the law"
Also, if you are going to try to make a play against the letter of the law you need to be excellent at maneuvering the details, which this solution is not. The definition of "disclose the existence of" is not confined to explicit verbal or written behavior and this could by every definition be disclosing the existence of something.
Something that would have a better chance of holding in court would be to encrypt the NSA Requests for information in a file, host them publicly but "lose" the keys. It would be hard to prove that it was more than negligence.
Then there's the "loss" of the keys - another act that is highly suspicious depending on how well it's orchestrated.
Finally, any documentation or meetings where you are outlining these moves would be highly interesting in such a case.
Wink wink.
> I remember an interview where he talked about how much he enjoyed listening to the traffic outside his apartment.
I recall that video - here it is:
Cage’s silence is indeed imperfect (as in, you can hear the sound). Their point is that even a perfect silence is ‘Coloured.’ Quoting the article:
“He was asserting that the bits in his copy of 433.mp3 [silence created by a particular method] had a different Colour from those in a copy of 433.mp3 I might make by means of the /dev/zero procedure, even though the two files would contain exactly the same bits.”
This sounded quite weird and slightly crazy at first to me (and then author mentioned the experiment was done as a joke anyway), but I started to see it like a neat example of how factors such as knowing how the recording was made shape our listening experience.
I'm yet to finish the article, and want to thank StavrosK for posting the link.
That's not unique to binary at all, humans are only fleshy machines made of cells, cells are only collections of atoms and atoms are only energy. Of course the universe doesn't care about any of those distinctions, those distinctions are "just" colorings imposed by our worldview.
"The legality of this has not been tested in any court.[citation needed]"
I would imagine the kind of court that would test this concept would not be held under the eye of the public.Since no human actually read the contents, they didn't "collect" your communication, so you haven't broken the law.
Remember, they themselves set the legal standard so that you can have all of the data you want, but it doesn't count as you officially having it until you actually look at it!
"We only have the capability to record your activity on server X. Currently you are using server Y. Click here to be re-assigned servers."
In other words, if such a company got an warrant regarding a user, they would always handle that user on server X. Therefore, that user would be able to tell they were being monitored (to some % certainty) by refreshing their server assignment several times. If they were always assigned to server X, they could conclude that the company was probably trying to record their activity. A user couldn't be 100% certain because it would be possible that they were randomly assigned to X every time.
When the NSL comes, this system will disclose information, violating the NSL. So you are compelled by law to remove the trip wire. The third party periodically requests data from me, and notices the wire didn't trip.
What law was broken by the above scenario?
The normal reply would (hopefully) no. Otherwise it might be "no comment."
I believe this would absolve the contact in question from perjuring themselves under the fifth amendment and would be no different than those "our website is hackproof" badges that get sold.
If someone wants to run with the idea, I'm game.
my own take is each person asks individually (through a service) and the company is then forced to respond via an automated method (or set up an api) to deal with the deluge of requests (sound familiar?)
That's just my opinion though.
But since the purpose of this method is to effect civil disobedience, maybe the same end could be realized via different means. Hypothetically speaking, if a service provider kept a database of all NSLs received, but failed to strongly secure the database, leading to its access by an outside third party, this shouldn't constitute "communication". The database could perhaps be made accessible via a URL ("to enable remote workers to view and process NSLs" or some plausible justification) but protected by a weak password. An employee of that service provider could then secretly leak the password to a third party. Bad network security is not a crime, and unless the third party revealed that the password had been leaked, there would be no way to prove that it wasn't guessed or brute forced.
Fail deadly mechanisms go off unless they are explicitly told not to. During the cold war, Russia implemented fail deadly policies in an attempt to assure a retaliatory nuclear strike would go off even if most in power were taken out by a first strike.
(fixed that for you)
of course they have. For example, having corporate "document retention" policies that are actually destruction policies is usual to avoid risks associated with legal discovery.
And actus reus is a fairly critical technical element of the law. If a company has a policy of issuing (true) warrant canaries, the non-act of not issuing a (false) canary would be a significant technical hurdle to prosecution. And the 1st amendment would be a significant hurdle to coercing a person to issue (false) canaries.
For a 'regular' warrant, a provider can "confirm" or "deny" being served. Presumably they can "deny" being served a secret warrant if one hasn't been served, because the terms of a secret warrant presumably only require them to decline acknowledgement if they've been served, in which case they could "neither confirm nor deny", couldn't they?
What if you had a security vulnerability on a server which contains a record of NSL's/subpoenas (for administration purposes), which is conveniently exposed on the internet. A customer could "hack" your server, and obtain the information, thus it isn't the ISP's fault - in fact, the isp claims no knowledge of this vulnerability at all.
EDIT: Actually, they could simply include the hash of a recent block in the blockchain.
http://en.wikipedia.org/wiki/Raymond_Smullyan#Logic_problems
The whole premise rests on people being intimidated into not fighting it.
The participating companies were active participants in the spying scheme using the Patriot Act and FISA requests, not search warrants.