9 ms·
GitHub's 2015 Transparency Report
- ademarre 10y ago0–249 National Security Orders received? > "we are not even allowed to say if we've received zero of these reports—we can only report information about these types of requests in broad ranges" Interesting. What are they really telling us with that range? Could they not get away with saying "1–249"? Edit: Nevermind. The document they cite[0] clears it up. [0] https://www.justice.gov/iso/opa/resources/422201412716042240387.pdf https://www.justice.gov/iso/opa/resources/422201412716042240...
- icehawk219 10y agoI believe this is what the security canary used to be that companies would use to skirt the rules until the rules were changed. It used to be that you couldn't say how many you received but you could say you hadn't received any. Now you aren't even allowed to say that.
- petercooper 10y agoHow does that work then? If I were American (I'm not) is it illegal for me to simply say or publish the sentence "I have received no National Security Orders"?
- Bartweiss 10y agoPresumably not. But it is illegal for you to say "I have received one National Security Order this year". Hence warrant canaries: they basically consist of creating a strong expectation of a (permitted) negative statement, such that its absence will be noticed. So far it's believed that you can't be compelled to maintain a no-longer-accurate canary against your will. edit: Wait, I see what you're referring to. [citation needed], because as far as I know warrant canaries remain legal.
- froh42 10y agoHoly shit. People in the land of the free discussing what they are legally allowed to say. Such tricks sound like stories from Soviet Russia that still linger around.
- deleted 10y ago[deleted]
- lettergram 10y ago"only for national security" just like Russia
- 86646 10y agoIn United States of America, government owns you.
- paulddraper 10y agoPeople have been discussing that in the USA since its inception.
- Bartweiss 10y agoSince when? Last I heard canaries were still going strong, although they're generally limited to one bit (letters: yes or no?) rather than any more detail.
- schneidmaster 10y agoNo, nothing has changed on that front. If you have not received any National Security Letters, it is legal for you to say "I have never received an NSL" (as other commenters have suggested). Warrant canaries rely on the idea that it is much more legally difficult to compel speech than to restrict it. There is no (non-secret) case law indicating that a NSL recipient could be compelled to lie and include the warrant canary paragraph in a future transparency report, while there is case law indicating that NSL recipients can be prevented from actively disclosing the letter (gag orders are fairly well-established in particular aspects of our legal system). The reason why warrant canaries are binary is that once an NSL has been issued, the case law that the parent commenter linked comes into play: companies may only indicate in buckets how many they have received (0-249, 250-499, etc). So you couldn't have your warrant canary say "I have never received more than 3 NSLs" then "I have never received more than 5 NSLs" etc.
- forgotpwtomain 10y agoSo what happens if you make a range of canaries? e.g. - We have not received any requests in Q1 of 2016. - We have not received more than 50 requests in Q1 of 2016. - We have not received more than 100 requests in Q1 of 2016.
- schneidmaster 10y agoIf I understand your scenario, the problem is that you would have to remove all the canaries as soon as you receive your first NSL. As soon as you receive a NSL, you may only disclose the number of NSLs you have received in the buckets I mentioned above, so you would not be able to say "we have not received more than 50/100 requests;" you would only be able to say "we have received 0-249 requests." So the canary still only works to tell people that you have never received an NSL.
- ChicagoBoy11 10y agoBut I think the "novelty" in his scheme is that he has separate canaries for different time periods -- so it may not be helpful in letting users know the number of requests received, but it would allow them to know when they had been received. Assume he had a scheme that just said the following: We have received no NSL letters in Jan 2016 We have received no NSL letters in Feb 2016 We have received between 0 and 249 NSL letters in March 2016 We have received no NSL letters in Apr 2016
- tibbon 10y agoThis confuses me too. I am allowed (as a private citizen or company who has never had an interaction with the feds) to say that I've had zero reports/requests like this right? Or is just uttering that a federal crime (did I just fuck up by saying that?) It would seem that it's perhaps illegal to say anything once you've gotten at least one of them, and they tell you that you can't do this anymore right?
- ChristianBundy 10y agoIANAL, but I believe you could say "I've had zero" until you get one, at which point you can only say "I've had between 0 and 249".
- tibbon 10y agoSo 0-249 really means, "probably at least 1, but I'm not allowed to say zero"
- lukasubo 10y ago0-249 probably means 249.
- andrewguenther 10y agoProbably not, per the official document[0]: > a provider may report aggregate data in the following separate categories: > The total number of all national security process received ... in the following bands: 0-249 and thereafter in bands of 250 [0] https://www.justice.gov/iso/opa/resources/422201412716042240387.pdf https://www.justice.gov/iso/opa/resources/422201412716042240...
- ioquatix 10y agoActually, 0-249 means -249 :D
- jstoiko 10y ago0-249 probably means 125.
- anonicode 10y ago> Edit: Nevermind. The document they cite[0] clears it up. That didn't exactly clear it up for me. Would you mind saying how that clears it up? Does it really mean 1-249 after all?
- espadrine 10y agoIt means in bands of 1000 starting with 0-999.
- chc 10y agoOr bands of 250 if you classify things a different way. It offers both options.
- euyyn 10y agoYes.
- ademarre 10y agoI still don't grok the dos and don'ts of NSLs and canaries, but that document establishes the origin of the range 0–249, which is expressly permitted. See also: https://canarywatch.org/faq.html https://canarywatch.org/faq.html I suspect they would not be using the 0–249 band if they were not gagged by a previous order. My uninformed interpretation is that they have received an NSL or FISA order, but not necessarily in 2015. So the 2015 number might be zero after all. Maybe someone more informed could confirm or debunk this interpretation.
- codezero 10y agoI noticed a bunch of DMCA takedowns coming from UCSD's CSE131 class in the DMCA repo: https://github.com/github/dmca https://github.com/github/dmca If you search for cse131 you'll find a bunch of repos still up. This kind of whack-a-mole is typical of DMCA and requires a lot of resources to manage.
- justinlardinois 10y agoThat's interesting. I can understand a professor wanting to control access to the starter code they provide to students, mostly to prevent cheating, but I've never heard of it coming with an explicit license. I know a few of my former UCSC classmates have school projects up on GitHub and haven't gotten any grief about it.
- codezero 10y agoYeah, I am pretty sympathetic to the instructor (a license is a license after all!), but at the same time wonder if the starter code and subsequent exercises being open makes the course too easy, and/or harder for the professor to grade aptitude, it may be a problem with the course itself.
- forgotpwtomain 10y agoI'm not sure what the point grading aptitude in intro courses even is though? Either you learn the material or you don't - in case of the later you are going to really struggle in upper level courses.
- justinlardinois 10y agoIn which case the department would much rather have your lack of learning cause you to fail the lower division course, so you either retake the course and learn the material or switch to a different field of study.
- Bartweiss 10y agoSpeaking from experience, it may not be a professor's concerns. Campus administration occasionally runs amok and specifies licensing and IP standards for individual courses out of fear of lawsuits, producing all sorts of weird results like this.
- jnewland 10y agoWhile we're here, http://www.nytimes.com/2015/03/31/technology/china-appears-to-attack-github-by-diverting-web-traffic.html http://www.nytimes.com/2015/03/31/technology/china-appears-t... also happened in 2015. Not a legal request to remove content, per-say, but something...slightly different.
- biogeneration 10y agoDoes anyone have any idea what happened with all of the DMCA takedown requests in September?
- zardeh 10y agoAmong other things, someone sent 20 requests for removal of their fonts (each request contained numerous files), and jetbrains requested the removal of ~500 product keys from across GH.
- voltagex_ 10y agoIt looks like JetBrains got a whole lot of keygens removed, plus one poor person's Hadoop demo code (which happened to have a filename of keygen.java).
- embiggen 10y agoAt least they still publish it. That's worth something, right?
- ghettoimp 10y agoSince nobody else has mentioned it, let me just point out that it's really great that Github is taking the time to compile and publish this kind of information.
- mtgx 10y agoThe FBI is trying to make it easier to give out NSLs as well: http://www.wyden.senate.gov/news/press-releases/wyden-places-hold-on-intelligence-authorization-bill-that-needlessly-expands-fbi-surveillance-undermines-independent-oversight http://www.wyden.senate.gov/news/press-releases/wyden-places... Contact your Senator/Representative if you don't want that to happen. Even though a similar amendment failed in the Senate last week, it was a close call. Also, next there they are supposed to vote on the renewal of the FISA Amendments Act, and I'm sure they'll try to further expand their spying powers some more then, too.
- ryanmarsh 10y agoOh my god the "fast die" take down request from Russia. Is that a real business? https://github.com/github/gov-takedowns/tree/master/Russia/2015 https://github.com/github/gov-takedowns/tree/master/Russia/2... http://fast-die.github.io/ http://fast-die.github.io/
- ComodoHacker 10y agoYou mean request or Fast-Die? The former is a real business. The latter is an example of trolling of Russian internet censorship agency.
- danbmil99 10y agoI don't get why employees don't leak the real stats anonymously. Perhaps companies should not try so hard to compartmentalize this information - trust 40 or 50 key people, enough to spread suspicion and enable plausible deniability. When a law is clearly unethical, don't work so hard to abide by it.
- anchpop 10y agoThe government could easily prevent that by punishing the company whenever there is a leak, instead of trying to punish the specific person. This may be what they do already
- nitrogen 10y agoUnfortunately (or fortunately?) not everyone cares whether their actions harm their employer.
- olalonde 10y agoIf the stats were leaked anonymously, how could we tell it was a legitimate leak versus some random troll?
- hartator 10y ago0-249 for national security orders. I think it's safe to assume 249.
- mod 10y agoIf you read elsewhere in the comments here, you'll see that it's not a safe assumption at all--"0-249" is the specificity allowed by the law. Your assumption was also my own until reading here.
- Sir_Cmpwn 10y agoIf any GitHub folks are watching this thread: please sue the government for the right to disclose the number of NSLs you've received, or better yet to have NSLs declared unconstitutional in general.
- nsqe 10y agoTwitter's already suing the federal government for the right to disclose NSLs. In March, their lawsuit was dismissed. However, the EFF is still working on it... https://www.eff.org/deeplinks/2016/04/disappointing-ruling-national-security-letters-not-last-word https://www.eff.org/deeplinks/2016/04/disappointing-ruling-n... http://thehill.com/policy/technology/278448-judge-dismisses-twitters-lawsuit-against-government http://thehill.com/policy/technology/278448-judge-dismisses-...