4 ms·
While I agree the canary should be considered dead on principle, I don't find this particular argument very convincing. I think the main point here needs to be
by dnbgfher 8y ago
While I agree the canary should be considered dead on principle, I don't find this particular argument very convincing.
I think the main point here needs to be that the entire notion of a canary only works if we can count on them being killed only for the purpose they were created. If it becomes acceptable to kill canaries because the signers are tired of signing them then we have a bit of a problem.
Now, for this specific case...
It sounds like you are arguing that a NSL has compelled them to make false statements. This seems fairly unlikely given what we know about the current legal situation. The idea that they may be lying for the sake of their business is more convincing.
However, if they are lying for whatever reason, why not just continue to sign the canary? The only plausible reason to do this is some sort of malicious compliance with a sloppily worded order compelling them to lie. It would make no sense for them to decide to lie for the sake of the business and then do all of this instead of just signing the canary.
If they have received a NSL this basically leaves two sequences of events, both of which contain some rather unlikely events. If I had to bet, I'd probably bet against them having received a NSL.
However, the canary should still be considered dead. They literally killed the canary. Their reasoning provided for it is really quite bad. Basically they ask users to trust their unsigned website because users already trust their (closed source) code. So they have either received a much more powerful NSL than thought legally possible, or are doing the worlds worst job of lying about not receiving a NSL, or they have not received a NSL and view a regular page on their website as a suitable alternative to their previous solution which involved three people in three different countries signing the canaries with keys stored on air-gapped computers. If you are counting on them for security, none of options are good.
- philipov 8y agoI think there's an argument to be made that the canary continuing to live is not sufficient to establish trust, for the reason you outlined. However, given that it is in fact dead, this is sufficient to revoke trust-- as you also pointed out, none of the scenarios are good for them. As for why they would kill the canary and then backtrack, I think a plausible story could be that the canary was killed by an engineer, and then the backtracking happened by management because they don't want to own the consequences. This could explain why there was a delay between removing the canary and putting out a cover story. Collectively as an organization, they're either acting in bad faith for whatever reason, or else they're incompetent.
- dnbgfher 8y agoI mean, a canary is only as good as your trust in the people putting it out. As for the engineer/management idea,their statement revoking it was signed the same as their canary. Aside from the exceptional circumstances I described earlier, if you trusted their canary then the statement should be trusted too. Like I said, I think we're most likely looking at incompetence.