10 ms·
Be that as it may, isn't this still an unacceptable collateral damage? So when you contribute code to an open source project, you generally do so under an open
by plq 4y ago
Be that as it may, isn't this still an unacceptable collateral damage?
So when you contribute code to an open source project, you generally do so under an open source license. All of them generally contain something akin to the following:
IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE
LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES
(this particular excerpt is from the BSD license)
I can understand taking action against the people who run the code. I can even understand taking action against people who were hired to contribute. But why kick some random open source contributor in the guts? What did they do wrong?
Are there open source licenses that protect the contributors from such unforeseeable damage? Or are we to watch our step from now on as open source contributors?
- throwawaylinux 4y agoWhy is it unacceptable?
- ensignavenger 4y agoThe US Constitution provides protection against ex post facto laws. A retroactive punishment is unconstitutional. It may be argued that these github accounts did not belong to us citizens and thus were not protected. Or it may be argued that Microsoft was doing this of their own freewill and therefore the constitutional prohibition does not apply. But there is generally within the American psych a distaste for retroactive punishments such as this.
- salawat 4y agoThis is not an act of ex-post facto lawmaking by a legislature. This is the executive doing what it has been tasked with doing under a mandate supplied by Congress in accordance with it's role as laid out by the Constitution. The Courts are not likely to be swayed by this argument. I doubt the legislature will touch anything that enables money laundering with a 12 foot pole. The novelty here is that prople are being forced to realize how destructive getting sanctioned is due to bearing witness to the power of the network effects involved. This was inevitable, no matter which way you cut it.
- ensignavenger 4y agoI was not making an argument in front of courts, I was stating why many Americans may find this action distasteful. As far as I can tell, the executive branch was not mandated to delete anyone who contribted to/was a "member" of the github tornado dev group.
- throwawaylinux 4y agoLots of things that some find distasteful are accepted though. Recently, along a similar vein, the whole "they're private companies, they can censor who they like" crowd made that clear. Hopefully none of them will be surprised or upset by this action.
- salawat 4y agoThe executive was mandated to produce a list of individuals that can be consumed in oan actionable way by industry, such that it can prevent access to the U.S. financial system. It did exactly that. These companies got that list, their legal, risk, and compliance departments got in a huddle, and they laid out an action plan to try to get ahead of the regulatory action, while minimizing any risk of contamination or liability. The government did not tell them to do that. Note, this is by design. The government telling them to would be unconstitutional. Rather, they acted in their own way, which to them rang as reasonable. That is how it rolls. Is it fair? No. Is it right? Arguably not. Is it concerning? Hell yes. It is what it is though.
- kube-system 4y agoSoftware licenses are a civil agreement between a developer and anyone who uses the code. So for instance, if someone uses code with that disclaimer, and it deletes their files, you cannot sue them for that damage. But, you can’t just put anything in one of these agreements; the law overrides anything you might state in a contract. Furthermore, software licenses govern the use of your code by other people. It doesn’t govern your use of the GitHub service. Your use of GitHub is governed by the GitHub ToS. Under that agreement, they can terminate service for any reason they want. They can cancel your account if they wake up grumpy on a Tuesday and just feel like it. Or, they can terminate service because they don’t want to touch anything that might be sanctioned with a 10 foot pole.
- bad416f1f5a2 4y agoThat license binds people who use the code you wrote & protects you from their legal claims. OFAC isn’t using your code. No open source license is going to protect you from US sanctions. From the Twitter thread it appears that the devs whose accounts were nuked were core contributors to a sanctioned entity. That feels fairly sensible & what a company who wants to comply with sanctions would do.
- baobob 4y ago> What did they do wrong? They wilfully contributed to the upkeep of a money laundering service. They should be thankful losing their GitHub account is the extent of the fallout, take it as a lesson that code can cause real harm, and act more judiciously in future when it comes to contributing labour to suspect projects.
- JohnJamesRambo 4y agoThere are so many other applications for Tornado Cash than “money laundering.” What if I don’t want my employer or friends to see what I do with my known wallet on a fully traceable public blockchain? Privacy is not illegal.
- PeterisP 4y agoWell, no matter what other applications for Tornado Cash may exist, since yesterday it is illegal to interact with Tornado Cash or assist them in any way for anyone within reach of USA jurisdiction. That's it. Privacy as such is not illegal, but that does not mean that government may not prohibit certain specific ways of achieving privacy.
- JohnJamesRambo 4y agoYes what you are saying is true and it is our right and duty to protest that decision. When will they sanction something you do like and need like Signal or cryptography? Are they aware of all the bad that comes about via http? Or cash?
- PeterisP 4y agoWell, the big legal limitation for these sanctions is that they apply only 'across borders' as OFAC can only sanction foreign entities (e.g. in this case asserting that TornadoCash-as-organization/project is controlled by North Korea), prohibiting U.S. citizens and companies from dealing with or assisting that foreign entity.
- PeterisP 4y ago> What did they do wrong? The argument probably is that they assisted a sanctioned entity by providing a contribution i.e. service to it. Quoting US Treasury "These prohibitions include the making of any contribution or provision of funds, goods, or services by, to, or for the benefit of any blocked person and the receipt of any contribution or provision of funds, goods, or services from any such person." However, the major factual question is whether they did violate any sanctions since the contributions generally were made before the sanctions were in effect - it's not that Github had to do it, but that they chose to be safe rather than sorry (in order to ensure that Github themselves don't violate the sanctions) and if they aren't absolutely sure they blocked people. [edit: apparently not everyone, some contributors are not blocked, so they apparently did some review before choosing whom to block] The key issue is that any collateral damage is considered acceptable, but any false negatives are absolutely not. If Github leaves even one actual agent of TornadoCash unblocked, Github has committed a crime, if they block a hundred unrelated accounts, that doesn't violate anything. > Are there open source licenses that protect the contributors from such unforeseeable damage? No, a contract or license can't absolve you from this prohibition if it applies to you. > Or are we to watch our step from now on as open source contributors? Yes, but not "from now on" but since before open source existed. There are entities you are not allowed to contribute to, and it's your responsibility to know and check who you are dealing with.
- dingleberry420 4y ago> The argument probably is that they assisted a sanctioned entity by providing a contribution i.e. service to it. And what if they did so before the sanctions? Is the US so happy to retroactively punish people who literally did nothing wrong?
- JumpCrisscross 4y ago> people who literally did nothing wrong? What on earth did people think a tumbler like Tornado Cash was going to be used for and by?
- dingleberry420 4y ago
- bluGill 4y agoProbably not to GitHub or the courts. If in a few years it is discovered that GitHub missed something they can tell the courts "We did our best to comply, look at all the accounts we killed [and other evidence], so go easy on us for an honest mistake." In general the courts look kindly on someone who tried their best to obey the spirit of the law but missing one hidden detail. If you are affected you could take this to court, and might even be able to convince them that the law went too far in incentivizing GitHub to delete your account. It seems very unlikely, but with a good lawyer courts can do weird things. If you do pull this off, then that would change court precedent, and when combined with a few dozen other cases eventually make it so courts will not accept deleting all accounts as a useful to to prove attempting to comply with the law. (Let me be clear, I doubt you could win this case, but it is theoretically possible so I offer it for completeness sake)
- bad416f1f5a2 4y ago> Probably not to GitHub or the courts. If in a few years it is discovered that GitHub missed something they can tell the courts "We did our best to comply, look at all the accounts we killed [and other evidence], so go easy on us for an honest mistake." In general the courts look kindly on someone who tried their best to obey the spirit of the law but missing one hidden detail. This matters a great deal when it comes to OFAC sanctions. The value of sanctions isn't "OFAC chasing down people on the SDN list", it comes from companies following federal law and blocking transactions that legally need to be blocked. And OFAC recognizes this – just look at their enforcement actions[0] and you can see examples where companies that build internal compliance programs and self-disclose violations come out with limited to no penalty[1], whereas companies that skirt compliance regimes place themselves at much more risk[2]. [0]: https://home.treasury.gov/policy-issues/financial-sanctions/civil-penalties-and-enforcement-information https://home.treasury.gov/policy-issues/financial-sanctions/... [1]: https://home.treasury.gov/system/files/126/20220721_midfirst.pdf https://home.treasury.gov/system/files/126/20220721_midfirst... [2]: https://home.treasury.gov/system/files/126/20201020_berkshire.pdf https://home.treasury.gov/system/files/126/20201020_berkshir...
- UncleEntity 4y agoTwo things I see here, a copyright declaration doesn’t protect you from law enforcement actions and publishing source code is a clear example of free speech. So you have to figure out for yourself if exercising your right to free speech is worth having the government blowup your life for the time it takes to “prove your innocence“. Because, I can assure you, they don’t care even a little bit about violating your constitutional rights if it gets in the way of whatever witch-hunt they are currently on. It’s the court’s job to sort those details out.