18 ms·
US Treasury FAQ on Cyber-Related Sanctions
- toomuchtodo 4y ago> While engaging in any transaction with Tornado Cash or its blocked property or interests in property is prohibited for U.S. persons, interacting with open-source code itself, in a way that does not involve a prohibited transaction with Tornado Cash, is not prohibited. For example, U.S. persons would not be prohibited by U.S. sanctions regulations from copying the open-source code and making it available online for others to view, as well as discussing, teaching about, or including open-source code in written publications, such as textbooks, absent additional facts. Similarly, U.S. persons would not be prohibited by U.S. sanctions regulations from visiting the Internet archives for the Tornado Cash historical website, nor would they be prohibited from visiting the Tornado Cash website if it again becomes active on the Internet. This is very reasonable! It balances economic sanctions around money laundering and transmittal with freedom of speech.
- staringback 4y ago"You're allowed to talk about this speech, teach it in textbooks and include it in other written publications, but you're not allowed to actually speak it"
- colinmhayes 4y agoExecuting code isn't speech. Code is speech, and it's being allowed.
- staringback 4y ago> Executing code isn't speech This is for the courts to decide I guess
- makoz 4y agoReally? If I execute a script that DDoS someone, presumably it should not be treated as "speech" as if it is a protected right. That's such a hilariously slippery slope since you can arguably do "anything" via executing code.
- arthurcolle 4y agoNah your example is more like performing a magic spell that prohibits others from speaking (DDoSing a public service site, as an example)
- nradov 4y agoDenial of service attacks are explicitly illegal under the National Infrastructure Protection Act (NIIPA). I don't think a defendant has ever successfully challenged that law on First Amendment grounds, so the basic legal issues appear to be settled. Of course as a practical matter it can be difficult to prosecute DDoS attackers under that statute. Either they don't leave hard evidence, or they hide in countries which don't extradite.
- CrazyStat 4y agoCourts have already decided this decades ago. At least as far back as Junger v. Daley [1], where the courts recognize a distinction between the expressive power of code as it is read by a person and the functional power of code when it is executed. While the expressive power of code creates a first amendment interest, the functional power of code may create a legitimate government interest in regulating that speech. The applicable legal test is from United States v. O'Brien [2], which ruled that even though burning a draft card may be expressive speech, the government's interest in draft cards not getting burnt allows them to forbid it without falling afoul of the first amendment. Junger v. Daley was cited as precedent in Universal City Studios v. Reimerdes [3], where the courts ruled that the functional power of DeCSS being illegal under the DMCA was sufficient to justify banning the distribution of the DeCSS source code. [1] https://en.wikipedia.org/wiki/Junger_v._Daley https://en.wikipedia.org/wiki/Junger_v._Daley [2] https://en.wikipedia.org/wiki/United_States_v._O%27Brien https://en.wikipedia.org/wiki/United_States_v._O%27Brien [3] https://en.wikipedia.org/wiki/Universal_City_Studios,_Inc._v._Reimerdes https://en.wikipedia.org/wiki/Universal_City_Studios,_Inc._v...
- vkou 4y agoIf speaking magic spells aloud caused flesh-eating demons to be summoned into our prime material plane, you wouldn't be allowed to speak magic spells, either. Klaatu, Verata, Necktie. Speech is speech, code can be spoken, and it can also be executed. The former is speech, the latter is action. Making API calls and flipping bits in a computer is what crosses the line from one to the other.
- cercatrova 4y ago> If speaking magic spells aloud caused flesh-eating demons to be summoned into our prime material plane, you wouldn't be allowed to speak magic spells, either. Yes? This is entirely reasonable if we analogize it to how fiction often approaches it. There might be some evil book, a necronomicon, or killing spells like in Harry Potter. In many fictional media, people are allowed to learn such spells, they're just not allowed to say the spells out loud. Reading and writing a spell is not the same as saying it and thereby executing it.
- yieldcrv 4y agoOkay that solves the First Amendment part, in your view (Citizens United is an example of ruling that transactions are speech, alongside its view that Corporations are afforded these protections) It doesn't solve Congress’ mandate to the Treasury where OFAC is used against entities that can appeal their own listing on the sanctions list. The smart contracts cannot currently do that.
- colinmhayes 4y agoCitizens united is unique because it is specifically about political actions which are the whole point of the first amendment clause about speech according to originalists. You've also mischaracterized the ruling, which was that spending money on political action is speech, not transactions.
- acdha 4y agoThat’s not right: you can even run the code as long as you don’t transact with the sanctioned parties. Matt Green could run a copy for his students to study as long as they don’t allow transactions which violate the sanctions laws, similar to how I can teach you to pick locks and practice but still expect legal consequences if I pick the locks at some stranger’s house.
- morpheuskafka 4y agoI'm not that familiar with this code, but if only specific wallet addresses and websites can be blocked, is there anything that stops people from just repeatedly cloning the service altogether and playing whack-a-mole with the government?
- notch656a 4y agoThat's the same argument I've presented below. The best response I've gotten so far is that there is basically 'precedent' for dealing with that of sanctioning the offender. Precedent is a nearly 3 year lag time... although I'm sure it won't take that long the next time
- acdha 4y agoI think it's important to remember that the government agencies ignored cryptocurrency for a while because it wasn't being used enough to be worth dedicating resources to it. That changed at some point, with different thresholds for different agencies, but now they're aware of the activity and there are services like Chainalysis which make it easy for them to contract for monitoring as a service. I would bet that the time to respond is going to get increasingly fast since there's been a push for ransomware which picked up after that Colonial Pipeline attack and really picked up with the news that North Korea was laundering significant sums. There are two things which I think will change that game substantially: 1. As this is taken more seriously, companies trying to stay in compliance with the law are going to be enforcing KYC strictly. That's going to make it harder to use things like tumblers because not only will you be paying more to use the service but you'll also be getting tainted tokens which an increasing fraction of businesses either won't accept at all or will accept at a discount rate to compensate for the decreased utility. I think that ratchet effect is going to really limit future services like Tornado Cash: when there's a non-trivial risk involved for using it fewer people will participate and those who do will expect to be paid more. 2. These services depend on liquidity because anonymity is a function of how many people are running money through it. The Treasury department doesn't really care if you and and a few curious friends set up a proof-of-concept instance because unless you can also pump the equivalent of millions of dollars into the system it won't be used by the people they're concerned about (ransomware gangs, North Korea, etc.) since it would take millennia to launder money at their scale. This is similar to how the goal for counterfeiting paper money isn't set to “impossible” but rather accepted at a low frictional level as long as it's too risky for anyone to attempt a sufficiently large-scale counterfeiting operation which could actually impact the overall economy.
- smsm42 4y agoYou allowed to speak it, you're not allowed to run actual transactions involving actual Tornado Cash funds through it. If you run this code on your property, it won't be Tornado Cash anymore, and as long as it doesn't interact with the prohibited properties, it's not prohibited. Of course, if you start doing the same TC did, you probably will get your very own designation pretty fast.
- yieldcrv 4y agoOkay so the registrar and github and others should all come back up Everyone was being paranoid about assisting a sanctioned somebody
- deleted 4y ago[deleted]
- miracle2k 4y agoGithub deleted these repos because they represented a business relationship on their part with the sanctioned Tornado Cash entity, not because they considered the code itself illegal. Other copies of the code have not been deleted by Github.
- notch656a 4y agoAfter reading OFAC's materials at least twice over, I still have no clue what the 'entity' TORNADO CASH even really is.
- A4ET8a8uTh0 4y agoI am of two minds about it, but overall I agree. It is good that Treasury clarified their position ( because heavens know it is hard to divine sometimes what they want to achieve given recent Biden's stance on crypto ). For once that FAQ seems relatively straightforward. Did open source ( and crypto ) become so important that Treasury got concerned about the rumblings ( because this story was making a long of news in banking )? I am genuinely curious what caused it.
- metacritic12 4y agoSeems like a forced defensive move given the new Coinbase sponsored lawsuit. Treasury would probably prefer these freedom aren't even given, but they'll lose on these points so badly that it's face-saving to concede first.
- salawat 4y agoNot really, I'd rank this as "saying the obvious stuff to get it done and over with". Treasury knows it has standing, and how. They don't give a squib what you do with the code. As long as you don't facilitate transaction processing with it (i.e. money transmitting) with it. The legal teams of the Crypto world basically have to convince the Supreme Court that the Executive does not have the right to engage in economic foreign policy. I don't see that happening.
- DennisP 4y agoHere are Coincenter's arguments that OFAC actually has exceeded their authority: https://www.coincenter.org/analysis-what-is-and-what-is-not-a-sanctionable-entity-in-the-tornado-cash-case/ https://www.coincenter.org/analysis-what-is-and-what-is-not-...
- buildbot 4y agoAre they lawyers who specialize in Federal law and financial crime?
- woodruffw 4y agoThe argument advanced here is perverse: you can’t erase the illegality of an action by making it autonomous. In other words: putting a brick on the car’s accelerator doesn’t absolve you when the car runs someone over — the law recognizes that a human or set of humans is the efficient cause of the crime, regardless of how much code (or steel) you obscure it with.
- notch656a 4y ago
- notch656a 4y agoI read the sanctioned SDN List. Am I reading incorrectly that if someone merely created a new TC instance with new addresses and website, it would not violate sanctions? I don't see the sanction list sanction the actual code, nor the execution of the code, but IANAL. The SDN here just shows the associated addresses, the published contract instance, and tornado cash website, no? https://home.treasury.gov/policy-issues/financial-sanctions/recent-actions/20220808 https://home.treasury.gov/policy-issues/financial-sanctions/...
- vorpalhex 4y agoIf you run the code in a way that nobody can interact with it.. that probably isn't a crime (not a lawyer). If you facilitate money laundering, that is still illegal.
- notch656a 4y ago>If you facilitate money laundering, that is still illegal. If that is your intent, then sure. But merely mixing funds does not meet the criteria for money laundering. The road crew who builds the interstate knows 100% it will be used for money laundering, yet builds it anyway and does nothing to stop it. (Same for guys at the gas station who sell the gas). Surely knowing money launderers use something isn't enough to be criminally culpable. >If you run the code in a way that nobody can interact with it. IANAL and not legal advice, but it looks to me though that a fresh published contract of TC to new addresses doesn't violate this SDN list, even if it interacts with others.
- rmah 4y agoIf you are moving money around on behalf of others and you have a reasonable belief that some of your users are Americans or will eventually deal with American financial institutions (pretty much everyone in the world), then you should have AML (Anti-Money Laundering) and KYC (Know Your Customer) processes in place. Not doing so is just asking for trouble. When you are eventually investigated by the authorities, saying "we didn't ask so we didn't know" is not considered a valid defense. More to the point, crypto mixers are obviously being used to hide the origin of funds. This is money laundering in the colloquial sense. Whether it reaches the level of criminality will obviously depend on a case by case basis. Running a mixer is, IMO, a very very dangerous road to go down.
- shiado 4y agoWith FinCEN Notice 2020-2 it's clear that the US wants to treat crypto as foreign bank accounts to coerce disclosure but that severely limits the scope of regulation they can do as it would place public blockchains as strictly not being American jurisdiction, and it would make monitoring American activity on these blockchains outside of the scope of domestic agencies and spy agencies would not be legally able to spy on American activities on these blockchains. When you understand these facts it explains why the US pursued dubious NK sanctions over what would be a much stronger case of considering the Tornado Cash protocol an unregulated bank which it is. There is a very big technical and legal distinction between what centralized BTC mixers do with UTXOs to be considered laundering and how the Tornado Cash protocol exploits how ETH works on-chain to combine ETH in a single account without taking KYC.
- polygamous_bat 4y ago> it would make monitoring American activity on these blockchains outside of the scope of domestic agencies and spy agencies would not be legally able to spy on American activities on these blockchains. I am genuinely not sure, is it still "spying" if the information is public for anyone and everyone to see? If I publish an attested list of my daily foreign transactions on my blog, I don't see why the government can't use that to prosecute me just because the website may be hosted offshore without it being considered "spying".
- legutierr 4y ago> considering the Tornado Cash protocol an unregulated bank which it is This is a very strong statement to make without also making a legal argument to back it up. Just because you assert that it is a bank does not make it so. What precedents, statutes and regulations would you cite to support your assertion?
- x-complexity 4y agoSeconded. The actions that can be done with Tornado Cash are specific & finitely-defined: Even if it could be translated into regular banking terms, what Tornado does is not something that a normal bank does, & what Tornado provides is nowhere near the functionality that a regular bank performs for its depositors/lenders.
- diebeforei485 4y agoThis is fairly unclear. Can I run this code on my machine? What about contributing to it?
- polygamous_bat 4y agoFrom TFA: > While engaging in any transaction with Tornado Cash or its blocked property or interests in property is prohibited for U.S. persons, interacting with open-source code itself, in a way that does not involve a prohibited transaction with Tornado Cash, is not prohibited. So I would imagine running this code on your own computer is entirely fine, since I see no possibility of you executing a "prohibited transaction" with it.
- diebeforei485 4y agoWhat does "involve" mean? Running the code for any sort of crypto project typically involves doing some verification work for the other transactions on the chain, one or more of which might be prohibited.
- lizardactivist 4y ago
- politician 4y agoMu.
- lizardactivist 4y agoMuh*
- NegativeK 4y agoThe discussions on this seem to be fixated on the implementation details, when lawmakers tend to focus on results. The desired result is for people to stop laundering money for sanctioned groups. How the Ethereum network does that isn't of particular interest to the law (yet), but "it's not designed to let us stop that!" isn't going to be an excuse. Somewhat related, I'm not sure how anyone didn't see this coming from a mile away.
- StanislavPetrov 4y ago"We must restrict the freedom of Americans so we can better restrict the freedom of people we say are bad". What's more important, the freedom of Americans or the possibility that North Koreans or other "bad" people on the other side of the world can escape the edicts of the US government? Personally I'm far more concerned with the former than the latter. I'm far from alone in thinking that we should massively downsize the federal government and strip them of most of their powers.
- miracle2k 4y agoWe all want results, but implementation details matter, particularly in law. The suit is merely saying that if law makers want to give OFAC the authority to sanction the Tornado Cash smart contracts, they have yet to do so.
- null0pointer 4y agoSo will GitHub reinstate the repository?
- UtopiaFans 4y ago