11 ms·
Decentralized storage company Storj removed their warrant canary
- labria 4y agoAccording to web archive, it happened somewhere between October and mid-November: The last time it was up: https://web.archive.org/web/20221021050048/https://www.storj.io/canary.txt https://web.archive.org/web/20221021050048/https://www.storj... The first time it's gone: https://web.archive.org/web/20221114070255/https://www.storj.io/canary.txt https://web.archive.org/web/20221114070255/https://www.storj...
- MitPitt 4y agoThere should be a public canary watcher, to notice dead canaries sooner.
- batch12 4y agoThe feeds could also be delivered via rss.
- World177 4y agoIt looks like the EFF had one. [1] Though, the website currently does not load, and from archive.org, it looks like they killed the project sometime before July 2021. [2] [1] https://www.eff.org/deeplinks/2016/05/canary-watch-one-year-later https://www.eff.org/deeplinks/2016/05/canary-watch-one-year-... [2] https://web.archive.org/web/20210712025824/https://canarywatch.org/faq.html https://web.archive.org/web/20210712025824/https://canarywat...
- kmoser 4y agoWe would have known this sooner, if only somebody had built a warrant canary canary canary.
- pacificmint 4y agoAt that point, you pretty much have to write it in Java. :)
- deleted 4y ago[deleted]
- deleted 4y ago[deleted]
- jsjohnst 4y agoHas the use of warrant canary’s ever been tested in the US courts, especially with an NSL (or whatever they are called these days)? I don’t ever remember a case, but maybe I missed it.
- woodruffw 4y agoNot to my knowledge. Signal's stated position is that it wouldn't hold legal water[1], although the EFF disagrees. [1]: https://web.archive.org/web/20141027143819/https://github.com/WhisperSystems/whispersystems.org/issues/34 https://web.archive.org/web/20141027143819/https://github.co...
- dane-pgp 4y agoWhat would "tested in the US courts" look like? Would the federal government take an entity to court, demanding that they put their warrant canary back up, as a form of compelled speech? No, I don't think there's been an example of that happening, but perhaps we would expect that if the government wanted to bring such a case, they would use a secret court, or an NSL, which would likely result in the warrant canary being added back to the site before anyone noticed. (An injunction against removing the canary could even be included in the initial secret warrant).
- apendleton 4y agoThe injunction against removing it wouldn't compel them to update it, though, right? In this one they promise to post a new one every month, so even if you're forbidden from removing the current one, unless they force you to create new updates, people would still notice when the current one "expires" without having been updated (and if that turns out to hold legal water, no reason you couldn't post new ones arbitrarily often -- daily, say).
- autoexec 4y ago> The injunction against removing it wouldn't compel them to update it, though, right? In the US the government can take over parts of your facility, and that could mean installing whatever equipment they want or even setting up camp and running ongoing operations on location. They'd have no problem updating the canary of a company who refused to keep doing it themselves. I doubt most business owners would risk losing everything on top of prison time though. The best we can probably hope for is that they'd decide to simply close shop like these guys did: https://www.eff.org/deeplinks/2013/08/lavabit-encrypted-email-service-shuts-down-cant-say-why https://www.eff.org/deeplinks/2013/08/lavabit-encrypted-emai...
- incompatible 4y agoSo what should the users do, switch to another provider that still has their canary up?
- deleted 4y ago[deleted]
- ramraj07 4y agoNo, give up on any cloud storage solution if you give a crap about this stuff..
- xref 4y agoAt the very least encrypt your data with your own tool of choice before uploading, so you’re not just using the provider supplied encryption
- yieldcrv 4y agoWhy would it matter in the storj system? I haven't caught up with them, did they ever decentralize the coordinator or whatever would it even be about the data uploaded? there are so many free options I’m over this
- mbg721 4y agoThe only winning move is not to play.
- deleted 4y ago[deleted]
- dvzk 4y agoWhat utility does that provide? In time the other provider will be issued a different warrant. The user threat model for every online service ought to include legal and illegal data seizure. Any imaginary nation which doesn't perform this legal function would simply be giving a mandate to adversarial actors to obtain the data by force and espionage.
- roxgib 4y agoI guess it's more about protesting and trying to fight the existence of secret warrants than any practical benefit for users? Which I think is fine if it's the best they can do.
- googlryas 4y agoIf the government can compel you to not talk about something, can't they compel you to not modify your warrant canary?
- woodruffw 4y agoThe argument goes that the government might be able to compel you not to speak, but they cannot compel you to speak against your wishes (and, in particular, to lie). The precedent supports that to some degree, but it's really not clear.
- MacsHeadroom 4y agoWarrant canaries need restated and re-signed regularly, daily in this case. That is what makes them canaries as opposed to something like a transparency report. The government probably can NOT compel you to re-sign and update an expired canary, at least according to the lawyers at the EFF.
- squokko 4y agoIn any case, you could probably tie up the dispute in courtroom process for more than 24 hours.
- AH4oFVbPT4f8 4y agoExactly, they (government) can ask you to continue to update, you decline, they sue to force the issue. Highly unlikely the courts rule so quickly that at least one day goes by without an update. This is the signal something has happened.
- whistl034 4y agoDo you think they would be in trouble if, sat 3 months in the future, they started saying they had not received any NEW warrants in the past 3,4,5,X months?
- Mistletoe 4y agoCan we please repeal the Patriot Act or Freedom Act or whatever it is called now? It’s been a one-way ticket down the toilet since this travesty was foisted on the stupid scared populace of 2001. I really frame my life in America in two sections, before and after the planes hit the Twin Towers. Not because of the tragedy which it was, but because that is when the America that I know changed and started becoming twisted. Optimism gone, privacy gone, thinking gone, replaced by fear and ignorance and lowest common denominator politics and TV.
- TheDesolate0 4y ago[dead]
- deleted 4y ago[deleted]
- dclowd9901 4y agoWhen the act was first passed, most of us really wanted some kind of sunset provision to be included. At the very least “once the wars in Afghanistan and Iraq came to a close” clause. You could already, even then, see federal agencies salivating at the carte Blanche lack of oversight.
- hprotagonist 4y agoi used to think it was 9/11; lately i’ve come to realize that, no, it’s just that i wasn’t alive for the same bullshit that has come before.
- autoexec 4y agoI do think that we crossed some lines post 9/11. It's likely that the US had always been violating the constitution by spying on American citizens, or were engaging in torture or secreting people off to black sites and indefinitely detaining them without trial, but after 9/11 it was all out in the open. It was sanctioned by the government. It became policy. In the decades before 9/11 the US government had the decency to lie to the American public about it. They told us that America was so great because it would never do those kinds of things. Those types of activities were held up as examples of horrible atrocities communist nations subjected their citizens to. Even as evidence came up from time to time showing that the US government didn't always live up to those ideals they continued to be expressed as what this country stood for. Post 9/11 that was no longer the case. This might be a more honest American government, but I can't help feeling like we've lost something.
- rvnx 4y agoIt could also just be a glitch as it appears it is a script that generates the .txt (and fetching external text / news as content). In NSLs, you are not allowed to reveal the existence of the request. Removing the warrant canary reveals the existence of the NSL. Sometimes courts also prohibit you from revealing that you gave away user account information to the police. In theory, using the (incorrect) logic of the canary warrant, you could publish a list of all user IDs and say "The police never requested the user information for these IDs below:", but this seems very gimmicky in front of a judge. At the end of the day, a company that is actually subjected to NSL wishes has very little reasons to remove a canary warrant. 1) They cannot be sued for lying in their canary warrant as this was a properly formed court request. 2) It is good marketing for them. 3) They risk significant criminal charges for no benefits. They really have no incentive to do so.
- bhaney 4y agoIf it was a glitch, I'd expect that they'd have fixed it by now to avoid the implications and potentially lose customers over it. Surely over the course of the month+ that it's been missing, they would have noticed it or had it brought to their attention?
- liamwire 4y agoGiven the way this warrant canary works, in that it’s published daily, wouldn’t the government instructing that you cannot opt to stop publishing the canary equate to compelling speech, and be a fairly clear path to a First Amendment violation? I ask this as a total outsider to both the United States, and US law.
- MacsHeadroom 4y agoYes, and this is the entire premise of warrant canaries. The GP is wrong and you are correct. Disclaimer: IANAL
- rtpg 4y agoImagine you are a 5 year old child, and the judge is your parent. You think that this argument would work for them? Trying to logic bomb your way out of this is just asking for a summary judgement against you. It doesn't matter if it's not logically consistent, most rulings aren't! They will simply ignore this argument. The counter to the "compelled speech" argument is that the government is not the one that forced you to start doing warrant canaries! You started doing warrant canaries, the gov't wouldn't ask for a remedy of you putting up continued canaries. You put the onus on lying on yourself, and if you don't do it you'll just be charged with revealing the facts. Government demanding you to compel speech is not what would happen.
- roxgib 4y agoIt would be interesting to see a company implement this on the individual account level, rather than for the service as a whole. As it stands, while certainly interesting from a legal standpoint, I'm not sure this achieves much other than confirming that secret warrants are in use, and perhaps giving some vague indication of their frequency.
- fathyb 4y agoI believe they can't because of the legality, it would remove the secrecy of the warrant. The canary allows a company to imply they got searched without breaching the secrecy. In this case, information got removed, which is not illegal because the information removed is not required by law.
- roxgib 4y agoSo if they're allowed to reveal they got searched, why the need for the canary? And if it works on a company level, why does it not work on a user level?
- AH4oFVbPT4f8 4y agoIt's not so much that the information got removed but rather they decided to not update the message. Failure of a new update is the signal that something happened.
- tptacek 4y agoIs there a particular reason to think any of this involved national security? The "standard" warrant canary is extremely broad, and would appear to cover any kind of warrant at all.
- mbg721 4y agoWell, there's our general goodwill toward the US government for their history in not abusing "national security" as an excuse.
- tipsysquid 4y agoI dislike the phrasing here. The proper design of a warrant canary is to actively publish new messages on some time period. No one should have actively pulled the canary, they just didn't publish a new message. This distinction, from my understanding, is important for legal reasons.
- Zamicol 4y agoThere was https://www.canarywatch.org https://www.canarywatch.org being pushed by the EFF that now appears to be out of service.
- jtolds 4y agoHey! Chief Architect at Storj here. Data on Storj is by default end-to-end encrypted with keys only the data owner controls (with optional support for sharing features). Only the data owner can decide who to share the keys with and who can see the data. Put another way, Storj can’t access data without the data owner sharing keys and access! However, if the owner shares the encryption keys and provides access to others, it can be further distributed by others. Storj does not allow illegal content per our terms of use and conditions. If someone has stored potentially illegal content and shared it with others, law enforcement may seek to obtain information by way of a subpoena, warrant, or other legal process. As you probably know since you're reading this thread, often such inquiries are confidential and the recipients may be prohibited from disclosing their existence. If you're interested in our encryption and security design decisions, there are a lot more details over at https://www.storj.io/disclosures https://www.storj.io/disclosures. Glad you're all paying such detailed attention!
- skibidibipiti 4y agoSo if law enforcement gives you a subpoena for a user’s content, you give them the encrypted data?
- btown 4y agoEncryption is all well and good, but only when paired with anonymization. It’s worth comparing the Storj privacy stance linked above, which describes numerous ways in which IP addresses might be logged and associated with accounts by their analytics providers, as opposed to e.g. https://www.privateinternetaccess.com/vpn-features/no-logs-vpn https://www.privateinternetaccess.com/vpn-features/no-logs-v... . Of course it’s a different business model, and I can’t vouch for PIA actually standing by those commitments. And I empathize with wanting to use best in class tooling to optimize your site experience. But prioritization of privacy, and commitments to minimizing log retention, are things you should consider revising to the extent you are legally able to do so. Don’t feel you need to respond here, of course, to that point!
- rsync 4y ago"As you probably know since you're reading this thread, often such inquiries are confidential and the recipients may be prohibited from disclosing their existence." Yes, that is exactly the kind of thing you're supposed to be taking a stand against and resisting. In fact, warrants like this are not "often" confidential - that is an aberration and an abomination - and a relatively recent one. We - all of us - should publicly oppose these measures and work to resist them. EDIT: I think I have misunderstood - the HN title is incorrect/misleading. Storj did not remove their warrant canary, they failed to update it. Interesting ...
- rsync 4y agoThe first warrant canary will, in a day or so, be 17 years old: https://www.rsync.net/resources/notices/canary.txt https://www.rsync.net/resources/notices/canary.txt We discussed it a bit more at length a few years ago: https://twitter.com/rsyncnet/status/1387090538273206274 https://twitter.com/rsyncnet/status/1387090538273206274 "What hasn't gone away are the nondisclosure provisions of National Security Letters that were amended by the USA FREEDOM ACT of 2015 and the 9th Circuit Court of Appeals' ruling that "the nondisclosure requirement does not run afoul of the First Amendment." ... "... and so we will continue. We will also continue to mirror internationally to CH and HK. A false, or coerced, publication will require cooperation across multiple continents, languages and legal regimes - all in seven days or less since we publish every Monday morning ..."
- EVa5I7bHFq9mnYK 4y agoI understand it's an open source project with p2p encryption. So for government to snoop, they must modify the code and let users download it and run the now insecure application. So in this case the GitHub code itself is a warrant canary.
- prirun 4y agoStorj has 2 ways to upload and download data: 1. The native Storj "uplink" command. Using this interface, a Go utility called uplink is run on the local client machine. It contacts a Satellite Node (the non-decentralized aspect of Storj) to retrieve a list of Storage Nodes that will accept the upload, then the file is split up and encrypted by the local uplink client code and sent to Storage Nodes recommended by the Satellite Node. In this case, the Satellite Node knows about the various pieces making up a file, the Storage Nodes have encrypted pieces of the file (but do not know how they relate to each other), and neither the Satellite Node nor the Storage Nodes could reconstruct the original file, even if working together, because the encryption key is stored on the local client machine only. 2. There is an S3 Gateway that gives Storj an S3-compatible interface. To use this, a Storj user would register a user account on the S3 Gateway, giving them an access key (login name) and secret key (password). When files are uploaded using the S3 Gateway, the access key and secret key are used to validate that the user has access to the specified bucket but there is no encryption happening. When data is received on the S3 Gateway, the Gateway uses the uplink technology to send split and encrypt the file and send the pieces to Storage Nodes. When a file is retrieved using the S3 Gateway, the Gateway does the reverse and sends the original, unencrypted file back to the S3 client. Storj customers using the Storj network with the native Storj uplink client should have nothing to worry about as long as their local Storj key isn't disclosed. For Storj customers using the S3 Gateway, it seems to me that by using data stored on the S3 Gateway, authorities could reconstruct files that were uploaded. For HashBackup (I'm the author), both interfaces are supported, though the S3 interface is recommended. Since HashBackup encrypts everything locally before doing any uploads, backups stored on Storj using either interface cannot be reconstructed without a copy of the HB backup key, which is only stored on the local client machine, is not part of the backup data, and is never uploaded anywhere.
- cvalka 4y agoWhere's your github repo and how does your project compare to restic/borg?
- jtolds 4y agoHi Jim! For our hosted S3 Gateway (called the Gateway MT), we have more details about how it works on this page: https://www.storj.io/disclosures https://www.storj.io/disclosures, in the section titled "Encryption for Gateway MT" The summary is that while the S3 gateway does have temporary access to unencrypted data during transit by protocol necessity, the S3 gateway does not keep the keys necessary to do this outside of the context of a request. HashBackup is also great!