TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Silent Circle's warrant canary is out of date

148 pointsby scotchmi_stover 10 years ago

16 comments

ThinkBeatover 10 years ago
First off I have no standing here, and I am nobody. I am a customer of Silent Circle though. (or so I claim)<p>I am sure that StavrosK is well known by the community and it is my fault that I dont know his connection with SilentCircle. His profile points to stavros at stochastic dot io.<p>But more importantly HackerNews is not a very secure platform.<p>We have no real way of knowing StavrosK is StavrosK, or if ThinkBeat is the same ThinkBeat as last week. Using Hackernews or any social media as a platform to &quot;override&quot; a warrant canary is ill advised. In fact I think it makes matters worse.<p>Properly signed messages through the announced channel is the way to go.
评论 #8796651 未加载
ThinkBeatover 10 years ago
Ok, so from a conspiracy perspective:<p>Lets say there was a good reason for the canary not being updated.<p>I the FBI or whichever law enforcement agency was involved in the process noticed that updates were missing, (or saw it because it was pointed out on a well trafficked website)<p>Could the law enforcement agency then compel the employees to post a note that it was just a mistake and it will be rectified soon? And then have them update it?<p>Since not updating it when asked would equal disclosing that the event had taken place, which under certain laws might be illegal?<p>This hurts my head.
评论 #8797185 未加载
评论 #8796924 未加载
评论 #8796556 未加载
readover 10 years ago
Is a warrant canary even legal? If it isn&#x27;t, what&#x27;s the point of having them?<p>From <a href="http://en.wikipedia.org/wiki/Warrant_canary" rel="nofollow">http:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Warrant_canary</a><p><i>The US security researcher Moxie Marlinspike states that &quot;every lawyer we&#x27;ve spoken to has confirmed that [a warrant canary] would not work&quot; for the TextSecure server.</i><p>Direct link: <a href="https://github.com/WhisperSystems/whispersystems.org/issues/34#issuecomment-49910725" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;WhisperSystems&#x2F;whispersystems.org&#x2F;issues&#x2F;...</a>
评论 #8796750 未加载
评论 #8796804 未加载
gpmover 10 years ago
Reading this canary has me worried, it doesn&#x27;t actually say that &quot;no warrants have been served, nor have any searches or seizures taken place&quot;, it only says that a declaration stating that will be provided.<p>Compare this to rsync&#x27;s (<a href="http://www.rsync.net/resources/notices/canary.txt" rel="nofollow">http:&#x2F;&#x2F;www.rsync.net&#x2F;resources&#x2F;notices&#x2F;canary.txt</a>), which this seems to have been based off of. It explicitly states &quot;No warrants have ever been served to rsync.net, or rsync.net principals or employees. No searches or seizures of any kind have ever been performed on rsync.net assets, including:...&quot;
评论 #8797164 未加载
spacefightover 10 years ago
Maybe they were indeed slapped with an NSL. What a nice christmas present, huh!?<p>If they failed their own canary - how could you believe them in terms of their warant canaray setup ever again? Not so much at all, I&#x27;d say.
评论 #8796481 未加载
spacefightover 10 years ago
So it looks now, that the canary got updated. No other information given, at least not within the canary itself.<p><a href="https://canary.silentcircle.com/" rel="nofollow">https:&#x2F;&#x2F;canary.silentcircle.com&#x2F;</a>
StavrosKover 10 years ago
[DELETED, wait for an official company response or canary update]
评论 #8796654 未加载
评论 #8796668 未加载
评论 #8796524 未加载
higherpurposeover 10 years ago
Does the US Patriot Act even apply to them anymore? They moved to Switzerland this year. Still, they should probably look into doing the same kind of thing for Swiss laws.<p><a href="https://blog.silentcircle.com/our-move-to-switzerland/" rel="nofollow">https:&#x2F;&#x2F;blog.silentcircle.com&#x2F;our-move-to-switzerland&#x2F;</a><p>If the warrant canary is out of date, though, I wonder if they moved to Switzerland <i>because</i> the US government tried to get to them, and it wasn&#x27;t just a forward-thinking action.
评论 #8796518 未加载
CGamesPlayover 10 years ago
The purpose of the canary is to provide the issuer with a way of saying &quot;I am no longer trustworthy&quot;. Since the canary has not been updated, nothing that can be said in favor of Silent Circle should be trusted. When the canary is again updated, it will be Silent Circle saying &quot;I can be trusted again&quot; (subject to the limitations about coercion as described in the canary message).<p>For now, do not trust that Silent Circle has not been compromised despite anything you may read in this thread. When the canary is updated, then you may return to the state that you had before: you can speculate that they are being coerced into lying about the canary, or that they are trustworthy. That choice is an has always been yours to make.
评论 #8796731 未加载
评论 #8796680 未加载
subleqover 10 years ago
I hadn&#x27;t heard of Silent Circle before so I looked at their offerings. Is it any different than what you get from TextSecure and RedPhone for free?
shalmaneseover 10 years ago
It seems to me that a warrant canary being updated after public notice is the <i>most</i> definitive proof we have that Silent Circle hasn&#x27;t been served with an NSL.<p>If the NSL had the ability to force an update, the canary would have been updated before anyone noticed it was a problem. If the NSL didn&#x27;t have the ability to force an update, the canary would still remain un-updated.
raverbashingover 10 years ago
&quot;As of Thu Dec 25 19:07:56 2014 UTC, here are the current headlines&quot;<p>So it&#x27;s up again?
评论 #8797032 未加载
astrojamsover 10 years ago
Does that mean they&#x27;ve been served a warrant?
评论 #8796452 未加载
sarciszewskiover 10 years ago
Good catch :)
spacefightover 10 years ago
That canary sits in direct reach of a LE (Law enforcement) of the US.<p>$&gt; whois 199.217.106.243<p><a href="http://myip.ms/view/ip_addresses/3352914432/199.217.106.0_199.217.106.255" rel="nofollow">http:&#x2F;&#x2F;myip.ms&#x2F;view&#x2F;ip_addresses&#x2F;3352914432&#x2F;199.217.106.0_19...</a><p>Edit: Typo law enforcement.
评论 #8796553 未加载
dangover 10 years ago
As long as it&#x27;s a false alarm, we&#x27;ll demote this story.<p>Edit: Ok, we restored it with a question mark. That&#x27;s a more balanced way to handle these; I just forgot about it.<p>Edit 2: Now that I think about it, there&#x27;s no need for a question mark on a factual statement. Sorry—I&#x27;m a little distracted right now! (We can change &quot;is&quot; to &quot;was&quot; if they update it, but someone will have to let us know.)<p>I&#x27;m going to detach this subthread now so it can go to the bottom as off-topic.
评论 #8796579 未加载
评论 #8796659 未加载
评论 #8796530 未加载
评论 #8796537 未加载
评论 #8796560 未加载