TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Silent Circle's warrant canary is out of date

148 点作者 scotchmi_st超过 10 年前

16 条评论

ThinkBeat超过 10 年前
First off I have no standing here, and I am nobody. I am a customer of Silent Circle though. (or so I claim)<p>I am sure that StavrosK is well known by the community and it is my fault that I dont know his connection with SilentCircle. His profile points to stavros at stochastic dot io.<p>But more importantly HackerNews is not a very secure platform.<p>We have no real way of knowing StavrosK is StavrosK, or if ThinkBeat is the same ThinkBeat as last week. Using Hackernews or any social media as a platform to &quot;override&quot; a warrant canary is ill advised. In fact I think it makes matters worse.<p>Properly signed messages through the announced channel is the way to go.
评论 #8796651 未加载
ThinkBeat超过 10 年前
Ok, so from a conspiracy perspective:<p>Lets say there was a good reason for the canary not being updated.<p>I the FBI or whichever law enforcement agency was involved in the process noticed that updates were missing, (or saw it because it was pointed out on a well trafficked website)<p>Could the law enforcement agency then compel the employees to post a note that it was just a mistake and it will be rectified soon? And then have them update it?<p>Since not updating it when asked would equal disclosing that the event had taken place, which under certain laws might be illegal?<p>This hurts my head.
评论 #8797185 未加载
评论 #8796924 未加载
评论 #8796556 未加载
read超过 10 年前
Is a warrant canary even legal? If it isn&#x27;t, what&#x27;s the point of having them?<p>From <a href="http://en.wikipedia.org/wiki/Warrant_canary" rel="nofollow">http:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Warrant_canary</a><p><i>The US security researcher Moxie Marlinspike states that &quot;every lawyer we&#x27;ve spoken to has confirmed that [a warrant canary] would not work&quot; for the TextSecure server.</i><p>Direct link: <a href="https://github.com/WhisperSystems/whispersystems.org/issues/34#issuecomment-49910725" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;WhisperSystems&#x2F;whispersystems.org&#x2F;issues&#x2F;...</a>
评论 #8796750 未加载
评论 #8796804 未加载
gpm超过 10 年前
Reading this canary has me worried, it doesn&#x27;t actually say that &quot;no warrants have been served, nor have any searches or seizures taken place&quot;, it only says that a declaration stating that will be provided.<p>Compare this to rsync&#x27;s (<a href="http://www.rsync.net/resources/notices/canary.txt" rel="nofollow">http:&#x2F;&#x2F;www.rsync.net&#x2F;resources&#x2F;notices&#x2F;canary.txt</a>), which this seems to have been based off of. It explicitly states &quot;No warrants have ever been served to rsync.net, or rsync.net principals or employees. No searches or seizures of any kind have ever been performed on rsync.net assets, including:...&quot;
评论 #8797164 未加载
spacefight超过 10 年前
Maybe they were indeed slapped with an NSL. What a nice christmas present, huh!?<p>If they failed their own canary - how could you believe them in terms of their warant canaray setup ever again? Not so much at all, I&#x27;d say.
评论 #8796481 未加载
spacefight超过 10 年前
So it looks now, that the canary got updated. No other information given, at least not within the canary itself.<p><a href="https://canary.silentcircle.com/" rel="nofollow">https:&#x2F;&#x2F;canary.silentcircle.com&#x2F;</a>
StavrosK超过 10 年前
[DELETED, wait for an official company response or canary update]
评论 #8796654 未加载
评论 #8796668 未加载
评论 #8796524 未加载
higherpurpose超过 10 年前
Does the US Patriot Act even apply to them anymore? They moved to Switzerland this year. Still, they should probably look into doing the same kind of thing for Swiss laws.<p><a href="https://blog.silentcircle.com/our-move-to-switzerland/" rel="nofollow">https:&#x2F;&#x2F;blog.silentcircle.com&#x2F;our-move-to-switzerland&#x2F;</a><p>If the warrant canary is out of date, though, I wonder if they moved to Switzerland <i>because</i> the US government tried to get to them, and it wasn&#x27;t just a forward-thinking action.
评论 #8796518 未加载
CGamesPlay超过 10 年前
The purpose of the canary is to provide the issuer with a way of saying &quot;I am no longer trustworthy&quot;. Since the canary has not been updated, nothing that can be said in favor of Silent Circle should be trusted. When the canary is again updated, it will be Silent Circle saying &quot;I can be trusted again&quot; (subject to the limitations about coercion as described in the canary message).<p>For now, do not trust that Silent Circle has not been compromised despite anything you may read in this thread. When the canary is updated, then you may return to the state that you had before: you can speculate that they are being coerced into lying about the canary, or that they are trustworthy. That choice is an has always been yours to make.
评论 #8796731 未加载
评论 #8796680 未加载
subleq超过 10 年前
I hadn&#x27;t heard of Silent Circle before so I looked at their offerings. Is it any different than what you get from TextSecure and RedPhone for free?
shalmanese超过 10 年前
It seems to me that a warrant canary being updated after public notice is the <i>most</i> definitive proof we have that Silent Circle hasn&#x27;t been served with an NSL.<p>If the NSL had the ability to force an update, the canary would have been updated before anyone noticed it was a problem. If the NSL didn&#x27;t have the ability to force an update, the canary would still remain un-updated.
raverbashing超过 10 年前
&quot;As of Thu Dec 25 19:07:56 2014 UTC, here are the current headlines&quot;<p>So it&#x27;s up again?
评论 #8797032 未加载
astrojams超过 10 年前
Does that mean they&#x27;ve been served a warrant?
评论 #8796452 未加载
sarciszewski超过 10 年前
Good catch :)
spacefight超过 10 年前
That canary sits in direct reach of a LE (Law enforcement) of the US.<p>$&gt; whois 199.217.106.243<p><a href="http://myip.ms/view/ip_addresses/3352914432/199.217.106.0_199.217.106.255" rel="nofollow">http:&#x2F;&#x2F;myip.ms&#x2F;view&#x2F;ip_addresses&#x2F;3352914432&#x2F;199.217.106.0_19...</a><p>Edit: Typo law enforcement.
评论 #8796553 未加载
dang超过 10 年前
As long as it&#x27;s a false alarm, we&#x27;ll demote this story.<p>Edit: Ok, we restored it with a question mark. That&#x27;s a more balanced way to handle these; I just forgot about it.<p>Edit 2: Now that I think about it, there&#x27;s no need for a question mark on a factual statement. Sorry—I&#x27;m a little distracted right now! (We can change &quot;is&quot; to &quot;was&quot; if they update it, but someone will have to let us know.)<p>I&#x27;m going to detach this subthread now so it can go to the bottom as off-topic.
评论 #8796579 未加载
评论 #8796659 未加载
评论 #8796530 未加载
评论 #8796537 未加载
评论 #8796560 未加载