Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

In the US companies can make canary statement... https://en.wikipedia.org/wiki/Warrant_canary


Those canary things seem so 2018.

In 2021 the most powerful canary statement should be "Don't trust us. Seriously, treat us as an adversary. We still want you to be our customer of course, but here's how we really recommend you use our service, Tor, semi-anonymous payments, etc. In God we trust, for everyone else use math."


Anybody serious has moved from "perimeter security" to "zero trust" in network architecture. We need to treat more of the real world the same way.


Any new tools developed with that in mind for us mortals?

Would love to sign up for some Tor-first services. So far the best we've got are Tor services that mirror public ones.


That canary statement would kill their userbase. Seriously, who expects a company to admit the value they provide is not much? They expect the more savvy users (ie, those who need the privacy, typically) to understand basic OPSEC.

I admit that the marketing is bad, I do not agree with it, and I do not tolerate it in terms of my own OPSEC. But, there's just no way they would just admit they provide hardly any value besides, in a VPN's example, being a tube to another place, and just another tube with ends that can be stopped.


Not having that canary may LITERALLY kill some of their users. If they have some decency they should own up to the truth and if they end up being out of business they will have a lot of goodwill for their next business.


And I 100% agree that they should. I'm just saying there's an incredibly slim chance they will. From a business perspective, which is the perspective they always take, it makes no sense.


> In the US companies can make canary statement...

What is far less clear is if you can trust the continuation of a canary statement to indicate the absence of the action it denies, since it is both legally disputed whether continuation of the statement could be mandated by government and because anyone who has an interest in the PR value of providing a canary statement also potentially has the same interest in continuing it as long as it is impractical to falsify.


>it is both legally disputed whether continuation of the statement could be mandated by government

Is compelled speech seriously in jeopardy? I saw the github issue for signal saying that some (EFF?) lawyers said that canaries are not that helpful, but that just implies that the government CAN compel speech. That would be bigger news than mentioned as an aside on a Github issue, I'd like to believe that would be news...


The canary is dead, and the fact is widely publicised, if not necessarily well known.


Our canary[1] - the very first one[2] - is alive and well.

In fact, it turned 15 years old this past April[3].

[1] https://www.rsync.net/resources/notices/canary.txt

[2] https://en.wikipedia.org/wiki/Warrant_canary#Usage

[3] https://twitter.com/rsyncnet/status/1387090538273206274



Gotchya.

I was referring to Protonmail's canary specifically, in the event that wasn't clear.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: