Earlier quoted context omitted.
Assuming they can't compel speech, this would require the canary to be updated and PGP signed daily by someone that can represent the company. Perhaps a principal officer or a board member? Even then, unless your contract states that the canary is managed in a particular way, they can simply lie. I can put a "canary" on a site and update it daily, even if every three letter agency were logged in and watching you real…
A canary in itself does not offer any cryptographic proof. The entire foundation is that the government cannot legally compel speech. The canary does not protect you against the service provider and nobody has claimed that. The theory is that it protects you against NSLs that would otherwise force the service provider to not disclose the NSL. Sometimes a canary is attached to a public financial report or something el…
I am no lawyer, but I don't see a problem with putting a lie into a financial statement that is in no way related to financial data. It would just be disregarded as unrelated to financial reporting. I am also not aware of any companies doing this. I could see this causing a deeper dive into an audit however.