Live data from Hacker News

GitHub deleted accounts of people who contributed to Tornado Cash repos

twitter.com

111–120 of 526 posts

Re: GitHub deleted accounts of people who contributed to Tornado Cash repos

#111
post #24

This is a good time time for EFF to step in. This is open huge so many terrible ways for abuse. 1. Make some random crypto project. 2. Motivate people contribute to it, see DigitalOcean hacktoberfest. 3. Replace the code with Tornado.Cash source. Everyone's account is banned by Microsoft. Also I wonder what happen if you didnt sent PR yourself, but someone crafted git commit with your email and added it to such repos…

GitHub didn't remove the account of everyone who ever contributed to the repository; if you go to the Web Archive many of the people listed under "contributors" still have accounts. Presumably, they just removed the people who were a member of the organisation.

Re: GitHub deleted accounts of people who contributed to Tornado Cash repos

#112
post #79
post #11

Earlier quoted context omitted.

Does Tornado being sanctioned mean that everyone who has contributed in the past also needs to be blocked? (It’s not clear from the thread whether the people blocked contributed after, or only before, the sanction.) For what it’s worth, I don’t see much evidence of people being upset at GitHub in the thread. There’s talk about decentralized alternatives, but not much actual pinning the blame on them.

This is the crux of the issue in my opinion. It seems ridiculous that the sanctions should apply retroactively to anyone who has dealt with a sanctioned entity at any time in the past - if the people contributed before the sanctions, they were not contributing to a “blocked person”, as the project was not blocked at the time. Imagine if, say, A foreign electronics company is sanctioned by the government - does this m…

Unless, of course, GitHub considers every single contributor to Tornado to be part of the sanctioned entity due to the decentralized nature of git? Seems like a very dangerous interpretation for open source in that case…

Re: GitHub deleted accounts of people who contributed to Tornado Cash repos

#113
post #18

Earlier quoted context omitted.

I thought they were contributing to the Python web framework called Tornado (quite popular especially before asyncio caught on, but still well-known nowadays).

I was like "what's a tornado repo? a reference I don't know about to a whirlwind of activity? maybe a bot attack of some kind." +1 disambiguation needed

Some of my repos look like they were hit by a tornado and frankly deserve to be deleted

Re: GitHub deleted accounts of people who contributed to Tornado Cash repos

#114
post #102
post #75

Earlier quoted context omitted.

Be that as it may, isn't this still an unacceptable collateral damage? So when you contribute code to an open source project, you generally do so under an open source license. All of them generally contain something akin to the following: IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (this particular excerpt is from the BSD li…

> What did they do wrong? They wilfully contributed to the upkeep of a money laundering service. They should be thankful losing their GitHub account is the extent of the fallout, take it as a lesson that code can cause real harm, and act more judiciously in future when it comes to contributing labour to suspect projects.

There are so many other applications for Tornado Cash than “money laundering.” What if I don’t want my employer or friends to see what I do with my known wallet on a fully traceable public blockchain?

Privacy is not illegal.

Re: GitHub deleted accounts of people who contributed to Tornado Cash repos

#115
post #75

Earlier quoted context omitted.

Because others are answering you in much more detail, I’ll give them more generalized answer – This is quite simply not how a sanctions regime works. The US government does not make a list of all the sanctioned persons’ assets, then start going after those in court. Instead, it goes the other way: any company with a US nexus watches those sanction lists carefully. When someone is listed they look at their internal re…

Be that as it may, isn't this still an unacceptable collateral damage? So when you contribute code to an open source project, you generally do so under an open source license. All of them generally contain something akin to the following: IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (this particular excerpt is from the BSD li…

> What did they do wrong?

The argument probably is that they assisted a sanctioned entity by providing a contribution i.e. service to it. Quoting US Treasury "These prohibitions include the making of any contribution or provision of funds, goods, or services by, to, or for the benefit of any blocked person and the receipt of any contribution or provision of funds, goods, or services from any such person."

However, the major factual question is whether they did violate any sanctions since the contributions generally were made before the sanctions were in effect - it's not that Github had to do it, but that they chose to be safe rather than sorry (in order to ensure that Github themselves don't violate the sanctions) and if they aren't absolutely sure they blocked people. [edit: apparently not everyone, some contributors are not blocked, so they apparently did some review before choosing whom to block]

The key issue is that any collateral damage is considered acceptable, but any false negatives are absolutely not. If Github leaves even one actual agent of TornadoCash unblocked, Github has committed a crime, if they block a hundred unrelated accounts, that doesn't violate anything.

> Are there open source licenses that protect the contributors from such unforeseeable damage?

No, a contract or license can't absolve you from this prohibition if it applies to you.

> Or are we to watch our step from now on as open source contributors?

Yes, but not "from now on" but since before open source existed. There are entities you are not allowed to contribute to, and it's your responsibility to know and check who you are dealing with.

Re: GitHub deleted accounts of people who contributed to Tornado Cash repos

#116
post #71

Earlier quoted context omitted.

No, because the US will invade and then perform war crimes on you if you imply that one of their soldiers has maybe performed war crimes and deserves to be tried for it.

In my experience in Afghanistan, it was other countries that performed more "war crimes" than the US (as in violating Geneva Conventions). Why do you think they make it such a big deal when the USA does it? Is it only because the US just prosecutes their own and doesn't recognize the international court? The international court does a much better job of keeping their decisions and the soldiers being punished, private…

But the US does not prosecute its own. Instead they go after the messenger e.g. Julian Assange. They also usually find the lowest scapegoat they can get instead of having the responsibility be at the command level.

Edit: Spelling of scapegoat

Re: GitHub deleted accounts of people who contributed to Tornado Cash repos

#118
post #24

This is a good time time for EFF to step in. This is open huge so many terrible ways for abuse. 1. Make some random crypto project. 2. Motivate people contribute to it, see DigitalOcean hacktoberfest. 3. Replace the code with Tornado.Cash source. Everyone's account is banned by Microsoft. Also I wonder what happen if you didnt sent PR yourself, but someone crafted git commit with your email and added it to such repos…

What would be the motivation to pull off that heist?

What motivation do someone have for swatting people?

Problem is that Microsoft is certainly overreaching here and this precedent will be abused by malicious actors. One day someone will come to work and find out that whole organization was banned on github just by forging to commits.

Re: GitHub deleted accounts of people who contributed to Tornado Cash repos

#119

Earlier quoted context omitted.

I have no sympathy for crypto whatever and I really don't care about who sanctioned whom and for what reason, but... Sanctioned project's contributors must be deleted from the server - where is that written in the list of things Microsoft has to do since you went out of your way calling everyone on the reply train ignorant?

It's written in the definition of the sanction given by the Department of the Treasury [0], i.e. at the level of US federal law, of which Microsoft must follow as a US company. > Sanctions Implications > These prohibitions include the making of any contribution or provision of funds, goods, or services by, to, or for the benefit of any blocked person and the receipt of any contribution or provision of funds, goods, o…

Prohibiting can simply mean deleting the git repo, the forks and contributions from your database.

This is just "deleting people because sanctions need to be severe and hurtful".

Re: GitHub deleted accounts of people who contributed to Tornado Cash repos

#120
post #104
post #92

Earlier quoted context omitted.

Git is not GitHub

A Github repository is decentralized among everyone who has cloned it, nothing about Github changes that. The other parts, like issue tracking, obviously are not.

It's not decentralized in any practical manner when everyone's local clone is pointing to the same, now no longer available, origin.

This could have been mitigated by having a pre-determined fallback origin (which could very well be something they had in place - I'm not familiar with this project).

Post reply on HN