Live data from Hacker News

GitHub deleted accounts of people who contributed to Tornado Cash repos

twitter.com

211–220 of 526 posts

Re: GitHub deleted accounts of people who contributed to Tornado Cash repos

#211
post #75

Earlier quoted context omitted.

Be that as it may, isn't this still an unacceptable collateral damage? So when you contribute code to an open source project, you generally do so under an open source license. All of them generally contain something akin to the following: IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (this particular excerpt is from the BSD li…

Probably not to GitHub or the courts. If in a few years it is discovered that GitHub missed something they can tell the courts "We did our best to comply, look at all the accounts we killed [and other evidence], so go easy on us for an honest mistake." In general the courts look kindly on someone who tried their best to obey the spirit of the law but missing one hidden detail. If you are affected you could take this…

> Probably not to GitHub or the courts. If in a few years it is discovered that GitHub missed something they can tell the courts "We did our best to comply, look at all the accounts we killed [and other evidence], so go easy on us for an honest mistake." In general the courts look kindly on someone who tried their best to obey the spirit of the law but missing one hidden detail.

This matters a great deal when it comes to OFAC sanctions. The value of sanctions isn't "OFAC chasing down people on the SDN list", it comes from companies following federal law and blocking transactions that legally need to be blocked. And OFAC recognizes this – just look at their enforcement actions[0] and you can see examples where companies that build internal compliance programs and self-disclose violations come out with limited to no penalty[1], whereas companies that skirt compliance regimes place themselves at much more risk[2].

[0]: https://home.treasury.gov/policy-issues/financial-sanctions/...

[1]: https://home.treasury.gov/system/files/126/20220721_midfirst...

[2]: https://home.treasury.gov/system/files/126/20201020_berkshir...

Re: GitHub deleted accounts of people who contributed to Tornado Cash repos

#212

Earlier quoted context omitted.

Not sure, thoughtcrime is a thing now in modern America?

> thoughtcrime is a thing now in modern America? Nothing wrong with writing code. Code is speech, that's settled law. But the Tornado Cash team wasn't just publishing. They were building a tool. Semenov styled himself as a co-founder and the group advertised open positions on its website.

Okay, how does that relate to open source contributors? Can you retroactively read their minds and determine their intent? Why does their intent even matter? What they were doing was not illegal at the time, and now they are being punished by the US.

Re: GitHub deleted accounts of people who contributed to Tornado Cash repos

#213

Earlier quoted context omitted.

This is not the level of comment quality I would expect on HN. You can do better.

Sorry but I try to avoid dumping huge amounts of information on people in every comment, that often doesn't go down well either if you can imagine. If you want more I'll elaborate. There is no possible way you can deploy this service anywhere while effectively complying with AML laws. It isn't going to work. But it's also the only real effective way you can obscure the source of transactions on a blockchain that's fo…

I mean, if you really think about it distributed public transaction ledgers were really primarily beneficial to those looking to actually understand more about where/how money flows. It's the classic problem of Networks. If there is enough information to ensure that something gets to one endpoint, and not others, that de facto becomes a tracking lever for surveillance and signal analysis. It's part of the package. There is no escaping it. As it giveth, so to does it take away.

Things like the Bank Secrecy Act are only there to guarantee a level of secrecy/protection from other customers. Law enforcement, government, and third party service providers are not counted there realistically. If you want financial privacy, you keep your own books. By that same token though, you don't get to act surprised when the authorities come a knocking with a warrant to crack open your books when they find out you made a poor decision of people to work/transact with.

Re: GitHub deleted accounts of people who contributed to Tornado Cash repos

#214
post #7

People on Twitter are either wilfully dumb or simply ignorant. GitHub had to do this. It was required of them by law. Tornado was sanctioned . > These prohibitions include the making of any contribution or provision of funds, goods, or services by, to, or for the benefit of any blocked person and the receipt of any contribution or provision of funds, goods, or services from any such person. This is, unambiguously, di…

> People on Twitter are either wilfully dumb or simply ignorant.

I think it's the culture of reacting to 240 characters or less. People already know what they want to feel and finding a quick and completely baseless confirmation bias on twitter is easy and rewards you greatly with dopamine.

Smart, mature people gather information before making a decision. Dumb people knee-jerk react based on low information. Twitter heavily encourages the latter by making the former very difficult to do.

Re: GitHub deleted accounts of people who contributed to Tornado Cash repos

#215

Earlier quoted context omitted.

...that enabled nefarious people to go about their deeds unpunished.

The nefarious people were probably on a unix system or a windows system. Should we go about and delete their contributors accounts as well? I’m not at all pro crypto but this enforcement does seem extreme. I do understand that Microsoft is just following the sanctions.

This is disingenuous. It's like responding to someone arguing for gun control with "all the shooters drank water, should we ban that?".

We can argue about the legit/legal uses of Tornado Cash and whether it deserves to be sanctioned - but do so in good faith rather than pretending like it is equivalent to a general purpose tool like Microsoft Windows.

Re: GitHub deleted accounts of people who contributed to Tornado Cash repos

#216

Earlier quoted context omitted.

Yes, pretty much. This is why I'm surprised more people aren't way more terrified about OFAC than there are. It's probably one of the nastiest diplomatic tools the U.S. has in its arsenal.

Nice, what's next? Jailing everyone who ever had an abortion? Why aren't y'all americans doing that yet, if it's apparently acceptable to punish people for things they did before the supposed crime was made illegal?

No post body was provided.

Re: GitHub deleted accounts of people who contributed to Tornado Cash repos

#217
post #129

Earlier quoted context omitted.

If the matrix project was run by terrorists then your comparison would be accurate. It is not however. Tornado Cash however is run by a group with the express purpose of money laundering which is a crime. This difference is important and is why they are now sanctioned and Matrix is not.

If we want to talk about important differences, then you need to understand the difference between money-laundering and privacy. In short, if you are not concealing the source of your funds to conceal a crime being committed , you are not guilty of money-laundering. It's that simple. KYC laws apply to banks and corporations, not individuals and not protocols and not code. Privacy is not against the law, and neither i…

If you are mixing your money with known criminals so that they can hide their money then you are money laundering even if you have other legitimate reasons for hiding your own money. The creative fiction that you can't know you are mixing it with known criminals is just that. A fiction. It has been known for a long time now that these mixers are used by known criminals. Continuing to use and contribute to that means you are knowingly helping to launder their money.

Re: GitHub deleted accounts of people who contributed to Tornado Cash repos

#218
post #144

Earlier quoted context omitted.

> GitHub had to do this. They only had to block accounts that contributed after establishing the sanction. It's not clear that they limited themselves to those. It would in fact seem to be hard to contribute in the limited time range between establishing the sanction and removing the project. There is also the collateral damage of removing unrelated projects that happened to be owned by these people. Couldn't github…

> only had to block accounts that contributed after establishing the sanction The people who built Tornado Cash are already in trouble. The crime--facilitating money laundering--has already been committed. OFAC is an enforcement office. Its lists are more like wanted posters than rules. GitHub is cutting ties with people likely to be charged with federal crimes. If some of them are going to continue contributing to t…

[deleted]

Re: GitHub deleted accounts of people who contributed to Tornado Cash repos

#220
post #24

This is a good time time for EFF to step in. This is open huge so many terrible ways for abuse. 1. Make some random crypto project. 2. Motivate people contribute to it, see DigitalOcean hacktoberfest. 3. Replace the code with Tornado.Cash source. Everyone's account is banned by Microsoft. Also I wonder what happen if you didnt sent PR yourself, but someone crafted git commit with your email and added it to such repos…

GitHub didn't remove the account of everyone who ever contributed to the repository; if you go to the Web Archive many of the people listed under "contributors" still have accounts. Presumably, they just removed the people who were a member of the organisation.

Ok this makes alot more sense. I can totally see how they would nuke every member of the org in an attempt to CYA. It sounded like they nuked every contributor which would have been insane.
Post reply on HN