Live data from Hacker News

GitHub deleted accounts of people who contributed to Tornado Cash repos

twitter.com

261–270 of 526 posts

Re: GitHub deleted accounts of people who contributed to Tornado Cash repos

#261
post #217

Earlier quoted context omitted.

If we want to talk about important differences, then you need to understand the difference between money-laundering and privacy. In short, if you are not concealing the source of your funds to conceal a crime being committed , you are not guilty of money-laundering. It's that simple. KYC laws apply to banks and corporations, not individuals and not protocols and not code. Privacy is not against the law, and neither i…

If you are mixing your money with known criminals so that they can hide their money then you are money laundering even if you have other legitimate reasons for hiding your own money. The creative fiction that you can't know you are mixing it with known criminals is just that. A fiction. It has been known for a long time now that these mixers are used by known criminals. Continuing to use and contribute to that means…

When I and a friend use E2EE between us neither of us are helping to hide a criminal's conversation regarding their criminal activity. The same can not be said about a mixer. They are not at all equivalent.

Re: GitHub deleted accounts of people who contributed to Tornado Cash repos

#262
post #248

Earlier quoted context omitted.

> nothing sinister about privacy Totally agree. One damning aspect of Tornado is we know it was used to launder money. Criminals used it. This was publicly reported and certainly known to the Tornado team. If you know your product is being used by criminals to do crime and you respond by shrugging your shoulders, I’m not sure what the expected outcome is supposed to be other than getting dinged.

I like to ask myself what money laundering even is and whether it makes sense and ideally it wouldn't even be illegal. Money laundering isn't the crime - it's just a convenient tool to dissuade crime. Ideally there would be no crime without violence and there is nothing but consenting individuals involved in money laundering. The crime happened before the laundering and that's what we should be preventing. Otherwise…

> what money laundering even is

Hiding illegal gains.

> crime happened before the laundering and that's what we should be preventing

Covering up a murder is a crime because we don’t want people helping murderers cover up.

> like this where innocent people are going to get screwed over because they utilized a tool that criminals utilized

People who used Tornado Cash aren’t getting screwed. Even the developers aren’t. They aren’t personally sanctioned. Their work, which has been used to launder money, is.

Third parties, like Microsoft, are choosing not to associate with them. (The developers who knew about the laundering, e.g. through the public announcements law enforcement made, and kept working on it are far from innocent.)

> doesn't even begin to touch on the vast majority of laundering that happens in fiat across international banks

Yes, there are other crimes.

People laundering money through banks get sanctioned and jailed. When banks make a habit of laundering money, they too get sanctioned. There is ample historical record of all of this.

Re: GitHub deleted accounts of people who contributed to Tornado Cash repos

#263
post #79
post #11

Earlier quoted context omitted.

Does Tornado being sanctioned mean that everyone who has contributed in the past also needs to be blocked? (It’s not clear from the thread whether the people blocked contributed after, or only before, the sanction.) For what it’s worth, I don’t see much evidence of people being upset at GitHub in the thread. There’s talk about decentralized alternatives, but not much actual pinning the blame on them.

This is the crux of the issue in my opinion. It seems ridiculous that the sanctions should apply retroactively to anyone who has dealt with a sanctioned entity at any time in the past - if the people contributed before the sanctions, they were not contributing to a “blocked person”, as the project was not blocked at the time. Imagine if, say, A foreign electronics company is sanctioned by the government - does this m…

It's called covering your ass. Github/MS need to protect themselves, which means taking all actions reasonably possible to fend off charges of obstruction or collusion.

Re: GitHub deleted accounts of people who contributed to Tornado Cash repos

#264
post #7

People on Twitter are either wilfully dumb or simply ignorant. GitHub had to do this. It was required of them by law. Tornado was sanctioned . > These prohibitions include the making of any contribution or provision of funds, goods, or services by, to, or for the benefit of any blocked person and the receipt of any contribution or provision of funds, goods, or services from any such person. This is, unambiguously, di…

>GitHub had to do this. It was required of them by law. Tornado was sanctioned.

Does anyone know if this sanction, "contribution or provision of funds, goods, or services by, to, or for...", applies also to individual human persons not associated with a corporate or institutional entity? Is there somewhere I can read about what sactions are, what they mean, and who they apply to?

If it's just a Microsoft problem and not a human person problem then the solutions are many and obvious for any tool that's useful. git itself is already pretty distributed friendly.

Re: GitHub deleted accounts of people who contributed to Tornado Cash repos

#265

This is an overreach, and it is going to backfire. The target here is a software package, essentially speech so, one step down That hill. At least congress isn't deluded, corrupt, and senile enough to try this. Edit: further, it seems they're going to have to shut down Ethereum too, because Tornado Cash's contract is a person, and subgroup of Ethereum under the definition of entity which falls under the definition of…

If it is used by e.g North Korea to evade sanctions then that claim isn't that much of a stretch.

However it is clean that we, the programmer community, needs some way to stop projects from being sanctioned (as opposed to companies or specific persons). One obvious way would be to amend open source licenses to not permit them to be used by the US government if it attacks any other project in that group or something similar.

I am sure something better could come up, but we have lots of power if we were willing to come together and use it.

Re: GitHub deleted accounts of people who contributed to Tornado Cash repos

#266
post #209

Earlier quoted context omitted.

I agree - GitHub can block whoever they want. But doing so despite not being required to by law is a valid reason to criticize them.

No. I disagree. Github should not be able to block anyone they want. We went through this about a century ago with railways, antitrust, and Standard Oil. I won't step through the details, but can provide more background if anyone cares. We landed with the concept of a "common carrier." Railways, as well as telecommunications companies, ISPs, public airlines, bus lines, taxicab companies, phone companies, cruise ships…

> Railways, as well as telecommunications companies, ISPs, public airlines, bus lines, taxicab companies, phone companies, cruise ships, motor carriers, freight companies, and others CANNOT discriminate.

Funnily enough, several of the things you have listed (I believe, actually, most of them) are not common carriers but contract carriers. That means they can discriminate, except against the enumerated prohibited classes.

Re: GitHub deleted accounts of people who contributed to Tornado Cash repos

#267
post #254

Earlier quoted context omitted.

Those aren't remotely equivalent, given that mixers mix up their inputs to obscure their outputs. By using E2EE yourself, you are not actively giving cover in the same way.

E2EE and onion routing protocols use similar cryptography to "mix" and "obscure" inputs and outputs. It is very much the same approach, just that we don't call it "message laundering" because we as society have come to appreciate private communication. I would tell you to just look at the Tornado Cash code yourself to verify this, but alas...

E2EE generally doesn't obscure who is talking to who AFAICT.

Onion routing does, sure.

Ethically I find that area very much a double-edged sword. It's great for privacy and people evading speech-hostile regimes, but it does also enable trading and propagation of CSAM etc. It's why I've never run a Tor or Freenet (does that still exist?) node, I don't want to support that stuff with my resources.

Re: GitHub deleted accounts of people who contributed to Tornado Cash repos

#268

Earlier quoted context omitted.

>Did the people who built blockchains with built-in mandatory mixing (Monero) or optional completely obscured transaction inputs (ZCash) also facilitate money laundering? Yes >Am I myself in trouble for having (co-)designed a mixing service [1]? Possibly? Depends on the details.

> Yes Then american banks should be sanctioned, they are also involved in money laundering too.

When they fail to take steps to prevent it, they are often punished. Here’s a few big ones from 2021 alone: https://www.forbes.com/sites/forbestechcouncil/2022/03/24/le...

Why aren’t these banks put on the sanction list where it’s a crime to do business with them? Because the vast majority of what they do is not money laundering and when they are discovered money laundering, they generally stop. And when they don’t, they are added to this list: https://www.treasury.gov/ofac/downloads/sdnlist.txt

Whereas Tornado Cash is a service that is known to enable huge amounts of money laundering, and nothing was done to stop it.

Re: GitHub deleted accounts of people who contributed to Tornado Cash repos

#269

Earlier quoted context omitted.

You are going to open a huge can of worms if you are going to start prosecuting people for software pull requests. Are we going to prosecute people who manufacture phosphor bombs for the US military as well now?

> going to open a huge can of worms if you are going to start prosecuting people for software pull requests Tornado is sanctioned, not the underlying code. Contributing to the project is legally tantamount to coding for a North Korean entity. This isn’t a start to anything, it’s established law and practice. Simply pulling shouldn't be a problem. But I can see law enforcement getting a subpoena for a list of accounts…

What would be the legal consequences of forking the project and create a new project with the code?

And speaking of code - North Korea has their own os which is essentially a reskinned version of Linux. Does that mean that the US government could go after people who contributed to the Linux project?

Re: GitHub deleted accounts of people who contributed to Tornado Cash repos

#270
post #246
post #209

Earlier quoted context omitted.

No. I disagree. Github should not be able to block anyone they want. We went through this about a century ago with railways, antitrust, and Standard Oil. I won't step through the details, but can provide more background if anyone cares. We landed with the concept of a "common carrier." Railways, as well as telecommunications companies, ISPs, public airlines, bus lines, taxicab companies, phone companies, cruise ships…

> As an individual or a small business, ones does not have an alternative to Microsoft Word, github, or Facebook. Google Docs, gitlab or bitbucket, and as for social network there's plenty out there. None of those are real monopolies. They _might_ be best in class, but there's no rule that says you must be allowed to use the best in class service.

Disagreed. They are de-facto mandatory to use. A former university I was at, for instance, published some required information on facebook. Saying "well, they should not do that" is as correct as it is useless and futile in practice.

I believe the information was visible to either all logged-in users or just all visitors, but that still requires facebook to serve the page to me.

Post reply on HN