Live data from Hacker News

GitHub deleted accounts of people who contributed to Tornado Cash repos

twitter.com

321–330 of 526 posts

Re: GitHub deleted accounts of people who contributed to Tornado Cash repos

#321
post #19

Earlier quoted context omitted.

The people were not sanctioned only the onchain addresses of Tornado were. Github was not providing any service to the onchain addresses.

The first two lines in the list were not ETH addresses: > TORNADO CASH (a.k.a. TORNADO CASH CLASSIC; a.k.a. TORNADO CASH NOVA); > Website tornado.cash;

Which is a company name and a website, not people. A company name listed in this manner does not extend to its employees unless they are acting on behalf of the company; any sanctions against individuals specify the individual's name.

Re: GitHub deleted accounts of people who contributed to Tornado Cash repos

#322

Earlier quoted context omitted.

> seems ridiculous that the sanctions should apply retroactively Anyone contributing to Tornado after it became public knowledge that it was used to launder money put themselves at risk. The sanctions are the enforcement action. A wanted poster. The crime, laundering money, was committed a while ago. > does this mean that anyone who has previously worked with them or bought their electronics has done so illegally? If…

What is not used to launder money? What separates pre-sanctions Tornado from any other tech that can feasibly be used for something evil (e.g. cash money, PayPal, any cryptocurrency, e2ee messengers)? Should we ask the government to publish a registry of approved technologies to ensure own safety?

> What separates pre-sanctions Tornado from any other tech that can feasibly be used for something evil (e.g. cash money, PayPal, any cryptocurrency, e2ee messengers)?

I don’t have the technical answer. But from the instant tumblers became a thing everyone with AML experience saw the endgame. It’s providing, as a service, a function directly analogous to real-world layering. It does nothing else. And nobody involved seems to have taken the prospect of criminals using their product seriously.

Messengers are not money, so laundering goes out the window. PayPal is regulated. And crypto does other things. Tornado just served to hide the origin of money. And it was used to launder illegally-gotten gains.

Re: GitHub deleted accounts of people who contributed to Tornado Cash repos

#323

Earlier quoted context omitted.

I am not demanding anything. I am just saying they have clearly done the wrong thing.

There is no moral obligation for someone to provide web services for free for any reason. There’s definitely no moral obligation for someone to do the same at risk of prison time. They do have a moral obligation to follow the laws of the country they operate in, though.

> They do have a moral obligation to follow the laws of the country they operate in, though

Why?

Re: GitHub deleted accounts of people who contributed to Tornado Cash repos

#324
post #267

Earlier quoted context omitted.

E2EE and onion routing protocols use similar cryptography to "mix" and "obscure" inputs and outputs. It is very much the same approach, just that we don't call it "message laundering" because we as society have come to appreciate private communication. I would tell you to just look at the Tornado Cash code yourself to verify this, but alas...

E2EE generally doesn't obscure who is talking to who AFAICT. Onion routing does, sure. Ethically I find that area very much a double-edged sword. It's great for privacy and people evading speech-hostile regimes, but it does also enable trading and propagation of CSAM etc. It's why I've never run a Tor or Freenet (does that still exist?) node, I don't want to support that stuff with my resources.

E2EE obscures everything, that is why it is called end-to-end. If Alice and Bob and John and Piper are all communicating with pseudonymous names in a Matrix room, you do not know who is talking to who or what they are talking about.

Re: GitHub deleted accounts of people who contributed to Tornado Cash repos

#325
post #11

Earlier quoted context omitted.

Does Tornado being sanctioned mean that everyone who has contributed in the past also needs to be blocked? (It’s not clear from the thread whether the people blocked contributed after, or only before, the sanction.) For what it’s worth, I don’t see much evidence of people being upset at GitHub in the thread. There’s talk about decentralized alternatives, but not much actual pinning the blame on them.

I'm assuming that the problem for Github is that they can't reliably know which of the contributors are "currently part of" TornadoCash and which ones are unrelated people who just contributed code some time ago, and since they absolutely must block the former, in the case of uncertainty the only safe option was to block everyone who seems related.

None of the Tornado developers are anonymous. They are all well known and respected members of the security/privacy community, and I have personally hung out with them multiple times in the US at public events, where they often speak etc. This isn't some shadowy cabal, they are programmers and mathematicians who think sometimes people might not want the world to see where they are spending their money. Crazy right?

Re: GitHub deleted accounts of people who contributed to Tornado Cash repos

#326

The commenters saying be reasonable, they were sanctioned, GitHub had to do this, should look into the last time code was made illegal or similar turmoil and what the developer community did in response…It was not accepting sanctions or govt failures to understand code as “well that’s that.” - Phil Zimmerman (PGP) was under criminal investigation for arms exports by releasing the code for consumer encryption. The cas…

I think its important to make a distinction between GitHub attempting to ensure they are in legal compliance with a sanction and approving of the sanction happening at all.

You can disagree with the sanction while still being understanding of GitHub trying to cut ties with the sanctioned entity. Or be critical of them being heavy handed in their compliance but agree with the sanction in general.

Re: GitHub deleted accounts of people who contributed to Tornado Cash repos

#327
post #51

I am by no means a fan of Tornado and what it represents in the crypto community - I think crypto has enough cretins already. But this is definitely a bit of a stretch to go after the creator(s) in this way. Reminds me of the US Gov trying to ban/limit all encryption. Didn't seem okay then and this doesn't seem okay now.

Not after the creators. The contributors. People who were submitting code changes to an absolutely legal piece of software.

AFAIK, it is indeed just the three creator accounts that got suspended.

Re: GitHub deleted accounts of people who contributed to Tornado Cash repos

#328
post #96

Earlier quoted context omitted.

I don't have particular vitriol against Tornado itself, they do offer compliance tool and seem to have just been an eventual outcome in crypto. I do however have an issue with the incredibly high rate of money laundering etc that flows through crypto. Particularly so with Tornado cash. It's the 'go-to' for easy money laundering. And no that's not a 'general ignorance' it's just a bi-product of having decentralized sy…

Tornado cash is not money laundering. It just isn't. Please stop claiming that. If it were money laundering, you would be able to purchase a house with the money you made from drugs and then mixed through tornado. You can't. It's indistinct from having cash you made from selling drugs. You still need to create a fake business to launder your money the old fashioned way if you want to have a legitimate origin for your…

> Tornado cash is not money laundering. It just isn't. Please stop claiming that.

If I deposit 200k USD into my bank account which came from Tornado.cash - They will ask for proof it came from there.

Tornado cash will confirm this with their compliance tools etc. However as to where it came from before is in practice today impossible to identify.

The bank // IRS whoever may suspect something bad, but unless they can prove it, and I pay taxes on it, then that money is considered clean.

All one would need to say is - I lost my original wallet(s) when I slowly dripped it from a few old accounts I had when I was mining back in the day into Tornado.

I'm sure there are other clever ways cretins will come up with too but thats just off the top of my head. A very effective annonomizing tool helps that.

I'm not condoning it, I just don't think you should be too naive to believe its not happening.

Re: GitHub deleted accounts of people who contributed to Tornado Cash repos

#329

Earlier quoted context omitted.

> The key issue is that any collateral damage is considered acceptable, but any false negatives are absolutely not. Even though “better 100 guilty persons should escape than that one innocent person should suffer”. Not that this was ever uncontroversial, but how did it ever go so wrong, that the very problems of government that modern laws sought to correct are gleefully recreated using private companies as enforceme…

Companies try not to break laws in general. If they think doing business with you will create a liability for them, they have a freedom of association right to deny you service.

Giving a legal answer to a moral question is backwards, I think. I understand the mechanics of how it works, but I’m asking how it should, not whether it does. (Franklin’s opinions on how trials ought to go are also hardly representative of the legal practices of the late 18th century.) It is not at all a universal opinion that non-natural persons should have freedom of association at all or in this manner.

I’m not trying to directly argue that they shouldn’t, though (as long as we allow that there is no moral principle that a non-natural person’s rights follow a natural one’s). I’m saying that it’s generally accepted to be a good thing that a (branch of) government can’t directly take away your livelihood without a good reason, and if you think the reason was not good there are reasonably unbiased ways to have your disagreement considered. For the most part, this applies to a government doing it by prohibiting a private party to deal with you. On the other hand, if the same state of affairs is reached by that government merely making it potentially very expensive for a private party to deal with you, somehow none of these standards apply anymore (or maybe they nominally do but nobody’s ever succeeded at enforcing them, which amounts to the same thing). That is what gives me the chills here.

Re: GitHub deleted accounts of people who contributed to Tornado Cash repos

#330

The commenters saying be reasonable, they were sanctioned, GitHub had to do this, should look into the last time code was made illegal or similar turmoil and what the developer community did in response…It was not accepting sanctions or govt failures to understand code as “well that’s that.” - Phil Zimmerman (PGP) was under criminal investigation for arms exports by releasing the code for consumer encryption. The cas…

I think its important to make a distinction between GitHub attempting to ensure they are in legal compliance with a sanction and approving of the sanction happening at all. You can disagree with the sanction while still being understanding of GitHub trying to cut ties with the sanctioned entity. Or be critical of them being heavy handed in their compliance but agree with the sanction in general.

You’d be on the “be reasonable” side of this I suppose.

Plenty of organizations in the past have chosen what side of this conceptual line to stand on.

One can end up looking like the EFF with a long term, very strong reputation of standing up for clear boundaries of what’s right in the legalcode context and go to court over it, or you can end up looking like GitHub.

Post reply on HN