Live data from Hacker News

CloudFlare’s last Warrant Canary was published over a year ago

cloudflare.com

11–20 of 145 posts

Re: CloudFlare’s last Warrant Canary was published over a year ago

#11
post #4
post #3

The glossary entry on warrant canaries is dated December 2020, but there is a more recent canary list in their 2022 transparency report ( https://www.cloudflare.com/en-au/transparency/ ) with the same 6 items in it. Bizarre they appear to have skipped the H2 2022 transparency report unless I’m missing something

H2 2022 and H1 2023

Give H1 2023 has only just wrapped up I optimistically presumed it would be in production now, but I’ve got no idea what the lead time on these reports historically has been

Re: CloudFlare’s last Warrant Canary was published over a year ago

#12
post #7
post #5

Earlier quoted context omitted.

Their Canary has more to do with their infrastructure being compromised. It's likely one or more of these statements are no longer true: 1. Cloudflare has never turned over our encryption or authentication keys or our customers' encryption or authentication keys to anyone. 2. Cloudflare has never installed any law enforcement software or equipment anywhere on our network. 3. Cloudflare has never provided any law enfo…

I wonder how pedantic you could legally get with that. Cloudflare has never been compelled to give up information to an agency called AAA. Cloudflare has never been compelled to give up information to an agency called AAB. ...etc.

Why do we have to be pedantic and can't just say when the FBI or CIA come after us?

Re: CloudFlare’s last Warrant Canary was published over a year ago

#14
post #8
post #5

Earlier quoted context omitted.

Their Canary has more to do with their infrastructure being compromised. It's likely one or more of these statements are no longer true: 1. Cloudflare has never turned over our encryption or authentication keys or our customers' encryption or authentication keys to anyone. 2. Cloudflare has never installed any law enforcement software or equipment anywhere on our network. 3. Cloudflare has never provided any law enfo…

#5 seems most likely.

They all seem likely given that they all have multinational precedent.

Re: CloudFlare’s last Warrant Canary was published over a year ago

#15
post #7

Earlier quoted context omitted.

I wonder how pedantic you could legally get with that. Cloudflare has never been compelled to give up information to an agency called AAA. Cloudflare has never been compelled to give up information to an agency called AAB. ...etc.

Why do we have to be pedantic and can't just say when the FBI or CIA come after us?

Gag orders.

Re: CloudFlare’s last Warrant Canary was published over a year ago

#16
post #7

Earlier quoted context omitted.

I wonder how pedantic you could legally get with that. Cloudflare has never been compelled to give up information to an agency called AAA. Cloudflare has never been compelled to give up information to an agency called AAB. ...etc.

Why do we have to be pedantic and can't just say when the FBI or CIA come after us?

The essence of a canary is you can't say they did, but you can stop saying they didn't.

Re: CloudFlare’s last Warrant Canary was published over a year ago

#18

So they got a warrant that they can't talk about. That seems obvious.

> That seems obvious. You would assume, but when the Riseup canary expired plenty of people seemed willing to believe that a procedural issue or carelessness was to blame.

Same with Spideroak.

Re: CloudFlare’s last Warrant Canary was published over a year ago

#20
post #13

Warrant canaries are largely believed to be unworkable. Ie federal lawyers are going to say "cute, but no, you cannot disclose that we warranted you in this or any other way."

Is there a precedent for compelling speech, even with something like an NSL?
Post reply on HN