Live data from Hacker News

CloudFlare’s last Warrant Canary was published over a year ago

cloudflare.com

1–10 of 145 posts

Re: CloudFlare’s last Warrant Canary was published over a year ago

#3
The glossary entry on warrant canaries is dated December 2020, but there is a more recent canary list in their 2022 transparency report (https://www.cloudflare.com/en-au/transparency/) with the same 6 items in it.

Bizarre they appear to have skipped the H2 2022 transparency report unless I’m missing something

Re: CloudFlare’s last Warrant Canary was published over a year ago

#4
post #3

The glossary entry on warrant canaries is dated December 2020, but there is a more recent canary list in their 2022 transparency report ( https://www.cloudflare.com/en-au/transparency/ ) with the same 6 items in it. Bizarre they appear to have skipped the H2 2022 transparency report unless I’m missing something

H2 2022 and H1 2023

Re: CloudFlare’s last Warrant Canary was published over a year ago

#5

So they got a warrant that they can't talk about. That seems obvious.

Their Canary has more to do with their infrastructure being compromised. It's likely one or more of these statements are no longer true:

1. Cloudflare has never turned over our encryption or authentication keys or our customers' encryption or authentication keys to anyone.

2. Cloudflare has never installed any law enforcement software or equipment anywhere on our network.

3. Cloudflare has never provided any law enforcement organization a feed of our customers' content transiting our network.

4. Cloudflare has never modified customer content at the request of law enforcement or another third party.

5. Cloudflare has never modified the intended destination of DNS responses at the request of law enforcement or another third party.

6. Cloudflare has never weakened, compromised, or subverted any of its encryption at the request of law enforcement or another third party.

Re: CloudFlare’s last Warrant Canary was published over a year ago

#6

So they got a warrant that they can't talk about. That seems obvious.

> That seems obvious.

You would assume, but when the Riseup canary expired plenty of people seemed willing to believe that a procedural issue or carelessness was to blame.

Re: CloudFlare’s last Warrant Canary was published over a year ago

#7
post #5

So they got a warrant that they can't talk about. That seems obvious.

Their Canary has more to do with their infrastructure being compromised. It's likely one or more of these statements are no longer true: 1. Cloudflare has never turned over our encryption or authentication keys or our customers' encryption or authentication keys to anyone. 2. Cloudflare has never installed any law enforcement software or equipment anywhere on our network. 3. Cloudflare has never provided any law enfo…

I wonder how pedantic you could legally get with that.

Cloudflare has never been compelled to give up information to an agency called AAA. Cloudflare has never been compelled to give up information to an agency called AAB. ...etc.

Re: CloudFlare’s last Warrant Canary was published over a year ago

#8
post #5

So they got a warrant that they can't talk about. That seems obvious.

Their Canary has more to do with their infrastructure being compromised. It's likely one or more of these statements are no longer true: 1. Cloudflare has never turned over our encryption or authentication keys or our customers' encryption or authentication keys to anyone. 2. Cloudflare has never installed any law enforcement software or equipment anywhere on our network. 3. Cloudflare has never provided any law enfo…

#5 seems most likely.

Re: CloudFlare’s last Warrant Canary was published over a year ago

#9
post #4
post #3

The glossary entry on warrant canaries is dated December 2020, but there is a more recent canary list in their 2022 transparency report ( https://www.cloudflare.com/en-au/transparency/ ) with the same 6 items in it. Bizarre they appear to have skipped the H2 2022 transparency report unless I’m missing something

H2 2022 and H1 2023

[deleted]

Re: CloudFlare’s last Warrant Canary was published over a year ago

#10
post #7
post #5

Earlier quoted context omitted.

Their Canary has more to do with their infrastructure being compromised. It's likely one or more of these statements are no longer true: 1. Cloudflare has never turned over our encryption or authentication keys or our customers' encryption or authentication keys to anyone. 2. Cloudflare has never installed any law enforcement software or equipment anywhere on our network. 3. Cloudflare has never provided any law enfo…

I wonder how pedantic you could legally get with that. Cloudflare has never been compelled to give up information to an agency called AAA. Cloudflare has never been compelled to give up information to an agency called AAB. ...etc.

Suuuuper pedantic.

For instance, 2 and 3 narrowly specify just law enforcement agencies, of which the CIA and NSA are not.

Post reply on HN