Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Well, not exactly. I'm not in the US, so I can't be served an NSL (or don't really give a crap about them), and I can't update the canary myself. I've messaged both the security officer and the person who updates it (well, I messaged the entire company, really), and I was assured we'll update it ASAP.


Sorry man. Obviously you don't understand how canaries are supposed to work, otherwise you wouldn't have posted in this thread to begin with.

I used NSL as a generic term. I'm not american either, doesn't change anything.

But seriously please stop posting. You're doing more harm than you help. You can't know IF something happened. Posting a public statement that nothing happened just puts the people that might know under more pressure. There is a good reason you can't update the canary yourself. Because if you could, it wouldn' work.

I cannot take your company serious that way.

Next time send the SMS without any public statement please.


Right. He has no clue on how the warrant canary setup works normally.

http://en.wikipedia.org/wiki/Warrant_canary

"A warrant canary may be posted by the provider to inform users of dates that they have not been served a secret subpoena. If the canary has not been updated in the time period specified by the host, users are to assume that the host has been served with such a subpoena."


No, you have no clue on what I'm talking about. How many people's data will get compromised if someone forgets to update a canary? Zero. The only way for a canary to fail catastrophically is for the owner to update it after the servers have been compromised, thus revealing sensitive data.

I'm not talking about trust in a company or how this makes one look. I'm talking about protecting people's data, and failing to update a canary doesn't compromise that.


> He has no clue

> No, you have no clue

Come on, lads.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: