Hacker News .hnnew | past | comments | ask | show | jobs | submitlogin

A point of feedback: I know it is illegal for you to inform users if you have received a warrant for their data, but you should devise a method where a flag such as 'third party access' is set in the user preference panel to let them know that somebody has accessed the data

architect this flag as part of any 'admin' access and describe it on your website - users would feel better about it

if the feds know your system is designed in a way that you can't help but to inform users that data has been accessed, it might dissuade them from approaching you with warrants in the first place



Interesting technical idea, but it ignores how power works.

The govt will just request that they change the code so that you're in compliance.


I poured through the laws and talked to a lawyer about it, though this was years ago. It is illegal to inform a user directly in any way, they can't make you re-architect your system to provide them a backdoor unknown to the user.

also the wording can not mention 'warrant' or 'fbi' so it has to be something like 'third party access'

I have been meaning to do this as a 'project' with full legal advice etc. and suggest it to google, other cloud providers

Edit: found that rsync.net already do this, in a different way, as a warrant canary: http://www.rsync.net/resources/notices/canary.txt




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: