How do you ban an open-source software project and make it stick?
Thats the question facing the Treasury Department, which last week added open-source cryptocurrency mixer Tornado Cash to a U.S. government list of individuals and entities blacklisted for violating sanctions. In this case, Tornado Cash which helps keep cryptocurrency transactions private made the list for violating sanctions against North Korea.
Hear more from Benjamin Powers about this story:
But Tornado Cash isnt a company. Its an open-source software project based on the Ethereum blockchain, maintained by people and servers spread around the globe. As the team wrote in a 2020 blog post, From now on, Tornado.cash is largely living by the precepts that code is law. No one can modify the smart contracts and the protocol is decentralized and unstoppable, as long as Ethereum isnt changed or taken down.
The U.S. action raises a host of questions about whether any government can effectively sanction open-source code, rather than individuals, and what widespread effects that might have for not just future open-source projects, but anyone who has used Tornado Cash. There have been 12,243 unique user deposits on Tornado Cash, according to Dune Analytics, a blockchain analytics platform.
They werent just sanctioning a specific entity or user like from, in this case, North Korea, said Seth For Privacy, the pseudonym of a privacy educator whose work focuses on the cryptocurrency ecosystem.
Instead, theyre sanctioning the entire tool, the entire open-source tool of decentralized smart contracts on [the cryptocurrency] Ethereum, he said. They went after the entire tool itself that had been used by an entity that was sanctioned. So that was a big, big shift from previously where normally sanctions are targeting an entity using a tool.
The Treasury Department added Tornado Cash to the sanctions list known as the Specially Designated Nationals and Blocked Persons List (SDN list) for allegedly facilitating millions of dollars in cryptocurrency transactions to the North Korean government at the hands of government-affiliated hackers.
In its statement, the Treasury Department said Tornado Cash has been used to launder more than $7 billion worth of virtual currency since its creation in 2019. This includes over $455 million stolen by the Lazarus Group, a state-sponsored North Korean hacking group that was sanctioned by the U.S. in 2019, which the department described as the largest-known virtual currency heist to date.
Despite public assurances otherwise, Tornado Cash has repeatedly failed to impose effective controls designed to stop it from laundering funds for malicious cyber actors on a regular basis and without basic measures to address its risks, said Undersecretary of the Treasury for Terrorism and Financial Intelligence Brian E. Nelson in a statement. Treasury will continue to aggressively pursue actions against mixers that launder virtual currency for criminals and those who assist them.
Contrary to popular belief, few cryptocurrency transactions are private.
Public blockchains, which can be thought of as digital ledgers, keep a record of all transactions. While cryptocurrency wallets or alphanumeric addresses where funds are sent are pseudonymous, the people behind them can be identified.
Indeed, people publicly post their wallet addresses online, and blockchain analytics or analysis companies like Chainalysis and Elliptic have made whole business models off of opening up the curtains and tracking cryptocurrency transactions.
They do things like identify, categorize and track addresses in real time, using modeling and visual representations to track changes on a blockchain and identify behaviors. In a sense, they follow the money.
Tornado Cash is a mixer, meaning that it helps obfuscate the origins and destinations of cryptocurrency transactions and makes them harder to trace, even for law enforcement. People can send funds to a smart contract on the Ethereum blockchain, which then mixes the funds, which are then withdrawn from another address. That contract address was on the sanctions list even though no one owns it; its merely a series of ones and zeros executing a task.
Chainalysis, a blockchain analytics company that has done multimillion-dollar business with the U.S. military and law enforcement, estimated that 18 percent of the funds received by Tornado Cash were from sanctioned entities, but said almost entirely, we should note, before those entities were sanctioned.
Detractors of the mixer service argue that its used solely by criminals for money laundering. Proponents tout the privacy-preserving function, which is also used by a significant number of law-abiding people.
While we and many others have been working alongside both sides in the aisle in a positive direction on crypto and privacy, this move blindsided everyone, said Josh Swihart, senior vice president of growth, product strategy and regulatory affairs at Electric Coin Company, creators and supporters of the anonymity-enhancing cryptocurrency Zcash.
After the government announced the sanctions against Tornado Cash, Microsoft deleted the accounts of Tornado Cash contributors and the project itself from GitHub, a platform where developers collaboratively create and maintain open-source software. It has over 83 million users.
Thirty years of hard legal work to establish first amendment protections around software distribution, blown up in a day by GitHub/Microsoft, tweeted Johns Hopkins University cryptography professor Matthew Green.
Trade laws require GitHub to restrict users and customers identified as Specially Designated Nationals (SDNs) or other denied or blocked parties, or that may be using GitHub on behalf of blocked parties, said a GitHub spokesperson in a statement. At the same time, GitHubs vision is to be the global platform for developer collaboration. We examine government sanctions thoroughly to be certain that users and customers are not impacted beyond what is required by law.
The move to sanction a tool, rather than, for example, a cryptocurrency wallet address directly affiliated with a national security threat, has sent shock waves through the cryptocurrency community.
The implications of [the Treasury Department] adding the Tornado Cash protocol to the sanction list was actually greater for the world beyond crypto than for crypto itself, said Omid Malekan, an adjunct professor at Columbia Business School who teaches courses on crypto and blockchain.
The U.S. government took the drastic step of sanctioning an open-source, decentralized protocol specifically actually adding the Ethereum addresses of the smart contracts where the code lives, along with the addresses to access the service, he said.
That effectively criminalizes the act of seeking financial privacy, Malekan said, and opens up a can of worms around open source such as whether the government will charge someone who wrote code because a criminal later used that code.
Seth For Privacy said there may also be risks for users of the Tornado Cash service. He wonders what will happen with any of their funds that interacted with Tornado Cash and whether that money would be subject to criminal action.
On Friday, Dutch authorities announced they had arrested a 29-year-old for being suspected of involvement in concealing criminal financial flows and facilitating money laundering through the mixing of cryptocurrencies through the decentralized Ethereum mixing service Tornado Cash.
Authorities said multiple arrests could not be ruled out.
Because crypto wallets cannot reject incoming transactions, an anonymous Twitter user out to prove a point started sending a slew of incredibly small, unsolicited transactions of Ethereum that had interacted with Tornado Cash to the public wallets of celebrities, in theory implicating them in potential violations of sanctions laws.
Malekan performed a similar public experiment on Twitter by donating a small amount of Ethereum, via Tornado Cash, to Planned Parenthood and to a secret group of Russians helping Ukrainian refugees. In both cases, he said, he committed a crime, but did so to illustrate that privacy itself should not be criminalized.
There are 10,000 vanilla reasons why somebody would want to use Tornado Cash for something completely mundane in a way that is not remotely criminal or illicit, he said.
Hailey Lennon, a shareholder at the law firm Anderson Kills Technology, Media and Distributed Systems Group, said the further sanctions regimes get from a direct connection to helping terrorists and covering the source of funds, the more you get toward developers and open source that gets really sticky.
She also pointed out that there is a tension between national security and privacy in this case, with national security used as a justification for intruding on privacy. Similar debates play out around encrypted communications, for example.
When 9/11 happened, it gave the Patriot Act sharper teeth, she said. It changed the way we travel and how financial institutions surveil transactions.
The governments actions have already made it harder for Tornado Cash users to access the service, although whether sanctions can truly eliminate an open-source project remains to be seen. In addition to Microsoft removing the code and contributors from GitHub, two major application programming interface and infrastructure providers, Alchemy and Infura, have blocked API access to Tornado Cashs front-end interface. That means users trying to access it through these APIs software intermediaries that let apps talk to each other cannot see Tornado Cash. Users can still reach the Tornado Cash service, but its going to get increasingly harder and more complicated over time.
I think the main things for a project to be prepared for when building their project is to make sure its built for adversarial environments, said Seth for Privacy. Not assuming that the current environment will last forever, or that their tool itself will always be considered above board and OK.
Thanks to Lillian Barkley and Alicia Benjamin for copy editing this article.
Original post:
Tornado Cash's sanction has the tech industry watching nervously - Grid
- Research, Evaluation and Learning at the International Rescue Committee - World - ReliefWeb [Last Updated On: August 10th, 2020] [Originally Added On: August 10th, 2020]
- Conserving Biodiversity with AI - BBN Times [Last Updated On: August 10th, 2020] [Originally Added On: August 10th, 2020]
- DevOps Fundamentals You Ever Wanted To Know - hackernoon.com [Last Updated On: August 10th, 2020] [Originally Added On: August 10th, 2020]
- Another Perspective on Evictions - Bacon's Rebellion [Last Updated On: August 10th, 2020] [Originally Added On: August 10th, 2020]
- Amitabh Bachchan on fans alternate job suggestion: My job is now insured - The Indian Express [Last Updated On: August 10th, 2020] [Originally Added On: August 10th, 2020]
- Will You Soon Download Packaging Machine Controls from the Internet? - Packaging Digest [Last Updated On: August 10th, 2020] [Originally Added On: August 10th, 2020]
- 5 free resources every data scientist should start using today - The Next Web [Last Updated On: August 10th, 2020] [Originally Added On: August 10th, 2020]
- Who's hoping to make an Epic impact on Green Bay area music scene with a new concert venue? | Streetwise - Green Bay Press Gazette [Last Updated On: August 10th, 2020] [Originally Added On: August 10th, 2020]
- Industrial robots are dominating but are they safe from cyber-attacks? - TechHQ [Last Updated On: August 10th, 2020] [Originally Added On: August 10th, 2020]
- Friday Rant - Rise of the Rogue-Bots? - Diginomica [Last Updated On: August 10th, 2020] [Originally Added On: August 10th, 2020]
- Important Reasons Why You Should Pick RoR As Your Web-Based Development Project - Customer Think [Last Updated On: August 10th, 2020] [Originally Added On: August 10th, 2020]
- Portrait of the software developer as an artist - ComputerWeekly.com [Last Updated On: August 10th, 2020] [Originally Added On: August 10th, 2020]
- Python may be your safest bet for a career in coding - Gadgets Now [Last Updated On: August 10th, 2020] [Originally Added On: August 10th, 2020]
- 1Password is coming to Linux - ZDNet [Last Updated On: August 10th, 2020] [Originally Added On: August 10th, 2020]
- IBM creates an open source tool to simplify API documentation - TechRepublic [Last Updated On: August 10th, 2020] [Originally Added On: August 10th, 2020]
- Mastercard : Accelerate Ignites Next Generation of Fintech Disruptors and Partners to Build the Future of Commerce - Marketscreener.com [Last Updated On: August 12th, 2020] [Originally Added On: August 12th, 2020]
- Expanding the Universe of Haptics | by Lofelt | Aug, 2020 - Medium [Last Updated On: August 12th, 2020] [Originally Added On: August 12th, 2020]
- UX Designer Salary: 5 Important Things to Know - Dice Insights [Last Updated On: August 12th, 2020] [Originally Added On: August 12th, 2020]
- Persistent memory reshaping advanced analytics to improve customer experiences - IT World Canada [Last Updated On: August 12th, 2020] [Originally Added On: August 12th, 2020]
- NextCorps and SecondMuse Open Application Period for Programs that Help Climate Technology Startups Accelerate Hardware Manufacturing - GlobeNewswire [Last Updated On: August 12th, 2020] [Originally Added On: August 12th, 2020]
- Buried deep in the ice is the GitHub code vault humanity's safeguard against devastation - ABC News [Last Updated On: August 12th, 2020] [Originally Added On: August 12th, 2020]
- Top 12 Most Used Tools By Developers In 2020 - Analytics India Magazine [Last Updated On: August 12th, 2020] [Originally Added On: August 12th, 2020]
- Facebook's React 17 JavaScript library: Here's why its top feature is 'no new features' - ZDNet [Last Updated On: August 12th, 2020] [Originally Added On: August 12th, 2020]
- CORRECTING and REPLACING Anyscale Hosts Inaugural Ray Summit on Scalable Python and Scalable Machine Learning - Business Wire [Last Updated On: August 12th, 2020] [Originally Added On: August 12th, 2020]
- Google: Here's how much we give to open source through our GitHub activity - ZDNet [Last Updated On: August 12th, 2020] [Originally Added On: August 12th, 2020]
- How Chriselle Lim And Joan Nguyen Created Bmo, The Coworking Space And Virtual Classroom Of The Future (With A Childcare Twist) - Forbes [Last Updated On: August 13th, 2020] [Originally Added On: August 13th, 2020]
- How Will Public Libraries Adapt To New School Year Norms? - Book Riot [Last Updated On: August 13th, 2020] [Originally Added On: August 13th, 2020]
- Google: We'll test hiding the full URL in Chrome 86 to combat phishing - ZDNet [Last Updated On: August 13th, 2020] [Originally Added On: August 13th, 2020]
- How to install Python 3 and PIP 3 on Ubuntu 20.04 LTS - Linux Shout - H2S Media [Last Updated On: August 13th, 2020] [Originally Added On: August 13th, 2020]
- What are Bitcoin Wallets: Everything You Need to Know - Programming Insider [Last Updated On: August 13th, 2020] [Originally Added On: August 13th, 2020]
- JSHint is Now Free Software after Updating License to MIT Expat - WP Tavern [Last Updated On: August 13th, 2020] [Originally Added On: August 13th, 2020]
- How to learn JavaScript: These are the best online courses - Mashable [Last Updated On: August 13th, 2020] [Originally Added On: August 13th, 2020]
- What developers need to know about inter-blockchain communication - ComputerWeekly.com [Last Updated On: August 14th, 2020] [Originally Added On: August 14th, 2020]
- Introducing the CDK construct library for the serverless LAMP stack - idk.dev [Last Updated On: August 14th, 2020] [Originally Added On: August 14th, 2020]
- IBM asked software developers to take on the wrath of Mother Nature - The Drum [Last Updated On: August 14th, 2020] [Originally Added On: August 14th, 2020]
- Aspire Technology Launches First Truly Secure Public Blockchain for Creation of Digital Assets - GlobeNewswire [Last Updated On: August 14th, 2020] [Originally Added On: August 14th, 2020]
- GM Creates And Shares New Workplace Safety Technologies - Pulse 2.0 [Last Updated On: August 14th, 2020] [Originally Added On: August 14th, 2020]
- Key Considerations and Tools for IP Protection of Computer Programs in Europe and Beyond - Lexology [Last Updated On: August 14th, 2020] [Originally Added On: August 14th, 2020]
- The state of application security: What the statistics tell us - CSO Online [Last Updated On: August 14th, 2020] [Originally Added On: August 14th, 2020]
- Open Source: What's the delay on the former high/middle school on North Mulberry? - knoxpages.com [Last Updated On: August 14th, 2020] [Originally Added On: August 14th, 2020]
- The Risks Associated with OSS and How to Mitigate Them - Security Boulevard [Last Updated On: August 14th, 2020] [Originally Added On: August 14th, 2020]
- news digest: Microsoft launches open source website, TensorFlow Recorder released, and Stackery brings serverless to the Jamstack - SD Times -... [Last Updated On: August 14th, 2020] [Originally Added On: August 14th, 2020]
- Build Your Own PaaS with Crossplane: Kubernetes, OAM, and Core Workflows - InfoQ.com [Last Updated On: August 17th, 2020] [Originally Added On: August 17th, 2020]
- ISRO Is Recruiting For Vacancies with Salary Upto Rs 54000: How to Apply - The Better India [Last Updated On: August 17th, 2020] [Originally Added On: August 17th, 2020]
- Does technology increase the problem of racism and discrimination? - TechTarget [Last Updated On: August 17th, 2020] [Originally Added On: August 17th, 2020]
- CORRECTING and REPLACING Anyscale Hosts Inaugural Ray Summit on Scalable Python and Scalable Machine Learning - Yahoo Finance [Last Updated On: August 17th, 2020] [Originally Added On: August 17th, 2020]
- In the City: Take advantage of open recreation, cultural and park amenities - Coloradoan [Last Updated On: August 17th, 2020] [Originally Added On: August 17th, 2020]
- Exploring the future of modern software development - ComputerWeekly.com [Last Updated On: August 21st, 2020] [Originally Added On: August 21st, 2020]
- Hadoop Developer Interview Questions: What to Know to Land the Job - Dice Insights [Last Updated On: August 21st, 2020] [Originally Added On: August 21st, 2020]
- SiFive Opens Business Unit to Build Chips With Arm and RISC-V Inside - Electronic Design [Last Updated On: August 21st, 2020] [Originally Added On: August 21st, 2020]
- Use Pulumi and Azure DevOps to deploy infrastructure as code - TechTarget [Last Updated On: August 21st, 2020] [Originally Added On: August 21st, 2020]
- Why ASP.NET Core Is Regarded As One Of The Best Frameworks For Building Highly Scalable And Modern Web Applications - WhaTech [Last Updated On: August 21st, 2020] [Originally Added On: August 21st, 2020]
- NITK figures 4th in Google Summer of Code ranking - BusinessLine [Last Updated On: August 21st, 2020] [Originally Added On: August 21st, 2020]
- Learn More About Dynamo for Revit: Features, Functions, and News - ArchDaily [Last Updated On: August 21st, 2020] [Originally Added On: August 21st, 2020]
- Linux Foundation showcases the greater good of open source - ComputerWeekly.com [Last Updated On: August 21st, 2020] [Originally Added On: August 21st, 2020]
- Programming language Kotlin 1.4 is out: This is how it's improved quality and performance - ZDNet [Last Updated On: August 21st, 2020] [Originally Added On: August 21st, 2020]
- Top 10 Languages That Paid Highest Salaries Worldwide In 2020 - Analytics India Magazine [Last Updated On: August 21st, 2020] [Originally Added On: August 21st, 2020]
- Programming language Rust: Mozilla job cuts have hit us badly but here's how we'll survive - ZDNet [Last Updated On: August 21st, 2020] [Originally Added On: August 21st, 2020]
- In-App Bidding Gathers Steam, But Adoption Looks Nothing Like Header Bidding On The Web - AdExchanger [Last Updated On: August 21st, 2020] [Originally Added On: August 21st, 2020]
- 13 thoughts on Fitting Snake Into A QR Code - Hackaday [Last Updated On: August 21st, 2020] [Originally Added On: August 21st, 2020]
- Newham test and trace app was designed by man who grew up in the borough - Newham Recorder [Last Updated On: August 21st, 2020] [Originally Added On: August 21st, 2020]
- 'Trapped in a code' the fight over our algorithmic future - Open Democracy [Last Updated On: August 21st, 2020] [Originally Added On: August 21st, 2020]
- Telegram launches one-on-one video calls on iOS and Android - The Verge [Last Updated On: August 21st, 2020] [Originally Added On: August 21st, 2020]
- AWS Controllers for Kubernetes Will Be A 'Boon For Developers' - CRN: Technology news for channel partners and solution providers [Last Updated On: August 21st, 2020] [Originally Added On: August 21st, 2020]
- Coding within company constraints - ComputerWeekly.com [Last Updated On: August 21st, 2020] [Originally Added On: August 21st, 2020]
- Open Source and Open Standards: The Recipe for Success Featured - The Fast Mode [Last Updated On: August 21st, 2020] [Originally Added On: August 21st, 2020]
- How Intel helped give the worlds first cyborg a voice - The Next Web [Last Updated On: August 21st, 2020] [Originally Added On: August 21st, 2020]
- Tiger Woods, Rory McIlroy near bottom of field at The Northern Trust - ESPN [Last Updated On: August 22nd, 2020] [Originally Added On: August 22nd, 2020]
- Intel Owl OSINT tool automates the intel-gathering process using a single API - The Daily Swig [Last Updated On: August 22nd, 2020] [Originally Added On: August 22nd, 2020]
- IOTA Foundation presents the current projects in the mobility industry - Crypto News Flash [Last Updated On: August 22nd, 2020] [Originally Added On: August 22nd, 2020]
- How 'Fortnite' and 'Second Life' Shaped the Future of Indian Market - Santa Fe Reporter [Last Updated On: August 22nd, 2020] [Originally Added On: August 22nd, 2020]
- Apple Enters $ 2 Trillion Club, Github's Chinese Counterpart And More In This Week's Top News - Analytics India Magazine [Last Updated On: August 22nd, 2020] [Originally Added On: August 22nd, 2020]
- As world grapples with pandemic, schools are the epicenter - ABC News [Last Updated On: August 24th, 2020] [Originally Added On: August 24th, 2020]
- Why Businesses Should Embrace Modernizing Their Legacy Applications - TechBullion [Last Updated On: August 24th, 2020] [Originally Added On: August 24th, 2020]
- Is It Time To Rename RPG? - IT Jungle [Last Updated On: August 24th, 2020] [Originally Added On: August 24th, 2020]
- Phantasy Star Online programmers on breaking new ground and their Diablo-style isometric prototype - Polygon [Last Updated On: August 24th, 2020] [Originally Added On: August 24th, 2020]
- How To Learn To Program In Python By Playing Videogames - Analytics India Magazine [Last Updated On: August 24th, 2020] [Originally Added On: August 24th, 2020]
- New Microsoft program to help develop the quantum computing workforce of the future in India - Microsoft [Last Updated On: August 24th, 2020] [Originally Added On: August 24th, 2020]
- How the Docker Revolution Will Change Your Programming, Part 1 - Walter Bradley Center for Natural and Artificial Intelligence [Last Updated On: August 24th, 2020] [Originally Added On: August 24th, 2020]
- The art of developing happy customers - ComputerWeekly.com [Last Updated On: August 24th, 2020] [Originally Added On: August 24th, 2020]