12 ms·
I noticed that their canary [0] has not been updated and it should have been updated at the latest on 21st of February. [0] https://crypton.sh/canary https://c
by holmb 7y ago
I noticed that their canary [0] has not been updated and it should have been updated at the latest on 21st of February.
[0] https://crypton.sh/canary https://crypton.sh/canary
- threatofrain 7y agoInteresting and concerning find. I think it would be useful to have a 3rd-party service that reliably alerts when canary conditions aren't fulfilled, along with a diff history.
- dijksterhuis 7y agocanarywatch.org existed until Q3 2019 [0] > The coalition of organizations which created Canary Watch explained their decision to discontinue the project by stating that it has achieved its goals to raise awareness about "illegal and unconstitutional national security process, including National Security Letters and other secret court processes." The Electronic Frontier Foundation also noted that "the fact that canaries are non-standard makes it difficult to automatically monitor them for changes or takedowns." [0]: https://en.wikipedia.org/wiki/Warrant_canary https://en.wikipedia.org/wiki/Warrant_canary
- rmrfstar 7y agoThe canary has been updated, but for some reason they rolled from SHA512 back to SHA1. Does not inspire confidence in their crypto-nerdery. Also, their logo is a bee. Bees make honey. Just saying. Operators of these services tend to fall into 3 camps: the cipherpunks, the crypto AG's, and the one coin's. I keep a strong prior on option 3, which means I need to be convinced a service is actually less hostile than whatever FAANG has on offer.