Toronto-Based VPN Provider Plans to Quit Canada over Lawful-Access Bill
citizenlab.ca154 points by speckx a day ago
154 points by speckx a day ago
I’m more concerned about OpenBSD. Given how centralized the project governance is, and its base in Canada, I can imagine the government attempting to (for example) force the project to serve backdoored images or updates to targeted people. A backdoor or bugdoor in the source would probably be spotted by someone, and I’m not even sure the bill allows a broad tool like that, but that’s not the only way to compromise software users.
Fortunately the mirrors are distributed, so maybe that reduces the risk.
Theo has been historically rather uninterested in taking a position on Canadian political issues such as this or engaging as an authoritative voice and source of information with the domestic media and politicians. For instance there is very little if any overlap between Theo and the Munk School's Citizen Lab or associated projects. Or anything that you could broadly classify as an effort parallel to the Citizen Lab. I am not quite sure why this is.
It’s strange because he was very vocal about US political issues during the early GWOT years. I would guess some kind of Canadian patriotism, but he’s originally from South Africa, so that seems less likely. Perhaps it’s just an abundance of caution about upsetting his (and the project’s) current home.
FWIW a lot of Canadians seem to avoid discussing Canadian politics publicly, though.
Knowing openbsd and Theo de Raadt I'm sure he will never ever comply with an order like that.
That's the neat thing about laws. You just put them in prison until the replacement does comply.
Like the other reply, I would expect them to just move the project to a different country then instead.
Honestly, the OS that prides itself on "Only two remote holes in the default install, in a heck of a long time!" is not going to introduce a remote hole on purpose, that'll be one cold day in heck.
This is really the least thing to worry about.
Except that doesn’t work with international software projects. Someone in another country takes over with consent of the community. It’s disruptive but not fatal if there’s sufficient interest in the project.
Problem is, where do you take a company like this if you want peace of mind that the new host country won't immediately try to pass a similar law?
Use a VPN from country that is hostile to the one you are living in. This way your own country won’t spy on you.
People tend to worry about other countries, but it is usually within the country they live in that they have to worry about their rights being infringed.
Step 1 is making back doors mandatory. Step 2 is banning anything they can't decrypt.
I don't know if the second part has been discussed yet, but it's only possible with the former in place, so it makes sense to just ram that in first.
Most people don't care about this at all because they cannot fathom what it actually means. It takes the government actually turning on you to understand at a visceral level and by then it's too late. It seems there have still not been enough historical examples of this to truly burn it into memory.
Or use a VPN from some punk who ignores the law. The future belongs to those who say "they can't arrest us all"
Except in the USA where they will, in fact, arrest everyone.
aka your local FBI agent. See ANOM or any of the other honey pots that glowed from kilometers away.
And even if they are not backdoored at first, once the state knocks on the developers door with the great offer that their kid will grow up with a father who is not in jail people's principles might change quickly.
I've been working through my options per digital freedom, human dignity, and non-double-taxation as a US citizen. It's a depressingly short list.
The real use case for satellite-borne data centers.
I fail to see how a satellite data center would fix this unless the company was entirely off planet
Hell, the whole company could be located on that satellite if it transacts in crypto-currency.
Despite the hype, crypto is traceable. It is harder than other currencies and one transaction is probably untraceable. However if you are running a business you are going to get repeated payments from customers and repeatedly pay your employees and suppliers, which in turn creates enough data that they can track you down.
Mullvad accepts Monero (XMR), the most private and untraceable coin available today. Your point is correct for all others though.
Mullvad will accept envelopes of cash. They go far and above any other company when it comes to helping their customers maintain anonymity.
In the US, transactions over $10,000 need to be reported regardless. I don't know laws in Europe, but I would expect they have something similar. Which is to say, you can accept envelopes of cash only for relatively small amounts of money before you are going to get in trouble yourself. The government doesn't like tax fraud, and without the ability to trace things, they can prove tax fraud just because if there was no tax fraud, you wouldn't have a certain amount of money.
You don't have to report all transactions over $10,000 in cash. Your bank, where you will probably want to keep the money, will report all transaction over $10,000.