Warrant canary


A warrant canary is a method by which a communications service provider aims to inform its users that the provider has been served with a government subpoena despite legal prohibitions on revealing the existence of the subpoena. The warrant canary typically informs users that there has been a court-issued subpoena as of a particular date. If the canary is not updated for the period specified by the host or if the warning is removed, users are to assume that the host has been served with such a subpoena. The intention is to allow the provider to warn users of the existence of a subpoena passively, without technically violating the court order not to do so.
Some subpoenas, such as those covered under 18 U.S.C. §2709 of the USA Patriot Act, provide criminal penalties for disclosing the existence of the subpoena to any third party, including the service provider's users.
National Security Letters originated in the 1986 Electronic Communications Privacy Act and originally targeted those suspected of being agents of a foreign power. Targeting agents of a foreign power was revised in 2001 under the Patriot Act to allow NSLs to target those who may have information deemed relevant to both counterintelligence activities directed against the United States and terrorism. The idea of using negative pronouncements to thwart the nondisclosure requirements of court orders and served secret warrants was first proposed by Steven Schear on the cypherpunks mailing list, mainly to uncover targeted individuals at ISPs. It was also suggested for and used by public libraries in 2002 in response to the USA Patriot Act, which could have forced librarians to disclose the circulation history of library patrons.

Usage

The first commercial use of a warrant canary was by the US cloud storage provider rsync.net, which began publishing its canary in 2006. In addition to a digital signature, it provides a recent news headline as proof that the warrant canary was recently posted as well as mirroring the posting internationally.
On November 5, 2013, Apple became the most prominent company to publicly state that it had never received an order for user data under Section 215 of the Patriot Act. On September 18, 2014, GigaOm reported that the warrant canary statement did not appear anymore in the next two Apple Transparency Reports, covering July–December 2013 and January–June 2014. Tumblr also included a warrant canary in the transparency report that it issued on February 3, 2014. In August 2014, the online cloud service Spider Oak implemented an encrypted warrant canary that publishes an "All Clear!" message every 6 months. Three PGP signatures from geographically distributed signers must sign each message—so if a government agency forced SpiderOak to update the page, they would need to enlist the help of all three signers.
In September 2014, U.S. security researcher Moxie Marlinspike wrote that "every lawyer I've spoken to has indicated that having a 'canary' you remove or choose not to update would likely have the same legal consequences as simply posting something that explicitly says you've received something."
As a matter before a court exercising judicial power, a warrant could be obtained against another person that prohibits its own disclosure of existence or non-existence. However, this could easily be remedied by amalgamating the right to a fair trial with the warrant canary. In Australia, everyone has a right to a fair trial under case law, and the larger picture of this law being the right to access a lawyer, if one were to write a warrant canary in such a way that seeks access to legal representation, it may have the effect of "triggering" the canary; informing the larger public of the existence of a secret warrant, and should an authority object or remove such a notice seeking legal representation, could be seen as that authority's infringement of this legal right in Australia and other common law jurisdictions. This would cure the inherent prohibition in reducing warrant canaries to be a matter of negative or positive action.
Australia outlawed the use of a certain kind of warrant canary in March 2015, making it illegal for a journalist to "disclose information about the existence or non-existence" of a warrant issued under new mandatory data retention laws. It is unlikely a journalist could give a correct canary in this situation anyway, as under this legislation the agency obtaining the warrant is not compelled to inform the journalist of the warrant. Afterwards, computer security and privacy specialist Bruce Schneier wrote in a blog post that "ersonally, I have never believed would work. It relies on the fact that a prohibition against speaking doesn't prevent someone from not speaking. But courts generally aren't impressed by this sort of thing, and I can easily imagine a secret warrant that includes a prohibition against triggering the warrant canary. And for all I know, there are right now secret legal proceedings on this very issue."
That said, case law specific to the United States would render the covert continuance of warrant canaries subject to constitutionality challenges. West Virginia State Board of Education v. Barnette and Wooley v. Maynard rule the Free Speech Clause prohibits compelling someone to speak against one's wishes; this can easily be extended to prevent someone from being compelled to lie. New York Times Co. v. United States protects one exercising the First Amendment to publish government information, even if it is against the wishes of the government, except under grave and exceptional circumstances previously set by act and precedent. The latter also carries the weight of acting against a direct government intervention similar to a government intervention against a warrant canary.

Companies and organizations who no longer have warrant canaries

The following is a list of companies and organizations whose warrant canaries no longer appear in transparency reports:
In 2015, a coalition of organizations consisting of the EFF, Freedom of the Press Foundation, NYU Law, the Calyx Institute, and the Berkman Center created a website called Canary Watch in order to provide a compiled list of all companies providing warrant canaries. Its mission was to provide prompt updates of any changes in a canary's state. It is often difficult for users to ascertain a canary's validity on their own and thus Canary Watch aimed to provide a simple display of all active canaries and any blocks of time that they were not active. In May 2016, it was announced that Canary Watch "will no longer accept submissions of new canaries or monitor the existing canaries for changes or take downs". The coalition of organizations which created Canary Watch explained their decision to discontinue the project by stating that it has achieved its goals to raise awareness about "illegal and unconstitutional national security process, including National Security Letters and other secret court processes." The Electronic Frontier Foundation also noted that "the fact that canaries are non-standard makes it difficult to automatically monitor them for changes or takedowns."
In 2016 the EFF announced it would no longer accept submissions of new canaries, nor monitor existing canaries. They explained that the project had run its course, that ample attention had been brought to canaries, and detailed warrant canary strengths and weaknesses they observed. As of Q3 2019 canarywatch.org no longer exists.