Skip to content
تُعرض هذه الصفحة بالإنجليزية.الترجمة العربية مُهيّأة ولكن لم تُكتب بعد. لا شيء هنا مُترجَم آليًا، لأن ادعاءً أمنيًا مُترجَمًا خطأً هو ادعاء كاذب.اقرأ بالإنجليزية

CANARY · FAMILY-WIDE · SIGNED ELSEWHERE

The warrant canary, and what it can and cannot say

GuardTalk publishes one canary for the whole family. This page explains what it asserts, where the signed statement lives, and why a canary is a convention rather than a guarantee.

What a warrant canary is.

A warrant canary is a signed statement that a project publishes on a schedule. It asserts things that have not happened. Its meaning is carried by the signature and by the schedule, not by the sentences alone.

The convention works by absence. While the statement keeps being renewed, signed and unchanged, readers may draw one conclusion. If a renewal is late, or a clause quietly disappears, readers draw their own conclusion. Nobody has to say anything they may be forbidden from saying.

That is the whole mechanism. It is a signal in the negative, and it is only as useful as the reader's willingness to check it on time.

What this one asserts.

There is one canary for the GuardTalk family, covering the system rather than this operating system alone. That is deliberate. A separate OS canary would let a compulsion against the system be answered with an unchanged statement here.

The family statement covers assertions of this kind:

  • That no warrant, order or subpoena has been received that the project is forbidden to disclose.
  • That no demand has been made to hand over signing keys, or to sign a build the project did not produce.
  • That no demand has been made to add a backdoor, a weakening, or a covert update path to any component.
  • That no seizure of, or compelled access to, project infrastructure has taken place.

The exact wording is the family statement's, not this page's summary of it. Read the signed text rather than this list, and treat the signed text as the only authority.

The cadence.

A canary is renewed and re-signed on a fixed cadence. The cadence is part of the mechanism: it is what tells a reader when a missing renewal has become meaningful. This project's cadence is not settled yet, so it is not stated here.

// confirm §19.11canary cadence and the shared security.txt

We publish no cadence figure until it is committed. Inventing one would be worse than stating none, because a reader would then start a clock that nobody is keeping.

Where the signed statement lives.

The canary is published, signed and renewed on the family site, and this page mirrors its existence rather than its content. The GuardTalk warrant canary

Verify the signature against the published key fingerprint before you rely on the statement. The fingerprint itself is not yet published, and this site prints the marker instead of a value. How signature checking works here →

// confirm §19.7signing-key fingerprint for canary and release verification

A mirror you reached over a hijacked path can be rewritten. Reaching the canary over the .onion mirror, and checking the signature, removes both of those worries. The mirror address is printed in the footer of every page here.

What a canary cannot tell you.

Protects against

A canary makes a compelled silence visible without breaking it, if the project is able to stop renewing it.

Limit

A canary is a publishing convention, not a legal instrument. Its force in any given jurisdiction is untested, and a court may take a different view of it than its authors do.

Protects against

A missing renewal is a prompt to ask questions, publicly and directly.

Limit

An unrenewed canary is ambiguous. It may mean compulsion. It may also mean an outage, a lost key, a missed handover or an administrative failure.

Protects against

A canary speaks only about demands made to the project itself.

Limit

A canary says nothing about what an adversary achieves without asking us. It is not evidence about implants, interception, or a compromise the project has not detected.

Why it matters less here than you might think.

The canary is worth publishing, and it is not the thing protecting you. The design goal is that a compelled GuardTalk can hand over very little that would help.

alphaThe verified-boot trust anchor is a custom AVB key (avb_pkmd.bin) that you generate and hold. A build we were compelled to sign is not one your device accepts. where this ends →

We hold no key that unlocks your device, and we ship no backdoor. That is not a promise to take on faith. The key model is documented, the sources are published, and the build is one you can produce yourself. The AVB key workflow → · Build it yourself →

A property of the design is worth more than a sentence on this page. The canary is published because it costs little and occasionally says something. It is not the reason your device is defensible.

Read the threat model → · Verify the build →

A canary is one signal among several.

Read it beside the threat model and the status board, which say what this build does and how far along it is.