China Tries to Extract Pledge of Compliance from U.S. Tech Firms
nytimes.com
nytimes.com
Our anger should instead be focused on solutions to surveillance that do not rely on trusting corporations. F/OSS tools and client-side encryption is the path forwards, not extracting unenforceable promises from trillion-dollar tech giants.
FOSS and client-side encryption alone are not going to solve this problem. If governments can openly demand and enforce whatever they like, then users of these technologies can be threatened with draconian punishment and be prosecuted as terrorists and pedophiles.
There needs to be counter pressure from consumers, consumer groups, experts and corporations in order for client-side technologies to remain a viable option for people outside the Ecuadorian embassies of the world.
Corporations are not in the business of appeasing local governments. Corporations are in the business of pleasing consumers so that they make a profit. They appease local governments only to reach consumers and they can't do it in a way that causes consumers to distrust them as that would be self defeating.
Also, what is in the economic interest of a corporation is not self evident. It's the people at the top of these companies who make these judgements. I'm sure many of them value their privacy more than the average person and their judgement is going to be influenced by that. The same goes for shareholders.
It's always going to be a balancing act for global internet companies so let's make our weight felt!
You're describing a world where corporations represent you, the consumer. But you're not a constituent of the corporation, you're a resource. Corporations want to keep you happy in the same way that dairy farmers want to keep cows happy, so they'll keep on producing money or milk. The constituents are shareholders.
The ones representing your interests are the elected parts of the government. Which, I know, is laughable in the US. But still, corporations are not it.
Your comments on open source and consumer counter pressure describe something hopeful.
a bit off-topic, but is there a country that is not laughable and the general public actually trust and believe the government have their needs in mind?
Not at all. I'm describing a world of partially shared mutual interest.
>Corporations want to keep you happy in the same way that dairy farmers want to keep cows happy
No. I have a voluntary business relationship with some corporations. Cows do not have a voluntary business relationship with farmers. Corporations cannot milk me against my will or slaughter me when I stop giving milk. All they can do is try to trade with me.
My relationship with the people of the country I am allowed to vote in is not voluntary. It's a result of the birth lottery. I don't even share many intersts with them as I don't live there and it's not a global superpower.
That said, it's not my intention to deny one fundamental fact: The extent of my influence on corporations as a consumer and as a shareholder depends exclusively on my wealth. My influence on elected politicians is much more complex and there is at least some chance of my being human to count for something regardless of wealth.
Fundamental rights to privacy cannot be based on wealth, but that doesn't mean we should ignore our shared interests with corporations where they exist.
"respond to the people at large" is an awfully general characterisation.
What corporations typically do is respond to wishes of their customers and prospective customers, provided they can make money from doing so. If one corporation does not, a competitor probably will. So there are potential alliances to be formed between consumers and specific corporations regarding specific political issues.
Again, I'm not saying that the market or consumer power magically replaces democracy or that the interests of consumers and corporations are naturally aligned in general.
Maybe in the perfect magical world of highschool civics where consumers have total freedom to choose from amongst competitive products and corporations are perfectly open about privacy. The reality is much less idealized. Corporations lie to customers daily. Contracts bind customers to not adopt competitive products. And state-sanctioned monopolies in many counties (US/Canada/China) severely limit choice.
Any publicly traded corporation, by definition, is only interested in money. Sometimes appeasing customers helps that bottom line, but often it doesn't. Sometimes screwing over you customers is the way, especially when those customers have nowhere else to go.
Those who would violate our rights are fighting this war on multiple fronts. F/OSS is an effective tool for defending against government hackers for some attack vectors, but aren't a panacea. There are a number of firmware and hardware attack vectors that F/OSS can't defend against currently.
And at best, F/OSS only protects those who use it and use it correctly and end-to-end. Human rights don't just apply to people who think they need them. Facebook/GMail/Baidu users still have a right to privacy even though they've chosen to use services run by companies whose business models inherently involve violating their rights. Users who think they are anonymous on Reddit/Imgur still have a right to privacy even though they don't understand that they are being tracked through ads.
I know that this is somewhat of a losing war, but we've won battles here and there. Remember that if it weren't for the legal side of this fight, many of the technical solutions we which are widely available today would be classified as weapons and therefore unavailable to many people.
Of course you can enforce it. Create a law that tech giants must comply with FISMA/FEDRAMP, ISO 27001, DFARS 252.204-7012. I don't see why that's such a bad thing anyways. Compliance is a necessity because its just thorough hygiene.
Why DON't we have a written process to change our firewall rules, a written process to review our code, a written process to rotate our keys. These don't seem like a burden to me at all.
In some areas, the US prohibits cooperation with the laws of other countries. The Arab League requires vendors to agree not to do business with Israel, and the US has a law forbidding US companies from complying with that. So there's a precedent for this. That's been enough to more or less break the Arab League's boycott.
The U.S. would likely be the TPP country most opposed to this. In fact, due to its copyright provisions (as of last leaks), TPP almost implies mandating censorship and internet filtering (in the form of take down notices).
2) Lots of laws in the arab world are not enforced. Outsiders often find these and assume they mean something. They do not. In totalitarian states what matters is what the ruling group wants to do. The existence or non-existence of a written law is very much beside the point.
The rest is expected but this to me is the most interesting one of the lot. We've seen these requests come up now and again, but I think we will be seeing the importance of "where" data is stored more and more in the upcoming years.
As a US citizen, I know that Google/Apple/Facebook/etc. have tons of data on me and acknowledge that the US gov't can generally get some of this data, but I'll be damned if those companies let Chinese/Russian/etc. governments access that data. More to the point, I don't think the US government wants information on its citizens stored elsewhere, and readily accessible to government inspection.
So let's not be naive and ask how dare China ask for the same thing. Of course they would ask that.
And the microsoft case regarding data stored in ireland[1] just adds more fuel to the fire.
New TPP agreement explicitly prohibits those laws.
>"To do so, American negotiators are leveraging trade deals with much of the developed world, inserting language to ensure “cross-border data flows”—a euphemism that actually means they want to inhibit foreign governments from keeping data hosted domestically." http://motherboard.vice.com/read/the-trans-pacific-partnersh...
However, the reasoning is quite different.
The EU wants data stored in the EU so that it is nominally protected from hostile country intercept and is subject to EU protection laws.
Whereas, China actively intends to use the locally stored data for intercept.
Now, one can argue that the local EU governments also want to intercept the data. Nevertheless, until we see The Great Internet Wall of Europe I'm willing to give those countries a little more slack that they might actually be trying to do the right thing.
As for GFW, yeah it's evil, but I don't see how that means that the chinese government is not concerned with others spying on them.
EDIT: Just to clarify, I hate all this spying with a passion. Just saying that the motives are the same for everyone here.
I see this a lot, but I don't understand the viewpoint at all. Surely, as a US citizen, you should be concerned about your information finding its way into the US government? Why would you care what the Chinese government knows about you? What are they going to do?
Blackmail you into doing something illegal, including, but not limited to, stealing trade secrets from your employer to be shared with state-backed companies. The reach of foreign countries doesn't stop at their borders.
Even if you locate your server farm outwith unfriendly jurisdiction, you still need to connect it to the rest of the world, and it's difficult to do that without engaging the services of a company that is susceptible to influence by an unfriendly government. You're also susceptible to being effectively (if not literally) sanctioned via the financial system.
Sidestepping jurisdictional issues altogether by operating entirely virtually is a better bet right now (c.f. ASICminer).
Hosting data for chinese users within china has been part of law for a while now, all servers hosting content that is licensed to be displayed in china must also be hosted in china. There are tons of rules that allow the government to control tech companies. If the law is not there and some tech company does something the government wants to control they can pass a law the next day if they wanted to. Laws are pretty arbitrary in china because there is only one party and they vote practically unanimously on anything the leaders propose
Would a Chinese judge stand up for your business to the letter of the law? Or follow orders coming from Beijing?
Where have you been for the last 10 years? The US regularly condemns China for backdoors in their equipment, they even do it with a straight face after the Snowden revelations.
Then, there's Europe with its data protections of unknown effectiveness for me as an American. Then, there's America where the sue happy, LEO's, and courts can get away with a lot. Your actual trade secrets, source code, etc are more protected here plus stronger patents. Then we have China and Russia where some employees and external parties on the network will be hacking the crap out of you while the government protects them when caught.
So, quite different situations in different countries even for same topic.
Plus, most products certified in those don't even have to turn in their source code. It's one of the reasons I call bullshit every time companies get such a certification and say it means something.
Unfortunately, the CEO who authorizes this kind of stupid action is rarely the CEO who gets bitten when China steals the business data, trade secrets, and the cuts the company out of the loop for a domestic company.
(a) sucker businesses over there with lure of cheap labor
(b) steal their intellectual property
(c) combine that I.P. with domestic activities to steal market share
(d) try to dominate the market with combo of cheap labor, domestic R&D, and freshly stolen I.P.
It's a dumb game for American companies to get into in the long-term. In short- to mid-term, there's plenty of money to be made while you have the I.P. and market. And, like you said, someone else takes the hit in the future. An externality.
When a business has things on a server somewhere and a relatively dumb client, it's REALLY hard to pirate, steal, copy, modify, etc. You can bake your "crown jewels" into the server and it never gets into the hands of the client.
One of the phone chipset manufacturers used to run service where they would compile your code for you. But they would NOT give you the compiler.
I was really annoyed as a developer, but I also understood the reasoning as it effectively kept the Chinese from cloning their kit.
The main benefit of that architecture is to protect against non-technical insiders and others who have less opportunity for physical attack. The compute nodes are stored in a hopefully-secure location with files similarly centralized. Additionally, if the mechanisms are technology agnostic, there's potential for further hardening, monitoring, obfuscation, recovery, etc.
Doesn't eliminate a Chinese-style threat, though, if it's connected to a network in any way and doesn't use high assurance components.
So yeah, without getting into the weeds, the Church was very much one of the major causes of the Revolution, and it lost plenty of it's authority as a result of the Revolution.
And now pretty much standard ( or going to be standard ) in every country.
This first paragraph seems to be an egregious and willful misrepresentation of the document[1] by the New York Times. Most of these promises appear to be good and reasonable ideas without an ulterior motive. The only part that I don't quite understand is #6 where they talk about the "supervision of society".
Farther down the article:
> The letter also asks the American companies to ensure their products are “secure and controllable,” a catchphrase that industry groups said could be used to force companies to build so-called back doors — which allow third-party access to systems — provide encryption keys or even hand over source code.
I don't see that phrase anywhere in this document, though the individual words do appear several times. Moreover, I don't see how anyone can reasonably argue that anything in the document implies third-party access to secure or proprietary information.
[1]: http://www.nytimes.com/interactive/2015/09/16/technology/doc...
Article #6 states:
"Accept the supervision of all parts of society. To promise to accept supervision from all parts of society, to cooperate with third-party institutions for assessment and verification that products are secure and controllable and that user information is protected etc. to prove actual compliance with these commitments."
No, if anything it is an understatement of how problematic this pledge is.
The only part that I don't quite understand is #6 where they talk about the "supervision of society".
"Supervision of society" is what the modern government of China has moved to as an quasi-alternative to traditional communist "Command and Control" planning[1].
It encompasses both the type of business regulation that is more familiar in the West (business licenses, safety regulations) along with comprehensive state surveillance of both financial/economic indicators as well as what many societies would consider "private speech".
[1] https://books.google.com.au/books?id=TfHGAAAAQBAJ&pg=PA74&lp...