Why I’m Having Second Thoughts About The Wisdom Of The Cloud
techcrunch.com
techcrunch.com
Do you need email ? Do not rely on gmail to store your email or you, use your own server, IMAP and a webclient such as roundcube when you are on the go.
Do you need calendaring? Use Ical and a webdav server.
Do you need file synchronization? Use rsync over ssh to your home machine instead of dropbox. (that's exactly what I do to back up my Android phone), do you want that to be completely automated? Call rsync from a crontab.
My last pictures? a gallery on my home server rather than using flikr or facebook.
Do you need to be reachable by phone from overseas? That's very tricky, since you don't control the phone numbering system, but I am doing really well with my home asterisk server, my android SIP phone and a bunch of SIP providers in a several countries. When I want to talk something with my tech savvy friends, I can use Sip 2 Sip directly (not skype).
It's susprising the amount of stuff you can do when you are running your own services on a trusted environment. Just a ssh + screen session is more than enough for me to do most of my daily tasks. In case I get increasingly paranoid of the goverment I could you just ship a box overseas or use a cheap controled VPS on a different country. I may not have freedom of movement (since immigration is definitely not a friction-free act), but my data surely has. I am not saying this is a perfect solution, but definitely it's much better privacy wise.
The only think I lose with this approach is the 'social' aspect of cloud services. People's attention span is short enough to force them to go to my personal services or my blog to check for my personal updates. Facebook success is that it offers a one single place where you can get a glimpse of how are your friends and beloved ones doing. That's why It's so important to invest on open distribution formats (a la RSS) we can trust and control.
The convenience of being able to access the data everywhere is too huge to sacrifice; this is only going to become more important as people check their mail from their ever growing number of devices - smartphone, tablet, home+office PC, to start with.
Instead, we need to make the cloud storage secure. Encrypted end to end services and protocols, federated encrypted services.
That is, if a sufficient number of users care enough about security to make security a differentiating feature. Previously, the vast majority of users haven't expressed a market preference for more secure services - maybe this will change when as people put more important information (critical business details) into the cloud.
Either the cloud service can decrypt your data (in which case the government can order them to decrypt it for the government), or the cloud service cannot, in which case the cloud service can't do anything useful with your data whatsoever.
DuckDuckGo manages to run a search engine without logging IP addresses or user agents...
But his stance on this issue goes back further; in 1999, he decided to publish this essay I wrote on the GNU web site, which calls out some dangers of depending on proprietary web services, although not specifically the privacy risks: http://www.gnu.org/philosophy/kragen-software.html
'Your ISP and the Government Best Friends Forever' - Christopher Soghoian (http://www.youtube.com/watch?v=jJDCxzKmROY)
To summarize, it's easier for police/gov to get data. Some companies provide user information to them without hassle or fee. A single request can list any number of names. MySpace and ATT love the government and go out of their way to help.
Um, no. When you store your data "in the cloud" (in a non-encrypted format), you have just made the decision to hand over your data to everybody with access to that data. That is everybody from TLA governmental entities that can subpoena "the cloud" owners to the janitor that empties the wastebaskets in the computer room.
Really?
The only thing that might be easier is for Google or the Government (via subpoena or collaboration) to get access to my data.
It is easier and it's a real concern.
Encrypt your disk and be smart in your choice of software: small fries are denied, and even the government is annoyed.
if your disk is encrypted, the plug should not be disconnected.
One possible solution might be encryption in the cloud, so that data is encrypted and decrypted by the client. Provided that the encryption was strong enough there would be no technical way that service providers could hand over data, although they certainly could still hand over access logs for traffic analysis and I think this is what's being asked for in the Twitter case.
I admire Wuala.com for refusing to create a cloud client because of the lack of security and ownership, regardless of the convenience.
If twitter managed to keep all the rights they want over our data, while also being able to prove that, legally, we own the data not them, then they could respond to subpoena requests with "you need to direct this to the user". (IANAL, I'm not sure whether to get to that would require a change of law or just of Twitter policies, or both.)
It's because we've invented all these new technology concepts. Trying to make things easy on ourselves, we apply old analogies incorrectly to new situations. So if I "own" my email at GMail, somehow I feel put upon when somebody else comes along and reads it.
We have centuries of examples of social norms to call upon when discussing concrete things like vehicles, houses, or personal effects. So if some official comes in without notice and takes my personal papers, not only is it possibly legally wrong, but it's wrong for a good reason and everybody knows it's wrong simply from using their common sense.
We just naturally assume that these assumptions will hold true with new stuff, but they don't. Lawyer-types are defining things like electronically consuming a work of art or reading a book (in ebook format) in ways that don't match up to normality. The system is working as it has always worked -- government and special interests see an opportunity and they take it. Nature abhors a vacuum.
So we're either going to need to educate a lot of people on what the new rules are, change the rules, or stop participating in technology the same way we are doing now. Otherwise we're going to keep getting results we don't expect, and it's just going to tick folks off even more.
If you ask me, we're at the point where (at least in the U.S.) new constitutional amendments need to be considered regarding electronic anonymity, the relationship of computers to people (it's an extension of their mind, not a device to play things on), and the right to peaceably engage in international commerce as individuals without any government observation, taxation, or interference whatsoever.
I doubt that will happen, though. But it's nice to dream.
Or lawyers could stop being semantic nitpickers. Since that will never happen, I wonder what other options exist?