We moved our servers to Iceland
blog.simpleanalytics.com
blog.simpleanalytics.com
Also, you should be careful in paying attention to international reports of "xyz never happens in Iceland". Yeah maybe it doesn't, but 1/3 million people live there, it could just be due to the small sample size, not that it's less likely to happen.
Using Iceland to get away from the Five Eyes? Really? What does this person think Iceland's undersea network cables are connected to? Unless the traffic is local to the country it doesn't make a difference in that regard.
1. https://en.wikipedia.org/wiki/Icelandic_Modern_Media_Initiat...
I wrote this article a few months back and since then some things changed. Somebody also enlightened me about the cooperation of Iceland with the US government [1], although no source has been linked. I think governments spying on data is something you can prevent with strong encryption and keeping the data out of the those countries that are known for it a.k.a. Five Eyes. That's what we do with our customers data.
I agree with your statement that "xyz never happens in Iceland" shouldn't be a reason for choosing a country. I'm still very confident it's better not to put our servers in any Five Eyes country.
For the speed I do think Iceland is not optimal. See the pings from this comment [2]. I realized this after moving to Iceland that the speeds where indeed slower than from Digital Ocean in Amsterdam.
I don't think your argument about the connection with cables are relevant. If you send your data encrypted it will not be possible to read the packets, right? Or maybe I don't get your point.
I'm thinking of moving our servers to Germany or The Netherlands. There are a few downsides with that for example the environmental impact. We are looking into other solutions to have no carbon footprint with Simple Analytics [3].
[1] https://news.ycombinator.com/item?id=19530972
- https://protonvpn.com/blog/5-eyes-global-surveillance/
- https://www.reuters.com/article/us-china-fiveeyes/exclusive-...
Which I think means watching data move across the lines.
If you'd like to pull your tinfoil hat even tighter: Germany, Netherlands, Iceland are listed above as broader members of signals intelligence sharing partnerships, as well as members of NATO. They have a discussion here of their policies and activities related to Cyber Defense:
- https://www.nato.int/cps/en/natohq/topics_78170.htm
If a government wants to take your hard drives it will. Unless there's explicit laws against the seizure of physical media, you're mostly relying on them either not having a sophisticated enough internal intelligence capacity that can do it quietly, or trusting in social reaction to a mostly boring, questionable infringement of property rights.
> I do not believe that the five eyes have the ability to break modern encryption.
Do not be so sure. The Snowden documentation shows that they have many tools, from actual private attacks on the encryption itself to attacks on the endpoints (e.g. undocumented zero-day exploits) that can get data pre-encryption and/or post-encryption. And they don't limit themselves to endpoints in their own countries (that would be foolish for any intelligence agency to do).
If private industry is on the cusp of quantum computing, then to me it’s a safe bet that intelligence agencies have had it for years.
However, an advantage like this disappears the moment that evidence of its existence surfaces. It wouldn’t be used except in existential scenarios for that country.
I'm not so sure; indeed there are examples of that (consider NSA setting the s-box parameters to make DES more secure) but at the same time there are so many "experiments" under way just I the course of everyday business (that happen to apply to dual use tech) that the military often finds itself a generation or so behind COTS / consumer tech.
> However, an advantage like this disappears the moment that evidence of its existence surfaces. [Thus] It wouldn’t be used except in existential scenarios for that country.
We've become more sophisticated since operation mincemeat (http://www.themanwhoneverwas.com). Such tech can be used for parallel construction: I discover via magic snooping that odyssey7 is planning something I don't like, and is doing it with odyssey6 who has poor security. I snoop on odyssey6 and build my case from that. Or I also learn that odyssey7 smokes pot, so break their car's tail light, have a cop stop them, search car, and magically find evidence used to build the real charge. Or whatever. The real breakthrough is hidden.
It seems reasonable that incremental developments might have been made sooner by government than academic researchers or industry. Indeed, there are examples. But leaps like quantum computing?
I’m not ascribing this to you but I’ve noticed that there’s often a crossover between people who, on the one hand, believe government is pretty much incapable while, on the other hand, having some near magic ability to make huge technical leaps.
Wartime is different, as then it’s pretty much all hands on deck.
Private industries, which can only approach moonshots tepidly out of fiduciary responsibility, are already making good progress on this. My hunch is merely based on the liklihood that the DoD - which spends unfathomable amounts on R&D and does not answer to shareholders - has been going at this longer and much stronger than any private organization.
As far as I'm aware, there is no evidence at all that the commonly recommend encryption algorithms have any serious vulnerabilities when used properly. Now, it's easy to say that researchers would be given gag orders if they found the "magic back door", but that's all just speculation and fear-mongering really.
Additionally, it would be in the US's best interest for there to be no backdoor. Any vulnerability in RSA for example could be exploited against them.
Just locate your servers where it makes business sense. Secure them against hackers and unauthorised access in general, as you should. Ignore the CIA/NSA.
In more seriousness, not all is purely making money. Some people prefer to make a difference in some things they have control over even if this doesn't increase profits. I find this a lot better than e.g. getting more money and then donating to charities that try to stop what the company is contributing to.
Maybe they are trying to reach more people through blogpost and HN post, but moving the servers to another country does not seem like just theatrics at all.
If you are actually a terrorist, smuggler, human trafficker, weapons dealer, you aren’t commenting on pull requests to EasyList.
Most people are boring and, despite what they may think of themselves, aren’t even close to being a surveillance target. It’s also ridiculous theater to think that the country a server is physically in matters one bit.
To be clear, I am not defending NSA, I am just saying that most of us are uninteresting in that regard.
You can play the statistics game and say that this will never matter for 99.9% of people, but when multiplied by all people who have info that'd hurt them if it became public (everybody!), it makes for a very powerful tool for oppression.
Actually such people are great targets for blackmail, to be used in espionage and interference.
https://en.wikipedia.org/wiki/Recruitment_of_spies#Recruitme...
It's completely naive to think that only serious wrongdoers are the targets of SIGINT, rather than simply anyone with usefulness to state motives.
But again, where Switzerland's cables are connected to? To same 14 eyes I guess.
One point being "In the US and EU, gag orders can be issued to prevent an individual from knowing they are being investigated or under surveillance. While these type of orders also exist in Switzerland, the prosecutors have an obligation to notify the target of surveillance, and the target has an opportunity to appeal in court. There are no such things as National Security Letters, and all surveillance requests must go through the courts. Furthermore, while Switzerland is party to international assistance treaties, such requests for information must hold up under Swiss law, which has much stricter privacy provisions."
I read this as, it isn't to say a government can't monitor what's going over the pipe for sigint, but if they specifically target a user for surveillance it must be disclosed to them and they have a right to appeal.
Nonetheless, if you're an American connecting to Switzerland for ProtonMail, the US govt will have some sigint, even if it's just your origin -> protonmail destination.
I'd go as far as to argue, as long as all communications are fully encrypted with the best possible encryption available (and no backdoors) it's fairly safe in any country for most general content. If you're extra concerned about privacy and surveillance (like I am), you should host in a country which has strong privacy laws but read up on the privacy laws, most of the time a country has good privacy laws for individuals, companies within the country, not foreigners.
Just my two cents away.
A quick look at their Wikipedia page tells me that it was created by people who worked at CERN, and that it is headquartered in Geneva.
So it's possible that the answer could simply be: Because that where the founders live (and it is also more advantageous that neighbouring France).
Why not:
If they were willing to turn over Jewish assets to the Nazis so easily, despite being "neutral", maybe you can't trust them to keep your stuff safe.
Before continuing I want to make it super clear that I'm not endorsing the Nazi's stealing art/gold/whatever. With that said, were Swiss banks handing over assets to the Nazis that had been previously held for Jewish families, or were they only holding assets for the Nazis which the Nazis themselves took from Jewish families? (This question is not intending make one option sound more morally acceptable.) My perception is the latter, but I could be ignorant. If I'm not ignorant (in this domain), I don't see why these events would call into question the ability of the Swiss to securely hold assets.
That is, I think I read long ago that the confidentiality of Swiss bank accounts was compromised during WWII for the benefit of the Nazis. I thought it was common knowledge.
However, I seem to be having difficulty finding a reference with Google at the moment.
Apart from the point about the cables, I'm thinking a re-read of Tom Clancy's "Red Storm Rising" might be in order...
This was the latter, and all parliamentary resolutions are inherently much weaker than laws because they generally only apply to that particular parliament and that particular government. And we've had many changes of both since 2010.
United States via Greenland, UK, Denmark.
My guess is most data, even at privacy focussed companies, ends up accidentally transmitted over a cable unencrypted at least once. It doesn't take much to forget to turn on strict HTTPS enforcement on cloudflare for example. Or to forget to encrypt your backups in transit. Or to have an employee download a database dump for testing over HTTP.
It only has to happen once for security services to keep it if it contains any data of interest to their filters.
It's also not the only attack model; it serves only as an example of the sort of power Five Eyes has within the five nations they wouldn't necessarily have in Iceland.
Another example: https://en.wikipedia.org/wiki/Room_641A
Colocating in Russia comes with its own issues.
Enemy of my enemy...
If you are afraid of a bogey men called Five Eyes and NSL, then colocating in Russia makes perfect sense.
If you are a publisher of KavkazCenter, you should probably host it somewhere in the US.
I.e. if it became illegal to say certain things about the US government, could I (an American citizen) hypothetically host my protest blog on a Russian provider and avoid prosecution?
Yes, you could probably safely criticize the US on a Russian-hosted blog, but in the scenario of a repeal of the First Amendment, I can't imagine the hosting location would save you from any theoretical prosecution.
This doesn't make sense. The normal way to do this is to terminate connections close to the users, in this case running a server in (or near) the US and a server in (or near) Europe. You don't have to pick a single point that's optimal for all users.
But if you are going to pick a single point, Iceland is not the point to pick. Connections don't follow great circle distance, they follow cables, and Iceland primarily connects via Europe. Have a look at https://www.submarinecablemap.com/ and you'll see that the only connection West from Iceland takes an indirect route via Greenland. If you run pings from SF to Amsterdam you'll see lower latencies than SF to Iceland.
While Iceland may not be a privacy paradise, I still think Icelandic hosted servers provide a higher barrier than US based servers for government data collection. The US government has a history of high volume warrant-free collection of user data - your setup in Icelandic appears more resilient to this approach. However, as others have pointed out, Icelandic hosted systems are still vulnerable to traffic analysis as well as physical and legal attacks on servers and key holders. The solutions to these types of problems though are more political than technical.
If the goal is low or zero co2 emissions, there's a number of datacenters in north america powered from 100% hydroelectric. In British Columbia, Oregon, central/eastern WA state and in Quebec.
Most countries who have INTL fiber cables running in/out of them will have a direct link to a "surveillance" country, but as long as encryption is sufficient then the data is still relatively secure. and pulling RAM to inspect the memory is a pretty hard thing to get away from.
I think this is as thoughtful as it gets when considering user and company privacy.
> so we kind of need to trust the hosting provider
If you're worried about someone physically attacking a server to compromise encryption keys, whether the data center operator is complicit is, sorta redundant. Moving to Iceland isn't going to solve any of the attacks mentioned.
That being said, hosting in colder climates makes a lot of sense from an energy usage perspective. I think they should have focused on that first.
Let me get it straight. The author is waxing about Five Eyes, country-level attacks, fiber optic taps, etc but bushes off the most direct attack as "we kind of need to trust the hosting provider?" Now that's the one weird set of priorities.
You aren’t encrypting anything?
Even if there's no 3rd party involved, we've seen NSA tapping onto private companies (Google) internal network as well. If any analytics company grows big enough, it's definitely becoming a target for the NSA.
For what it's worth, the author claims that Simple Analytics respects the Do Not Track (DNT) browser setting, so that user would be able to have it his way without needing to install EasyList. But of course that is something that requires a degree of trust, and DNT seems to be a failure for the most part, because of all the other parties that do not respect it.
So I am surprised to see that have finally done it.
The other one is Fathom [1], doesn't seems to be in development anymore.
Maybe that's why there are data centers in Salt Lake City. High elevation, nearby talent pool, relatively central to the US.
I don't know why people use Salt Lake City as a location for data centers in the sense of its cheaper to cool. We are high elevation, but we are a high-elevation desert. It's usually pretty hot here. We have winters, true, and it's way dry here, but the winters are rather mild, especially compared to places like Wisconsin or Chicago, where I am originally from. It must be because of cheap electricity and/or tax laws. We have a lot of wind power here, and some coal power as well. One thing's for sure: cooling isn't why they build datacenters here. I have no idea why but I'm not complaining either :)
Also, it is quite a bit cooler than say Las Vegas or Phoenix, while being more central. The relatively mild winters is also a benefit in terms of geographic stability, you're less likely to see structural issues than you would in other areas of the country with more wild swings. It's also possible for certain components to be too cold as well.
Tax incentives and a relatively less expensive labor pool don't hurt either.
Salt Lake City isn't even significantly cooler than San Francisco and Seattle.
https://www.currentresults.com/Weather/US/average-annual-tem...
Perhaps if you could build a data center at 10,000+ or 12,000+ feet, it might make a difference.
First, the I-80 corridor is one of the most important and highest density fiber backbone routes on the continent, which runs right through the city. From a network topology standpoint, this makes it a pretty great place to aggregate massive quantities of data from around North America.
Second, it is a large city in one of the most geologically and meteorologically stable places in the continental US, far from an ocean (or anything really), which makes it a good choice for disaster recovery and backup sites. That locale has been used for this purpose for decades, not just for data centers.
tl;dr: Virtually unlimited and extremely well-connnected bandwidth in one of the least disaster-prone regions of the US.
Oregon's High Desert (https://en.wikipedia.org/wiki/High_Desert_(Oregon)) is a good one.
Apple and Facebook have data centers in Prineville, OR. Google has a GCP data center in The Dalles. Amazon has at least one in Port of Morrow and one in Port of Umatilla.
In fact they can be all lined up on a 236 mile stretch. https://goo.gl/maps/inGGCCk2qBb8Bg5z5
Back in 2011 Facebook published about the efficiency of Prineville data center, mentioning 100% outside air direct evaporative cooling https://engineering.fb.com/core-data/designing-a-very-effici... and efficiency of water use https://www.opencompute.org/blog/water-efficiency-at-faceboo...
...Now in 2019 we have data centers in various locations across the world but efficiency goals are no different if not more ambitious. So something more flexible was developed and now in production. https://engineering.fb.com/data-center-engineering/statepoin... IIRC it doesn't mean we high deserts aren't special anymore. They still are.
Research what pedophiles, drug dealers and terrorists are using and use that
Am I the one not understanding heat transfer ? Because if companies follow suit and this is done at scale, good luck with the rising temperatures, Iceland.
That seems pretty unrealistic - think about the scale of energy that would require.
This may be difficult, from the cases I know.
The PR to add the site to EasyList never went through, it currently isn't in EasyList and never was.
It is still there:
https://github.com/easylist/easylist/blob/master/easyprivacy...