The era of borderless data is ending
nytimes.com
nytimes.com
Providing privacy rights is very much not a "nation accelerating efforts to control data", and shame on the NYT for muddling this.
How so?
Positive freedom is a right to do something. (e.g. free speech) Negative freedom is a right to be free of something (e.g. violence)
Actually, it just occurred to me that free speech could be categorized as both: positive freedom to engage in speech and negative freedom to be free of government-based silence of that speech. Interesting.
Edit: I guess this is saying the same thing as 'User23 with so many words; "privileges and immunities" are probably better terms to use.
My pet hypothesis is that the US perspective is prescriptive, because the ability of the state to enforce the rights has not been seriously compromised in a long time. The rest of the world is more familiar with the idea that the guy with a bigger gun may one day show up and take your rights away.
In practice in the U.S. we pretty much call things 'rights' any time we believe that people should have them by default.
I think there are two sides to this, as you yourself point out, but I also think the concern over data sovereignty is a valid one. Just imagine what would have happened if Russia had relied as heavy on Azure and AWS as the Danish public sector. Now I’m not suggesting that we in Denmark are going to elect a dictator and invade Sweden, but as far as national sovereignty goes, you sort of have to consider a world where we would do something that insane.
Then there is the issue of the wider internet moving from a fun playground for geeks to becoming as much a part of our daily lives as crossing the street. Most countries have laws prohibiting you from crossing the street in your birthday suit, even very liberal countries like Denmark don’t allow that. It would be admirable, but perhaps a bit naive, to think the internet would not be affected by legalisation as it’s importance and influence grew. I think the fact that remains as free as it is, is mainly because the current western leadership is quite old. I don’t expect the coming generations of politicians to be as lenient toward the advertising industry that the previous ones have been. What the EU has done and is doing so far is only the beginning, we will se far more legislation on our rights in the future and I wouldn’t expect major advertising companies like Google and Facebook to have much of a future unless they adapt quicker than they are currently doing.
With legislation, however, comes complexity and sometimes side effects as you point out. We have a filter to guard against piracy and property rights in Denmark. As so many other countries, and while it was original intended to block the pirate bay, child protection NGOs lobbied and eventually got sites containing child pornography included in the filter. I’m in no way advocating that this was wrong, but maybe it should have been two desperate filters as stealing Independence Day and Coyote Ugly is hardly the same crime as abusing children. Because what followed was that other NGOs and political interest groups added more and more things to the filter. Leaving it a mixed box of things, most of which should very likely be banned, but I think you sort of get my point in that nobody really knows what can or cannot be added to it because it quickly stopped being a “anti-pirate” or “anti-child-abuse” filter and became a “anything the political majority agrees is bad filter”. Or a very good example of exactly what happens when legislators get involved. There are side-effects, but I don’t think you should fault the NYT for also mixing up things in something that is really far more complex, than what I have outlined here.
I think data sovereignty, privacy and censorship in general are interesting subjects that I hope established media will take more of an interesting so that we can have a proper public discourse about it that involves non-techies and non-technocrats.
I'd like to add/clarify/point out that there's two very different kinds of law/policy nations can go for here:
1. passing requirements that anyone processing data needs to meet some set of guarantees, e.g. privacy (including against state actors, e.g. CIA/NSA), cyberbullying handling, or copyright enforcement. This also includes (the absence of) safe harbor agreements.
2. passing requirements that data processing happen in a particular place, regardless of intent (could be in the belief that place X provides better privacy guarantees, could be because place X can censor/control data)
The latter doesn't solve anything from the citizen's perspective, even if that's the intention. But it does address the issue of "invading Sweden".
I personally consider the former much more important, but the latter is sometimes necessary too. But they need to be clearly identified in discussion. They are not interchangeable and sometimes issues better addressed by one are used to try to argue the other.
If it chooses to move that data elsewhere, that is its choice, and also liability if moving that data runs afoul of regulations in the original country. The foreign country itself doesn't really matter, the entity is doing business in the original country, and would be held liable there by its users/business partners according to local laws.
>The foreign country itself doesn't really matter
Of course it matters. Every country has legal differences on the definition of privacy and associated liabilities (if there any at all). In addition, it's unlikely that one country can establish jurisdiction over data in a foreign country without violating national sovereignty. Arguing that doing business establishes a legal nexus with someone of a particular citizenship opens up a massive can of worms about whose law applies where.
Data is generated in the location where a human user interacts with the system, whether that be with a fully local system, some random website with a server in who-knows-where, or just configuring a domain for e-mail.
(Yes, AI actions are a separate can of worms.)
> > The foreign country itself doesn't really matter
> Of course it matters.
It doesn't for suing for rights, that's the point of generation-based legal authority. The legal transaction is taking place in the user's location, and by offering services there, you are agreeing to the local legal framework.
> Arguing that doing business establishes a legal nexus with someone of a particular citizenship opens up a massive can of worms about whose law applies where.
This is already the case, except with location and not citizenship. Safe harbor agreements just used to make this much less of an issue until they disappeared. You really can't expect to do business somewhere without adhering to the local legal framework.
I'm not sure why anyone with "national security" concerns ever trusted American (or anyone else's) tech platforms to begin with. Everyone spies on everyone, and many current alliances are not even 50 years old---a blink of the eye in historical perspective. Even if some other nations have "better" privacy laws than the US, those are only laws. They can be changed rather quickly if the political winds start blowing differently.
I honestly had to look this up since I did not believe you that Denmark would take until 2016 to realise that keeping public sector data in a foreign country was a bad idea. I mean what, Bush and Snowden didn't convince Denmark that the United States was not a safe place for data? All danish public data getting a nice look over by the NSA didn't alarm anybody?
Is business continuity more of a concern amongst the Danish than privacy? The only novel thing I can recall Trump doing is effectively barring Huawei from using things like Google Play Services. Or is Trump simply enough of an asshole that the higher ups got riled up about him? It's so strange to me to think a country would only be concerned about this after Trumps election, to me data sovereignty seems like something one should have been concerned about around the late 90s or early 00's.
This entire article just baffles me as if data sovereignty is some bizarre development instead of something you should have been thinking of from the start. Does the government of one country store its personnel files in the warehouses of another country? Seems kind of insanely naive to me.
So you are sort of right, that our leadership trade away privacy. Similar to how they secretly allowed America to house Nuclear weapons at the Thule base doing the Cold War, and, how we typically participate in American lead wars in some form or another, as well as a range of other things.
You call it naive, but it’s quite frankly the reality of being a tiny western country. In a sense you can think of many European countries as you would vassal states to the Roman Empire. It’s obviously more complicated than that, and the comparison is a little daft, but in essence you dance when America tells you to Dance. What happened with Trump wasn’t America electing emperor Nero or Caligula, and then sort of doing business as usual, it was a sign that America might not keep on trucking.
China has famously been aggressive at controlling data. We all know this and no one thinks it’s about privacy. But the EU has been pushing to on-shore their citizens data. They have been pushing it for privacy AND pushing it as a national security issue. The EU has strong privacy laws, but they also have aggressive tech laws generally. Cambridge Analytica proved that privacy could be security and the whole drama around FB and the elections made nations weary of leaving the US laws to manage platforms.
Everyone wants more privacy - it’s the sugar to the anti-us tech pill. On-shoring data or requiring local companies own the data (and CX) will help local industries at the expense of Silicon Valley bottom lines. Oh and local companies can be controlled by local government, which makes censorship much easier, a convenient win for power grabbing governments.
TLDR Privacy is one of digital “think of the children” phrases that lets governments power grab.
Facebook, on the other hand, has sold some of my advertising data, and if I piss off Facebook I won’t be able to share memes on a website. There is hardly a comparison.
You can't just say that, you can't just talk shit about every single government that ever existed, like there was no differences between them. That there was no difference in intent. Like if you were on a desert island with nine other people, would you say that about the organization among the ten of you?
Further, I honestly prefer the contracts the governments of the countries in which I am a citizen to the contracts of practically or literally all businesses and institutions I've encountered.
If governments are muddling it, that makes it even more important for the NYT to un-muddle and call them out on it. And I absolutely agree some countries are using privacy as a dishonest argument.
Apologies for not being clearer here, it's the lack of distinction in the reporting that really riled me. Privacy requirements can — in theory — be met regardless of where the data is actually stored. It just needs to be a place that enables compliance with these requirements. Which just happens to frequently (and sadly) run afoul of "lawful intercept/access" laws.
And I really wish the NYT would have pointed that out.
Who's waging that war if not the State?
Who has been calling for ever more regulation and (therefore) Big Government if not Doctorow?
One has to be a fool to think that giving more power to the government will result in more freedom.
For example, if the user's data is only supposed to be kept in the EU, and if the user tries to login connected to a US node, should the app forward the request to the EU node (and how would it know?), which then accesses the EU database? If all nodes are connected to all regional databases, does it even make a difference?
Basically, I am very confused about regional separation of data while still running a single application.
But that's rare. Generally the data lives on a regional server and gets accessed by a CDN in a region near where the data will be delivered. If you're allowed to sign in from that region, then you're likely authorizing transfer of data (for the duration of that session) to that same region.
As for multi-region replication, it's often the case there are multiple regions in the same country - for example, us-east-1 and us-central-1. No jurisdictional problems to host the data in two regions in the same country, after all.
As to how you look up what region the user's data is stored in, well, you can keep a list of users and regions. Worst case, force the user to remember their region, and use separate copies of the website (and DNS) to pick a region to sign in on. For example, the same app/website, but at different country domains.
However, if any of these approaches are done, the operational complexity will be immense, and latency for requests much higher than they could have been. A lot of message passing would be required to build such an architecture, and a lot of bandwidth would get wasted, not to mention the unnecessary costs.
A simpler approach would to store core business data regionally, but peripheral data everywhere. For example, a todo app would store all user records, project lists, and other data everywhere, but the actual todos regionally. And yes this becomes infinitely complex will collaborative cross-region applications.
I don't think there are any good solutions yet to this, and governments should invest in creating better solutions before forcing to go down this route.
What part of your question is the concern of a bureaucrat? We can drop a couple 9s of uptime in the name of local data primacy right? (I specifically didn't say "data privacy") :)
You have to take steps to prevent this.
In China, the justice system is part of the CCP and if you don’t comply, your company is gone.
Germany sure, but The US? Do you not remember the Snowden leaks at all?
Almost every company I've worked with the past several years has had a very strict No-US-Servers-Ever-policy, because people don't trusts the US government to not snoop around.
Haha, good one.
There might be a law that allows government to obtain the data if it is a matter of national security. And what is considered such a matter is up to government to decide.
Roaming access can be handled through a VPN
For example, American and EU users sharing documents and requesting comments be added. How do you manage both isolation and sharing? Do you copy such documents to both regions? Do comments live in the same region as the document, or in the region of the creating user? Do you just give up on foreign key integrity for documents, comments, and users because they could be in separate databases? If your American servers can request data out of the European region on demand (subject to business logic), are you really protecting data to the standard the law demands?
This assumes the law's purpose is to protect citizen's data and that it's not just a way to bully tech companies into submission by writing impossible to implement laws and selectively enforcing them.
should the app forward the request to the EU node (and how would it know?)
You have to add a home jurisdiction field to the account.
I think it's no secret that nations with the most market power were always for "free trade" and calling it so.
Besides, the US also had multiple opportunities to fix their spying laws to give EU countries assurance their citizens data would be protected but actively chooses not to.
That's NOT at all the end of borderless data, it's just the beginning of the end of GAFAM dominion since most States in the world and few Citizens start to want their own systems under their own control. Witch is actually mostly VERY good, the not good part is censorship but the west world authorities can only remain silent since their own censorship on their own people from Assange to present censorship and mud machines of "third parties" subjects they dislike (no matter the reasons), the missed part is popular reaction that so far AFAIK is hyper low.
My fellow HNers if we want, for good reasons, a homeserver with our data instead of someone else services that can be banned, changes overnight in unpleasant manner, ... why someone else should want differently? Does this means the end of borderless internet? IMVHO DEFINITIVELY NOT it means just the end of some hyper giant players witch can be observed elsewhere like the end of mega-ships, mega-planes, mega-projects etc or just the passage from mainframes to clusters.
The negative part is that we still not get much freedom simply because ways to control us are so many that even dropping smartphones and IT giants accounts to the bin (witch means GAFAM in the west, Yandex in Russia, Tancent in China etc) does not change anything since now digital controls is done by private parties (the aforementioned giants) under States laws like digital payment push, social scoring etc witch is the actual real dangerous and disastrous thing. For that the real missed point is: people need a basic IT culture to understand because now IT is a basic component of our society and to be Citizens we need to know a bit our society OR we can only be subjects/parasites. Only with such basic culture people in sufficient mass would push against certain dangerous aspects ON TIME.
As an user, do I really care whether my data is in the US, Germany or New Zealand, if all of Big Tech can exploit anyway?
The only way for privacy is to have systems that never collect the data in the first place.
A lot of the applications that we use today do not need to take your data to offer you functionality, but they could simply push their code to a computing environment controlled by the user, and run from there.
My data, my network, my choice how it becomes available to me when I'm away from my home. I don't want cloud in between.
societies, and our regulatory frameworks, need to move beyond the idea that "data is produced and resides within a particular geo". Not only is it not, it is also holding us back from leaping forward / bootstrapping into the beyond-meatspace.
A rich nerd needs more than criminal protection, BTW.
Just a few basics:
Without the machinery of society running well, wealth becomes quite burdensome. The nerd needs said wealth recognized, means to transact, enforce contracts, currency to trade with, and all that depends on courts and governments of some kind. And there is more. I just sort of stopped.
There will be value in the "ether", but it will also intersect real space and there is the relevance.
Talking about this is sort of like those free energy machine discussions where everyone excited about the machine potential forgets about the initial energy input and how entropy will bleed it away however slowly.
Wealthy nerds do not just appear and create in a vacuum. And no judgement on the idealized nerd being discussed. Could be a wealthy anyone!
A poor nerd needs the same protection as well as the means to do all the basic human stuff needed to exist and practice nerdery. (I laughed at that being a defined word)
In terms of being a nerd and creating ethereal value, it looks to me like assuming wealth just makes it considerably easier to ignore where this stuff meets up with reality, a lot like some free energy machine presentations end up compelling enough to sideline the initial energy input...
Rich nerds don't pop into existence out of a vacuum, but now that we exist, we can move to the country that suits each of us best and do the same work with roughly similar incomes.
Yes, we still need the common infrastructure, but for the most part, I need a fast internet connection and a lack of bullets coming my way. This drastically reduces the hold any one country has over me, which is what allowed me to wave goodbye to my country of birth and move to a country where I like the tax/spend pattern more (Canada).
Theoretically, one could site all earning, investing, and banking in some tax haven and just use a credit card to transact. We'll still need countries, but they will be more like regular infrastructure providers (civilization as a service?).
Let's talk about farmers and fields for a moment:
Early on in human history, the first farmers began their work with fertile ground.
Mistakes were made, understanding gained, improvements were also made. And this is just humans being humans.
Over time, it was observed the earth can become parched when farmed too many times without putting some of the yields back into the soil. There are no free lunches. Every so often, it is necessary to invest in the earth so that it remains fertile and yields bountiful.
Farmers, having once learned this, continued to do it, and everyone is living in relative harmony.
Along comes big Ag. Good yields are not good enough. They want the maximum, and they ignore history and proceed to max the ground out, and of course it becomes parched.
Rather than invest in the maintenance of fertile ground, which requires some crops be grown to be turned back into earth, they treat the ground chemically and continue.
And now there is a top soil problem where there was once fertile ground. And so they basically mooch top soil from somewhere else, and on it goes.
Turns out those high yields are quite expensive for everyone else!
Now, let's look at what you say you need:
For example, what gives that fast Internet connection value?
A wealthy society in which to derive that income! This is fertile ground. See where I am going with this?
What happens when that wealthy society is not maintained? In other words, what happens when the ground becomes parched?
Bullets, among many other things like it being harder to get that income due to lower demand as greater numbers of people struggle due to growing economic problems and those are generally due to labor not paying what it costs for people to actually exist and show up for work and perform that labor, and also generally due to debt accumulation in the form of "parched" societies in serious need of reinvestment.
It's great to maximize it for you, thinking of only your considerations as if the rest of the world just comes gratis. It doesn't you know.
Really, this is all no different from the farmer who does not see the need to reinvest in their ground. What they do is get all they can and when that ground becomes parched, they call it someone else's problem and move to new, fertile ground where they wash, rinse, repeat, until they have a lot of wealth accumulated and have left behind a lot of parched ground for others to restore to being fertile, and doing that isn't cheap!!
That farmer could have invested in their ground, still could have accumulated considerable wealth, but would not be costing everyone around them very large sums of money while doing it.
Nobody exists in a vacuum. Everything costs something. And if you are not paying it, someone else is forced to, and or where it's not paid, other costs and risks, such as bullets, tend to follow soon after.
That's it. Ideally some food for thought regarding "needs" being far greater than the idealized picture you put here.
Even if you could go back to the wild west days of the 90s, most people these days would just complain about how people could go ahead and say whatever they wanted without being cancelled.
We started with the dream you're referring to, and it couldn't stand up to the crappiness of reality.
There is no sphere that is outside the government's control. None. Create one, and the government will come round to enforce its will on it.
Copyrights and parents provide assurances that spending large sums of money (millions/billions) to create new technology won’t be in vain. There are issues with both (too long copyright, patent trolls, obvious patents) but they are better than not having any protections.
Why would anyone make a movie or game if it’s going to be almost exclusively pirated? Would anyone invest in new camera technologies, computer graphics techniques/algorithms, motion capture tools, etc?
Why would anyone spend millions/billions creating new vaccines and medicines if anyone could copy them and they weren’t going to get paid for their research. Good will only goes so far.
You’d only do it if the budget (risk) was peanuts, and unfortunately innovation needs money. People need a roof over their head and food on the table. Which would leave only rich governments with the means to fund such advancements, and their ideology often won’t be aligned to such endeavours.
People keep saying that, but no one comes up with any data to back up the assertion.
> Why would anyone make a movie or game if it’s going to be almost exclusively pirated?
Because they like it? See: 0AD, Nexuiz, Battle of Wesnoth.
> Would anyone invest in new camera technologies, computer graphics techniques/algorithms, motion capture tools, etc?
I read someone posing this question and proposing the answer that yes, patrons are going to crowdfund what they want to see.
> Why would anyone spend millions/billions creating new vaccines and medicines if anyone could copy them and they weren’t going to get paid for their research. Good will only goes so far.
Wait a minute:
> they weren’t going to get paid for their research.
Lack of protection is not connected to lack of remuneration. US government spends millions/billions to get data from the outer space, despite that data not being protected.
> innovation needs money
Makes me wonder how the innovation of money came about before there was money to spur innovation.
A drop in the ocean compared to all the other games out there. These people could afford to make the games because they have other income sources. So sure, if you can do it, great. They are the exception not the norm.
> I read someone posing this question and proposing the answer that yes, patrons are going to crowdfund what they want to see.
Most people wouldn’t contribute and just rely on others to donate. Limiting the amount of development and discovery.
> Lack of protection is not connected to lack of remuneration. US government spends millions/billions to get data from the outer space, despite that data not being protected.
Yes as I said it will then end up being the rich governments that get to pick and choose what’s important. Do you see the US government funding research into safer abortion techniques? Improved methods of detecting defects in babies (so you can consider aborting them?)
Just look at the lack of innovation in Soviet Russia vs America.
> Makes me wonder how the innovation of money came about before there was money to spur innovation.
Innovation needs money or barter or other form of remuneration.
You're moving the goalposts. You asked why, and I answered.
If you show why they can never possibly become the norm, you might have a starting point for more discussion.
> Most people wouldn’t contribute and just rely on others to donate.
And that's cool. Most people don't use any given product. It's those who care that are important here.
> rich governments that get to pick and choose what’s important
I fail to see how that's different from today. The rich are the ones who decide what kind of movies we see, Hollywood being a prime example. They decide what kind of intellectual property laws exist to favor which research or medicines, and they are responsible for ridiculous insulin prices (just look at USA versus anywhere else).
If anything, forcing people to self-organize by crowdfunding or following their hearts provides a chance to shift the balance.
> Innovation needs money or barter or other form of remuneration.
Have you never done anything because you got a kick out of it?
That is th biggest lie of intellectual property.
Just having a patent or copyright on something does NOT guarantee income. The assurance is a perpetuated myth.
Either are only good if you can find someone willing to pay for licences.
In many cases, reality has proven that economic actors find it preferable to spend resources to avoid having to pay for licences. See all of the duplicate work in IT an patent proliferation in pharma.
Many many patents only ever had an impact on the world after they expired.
Many trade secrets were lost forever and didn’t impact the world.
Patents are a tool to disincentivise trade secrets and that is good, but they do a lot more than that and much of it is harmful.
Many more patents are created by companies that are producing the patented products themselves. They're not looking for anyone to pay for licenses, they're looking for protection against people copying what they're doing.
Doing that without eroding national sovereignty is essentially impossible. We would need something like the European Union for all of humanity.
And even the somewhat limited powers delegated to the EU were enough to cause serious backslash as we have seen during Brexit.