Afterward Uber helped Macron campaign who then ordered National Financial Prosecutor's office to "stop bothering them" so I don't think anything new happened since.
Edit: Some sources in below replies for infos on both. Turn out I'm wrong for 2nd part it started earlier than his campaign.
Isn’t that kinda definiton of corruption?
Pretty crazy to support a business designed to never pay tax. This bring nothing beside "precarious employment".
It’s been rebranded to “lobbying” and “campaign contributions”. Much cleaner. Better optics.
EDIT: Article on the kills switch https://www.theguardian.com/news/2022/jul/10/uber-bosses-tol...
You shouldn't really be able to have it both ways, should you?
Unless there is some international law or treaty mandating that?
Nor is it likely.
All the accounting, insurance, banking, regulatory, etc… paperwork legally necessary for even a large company in France can easily fit in a set of binders that fit in a single bookcase.
So it’s literally possible for all of it to be ready and available for inspection before anyone even touches a keyboard. And in fact that was the case for every company in France pre 1960s.
Preventing access to your accounts during an audit is quite fishy, especially for an onsite audit without warning which, in France, is supposed to happen only if the authorities have doubts that you could make some evidences disappear. During an audit, the CEO is supposed to provide the documents, the inspectors are not supposed to access your files themselves I think.
(So blocking access for security reasons is bullshit, to answer someone else, the right thing to do is to have all the pieces in order for when an audit happens anyway)
Clearly in this case Uber got a superior authority to do so, and in any future case that will still be a likely possibility.
Also when the government is really motivated, he can arrested the founders or executives directly (Pavel Durov). Which is what they should do to Netflix execs if they are doing business illegally.
You're in favor of holding executives hostage to demand access to data? If they actually did something illegal, they can be arrested/tried for that, but arresting executives as a means to coerce companies into doing stuff is a total perversion of the rule of law.
Turns out that witholding data as a company executive is outright illegal, so yeah, we're in favor of it and they can get arrested and charged for for it.
Except in this case it's not the executive that has the data. The data is sitting on some cloud server somewhere, and the executive no longer has access because the CISO got wind of the raid and locked his account. If you're holding the executive, you're not holding the executive because he's refusing to cooperate with a warrant, you're holding the executive as a hostage so HQ would turn over the document.
If executives don't want to sit in jail due to their company's shady tactics they can just not approve those tactics.
Alternative would be to shut the business down completely until they cooperate.
You think the VP of Uber France was involved in the approval of global IT policies regarding locking accounts when there's a raid?
This is a very emotional way of saying "you're in favour of enforcing contempt of court rulings against people who try to obstruct the judicial process".
it's not clear whether the executive has the ability to turn over the documents.
It is just a company--a group of people granted certain rights. They have databases...fancy filing cabinets. Just because the company is famous shouldn't preclude their filing cabinets from being searched (presuming legal processes are used and not abused).
That analogy doesn't work, because the "filing cabinets" are actually sitting somewhere else, possibly in another country/continent. It's not obvious that authorities in one country has authority over documents stored in another country.
No? Then the world is a lot more complex than property rights trumping everything else.
On one hand, if the condemning evidence can’t be provided by someone other than me, should the case be prosecutable?
On the other hand, any sentient human can come up with examples of cases where it might be reasonable to search my belongings for evidence; multiple independent witnesses point to me being guilty of murder and investigations have otherwise stalled. Or anything of the sort.
What if all the independent witnesses are not independent? What if I’m not the guy, but just a lookalike? What if I’m being set up by the authorities?
The easy thing to do here is to say well okay SOMETIMES it’s okay to search one’s belongings but not for like any silly reason or anything like it has to be a real serious one. Then it’s just a matter of where to draw the lines, and who should get to decide.
I like the more absolute stance I made earlier; the government shouldn’t have any business in my personal belongings. Some crimes will go unpunished and that’s a price I’m willing to pay.
I agree that customer data needs to be protected, but it is bold to assume that is the case at all with these powerful corporate entities: if they lie to the state when filing taxes what makes you believe they are ernest when it comes to the protection of their users privacy?
Maybe it is a weird ideology I am holding here, but the more powerful an entity is, the more transparent it should become — nowaday we got this completely reversed with poor people being naked in front of the state and big corps literally fooling everyone.
Edit: some also seem to think the state is the behemoth that jumps on the poor little companies here. To that I just have to think about the account of the German public prosecutor Bäumler-Hösl (of wirecard fame) where she told about a raid on a bank where she and 4 collegues were opposed by 130 (!) company lawyers.
In general this is not what they do. What they do is read the tax code carefully and structure their operations in such a way as to minimize taxes, e.g. because tax is paid on "profits" (revenues minus expenses) so they shift more expenses into jurisdictions with high tax rates etc., causing "profits" to go down in those jurisdictions and up somewhere else.
Then they don't pay any taxes in the jurisdictions with higher tax rates and politicians go on TV and complain about the companies following the laws that the politicians enacted. Because if they actually fixed the laws, the taxes would be paid based on the extent to which the company does business in that jurisdiction, and then companies could only avoid taxes by not doing business there (costing the country jobs) or, for taxes associated with local sales, by raising prices there. Neither of which the politicians actually want to do, so instead they pass laws that allow companies to avoid taxes and then complain about it when the companies do it.
For companies that deliberately obstruct justice work? Have the board and a healthy amount of executives serve 20 years in a high security prison, seize the assets and investigate their investors' due dilligence process. Gather proof with infiltrated workers.
Tech leaders need to learn that criminal conspiracy is not part of a good business plan. If they start using mafia tactics, so can Justice.
If we're trying for a metaphor that would be a similar situation pre-digitization, the cloud servers containing business documents could be considered head office, and the office being raided would be the branch office. The branch office would continually be communicating with head office for their operations, and that communication would be shut down during the raid.
This isn't a great metaphor because the "head office" has become sort of stateless and ephemeral with digitization, but that's part of the interesting question the OP was posing, how does law enforcement collect evidence when that evidence is hosted on cloud servers in nebulous datacenters?
There's already "a law for seizing the IT system of a company", it's called discovery or a subpoena.
“””
United States v. Bridges, 344 F.3d 1010 (9th Cir. 2003)
There was probable cause to search the defendant’s office based on the information in the application that documented his efforts to provide illegal tax advice to various clients, including undercover agents. The search warrant in this case, however, was overly broad. It listed, among the items to be seized, “All records . . . documents . . . computer hardware and software . . .” Though this list was detailed, it was too expansive. There was simply no boundary to what could be seized. In addition, the warrant did not specify the crimes that were the subject of the search (nor did the warrant incorporate the application) so there was no limitation in that manner. Though the application was detailed, the warrant was not. All evidence should have been suppressed. (No discussion of Leon).
“””
https://casetext.com/analysis/search-and-seizure-particulari...
At that point, whether you are in contempt or not depends on the answer to the question "did you know that the cops were entering to look for evidence before you threw the keys?" Whether the judge holds you in contempt or not is a function of the free choice of the judge and is not related to the answer to the first question (though whether or not the judge should hold you in contempt is a function of what the judge believes about what you believed).
[0]https://arstechnica.com/tech-policy/2020/02/man-who-refused-...
If the judge receives a call from the ministry of justice, they will care a great deal about the distinction.
And if a corporate entity finds a way to openly defy a national government, it tends to happen that those governments find a way to change the law (they're the ones making it, right? :P) for that defiance to become punishable by other parts of those governments which can sanction the corporation, prevent their operations within the country or even throw people in jail.
One is, what does the law say? Did they violate it? Is it illegal for a foreign subsidiary to temporarily shut off access to a branch office? How would we like this to work? Policy arguments about law enforcement vs. due process and government overreach.
The other is, politics. If the local government is captured by a cartel of taxi medallion holders who don't like Uber, the government is going to find a way to screw Uber, regardless of whether Uber is complying with existing law. But then it's politics and Uber is a multi-billion dollar corporation, so they have the option to capture the government themselves.
Of course, that leaves the meta argument. Maybe deciding what should happen based on the second method is worse than the first, so how do we prevent that from being what happens?
Did you miss all the screaming of US corporations in relation to EU Acts like DMA? Those changes are exactly what happens when you start to think that law and people behind it are separate.
What if the safe was never in your house at all, but it was in a foreign country across an ocean? And when the cops showed up, you simply threw the keys across the ocean too?
If the cops know of something particular in the safe, then maybe the judge could find you in contempt for not producing that thing when ordered by the court, but otherwise, I don't see how they have any legal leg to stand on.
IIRC, they did it in the US too.
Do you have any articles about this? Because this is insane if true.
We had a raid in one of my previous company due to copyright violation due to a user uploaded content. Authorities came in to take in all the codebase, reports and even employee devices. Basically once given court permission, police would try to collect all the unrelated things which could be taken in the permission, so that they could extort you later.
I know nothing about French law, but this whole thing gives me “organised crime” vibes. In many jurisdictions the punishment dramatically increases when a crime is commited as an organised group whose purpose is to commit said crime. As i said i know nothing about French law so i don’t know if the same concept is present there, let alone if the letter of the law would fit the situation.
But yeah i agree with you they won’t care unless they are sitting in a cell with the chance of sitting a lot more in a cell.
I have no idea what french law says about it but I think it's morally fine and don't care that uber did it.
These seem like closer real-world analogies for what exactly a warrant to search someone's computer should entitle the police to do.
$COMPANY is $COMPANY all around the world and if $COMPANY wants to do business in $COUNTRY (which is not an obligation, they choose to), then yes, they have to entirely cooperate with $COUNTRY.
If they don’t want to, they can still do business elsewhere.
This is the thing which is not the case. The subsidiary in the US is nearly always a different company than the one(s) in Europe. They'll have different management and different lawyers etc. Sometimes they even have different owners, e.g. because one of them is a joint venture with some other company, or a franchise. And they have to be different, because different countries have different laws and those laws often conflict with each other. So the subsidiary in the US follows US law and the one in France follows the law in France.
You could try to make it otherwise, but it's pretty obvious what would happen then. Companies couldn't formally operate in multiple countries because their laws are incompatible, so instead there would be a straw front company in any given country that nominally isn't owned by the conglomerate, but is effectively just reselling their product/service in that country for an additional margin that only pays the salary of local management. To prevent this you would have to ban companies from having foreign suppliers, which is not very practical.
And since countries know that's what would happen, they allow foreign subsidiaries to be regarded as separate entities even if they have shared ownership, instead of demanding the charade.
Well Netflix is nice and all but I prefer social security and teachers in school.
https://fred.stlouisfed.org/series/FYFRGDA188S
Basically flat since the end of WWII, significantly lower before the war. At the height of the New Deal, less than half of what it is now. And that's in the face of significant growth in real GDP per capita. Probably not a dissimilar story in most other Western countries.
The problem isn't in the amount of taxes being collected, it's in where the money is going.
Can a French prosecutor use Uber's systems to deliver a malicious payload to my phone to gather evidence? If so, is Uber required to assist them in this task?
Regardless, the government violating an individual's rights doesn't mean we should yell at uber, it means we should yell at the government.
Ross could argue he forgot his password to unlock the data in a single users case.
In the corporate case it would be hard for Uber to argue that the entire company now has no access to any of the subpoenaed data.
Also we can claim whatever we want but that doesn’t mean it’ll protect us in court.
And the 2nd half just reads like pure corruption to me, they paid off some politician (who just so happens to wield the most power in the whole country) to pressure him to get them to stop their investigation into their illegal acts? In what universe could that 2nd sentence be construed as anything other than slimy, corrupt behavior?
Why did you conclude that?
There were some user uploaded pirated content in our platform. As far as I know, some media company won approval by some judge for a raid to discover the extent of piracy. It's just in the police rulebook to get everything during the raid where there could be pirated content, including employees laptops.
Might be wrong...
If you aren't -- you'll find the enforcement end of the tax authorities in ANY country are pretty efficient. Even in third world countries where many services are falling down the tax authorities will be a well oiled machine as the stability of the entire country rests on the government even corrupt ones to collect taxes.
If the state turns up at that address, and you tell them they’re at the wrong address, then the directors start becoming liable for fraudulent behaviour.
It was a good listen. At first she needed to go empty handed, but then teamed up with competent tech guys. After that the smug faces stating, that the amount of data would be to much to handle for her little department quickly turned into concerned faces.
thanks much!
> Tim Pritlove: Okay, zweiter Bildungsweg. Welches Instrument haben Sie denn gespielt?
> Anne Brohrhilker: Klavierung, Pferdflöte.
Oh, AI transcribed. Nevermind.
Sounds like it would make it easier for law enforcement. They no longer need a warrant against/for the company they're investigating, just the place where their data is stored. Get the warrant, raid the place and grab the drives, then continue the investigation. Done the right way, the company under investigation wouldn't even notice it.
And its sad to see the atrocious quality of the BBC article. Even high school students learn that a journalistic piece, should make sure it touches the Five Ws of good journalism...
https://en.wikipedia.org/wiki/Five_Ws
The Hollywood Reporter has much better quality reporting including context: https://www.hollywoodreporter.com/business/business-news/net...
Plus you can engage in some jurisdiction arbitrage where all the documents pertaining to country A is stored in country B, and all the documents pertaining to country B is stored in country A.
> Second are they really going to raid and take the drives at an AWS data center that has other customer’s information?
You can also ask AWS to produce the files/documents for you.
Not an AWS expert but how does that even work? Does AWS connect to your HSM remotely? Or is a cloud HSM that's also hosted by AWS?
I actually was imprecise with my wording.
A customer managed KMS key is any key that you make instead of using an AWS provided key. AWS still has the means to theoretically decrypt the data.
I am actually referring to a customer managed KMS key where you import your own key material
https://docs.aws.amazon.com/kms/latest/developerguide/import...
There is also CloudHSM
https://aws.amazon.com/cloudhsm/faqs/#:~:text=AWS%20CloudHSM....
I don’t know how far “AWS doesn’t have access to your keys go” when it comes to a government subpoena.
I do know that if anyone accesses anything on your account from AWS, all sorts of internal alarm bells go off at AWS and it would still show up in your CloudTrail logs.
I’m sure there is something that allows internal AWS employees to access your account in unauthorized ways. But I never heard about it in 3.5 years working there in the Professional Services department.
Raiding AWS: call Amazon, provide subpoena, Amazon can either give access to the account or provide copies of data. This would only allow access to non-customer encrypted data.
I played with encryption schemes and obfuscation pretty heavily for a long time, but at the end of the day companies operate within the legal frameworks of the countries they reside in. If you don’t cooperate, you could end up in jail anyway.
I think the conclusion I’ve come to is that you have to play by the rules. If you don’t like them, is it really worth falling on the sword for a corporate entity?
Isn't most data in the cloud heavily distributed and broken into shards across many racks and drives and such? And encrypted so is useless outside of the custom block storage system employed by the cloud provider?
They would need to decrypt and assemble the shards to get usable data out.
I have no clue how they would even know which drives out the tens of thousands to grab, and they would also have other customer's data on them.
https://leb.fbi.gov/articles/featured-articles/executing-sea...
Or in China, just take the entire data center. https://www.theregister.com/2018/01/11/icloud_china_goes_to_...
I would hire homeless people to “run” the company.
Ultimately, if you really have bad intentions, you find a way. It’s a question of risk and responsibility if you want to put yourself in such a position or not.
The police could just find the correct targets and raid their home instead.
It's called "object lifecycle management", because I guess fraud was too catchy.
Either "the law" can be trusted, and there's no point to deleting data after a cut-off date, or the reverse is true and you're no worse off getting caught deleting data.
I believe the law actually provides a middle ground. You're liable for tax fraud for X years, but you're allowed to delete the data after Y years. Since X > Y you make it much harder for the tax office to sue you if you delete data. Plus make it pointless for them to use their other investigative powers against you, which is in reality more important, especially for smaller firms.
Or are you talking about deliberate destruction of accounting records, which are required to be held by the relevant law of the governments?
[0]:https://www.legaldive.com/news/doj-google-spoliation-hangout...
https://www.eff.org/deeplinks/2013/05/update-email-privacy-l...
https://en.wikipedia.org/wiki/Electronic_Communications_Priv...
> under penalty (you shall bring with you)
[0]: https://www.merriam-webster.com/dictionary/subpoena%20duces%...
It’s pretty obvious to them and would be counted as obstruction of evidence
As an American, I'd be really surprised if we let that happen. I looked and found it apparently happened once, in 2009 in Texas: https://www.cio.com/article/278564/data-center-when-the-fbi-...
It resulted in another company essentially being shut down, and suing for their data back. Crazy. There has to be a better way of doing that digitally (I assume there is, these days, and we won't see something like this again).
I was mentioning how things have moved to the cloud these days, and what the implications are for innocent unrelated parties’ data, given that the cloud involves this overlap of data on one device.