Snowden leaked that fact before Microsoft made the admission. But it's good that it's coming from them officially nonetheless.
Snowden leaked that fact before Microsoft made the admission. But it's good that it's coming from them officially nonetheless.
But companies can be a lot shadier than we give them credit for. Like, remember that "wink payment" contract between Google and Israel? If Google knew what they were doing, they accepted the contract to do the illegal thing, so they'd sell their product and get money, but they were planning to simply not do the illegal thing, breaking the contract (the customer would never know and if they somehow did, you can't stop using a cloud on a dime) but not breaking any laws.
If Microsoft knows what they're doing, they'll accept contracts from EU customers that say "we will never give your data to US authorities", they break it immediately, don't tell the customer and the customer never finds out.
Alternatively, they can give the US government a bunch of nothing, in order to comply with the EU customer contract, and pretend this is all the data the customer had on their account. I doubt this will happen though.
Moreover, again as I understand, after a certain point the leaks are stopped, because the message was sent, and people now know the most important bits behind the curtain.
but, your over all picture is still, sadly correct.
When it's secret, how can you ever check? Even if it was just because the person on top or in the middle had a personal judge, they'll always say it was for legitimate spying purposes and no-one has any way to call them out.
Without oversight, abuse is inevitable.
You have two choices:
* Limit the damage that a person can do- IE; don’t aggregate everything in the hands of one person.
* Tonnes of oversight into who accesses the data and why.
In theory the US chooses the latter, but only for nationals and the snowden leaks were proving that this was basically just a rubber stamp and constantly was bypassed on technicalities..
.. outside of the US, there’s no legal framework to protect your data from US authorities, no matter who they are, at all.