US Government: You Don't Own Your Cloud Data So We Can Access It At Any Time
yro.slashdot.org
yro.slashdot.org
The paradigm seems very similar - I go to a service provider, pay them money to give me certain amount of private space, put my stuff there, lock it with a key and go on my merry way. When I want to get my stuff out, I go to the location, unlock, get the stuff, re-lock and go.
US laws seem to have very strong protection against someone going and taking my stuff from there. Even if the bank or the storage place go bankrupt, I'm fairly sure no one is legally entitled to go through the stuff that is being stored.
Further, if one of the bank's or storage place customers happens to store something illegal, law enforcement typically needs a warrant to seize it. However, in no way are they entitled to take or destroy property of others, not relating to the warrant.
The ONLY meaningful difference seems to be that they can't easily just access the "storage box" associated with the warrant, and servers are much more portable, so they feel entitled to just take the entire thing. I guess that if your bank had no way of opening the lockbox, law enforcement might feel entitled to take the entire vault...
Here, it's not surprising that the government wants to take a position that gives them greater power to snoop around in files you store in the cloud.
It's perfectly reasonable to look at your data in the cloud like a safety deposit box. But alas, government tends to follow a path that gives them greater control and not less. This is just another instance of that tendency.
That means that the US government only needs the approval of the service provider (via warrant or subpoena) or no approval when they sieze that provider.
The difference from the storage locker or safe deposit box example above is that for those services, you hold the key. You are not putting your stuff in those places so that any passerby can rummage through it.
Websites/services that provide more limited distribution services, e.g. dropbox, or anything where you need to grant permission to individuals, are a bit closer but still not really the same as the safe deposit box example. You should be sure that the rights you are granting by agreeing to the terms of service are more limited.
For cloud storage where you really want to limit access to the content to yourself only, you need to be sure that not even the provider can access it. I.e. encrypt it before it leaves your machine.
However, my main concern is not so with no one reading the data, but with data being taken and not returned.
There is a lot of additional complexity -- not only are there other contracts in play (e.g. contract between Megaupload and Carpathia and any other contract between Goodwin and any other 3rd party impacting the data), but also the issue of whether and how the court will enforce those agreement.
The government's ability to access the data changes depending on how these agreements are interpreted/enforced.
If you want to get really pedantic, there is also the question of whether the court is appropriately exercising jurisdiction and therefore has the authority to make and enforce such a ruling.
Rarely true anymore. Most sites that accept user-generated content explicitly state that the users retain ownership rights, but grant the site operators a broad license to republish that content.
But that doesn't matter because the government does not need anyone's approval if they have a warrant or subpoena. Compliance is not optional and supersedes IP protections.
Don't confuse what the constitution says with what the current "legal perspective" is. Under the constitution, most of the government is illegal.
Since the US Federal government doesn't follow the law, there's pretty much no limit to what they can do.
Hell, in the megaupload case they violated the laws of New Zealand and the USA, and still are not giving people the illegally seized data back.
I'm not familiar with this. Do you have links to where this is said, or articles about this abuse? I searched a bit and came up with some similar things that were debunked (http://www.snopes.com/politics/business/safedeposit.asp) but nothing about this specifically. Thanks!
Other than rulings by the judge, of course.
In the same vein, we've now reached a point where the Supreme Court's decisions are increasingly (if not all) unconstitutional.
The problem is that there's no 3rd party to settle a dispute with the government. If you and the government have a disagreement, the government decides who's right.
If the Supreme Court ruled the sky was red, the sky would still be blue.
I live and work in China, and often advoces the same lines to my colleagues, most of whom are trusting Apple with all their files. They don't see the danger, but even if you leave politics aside, moral values and taboos change much faster than we think. For instance, the "loli" thing in China is not taken as seriously (litote) as it is in the West, and many pics/drawings that would send you to jail in US are deemed most innocent here. But in 20 years it can be different.
The electronical devices I buy are my property, I have root access. I can change the software running them.
My files belong to me and no-one else. I am responsible of them, if some are lost it is my fault.
Etc.
You mean a server? I don't want to be one of those people who bitches about using "cloud" as a buzzword, but there has to be some sort of limit.
> You mean a server?
Yes, it was some kind of ironical use. But in fact the remote storage and services we call "cloud" is not more revolutionary than the same thing done locally.
With all those new tablets we move around in our houses and outside[1] we certainly need a central repository of things like our music and pictures, and Google and Amazon et al. know it well enough[2], but I do not agree to trust them with my important stuff, and some recent bad experiences show that data sent to the "cloud" is not your anymore, except if you run this "cloud" on your server.
1 .http://www.codinghorror.com/blog/2012/11/do-you-wanna-touch....
You certainly have a private cluster.
While "cloud" is associated with living in some datacenter somewhere, it is not a precise technical term, and there's a lot of marketing towards businesses to "build an enterprise cloud" (where it's a private cluster in a datacenter or building owned by the business.)
You seem to imply that there's a minimum latency between your personal machine and the "cloud" machines for the cloud term to apply. Or just that the servers have to be owned by someone else?
I think the real meaning (or intended) for "cloud" is a cluster, or set of services that are designed to run on clusters....a collection of machines that provide services, as opposed to the specific meaning of "cluster" which is a set of machines providing a specific service.
not latency, abstraction. If i'm building a server out of parts and wiring it up in my closet, that's a server. If somebody else wires up a server in their closet and rents it out to me, that's a cloud. The cloud means not having to think about things like hard drives failing, and keeping hot spares of servers. So yes, that often means failover clusters but the real point of cloud is that it doesn't matter whether it's a cluster or not - the physical architecture is somebody else's problem.
Pre-cloud that was called "hosting" :P
I never got why people mistrusting the cloud implied the cloud should not be used. Surely a local server AND a cloud server would be the best solution? It's been drilled into my head that everything will fail eventually, so you should base your technology across many different services that are unlikely to fail simultaneously.
So unless the government pulls their server just as you upload your encrypted file, and somehow your HDD simultaneously fail immediately after upload, Dropbox does not have the same vulnerability as Mega/Rapid/etc-Uploader if you're uploading encrypted files.
If you mean to say that the government will maliciously delete all files WHILE keeping Dropbox servers online. that is a possible scenario, but extremely unlikely as to not even be worth pondering (i.e. there is no benefit to the government to do that).
Though I must also add: Dropbox is a synchronization service, not a backup service. And even if Dropbox was a backup service, you should have multiple redundant copies of critical files. Don't put all your eggs in one basket and all that.
- Rogue (or just bored) employees of web companies accessing customer data for fun or profit. (Happens much more often than you think, also in govt agencies.)
- Internet criminals breaking into cloud accounts and stealing data.
- Companies using their knowledge of their customers against those customers in disputes and legal challenges.
- Companies trying to extract the most financial value from customer data by selling it to questionable outfits.
- Foreign intelligence services and outright criminal organizations getting access (through 'hacking', bribery or threats) to any information hosted by any web service and many government institutions.
[I mean, for Christ sakes, if a news publication (NoTW and other tabloids) can buy some very private data of celebrities from UK police, how hard would it be for an organization with bigger resources and no fear of legal retribution to access any electronically stored data - especially by companies?]
* * *
And yet the trend in our merry startup world is to put everything in the cloud. Try asking any web company for a self-hosted version of their service.
For instance, can I get a Evernote server software to roll my own Evernote server? (Compiled and obfuscated, encapsulated in a VM appliance, I don't care.) Even if I was willing to pay for it like for any other software? No. Actually, Phil Libin was asked about it on the Triangulation show on TWiT. His answer? (paraphrasing) "Well, um.. It would be hard, um... The real question is: how do we make you trust us." Well, if that's your answer, you've already lost me. I mean, go ahead, keep my recipes and random silly photos. But if you expect me to trust you with my private documents or my schedule or anything of any IP value from my work, then you have a much bigger problem than communicating.
And so does your company, dear HN reader.
(Well, unless you're doing something frivolous, of course. If you're into the next FartingApp™ or photo-sharing-with-a-twist website, then I guess you're safe, for the most part.)
Some tiddly micro-nation will get some decent bandwidth, implement strict privacy laws, and become Switzerland for data.
Iceland and Switzerland are possibilities. As is panama.
Right now, the US has managed to violate he privacy laws of almost every country- famously Switzerland bank secrecy is no more.
But the decade of bullying other countries in the name of "terrorism" is not making a lot of friends, and as the power structures in the world shift, eventually someone will get the balls to stand up to the USA.
Panama might be that country, because China is heavily invested in the expansion of the panama canal. The canal is a massive proportion of the countries economy, and much of the economy that isn't the canal is indirectly boosted by the canal.
With China as a strategic partner, they may be willing to stand up to the USA. Not now, not yet, but in 5 to 10 years.
Europe and the US are both in the middle of massive financial crosses, which will likely result in the destruction of both currencies, and a significant amount of damage to asia as well... but as a result, confiscatory tax policies will go into effect and capital flight from these regions will accelerate. The diminished demand will hurt asia and south america, but increasingly businesses will relocate to those regions.
If you share a house with someone, and leave your drug paraphernalia in the common area, if your housemate invites the police in and they see it there they can use it in court and leverage that to search your room.
I disagree with their argument, but they are suggesting that the cloud provider is your housemate and you gave up control when you uploaded it to their common area.
Furthermore, I continue to be irritated that non-EU companies don't comply with these laws while still offering their services in the EU. You can't have it both ways. The physical location of the server or the legal entity behind it shouldn't matter: if you want to offer your services to a country, you should have to abide by local laws.
It's issues like this that really emphasise just how young the Internet is, in that the law still hasn't caught up. I find it sad that a lot of these issues are being resolved "accidentally" (i.e. when it comes up in court and laws that predate the digital world are used to set bad or misguided precedents) rather than proactively, by trying to make new laws that take the nature of the Internet into account. Surely that's what the EFF should be campaigning for. Why not require, by law, all cloud providers to offer an API to let users access, modify or delete any and all of their data?
This scheme is not infallible. Although signing the declaration makes it impossible for a third party to produce arbitrary declarations, it does not prevent them from using force to coerce rsync.net to produce false declarations. The news clip in the signed message serves to demonstrate that that update could not have been created prior to that date. It shows that a series of these updates were not created in advance and posted on this page.
The reality is this: In neither jurisdiction are you safe, because in both jurisdictions the government will sieze or snoop on data at will. Sometimes it will do it publically with warrants (Which are generally fraudulent in the US and used to sieze things that are not covered by the warrent also.) Or they will simply pass some law "to fight terrorism" or "tax evasion" or "money laundering" or "child pornography" that exempts them from having to comply with the other laws.
It doesn't matter. You cannot trust government because government is evil. It's like expecting a fox to guard the henhouse. It's silly if you think about it.
Is the RIAA claiming that the songs distributed by their constituent organizations are somehow private? No. They are claiming that they have the right to determine what happens to the bits after they have sold them on to another party. The arguments are over the extent of those rights of long term control.
The right to privacy of unsold, unpublished bits held by a third party under contract is what is being discussed here. The question is whether by storing your property in the safekeeping of a third party, do you lose your right of privacy?
It's a complex question. Among other facets, we need to consider what people think of as "private" -- because, ultimately, law ought to match up with the general opinion of the community it serves.
The RIAA doesn't have any bits worth protecting in the same way that people's private information warrants protection.
So artist 'x' is a citizen and their privacy (and hence their private data) warrants protection just as much as any other citizens privacy. Whether or not the data they produce and release into mainstream culture (which is in the end an affair between citizens) warrants economic protection is an entirely different matter.
It might well, but they're in HR.
How about the argument that bits are different than physical property and can't be stolen?
Now, the government believes the same thing and suddenly, when it involves you personally, it's wrong.
The hypocrisy in the tech community doesn't surprise me. I've been witnessing it for years.
I have a manuscript for a new book which I keep in a safe at home. I may believe that once a book is "out in the wild", anyone should be allowed to copy it. However, that does not mean I think it is OK for the government to have the right to open up my security box at a bank and read the manuscript if I choose to use "cloud safes" (AKA banks) instead of my own personal safe at home. The problem here is not really the reading of the book, but interfering with my agreement with the bank that only I should be allowed into the safe, regardless of what may or may not be in there.
Now, about being 'stolen'. The argument about bits being free is that you can copy them anywhere. I think you can see how deleting from someone else's server is not the same thing.
The government is not causing problems by copying the drives, they are causing problems by confiscating them.
In this particular case there is no hypocrisy.
Personally, I don't believe the government is stealing anything. They're violating people's privacy, which is a different thing and does not require the data to be property.
How long will it be before every country goes to extreme lengths to avoid the American legal jungle?
I'm happy to give up some features (collaboration, web access) for the peace of mind that comes from random governments not being able to read my data whenever they like...
Or do I have to roll my own?
You could zip up your files, encrypt them as strongly as you want and then upload them to some server somewhere at any time (Say you get a hosting account) and then nobody else but you has access to your password, and presumably that would be a solution you seek-- but maybe not the same level of convenience.
I think the convenience (depending on what you want) is intrinsic to the lack of security.
Cloud computing has become so seamless that it's difficult even for experienced users to tell when their data is being sent somewhere else unless they pay attention all the time. For example, Office 2013 is very keen to save all your documents to SkyDrive.
Maybe it'll improve if we start putting encryption keys in physical charms that you can hang on your real-life key-chain; then again, there is no locksmith, so maybe not.
Zero knowledge is the answer. We need to become accustomed to securing our data BEFORE we make it 'cloud available'.
However, anybody running a business on customer data might want to think about the implications of this. The real question is where to put the servers. The EU isn't much better about this than the US (since they've spent most of the last few years with their heads up in America's bottom anyway).
One might argue that my words in a document are not property, however they are often refereed to as intellectual property (refers to creations of the mind for which exclusive rights are recognized in law). They are mine and I hold the exclusive rights to them. I want them back. What right does a government have to take them from me?
If you do this now, while you're a startup, you'll have a lot less hassle in the future when you're losing customers because of jurisdictional problems.
Right now, people are only barely aware of the growing surveillance state in the USA. They're all aware of it, of course, but they think that only terrorists have to worry. In the last couple years, increasingly the government has gone after regular people, like hip hop blog authors, and people using megaupload to avoid emails file size limits.
I'm sure for many of you, you don't care cause you're hosting cat pictures or whatnot. But if you've got customer confidential data, especially financial data, it would be a good idea to find a jurisdiction that still respects privacy.
I'm not a lawyer and this isn't legal advice, but my casual explorations indicate that Iceland might be a good jurisdiction.
My company still runs a datacenter within that country - but we assure that no users that reside there also have their data stored there. Making it cross-jurisdictional, even a little bit - the user data is still in the EU - does wonders for privacy.
I wish that the courts would rule cell phones and hosted services an extension of the human mind (and thus protected under the fifth), but I doubt I will ever see this. Too many people fail to see how vulnerable they are.
There are various bodies (perhaps fewer now than maybe 5 years ago, though) that have the power just to demand data from an ISP without a court order.
Edit: Many of their servers were located in the US.
hastur 18 minutes ago | link [dead]
US Govt can force a US-based company to handover customer data from an overseas data center.
So no, you're not safe in London.
[In fact, due to close cooperation of intelligence services of the five Anglo-Saxon countries (Five Eyes), you're not safe in any of them if you want to do anything that challenges the interests that US law enforcement and intelligence protect. That includes any activity that would unsettle current intellectual property and copyright regimes, strong political activism, completely free speech, etc. If you're a web startup, that of course applies to your users too.]
Note to hastur: it looks like your snarky one-liners got your account auto-banned, so now nobody can read your comments that are actually interesting.
And yeah, snarkiness seems to be my involuntary hallmark... ;)
The US government generally considers anything on US soil, owned by anybody, to be their purview... but in the Megaupload case they siezed servers and data in new zealand, along with the USA.