US free to grab EU data on American clouds
euobserver.com
euobserver.com
When are people going to realise clouds are dangerous? You lose control of your data regardless of smart programmers or civil rights. You can never ever be sure it wont be taken, spied on or just lose it.
Yes, there is a huge convenience to clouds, no doubt what so ever, but I will never ever trust them.
Use? Yes.
Rely on? Assume to be secure? Assume to be private? Assume to be always available? No, never, ever.
Trust in a US justice system where my data might be? Well, we've seen that plays out. The US justice system scares the hell out of me. So much so that I personally avoid everything I can that might bring me with in the orbit of the US justice system.
And I really don't like the way our data is being herded in to one place, or several holding camps. It really feels like the data equivalent of an internment camp. Put it all in one place so the authorities can control it and us, or just open fire.
You know, if government interference was really just for stuff like anti-terror, then I could accept all this. But its not. They seem more concerned with the profits of media companies and copyright than anything that really effects us plebs.
Oh, got to go, I think I just saw a black helicopter... I'll have rant at that.
Such services are offered with explicit notion of data protection against US laws, giving "us" EU people a safe harbour of data protection where we are (at this moment) sure "our" laws applies to "our" data.
And you think this kind of polical anti-US-justice-system rants help you in this? You are already on the top list of potential targets, if not for anything else, just for the above comment.
Kidding aside, it's not about the cloud. The cloud is a detail in this discourse. If you cannot trust the justice system or the government you fight, vote, motivate people, organize etc to change them and how they work.
Just avoiding this or that (in this case, the cloud) means nothing in the grand scheme of things. They'll get you in another way.
Yes, but what if you don't live in the same country as the government you don't trust? Should I try get the people and politicians in the EU to back a war against the US?
The best thing that could happen to the US (citizen here) is for the rest of the world to shun our data infrastructure and services. We would then have a chance to see the error of our ways.
You're arguing that to stay safe from the U.S. Government, one ought to abstain from criticizing the U.S. Government?
You're right in practical terms, I guess. But this sort of attitude is toxic to democracy.
Everything is a goddamn service now - even my fingerprint reader wants an Internet connection - yeah, screw you Authentec!
Even managing multiple WP sites now has to be done via a third party service: https://managewp.com/ (I've got nothing against them, they're very good - in fact, there is no better local alternative, which is what makes me sad/angry).
That is worrisome on many levels at once.
One connection is for the software updates, and there are 2 other that I have no idea what they're used for. The TrueSuite app has an app store link and the features to export and import the fingerprint scans... So much for security...
Fingerprint readers would make for a pretty good tool if you want to apprehend people on the lam, especially since you can lift their fingerprint, their location and a date/timestamp all at once. And they're self selecting in that the kind of people more likely to be doing naughty stuff would also be more likely to invest in such things as fingerprint readers.
It's free, and UK-based - so benefits from EU data protection. By @humanmadeltd.
EDIT: Running on EC2 AFAIK, so subject to Safe Harbor, FWIW.
I've been attempting to have a dispute with the uk government over this and failed. In a nutshell - revamped uk government website gov.uk launched recently, using google analytics. When I questioned why as US company was being informed about my interactions with my government a ticket was opened at a helpdesk service and I was told that it was ok because google were not allowed to use the data. The helpdesk service are based in San Francisco.
There was a big fanfare a few months back about how gov.uk was modern, useful, using industry best practices, open source tech and was just generally awesome and cool. I think what's happened is that they've either outsourced to or hired in a bunch of hip, trendy web developers s who had no real comprehension of data protection.
As someone with an interest in computer security, and who has in the past lived with data protection consultants, this disturbs me.
Anyone know which minister or ministry in the UK government is ultimately responsible for the UK government electronic data presence? Or who I might approach about these Data Protection concerns?
I must admit to being a little surprised that they are using Google Analytics plus the site doesn't have a privacy policy either. It seems a little bizarre to have a cookie policy but not one detailing usage of user information generally.
They may have already spoken about it. I guess they have a searchable archive somewhere.
(http://www.chiark.greenend.org.uk/mailman/listinfo/ukcrypto)
BUT they've really dropped the ball by feeding analytics data about UK citizens to a bunch of US firms. IMHO. And not because I think the US is the worst place in the world ever, but simply because it demonstrably does not respect private data in the same way the EU does, especially when it comes to people who are non-citizens.
This is why we need to move towards having everything encrypted locally, before sent to the cloud, and make it brain-dead easy for most people to do that. Or maybe we'll all start using Bittorent Sync for our own devices.
Then you're not adding anything to the discussion. Some people will know who you're talking about because they know what he did. The rest of us don't know who you're talking about and still don't know what he did.
Care to enlighten us? :)
Nonsense and this is a cheap way to try and manipulate me into satisfying your curiosity.
The fact is, my statement probably applies to most (all?) of them in some form or another. As written I'm sure some people will assume I mean someone they know some dirt on and others would pick someone else.
The whole " still don't know what he did" is exactly the kind of politics I wanted to avoid while making my point as anything I would point to in my example is likely to draw out apologists and start a big fight about "what is evil anyway?". Exactly the kind of thing this site doesn't need.
And in any case I was probably specific enough for most to correctly guess who I was thinking of, as it is.
This statement has been true for at least the last five people to hold office.
If the EU doesn't agree with this, it would be better to create an economic environment that facilitates EU-based tech companies, instead of having its citizens depend on US companies.
We could even turn this around to "The EU can now seize data from US citizen from companies that operate in the EU."
Seizing data without a warrent is always wrong and can never be right regardles of citizenship to any country. Simple example the EU seizes data from US citizen and the US from EU citizen and then they just create an "foreign information exchange database" nobody knows about. Because we have to fight terrorism.
This is the right way to go.
Countries have privacy laws that are regulate how personal data has to be held. These laws are mandatory for any company operating on EU soil for instance, including american companies like google or amazon having EU datacenters.
Now, it might seem ok for you that the US government can obtain the personal data stating that, since these are US companies indeed; but the condition they had for operating in foreign countries was to abide to their laws, including the privacy laws.
Thus, a solution could be for these US companies to close their business in europe; that would help creating an economic environment that facilitates EU-based tech companies... (though that not the world I'd like to live in...)
Or, putting it other words: the US should create a better legislative environment that facilitates US tech companies to continue to be successful world wide.
European companies considering hosting personal data on American servers need to consult the so called Safe Harbour List, which is a list maintained by the American Department of Commerce: http://safeharbor.export.gov/list.aspx
Now, what it means when a company is on the safe harbour list, is that the company has declared that it adheres to a privacy policy that complies with the U.S.- EU Safe Harbor agreements: http://export.gov/safeharbor/eu/eg_main_018493.asp
As the OP shows, this is by no means adequate protection against American government surveillance. But then again, many European governments also have surveillance laws in place that allow certain government agencies access to hosted data, emails etc. with or without warrants. Often, the scrutiny of your local government is just as relevant a concern as that of being watched by the US government.
Point basically stands though.
Protecting me is somehow one of the missions of my government. Even if they tend to be quite bad at it, that still has to be on their minds.
The American government (or any foreign one), on the other hand, can and will screw me over, if they need it. And they will brag about it to gain poll points. Protecting me isn't part of their mission. Why would it be ? To them, I am the enemy.
Heck, it probably is illegal for us to store customer data in the US in this case.
FISAAA also forces US Internet giants and other tech companies operating clouds in the EU to hand over the data or face sanctions, says Bowden."
According to this, they can request data stored in EU server if the company is American. This means that it does not matter where the servers are, they will still get the data.
So, time to start to migrate to EU companies for hosting any sensitive information. Anyways, the cloud will never be secure, so the best we can try to do is Encrypt as much as possible, and not use the cloud for any sensitive information.
The one useful thing I see from the cloud is: Private Cloud in your house. With fiber getting more, and more distributed, we can soon have our home cloud with Music / Movies / series / news / email / phone all routed to our home cloud then to the devices. Now that would be a nice usage of the cloud!
Especially countries with natural advantages in this area that are already trying to move in this direction. Iceland comes to mind.
People will become more and more careful and uncomfortable with the cloud in the coming years.
Most of the human race are ignorant peons who can't spot a warning a mile away. A fine example of this is the amount of people I saw in hospital gowns outside my local hospital the other day with oxygen masks, yet they were outside smoking.
Get the hint people!
I haven't played with them yet, so I can't say if they are any good.
EC2 alternative: http://jiffybox.de Not as feature rich as EC2, but they do have an api to launch, stop, and resize instances.
S3 alternative: http://www.hosteurope.de/Cloud/Cloud-Storage/ They say it works with S3 compatible desktop software, so I guess it uses a similar/same api.
(I'm on my phone right now and can't find the English versions of the sites, I have linked the German sites instead)
I am currently using Fastmail, which is operated by an Australian company owned by a Norwegian company, and apparently their servers are in the US.
Everytime I read stuff like this, I keep saying to myself that I should move to a European company...
Any Asian-European company that I had worked with forbids the management of any critical information by any American company, not just cloud, for this simple reason.
This is just as they should though, it's not as if the U.S. would feel it's a good idea to host their cloud services in China on Huawei kit. For better or worse the days when "gentlemen do not read each other's mails!" fell by the wayside decades ago.
Nations need to either agree specifically not to read each other's data in transit (perhaps this is the EU-US "Safe Harbor" that's being talked about?), or assume that their data would be read and plan accordingly.
Note that we already have to do this planning as tech developers anyways. If we had sensitive PII we wouldn't store it unencrypted on a shared host with world-readable files, would we?
Also, I wonder what's going to happen when American companies hand data to the US Gov't in compliance with US law but in breach of privacy laws in the non-US territories they are operating in : large-scale breaches like this will not only earn them hefty sanctions, but could also lead to some courts shutting down their services altogether...
US saying they can grab data just means US companies who want EU business need to set up EU companies with servers in the EU. That means more work for EU citizens, and more tax[1] paid in the EU.
For me (as a European) it all seems pretty good.
[1] Albeit minimal tax with their borderline illegal weird methods to avoid tax.
Once security trumps liberties you are on a downward spiral.
This is resulting in the instant removal of Google Analytics for us.
After all that's what cleaned up business practices significantly at the start of the industrial revolution.
In fact, this is just another growing pain in a new industry.
Industrial Revolution => Child Labour
Automobiles => Safety
Data => Privacy
Are they perfect now? Of course not, but they became better.We're using Google Analytics and GetClicky.com right now, both from the USA.
most big enterprise companies (banking, finance, pharma, manufacturing, etc) have, regardless of their HQ, an office in the US. so, to be "protected", they would need to cut those office off completely.
just sucks that the US market is one of the most important ones.
so where else would you like to host? China? India?
and what exactly guarantees your German super private cloud not to be attacked by:
1., The classic internal employee with a USB stick
2., The NSA which won't stop at some magic fluffy national border which doesn't even exist on the net.
3., The manufacturers of the hardware you're working on, from Chinese chips in your notebook to the components in your networking equipment.
and don't get me started on ISPs.
You want to be secure? Do not connect to the Internet, ever. Good luck in the economy though.
The only conceivable reason for such loophole is a reciprocal agreement. We can't spy on our people but you can and vice versa. Looks pretty bad.