NSA - The Price of Hypocrisy
faz.net
faz.net
http://en.wikipedia.org/wiki/Casio_F91W#Claimed_use_in_terro...
(See also: encryption, tor; next up, using any OS that isn't certified NSA-backdoor-compatible?)
But the real catastrophe here is that these U.S. companies have suddenly and irrevocably lost the trust of the rest of the world, as the article rightly points out. Software is one of America's last bastions of competitiveness and our stupid government has managed to undermine even that.
So long, Internet. It was fun while it lasted. I just hope there will still be a few good paying jobs left after the crash, maybe in the field of cryptographic communications; that seems like it's got a lot of potential in our post-privacy era.
Google's reputation is, after all, based on "do no evil", is it not? Hundreds of millions of people all over the world trusted them to ethically handle ads and personal data and all that. Google took a principled stand on Chinese spying and censorship, remember, and it cost them probably billions of dollars in business in mainland China.
A reputation, once lost, is not easily restored.
And don't be naive. The judges are in my pocket, public opinion is in my pocket, I have power which your money can never buy and you are on your own, as all of your competitors are just waiting for the chance to jump in and destroy you.
It is not immediately clear the stakes are that high, and a counterargument with some validity is that a failure to cooperate will cost a lot of lives from future mass causality terrorist actions. And the penalty is squalid, e.g. see the example of Federal prisoner Joseph Nacchio, former CEO of Qwest. Note the truth behind his conviction doesn't matter a long as there is enough solid suspicion.
It is not as though there were no warnings:
https://www.gnu.org/philosophy/who-does-that-server-really-s...
I always said that and I believe that the "cloud" is just some intermediary paradigm, in some time and hopefully soon, people will host all their data at home and will only upload it encrypted to on line vaults to have them backed up and redundant for accessing.
For now, I am really looking forward for an Evernote / Dropbox hosted outside of USA/UK/etc to start.
Then, you make some sort of lifetime guarantee that you'll keep up with changes in storage and interface technology. Guarantee that the thing will be later upgraded to seamlessly translate people's wedding photos to the next big image format. Guarantee you'll keep it forward and backwards compatible to future OS updates. Guarantee it'll work with future phones and tablets, etc.
Maybe even build in some kind of automated off-site backups in case of fire, theft, flooding.
If you made it simple, and if you earned people's trust that this is really an investment - I think you could really clean up with local home storage.
Since we're not all IPv6 yet, the cube will need to set up a secure tunnel out of the home network to a public endpoint, probably on a server run by your company. All syncing would have to go through that server, preferably with end-to-end encryption so the server can't access the data. (It can still be captured for offline cracking, though.)
Edit: typo.
The article calls out smart devices. I've fantasized about having smart devices of my own, but in my fantasies they answer to me and collect data into my systems. Which means I need to learn a bit of embedded programming and some electrical engineering to build my own, after I've learned how to set up my own servers. I don't see this as viable for normal consumers.
Even I don't manage all of my own information. I switched to Gmail because I just can't keep up with spammers. I have a life.
>sync protocol that leaks
Que? The sync protocol had better be open, or it's worthless.
I disagree. There are many signs that at least some people are moving in this direction. Think of things like SpaceMonkey, OwnCloud, various plug computers, the 'Raspberry Spring' (small embedded ARM devices) and many others besides.
Sure, these don't fulfil all of your criteria but the fact that they exist at all indicates that we're on the right path.
It's fair to say that the relative number of people doing something right now may be low but it's completely wrong to extrapolate that to the future the way you're implying. We don't know what will happen.
My post above is attempting to support my view that there is growing interest in solutions like the kind you asked for (e.g SpaceMonkey raised 3x its funding goal on KickStarter). Whether these solutions actually become successful in the long term remains to be seen but I feel we're further along than your comment suggested.
The hardware is small, cheap ($20 - $200, or more if you prefer) and low-power. And the truth is: having _any_ dedicated box means you're getting more hardware allocated to your use and data than most SAAS providers provision on a per-customer basis. With modest amounts of RAM and an SSD performance will top most cloud services.
The software is self-configuring. One thing the Debian team has been working on for nearly two decades is how to take all the pain out of deploying systems, and while it's not perfect, it's really damned good. With a focus on "sane by default", there's no initial package selection.
The "Federated" bit says that your data is replicated on other nodes, either of your specific choosing or based on an arbitrary selection. That can include encryption of non-public data.
And there's a possible business model: set up self-hosted systems for individuals or businesses, or host small numbers of sites (it would take a lot of work for the feds to track down tens of thousands of providers rather than a handful of large players).
Email, webhosting, file storage, email, messaging, social networking, on an open framework.
This was news to me.