EDIT: Relevant XKCD for people calling for technical solutions to the problem: http://xkcd.com/538/
EDIT: Relevant XKCD for people calling for technical solutions to the problem: http://xkcd.com/538/
- Politically, we should punish anything associated with the NSA.
- Socially, we should shun everyone from this date forward who works directly with or as a contractor for anything associated with NSA/FBI/CIA/DEA/DIA. We should not hire any programmer who, from this date point forward, has worked in those capacities. They are destroying our profession and businesses.
- On the engineering front, we should be designing technologies for evading the NSA et al, and spread those technologies. We need to do everything possible to make them easy to use and make them widespread.
- Any person or company who stands up to these organizations should be lionized and we should try to patronize their businesses or employee them. Especially if the suffer consequences like jail and torture.
- Facebook, Google, especially Palantir are known collaborators and we should treat them as such
Google, Microsoft, and Facebook basically have had billions of dollars shaved off of their future market capitalization -- though I have not seen anyone say this yet.
For everyone abroad who is technically adept and talented, the vaults of wealth have been unlocked for you; just copy the successful offerings of American companies. Don't worry about software patents or trademarks unless your country is complicit, you'll have the autonomy of a oligarch (said with some sarcasm.)
There is one solution here: open source, distributed software. If you want to build a company to promote real security this is your only option.
If you are non-US citizen and your customers request a product similar to US product please do exactly as AJ007 says. It will help you, the world, and the US long term. I say this as US citizen and SW dev. Please take our jobs and customers! We don't deserve those customers if we can't protect them and their data.
However, you should only build it if customers are requesting SAAS (or other offerings). Be very careful about blindly copying US business b/c many are successful simply b/c they are almost "Apparatchik" entities, supplying and protected by the US Gov. For example, if you copy Palantir or even Google/Facebook you may not succeed b/c you won't have customers in the same way the US does. But overall, this is a great opportunity for devs from Switzerland (and the like) to get some new customers.
Likewise, this is also very bad news if you are a Chinese or Russian internet company and expect to become a dominant player in the US consumer web/digital/mobile market place.
Not to mention, most countries will pretty much cooperate with the US when it comes to intelligence. The only ones that might not are countries like Russia or China that have their own military-industrial complexes, which are just as eager to get at your data and a lot less scrupulous about using it.
What are you doing on your own checklist? Those are some pretty extremist notions.
If part of your hiring criteria was to exclude anyone who had worked for a contractor or directly for a government organization, I doubt many people would want to work for you. Not because they had violated your criteria, either.
I'm referring to a very small percentage of the government and contract workers who are involved in security and surveillance. I'm not talking about VA or even the regular marines/navy/police.
I won't be doing this explicitly.
Whether people would want to to work in a place that explicitly will not work with former NSA contractors depends on the area. In SF, Boston, NYC, Portland, maybe LA it would probably help you hire good workers. Obviously, in DC or Houston it would be more controversial and hurt the company. Remember these organizations/contractors are destroying our jobs, especially in silicon valley.
If you're in the US it seems kinda pointless to try to move to overseas hosting; the NSA will probably just focus on the client side.
http://www.spiegel.de/international/world/bild-908609-515222...
It is quite possbible that, come September, some of the government parties might lose a few percentage points due to the citizens being annoyed about the erosion of the rule of law. We'll see.
The culture that brought us the SS and the Stasi.
The culture that brought us the SS and the Stasi.
Really? Really? With an account that is as old as yours you cannot avoid posting a comment like this? Do you consider that mature? Useful? Reasonable?I don't. You just disqualified yourself from any meaningful discussion, ever.
My wife treated people with mental issues for some time and I have the utmost respect for people that can handle this stuff.
You, instead, are without protection. You post stuff like this and shout out to the world that you have no clue, that you have no idea what your are talking about, what the topic of this thread is and .. just show that HN really should provide a feature to ignore other people.
Please - go away. You didn't contribute and you're a sad, sad idiot.
There are very strong open source, transparency and anti surveillance movements in Germany. Stasi is the entire reason WHY we have strong privacy laws here.
How does one do that?
Well, I don't know if this is still done today, but when I was in 7th or 8th grade, they (school) drove us, by the busload, to visit a concentration camp.
We were shown the lampshades and wallets made of human skin. The place to stand where inmates would be executed during what they thought were medical examinations. And so on and so on.
It is quite possible that the next "Western" genocide will happen somewhere in Europe. But as somebody who has grown up here, I can assure you it won't be in Germany.
I just wish that history was thaught like this everywhere.
But the tolerant and open minded strain is pretty dominant. Germany is 9% foreigners. Frankfurt is like 30%
Current German culture is equivalent to German culture under the Third Reich? Really?
Is current American culture equivalent to early-through-mid 19th century American culture? Should we discount everything the USA does because you once kept/traded/abused black people as property? Then continued to legislate such thinking via Jim Crow well into the 20th century?
Now that I look, I notice your post history is littered with anti-German racism rooted in complete historical ignorance. I'm wondering what your angle is.
Germany is a better bet. While they are no doubt tapping lines, Germany and the EU have made no moves to actually perform hostile interventions into data-centers or private servers. This means that encryption is still a very viable security measure for protecting your data in the EU. The EU simply has a far better track record with privacy related issues.
It's not about perfect security, it's about getting the best security you can hope for - and that means moving away from anything USA hosted.
The short-term answer is to encrypt everything users have to store, and don't handle their keys, but it's a stop-gap: the only real answer is political and that's where things have to be fixed for good.
How that actually manifests itself, depends on how desperate people become to retain some sovereignty over their livelihoods… which begs the question, where are we now and who could provide the resources/environment to foster the type of change that is needed?
Users can not and will not securely manage key material.
And Germany has also laws which force every mail provider to install an access point to the German authorities and intelligence agencies. I am not sure if also a generic saas platform would have to do it, but it is quite possible.
Better pick Switzerland or Island.
Thanks for the heads up - as I said in the OP, it really is a difficult task. Those kind of laws are exactly what need to be avoided when choosing a country to host in. I don't believe that this kind of thing can be carried out in absolute silence though, so if a country is actively modifying and silencing hosts it's fairly likely that word of it will leak somewhere.
If I get a chance, I might try to put together a red/orange/green overview of known laws and practices in different countries that would affect hosting services there. Unless someone is already working on that and needs a hand?
It's up on github, so hopefully everyone can submit pull requests with data and we can crowd source ourselves a very informative map.
https://github.com/Ryan-ZA/hosting_safety_map
EDIT: I also submitted a link to it on HN. Hopefully interested people will see it and can help out with data.
We have a great privacy commissioner ( http://www.priv.gc.ca/index_e.asp ) but the office holds no power so far as I can see, and the Canadian government has a pretty solid track record of being obsequiously cooperative with u.s. interests
Cooperative with U.S. interests is generally assumed by almost any country - this map is more about the (hopeful) safety of your servers in data centers in different countries.
http://arstechnica.com/tech-policy/2011/05/german-police-sei...
But in regards to cryptography and chances for legally fighting against such orders it could be better. At least on paper. The most likely outcome if lavabit would be hosted in germany would be a police raid that would take all servers for investigation with them. This happenend e.g. for poeple running Tor exit nodes.
Focus instead on encryption.
While it's true that they are victims, they are in a far better place to demand change or to defend themselves. Money buys the ears of lawyers that the average person couldn't even afford to speak to.
Fighting the USgov isn't a decision to take lightly regardless of how much money & resources you have. I cannot condemn a company that backs down from that battle. It could hurt an employee(s) significantly, or the whole company. While I agree they have the most resources to fight it, they're not immune to harm from USgov.
Absolutely!
Unless of course, what you referred to is that most of the traffic goes via the US soil anyway. But then again, why to stay in the US? Move whole business and yourself abroad :-)) Ironically, I found much, much, much more freedom in post communistic Poland than - oh irony! - Land of the Free.
After all, those countries wouldn't be 3rd world countries, if they had the power to resist US threats/requests. Or they are part of the "axis of evil" (or whatever the current propaganda term is), in which case the internet connection to that country could either be cut off, or be heavily censored, if it isn't already happening.
For example I also live in a small EU country. By no means this is a 3rd world country - we have pretty strong IT industry (e.g. some globally successful antivirus companies etc.) and the country is certainly developed enough to host companies providing SAAS. Yet we have certain advantages against the US:
1. our government is way weaker than the US government - their resources are obviously not even close and they would not be able to do what US government does even if they wanted to. But we are still an EU state and we can use EU as a shield when Americans come knocking.
2. it is a post-communist country and people still remember the experience of living in totalitarian/authoritarian country. Opposition against any sign of 'bad old times coming back' seem to be much stronger than the opposition of common American people against recent freedom-stripping. For example there was a proposal that our internet providers should be required to block un-licensed online gambling. The public backslash against 'censorship' was so big that the plan had to be abandoned in few days and the politician who proposed it had to apologize. Many things that are now normal in US or UK and some other western countries would not be possible here.
3. we are still an 'American ally' but the US are not nearly as popular with common people as they used to be here and anti-Americanism seem to be growing. Many politicians exploit that and see opposing to American requests as an easy way to score political points (we have seen this for example when US government wanted to build a part of their missile defence system here).
I am much more worried by corrupt workers in my ISP or telephony provider than I am about my government.
Many governments are much worse than the US; they not only snoop on data but they imprison or kill people as a result of the things they find.
I'd be interested to hear about countries who will i) stand up against the US & ii) not be at large risk of corrupt employees.
(http://www.freedomhouse.org/report/freedom-net/2012/egypt) etc.
Encryption is OK but doesn't solve the problem. There's always metadata and whom can your trust with your encryption? You have to assume that hardware and software you use has backdoors. Mobile phones for example has even official backdoors, your SIM card can be remotely changed and so on …
Hoping that this is true, moving to services from one’s home country would make some sense. Of course, this is more easily possible for people from larger countries than, say, Luxembourg.
This was a concern earlier but my guess is that this will only increase in the near future.
Also, practical key management is still an unsolved problem. The web of trust never took off and the PKI is fucked. Encryption is only as useful as the keys being used to encrypt.
Focus on encryption, to keep ahead and protect the data.
Move out of the US, because it sucks, is far from 'the land of the free' anymore and needs to learn that its place in the digital world is not at the top, but more around the center. Between lots of other states that fail and fail again, in terms of surveillance..
That's infuriating. It's the same as having an insecure system and then charging a hacker millions of dollars in restitution to re-architect the system to do it right.
Those firms wouldn't have to leave the US cloud providers if they had assurances that the US wasn't spying on them for no good reason.
If they were outside of US-and-friends jurisdiction, they wouldn't be shut down and there wouldn't be a gag order.
If enough people leave US based companies for foreign companies it will put pressure on the government. I have a feeling this pressure is already underway.
You should try finding a SSL cert retailer that's outside of the US. The only ones I could find that would actually sell me certs without a phone call charged at least $200 for a basic certificate. https://swisssign.com/en were the most sensible looking ones I could find.
Though, if you are pinning in an app and not just in-browser, you can bundle your internal CA cert in the binary and sidestep the whole mess.
This is what I advise my customers that have security-sensitive stuff do. The PKI can no longer be trusted.