I plan on spending the next few months moving most of my accounts back to self-hosted, or at least hosted nationally.
I plan on spending the next few months moving most of my accounts back to self-hosted, or at least hosted nationally.
Mihail Bakunin
It's frustrating. I don't believe the US should spy on foreign citizens. But in order to present a bulletproof argument, I have to focus on "American Citizens".
The main reason for this is because spying on American citizens is actually illegal. If I let the concept of "foreigners" into the discussion, I lose the constitutional, legal, and rhetorical footing that is already pretty tenuous.
Imagine the same kind of position in the physical world. A multinational storage company would be forced by the USG to open up a client's storage locker somewhere in Europe, copy all the documents in it and send them to the US.
If nothing else this is a very serious threat to the US as the global provider of tech services.
MI5/6 doesn't go 'oh poppycock, they've hopped on the chunnel and fled to France.' They talk to the French agencies or if it's too secret, they go and do it them self. Mossad doesn't give a damn where in the world you are.
'Everyone, everywhere, our laws only exist in our country' is, and has been for a long time, standard operating procedure for these agencies in every country for basically their entire existence.
I didn't change the topic at all. I can't quote the relevant laws in this case but as far as I know the law in Europe is that you need a warrant to get the information and that requirement doesn't disappear if the owner of the information is a foreigner.
That's what's truly amazing in the USG's position. I agree that everyone tries to spy on information on the wire, but the idea that you can demand any information at rest from any company as long as the owner of the information is a foreigner is an amazing position to hold.
There are two other reasons to move your data to your own jurisdiction from US services. 1) the US has the most well funded military so your local spooks probably have less capabilities 2) if one of your local spooks spies on you at least you're in the same jurisdiction and have a small amount of agency (the courts, the vote).
But just remember: everyone is spying.
We're all in this together, and running from one nationality to another will only change the name and face of who is watching you.
However, there is a thing called economic espionage. Depending on what you're doing, having your own government spy on you can be a very different thing from having a foreign government spy on you.
And no, I don't believe for a second the NSA isn't involved in economic espionage: http://news.bbc.co.uk/2/hi/820758.stm
Gut feeling? Not all countries have can afford an expensive program like NSA.
Can anyone recommend a Linode alternative not US based?
But ensure you choose their French data center and not the one they now have in Baltimore...
No affiliation other than being a Gandi customer for six years.
We're all dealing with 'unknown unknowns', that which we don't know we don't know because it's so secretive. If it were a 'known unknown' (such as "What is water made of?"), we could at least know where to go to find out such information (and actually find it out).
This is a case of known unknowns - you don't know if any given piece of digital information about you has been collected and investigated, but an easy way is to simply assume that it all has. Same with encryption backdoors - we know they're possible, we just don't know where they exist. What's more, we even have examples of these kind of things existing from things like the Great Firewall.
Unknown unknowns would be (for example) a sufficiently general P = NP proof rendering crypto as it exists today obsolete, efficient large qubit quantum computing clusters running Shor's algorithm, or mind-reading at a distance apparatus, or genuine telepathy, or anything that's completely off the charts.
Assume all the certificate authorities based in the US are compromised, all the cryptography implementations from the US are backdoored, and all the communications transiting in the US in any form are available to search by whomever you least want to see them.
For example, have they recorded all IP traffic ever? It's possible, but absolutely overwhelmingly unlikely. But all IP traffic originating from $small_anti-US_country_x in the last year? That's a whole lot more plausible, and thus probably worthwhile to defend against.
Also, does that mean non-US CAs are trustworthy? Are non-US comms also subject to tapping, modernday Ivy Bells[1] style?
Also, you have no real idea of exactly if/how they're analysing their captured data in order to extract "threat metrics" or whatever. Posting in a reddit thread about kittens would seem utterly innocuous to virtually everyone; but suppose their steganography detection throws a false positive on your image and by random coincidence they also have hits from some IP once used by a 'terror organisation' in the same thread.
Should threats of that nature be considered, purely because they're possible? How do you clear your name? Why won't you give up the password to the bomb plans claimed to be embedded in your image file? Is it because you're protecting other commie mutants[2]?
How much paranoia is reasonable?
[1] https://en.wikipedia.org/wiki/Operation_Ivy_Bells
[2] https://en.wikipedia.org/wiki/Paranoia_%28role-playing_game%...
This is overblown out of proportions, anyone that ever had any contact with secret services knows, the only rules they follow is their own, regardless of the country.
Basically, I've always accepted that whatever I do online is public anyway. That doesn't mean I endorse that, and I'd rather give my money to local companies than endorse the US at this time.
But either way surveillance is either good or it's bad, I've never understood the reasoning of people who say that it's OK for their own state to do surveillance as they're "probably inept" anyways.
Would you be OK with NSA surveillance if the NSA were inept? No, you wouldn't, so apply the same standard to your own nation as you do to the USA.
The very principle is wrong, but if we assume everyone is surveilling us (which is what is being discussed as people make excuses for the US government doing it), then you'd want to be surveilled by the ones who are the least likely to actually hurt you.
It's obvious no one is thinking their own government will never try to break laws just because they're national, but the extent to which they'll do it is far, far less than the US government. For the very practical reasons of political capital, budget, technological and intellectual capabilities.
I am old enough to have gotten the last bits of it, as we learned to move to democracy, so I would call our secret services anything but inept.
The US certainly holds less power over foreigners, but the CIA's job is to blur the distinction between citizens and foreigners, and the CIA operates with essentially no oversight or restrictions aside from its budget.
Although the reasoning you mention is a better way to express one of the points I was trying to make.
People-focused forces (such as the police or an army) don't have the same issue.
Nor do technologies that are relatively cheap, such as the kind of computer hardware that would help a state surveil its own networks.
If anything, America is slipping compared to the rest of the world with regard to the quality of their computer programmers and other computer-focused developers. Even countries like Estonia could certainly find someone to help them develop competent surveillance if necessary.
The only limitation is that they'd probably not be able to attack the underpinnings of cryptology the way the NSA probably can, but we as computer professionals already know that usually the crypto is not the problem, it's the people or the implementation that is, and both of those are within reach of the Estonia state, if they really wish.
Remember we're not talking about the people foisting this on themselves, we're talking about the government taking on that power.
Still, I'd rather my money went to local interests, and my data stayed within a sphere I have some control of.
Yeah, that has an appeal all its own completely independent of what you feel about spying in general.
The USA certainly does the same in reverse, there's always a big push for buying things "Made in the USA" so it's fair to push for it the other way. :)
If you want to visualize this, think of the world's navies. Who else but the US navy can even operate globally? Who has naval aviation? You might come to think there is a qualitative difference in the ability to do spying.
Just think about the use of microsoft os/programs in the government and how much they could lose.
Speaking as an American, if they do this to US tech companies, imagine what they do non-US companies.
Use a 0-day remote exploit to get a login, exfiltrate data.
Use a known, unpatched exploit to do same.
Use 0-day/known local exploit with sophisticated spear-phish trojan to do same.
Use leverage over domestic software suppliers to ship a customised exploitable (or directly backdoored) update to target company. Ditto domestic hardware manufacturers.
Black-bag (or diplomatic quid pro quo) tap of external or internal comm links, to get either raw traffic or encrypted. If the latter, apply other complementary techniques to obtain keys.
Infiltrate company with agent who can deploy local exploit via physical access, or who can bug/exploit workstations of users to obtain privileged access to server.
Bully/dupe the German government into raiding & seizing the server as part of an international terror/crime investigation. Acquire disk image from seized machines via direct or complementary techniques.
Purchase/acquire German company via a domestic front company. Demand IT infrastructure be 'harmonised' with acquirer and moved to US.
...and many, many more. The only reason not to do most of these things is because the cost/benefit analysis doesn't make it worthwhile to do universally without any prior suspicion.