EU Parliament adopts resolution to set standards for cloud interoperability
blog.mist.io
blog.mist.io
To me, this is a natural part of the concept of privacy. I can have momentary privacy: the assurance that nobody is currently watching through my window, listening to my phone calls, or reading my emails as I send them. But there's no assurance of future privacy if we don't have the right to destroy our old data, wherever it may be held.
When people provide an entity with information, they're doing so under the framework provided by current legislation regarding privacy and freedom of information. If these rules are subject to change - through new anti-terror legislation, for example - their information may become accessible in ways that they did not expect when it was originally provided.
I don't think it's possible to maintain any real sense of privacy while this remains the case. How can your data be considered private when it can be opened up for inspection at a later date, under a different regime? There's currently no way to participate in a connected economy without giving away your future right to privacy.
Edit: and the reason I've been hoping the EU will do this is that, realistically, nobody else will.
I appreciate the sentiment regarding security and interoperability, and they might be able to declare their intention to procure only systems that meet X standards, but I hope they refrain from broader impositions on commercial users and cloud providers.
NSA articles aside, I see businesses fleeing regulatory burdens faster than the possibility of surveillance.
With EBICS, you transmit a bank command file by encrypting, encoding and wrapping it as CDATA into an XML file and then repeating the process. You have to use different kinds of wrapper files with different kinds of intricacies for each type of file you might upload to your bank.
The whole specification is 200 pages, and all it does is transfer files.
I volunteered to go to a website, that volunteered to use that service. I can choose not to visit the source sites or the associate ones.
The problem I see with all of this "the governments - or - some government - or - the UN - needs to protect our privacy!!!"
Against whom? Facebook? Google?
How about GOVERNMENTS. If you ask me, any sort of nefarious behaviour commited by web companies are most likely the product of a larger, coercive form of behaviour starting from the government.
How do you know those sites have those trackers before visiting them? The only way to "opt-out" of the sites with such trackers is to stop using the web entirely.
Against whom? Facebook? Google?
How about GOVERNMENTS.
Actually, yes. In the (European) country I live in, public organizations have been prevented from invading privacy (e.g. setting CCTV cameras) by our national data protection commission.
If you ask me, any sort of nefarious behaviour commited by web companies are most likely the product of a larger, coercive form of behaviour starting from the government.
How is web analytics and personal data mining a product of State spying? And even if it is, how is it justifiable on that basis?
iframes going to facebook, scripts going to google-analytics.com/ga.js, etc mixed with knowledge about what these elements do (facebook iframe article, obvious in regards to analytics, etc).
> In the (European) country I live in, public organizations have been prevented from invading privacy (e.g. setting CCTV cameras) by our national data protection commission.
So public organizations are prevented from data gathering from themselves? Well that solves that problem. I'm sure if the NSA comes out and says they'll start enforcing protection against spying that some would even believe them!
> How is web analytics and personal data mining a product of State spying?
I'm not saying it is! I have no problem with facebook or google. I don't use facebook, and use google only to the extent I am comfortable with. Never have these companies used this information, some exploitable, to exploit me. They want me to use their services.
On the inverse, could you explain to me in your own words why this legislation is necessary?
This is a bold move, and much more significant than some attempt at standardisation that probably won't work.
It will make it more expensive to hire a VM, probably, and I wonder if there will indeed be any benefit (given that cloud providers will have to start vetting and inspecting the source code on the VMs people are running - potentially taking away all the benefits of programmatic instance deployment.)
Come on HN, let's help the EU. Anyone got any great ideas? Because I don't even understand the question, much less what the answer would be.
Edit: notice how everyone is just "assuming" what they mean. The problem is not well defined.
How would you ensure service portability between Google App Engine (runs software, no access to the OS), AWS (Linux VMs) and Azure (Windows VMs)?
But portability between, AWS, Google Compute, Azure, Rackspace, Softlayer, Nephoscale, Linode, Digital Ocean, etc would be quite beneficial.
Personally my take is that the proposed abstractions are too low level to be of genuine use as an abstraction layer across cloud providers - but I'm biased in that I was involved in the research and development of a higher-level abstraction that provided something closer towards a PaaS approach - roughly equivalent to provisioning an instance (with disks and networking as required) and configuring it with puppet (this was back in in 2007 though).
The general attitude I've got from cloud providers when I spoke to them is that small providers like the idea of standards (reduces barrier to picking up their service) and big providers have no motivation to allow such mobility or multi-cloud use.
Yeah, what vagrant has been able to acomplish so far is an example of this. There are many features that only work on some providers, usually just VirtualBox, and the AWS support is largely limited to controlling instances (vs configuring them).
I think it'll get there eventually, but there's not a lot of motivation/incentive from the established players.
Does anyone here really believes that any of this is going to make a measurable, positive difference in a regular Internet user's life? That somehow more government meddling is a cure for government meddling? Weren't European spy agencies cooperating with the Americans?
It's yet another power grab of the "no crisis should go to waste" kind.
I think that there was a draft EU directive to standardize on mini-usb, but it was scrapped after manufacturers voluntarily complied. Apple argued that their usb cable to lightning/doc connecter (which can charge from any usb charger/port/etc.) was required for analog speaker docs and the like, and the EU let it pass.
Anyway I found some info: http://www.engadget.com/topics/mobile/2009/02/15/eu-commissi... Looks like the European Commissioner scared them, then http://www.engadget.com/2010/12/29/european-standardization-... the phone manufacturers agreed to the standard, followed by the CEN-CENELEC and ETSI officially mandating the standard, followed by (most) phones actually coming out with micro-USB.
They include an adapter in Europe.
Anyway, I'm not gonna repeat the usual libertarian 'crap', I just want to add, that the justification of regulation governments enjoy is what makes them possible to eventually go a litte bit 'over the edge' like the recent Snowden scandal.
Maybe legislate an easy way to download all my emails from gmail and upload them to outlook.com. Wouldn't that be very useful?
Thankfully, gmail do not keep your emails hostages like that, and users can transfer their property away into a private servers if they ever get tired of the constant spying-for-profit.
ssh user@rsync.net s3cmd get s3://rsynctest/mscdex.exe
ssh user@rsync.net s3cmd ls s3://rsynctest
Done and done.Ask about discounts for HN readers.