Microsoft fights U.S. warrant for customer e-mails held in overseas server
m.washingtonpost.com
m.washingtonpost.com
In this particular case, it seems obvious that a warrant is inapplicable, since US law enforcement officers don't have the authority to seize Microsoft-controlled data located on servers in Ireland. If Microsoft had instead been served with a subpoena, they would be required to hand over any documents that they had access to, regardless of the data's physical location. However, there are strategic advantages (for law enforcement) to favor warrants, since they're much harder to challenge, and that treaty obligations with foreign countries might restrict the kinds of data that can be retrieved from overseas servers.
If it's that hard to get the necessary paperwork done for this they should fix their system not complain to the courts that it takes to long.
http://www.theguardian.com/business/2014/may/30/bnp-paribas-...
On top of the potentially huge fine, BNP Paribas could suffer a temporary ban on processing dollar transactions, a business that is essential to the operations of an international bank.
Are USA officials able to enforce these sorts of restrictions on e.g. the sidewalk moneychangers one finds in any developing nation? There are more dollars (both physical and in ledger books) overseas than in the USA. At what point does a bank in another country become vulnerable to this sort of restriction? Are officers going to show up outside the bank and yell "give us all your dollars!"?
the Indonesian National Police “were astonished and irritated that the NYPD showed up,” a federal source explained
Alternatively, the Irish Microsoft corporation could decide to prevent the US corporation from having access. It could be argued that they are legally required to do this. Then the US corporation can say they no longer have access. It doesn't matter that the US corporation is the only / majority shareholder because the shareholders cannot compel the company officers to do something illegal (i.e. provide access).
Basically there is no winning for Microsoft, except keeping it secret, having the US government pressure the Irish not to sue, or having the NSA pay possible fines.
Given the history of EU court vs Microsoft, and the market size of EU vs US, Microsoft has no easy solution to the problem. The US government might pressure the Irish, but would have a harder time against European union (which I suppose is part of its design).
I think the motivation is somewhat along the lines that the company didn't have a choice in the matter. Personally I wish that didn't matter and that the privacy breaches would have been prosecuted - I can think of nothing that makes legislative changes faster than companies having to choose where to do business because it would not be possible to do business both in USA and EU.
There have been some very shady dealings between Europe and the US, in areas as sensitive as financial and travel information, where it seems the US has demanded data and Europe has conveniently overlooked and/or hacked its own privacy and data protection laws so they can provide it.
I suspect given the increasingly anti-EU sentiments in many European countries and the outright hostile behaviour of the US toward foreign citizens in recent years, this situation isn't going to last much longer. Someone in politics is just waiting to make their career by telling a weakened EU administration and/or the US where to go, presenting themselves as the people's advocate and defender of basic human rights. This issue provides a convenient and potentially very effective vehicle for anyone with such ambitions.
Put another way, the asymmetric legal, economic and diplomatic relationships that have favoured the US for some time are essentially a bet that the US is worth more as a partner than any cost that asking "how high" will incur. Sooner or later, someone is going to call them, and at this point I'm not sure whether they're just bluffing.
Would citizens of the EU have faith in such a candidate anyway who will basically play the same game as their predecessors? Would anyone with the technical capabilities to develop and use encryption/steganography software for things they deem necessary to encrypt, put any trust in such a candidate over themselves?
Seems like a growing market to sell people on privacy as a service, which means there will be a growing market for those who want to subvert such…
Firstly, the means to make mass surveillance significantly more difficult and expensive already exist, we just don't use them routinely as a society. This lack of security and privacy awareness is harmful for many reasons, only a few of which are related to potential abuses by government organisations, but part of the reason they haven't been used more is because of the pressures imposed formally and no doubt less formally by governments. There is always going to be a balance here, because obviously there are bad people in the world and governments are expected (reasonably or otherwise) to protect their citizens and organisations against those bad people. I doubt any government is going to willingly give up all possibilities to intercept communication, but I think you could have a situation with much more transparency and oversight than we have today to keep that power in check and directed to its intended purposes.
Secondly, one of the most disappointing things about this whole affair is that our own intelligence and security services (I'm in the UK) seem to be more concerned with covering their backsides and keeping tight with their US chums than they are with actually, you know, providing for the security of their own country. In an era when foreign surveillance is a significant threat to everyone and so-called allies are among the prime culprits, the duty of our services is to treat those allies as hostile to the extent that their observed behaviour demonstrates they are hostile, and to respond proportionately. US spying on all our citizens' data? Promote encryption as standard and advise businesses on how to keep their data out of US jurisdiction. If allies have legitimate grounds for wanting sensitive information about British people (and I'm certainly not saying they won't have legitimate grounds for doing so from time to time) then let them request that information through proper channels and in compliance with our laws (and make sure our laws provide for assisting allies appropriately but with appropriate controls and oversight as well).
Ultimately, you can't rationally expect governments to protect their people without allowing them to use the technical tools and legal powers necessary to do so, but neither can you rationally protect your society and way of life by destroying it. This debate is all about resolving that inherent conflict in as fair and practical a way as possible, and to that extent, I think some fresh views in politics could improve the current situation considerably.
One has to acknowledge that it is also not presently in the interests of those who have kept it so. Transparency is a two way street, if everyone as individuals had access to such information that is in the hands of the few to leverage, many aspects of our society could also be made better. After all, "encrypt all the things" makes one wonder about the effort exerted is worth it all, especially if it enables individuals to deceive/mislead/exaggerate to others in the name of privacy.
Secondly, one of the most disappointing things about this whole affair is that our own intelligence and security services (I'm in the UK) seem to be more concerned with covering their backsides and keeping tight with their US chums than they are with actually, you know, providing for the security of their own country.
I question how much "security" there needs to be when governments, corporations and individuals go to such lengths to hide such information from others to maintain the asymmetry of information from individuals of the public, and wonder if they're would be more "security" provided if the public who funds such boondoggles had access to such infrastructure. I'd rather have API keys than the hand-waving/profiteering/"we know whats best for you" media/policy makers and it's enablers tell us what they think we, the public, should know of what they do on our behalf, because only they should be responsible for protecting us, and not ourselves as individuals?
I never have expected any government to protect "their" people, when all of them to some degree are actively harming them and continue to do so through various means unaccountably with claims onto behalf of the public.
Part of Microsoft's solution to the problem is getting this headline published. While the article suggests that this has been going on since before the Snowden information disclosures arose, demonstrating that they're resisting is a change from the perception many had regarding Microsoft's stance on these issues when the Snowden content first began to be published. This excerpt supports this point:
"Microsoft’s efforts to push back against the government in this and other cases, company officials say, predate the disclosures by former National Security Agency contractor Edward Snowden about the reach of U.S. surveillance. But the revelations, which began a year ago, “certainly put a premium on demonstrating to people that we are fighting,” said one Microsoft official who spoke on the condition of anonymity because he was not authorized to speak for the company."
Perhaps consider moving all operations to Europe.
http://en.wikipedia.org/wiki/European_Union_Microsoft_compet...
If, e.g., Europe, is serious about protecting and defending against the demons that are quickly consuming the USA; they need to put in place meaningful, positive controls in place.
We really need to start coming to terms with the fact that we, the USA, are quickly becoming or maybe even are the most dangerous force humanity has ever seen. Sure, we are not "doing anything wrong" other than killing civilians and even out own people against our own laws by rationalizing ways and reasons to sidestep our most core fundamentals; but we will all rue the day that the force canalizes and stripps off its mask to reveal something far more sinister than most people could even imagine.
You have to remember, no horrible regime took power by saying they will graduate to brutalizing their own people. Put it this way, we are well into several meth highs, still insisting that we will be able to stop when we want to and control any addiction that may arise.
The court's argument could be that MS should be required to design their systems to make it possible to comply with their requests.
This is why Microsoft are in a Catch-22 situation, and why the correct solution for Europe is probably to just stand their ground until the US realises it has gone too far in expecting its laws to apply to the whole world and is now asking the impossible at the expense of its own business community.
(Assuming the US court claims jurisdiction, which is more or less what this case is about)
Not all cloud services have this limitation. However I suspect that there will always be some metadata that the government will be able to request from the cloud provider, and this legal question will still be relevant.
How does it work for companies that are separately incorporated in another country?
For example: I had a argument with someone from Goldman Sachs Switzerland. They are claiming that their data is out of reach from the US dept. of justice because they are a separate entity incorporated in Switzerland. I have also heard that as an argument from a datacenter provider (Equinix).
Don't profits from these Swiss corporation still somehow make it to the parent company?
What does the parent company do when served with an NSL for data located in the Swiss company?
BTW the funniest thing about Goldman Sachs Switzerland is that they do not accept US customers as they are considered 'toxic'.
BTW the funniest thing about Goldman Sachs Switzerland is that they do not accept US customers as they are considered 'toxic'.
Practically no Swiss bank accepts US customers at this time. This can be quite a hardship for US citizens living in Switzerland. But they deem the risk just too high and rather forgo the business.To clarify what your Goldman friend meant.
Swiss banks are obliged to keep customer identifiable data ring fenced and within the country. That is, it can't even be processed offshore. It has nothing to do how the entity is setup legally.
For example (I work for a Swiss bank). I can easily remote access my desktop from home, or, if I have my laptop and token with me, from any other location in Switzerland.
There is no way to access the systems from outside Switzerland.
Singapore, btw, has comparable laws and also ring fences data for use only in Singapore.
Can you remote access your home desktop from outside Switzerland? :)
If someone where to be caught doing that, she/he would not be able to say it was technically possible so it's OK. It's technically possible but legally forbidden. So the message is: do it at your own peril.
Reality and law don't always agree but when these things go to court, law has the upper-hand :)
What about IT people? Such companies generally bring in IT professionals for projects from other entities such as the US headquarters.
It's unlikely that an US top executive has a valid business reason to see Swiss data when visiting the country. If such a reason exists he can surely see it, but it's probably illegal to take the data out of the country in any form. (I'm guessing here, but Swiss criminal law is quite finicky on the issue of bank secrecy).
If the top executive tries to asshole his way into the data (as in: "hand over the data, or you're fired") any halfway smart employee would immediately inform compliance, where a whole cacophony of alarm bells would go off.
As for IT professionals. Sure, a lot of foreign IT professionals work for Swiss Banks. But the need to access actual customer data is very, very rare. If the need exists, they can surely see it, but only from within the country's borders.
If Microsoft or any company does foreign business and that specific business stays out of America, the American justice system has no business at all trying to reach it's fingers into it except by established treaty and/or cooperation with foreign governments.
Imagine the uproar if China or Russia decided to do the same to data held on US servers...
With the news here confirming that communications area resistance is beginning on commercial grounds... and from well funded pockets like Microsoft's... a ray of hope exists that the whole tide may be beginning to turn. The truth, ladies and gentlemen, is that we can choose freedom - the natural result of decentralization, encouraged by the jurisdiction-hopping internet - or we can have a feel-good, artificial, dangerous kind of centralized-power-billed-as-safety: one, or the other. It is pertinent to remember what Benjamin Franklin said: Those who would give up essential liberty to purchase a little temporary safety deserve neither liberty nor safety.
Julian Assange's strong statement in Cypherpunks that we are galloping in to a new transnational dystopia is certainly correct. Yet it is also true to say that, with massive transnational corporations even so blindly led as by the profit motive, commercial interest in reaping the custom of the decentralized masses actually aligns with the disempowerment of rogue nations acting continually in defiance of international law and other jurisdictions' right to self determination (such as the US) and instead acts to benefit the preservation of basic digital freedoms for the many.
It's far too early to see what kind of world we will pass on to the next generation, but we are at least blessed to live in interesting times.
That's a silly argument, because it's like saying I'm going to grab papers from your home, but I'm not searching your home because the papers will only be read back at the office.
BTW a logical fallacy cannot apply to a personal value judgement.
https://archive.org/download/gov.uscourts.nysd.427456/gov.us...
The most dangerous argument made by government. There is no end to it. Someday the exact same argument will be used to ensure we all have a telescreen in every room of our homes because not having it would "severely undercut criminal investigations.”
Which in fairness the country has only had for a very short amount of time and takes very seriously.
MS is fighting the wrong battle here.
When you're in a middle of a drug case it's pretty normal that they read your emails.
It's not normal that they read secretly my emails when they have nothing against me.
Because of - to some extent understandable - reasons MS hate is still quite strong among this community but destroying an MS-related thread is unnecessary.
Whilst our opinions are indeed irrelevant, they still try and influence the discussion.
Why? Because the military-industrial complex has invested vast amounts of public money in technology, contractors and employees to allow them to do just that.
Companies like Booz Allen Hamilton are making buckets of cash selling the government this kind of tech and the contract staff to go with it.
The government buyers are being taken on jollies in the Caribbean and receiving nice kickbacks for authorising the public purse. Next year both parties plan on increasing the budget. And so the merry dance goes on getting bigger and bigger every year.
The projects were only content management system projects with minimal privacy concerns. One project did have some customer data but the others were mostly just marketing material.
Stories like this are just going to dry up the final remaining non-u.s. customers for u.s.-based cloud computing companies. It's almost like the u.s. government is trying to screw u.s. companies.
I love it when you play rough, you sexy beast! DO NOT FORGET WHO OWNS YOU, SLAVE! YOU ARE MINE!
Love, Obama and the NSA Spooks
P.S. I left you a little something extra on the nightstand, get yourself some makeup.
http://upload.wikimedia.org/wikipedia/commons/c/c7/Prism_sli...
http://en.wikipedia.org/wiki/NSAKEY
Edit: Why the downvotes?
To be honest I'm more worried that the crypto service providers as supplied aren't available in their shared source license.
"I love crypto, it tells me what part of the system not to bother attacking" -- Drew Gross, forensic scientist
OpenSSL, GNUTLS, Secure Transport
Done!