Microsoft adopts first international cloud privacy standard
blogs.microsoft.com
blogs.microsoft.com
>The standard requires that law enforcement requests for disclosure of personally identifiable data must be disclosed to you as an enterprise customer, unless this disclosure is prohibited by law.
Since the policy of several governments seems to be "collect everyone's data and don't inform anyone about it under penalty of law," it's a pretty weak protection. Seems like the only way around it is removing centralized keys. Even if you trust your own government with the data, there are probably other ones you don't trust and you have no control over that will collect your data if they have any opportunity to do it.
At least they're at least saying that they will be transparent whenever they are legally allowed to do so, which is something.
If you are multi-national and not having your own certificates, I'd be happy to do some consulting for you.
Owning your own encryption keys also has other issues: Do you issue per-user keys, or an org-wide key? If you issue per-user keys, how do you share documents between users? If you have an org-wide key that gets compromised, how quickly can you re-key every device and re-encrypt every document (how do you even detect that it's been compromised?)? If you encrypt using your own keys, how does that impact any processing that happens 'in the cloud' (eg. search indexing, batch processing)? Do you need to run encryption endpoints locally that users can access all the data through?
All of these problems are solvable. All of these problems can become a nightmare depending on your org, rollout, users, existing environment, etc.
I guess the point I'm making is that 'encrypt all the things' is rarely the {best,easiest,possible} way to do things.
* Microsoft Corp, U.S.A.
* Microsoft AG, Germany
* Microsoft, China
* Microsoft, Russia
* Microsoft, India
And have each one of those independently generate key material that, when combined, can be used by the user to generate their decryption/signing keys, which are used to secure their data.
In order to compel this system to give the user's data to a third party, all five governments involved must compel all five entities involved to release the key materials.
Of course, even better than 5 "Microsofts" would be a general distributed protocol in which users trust X companies in Y countries with their data, such that no less than Z < X companies are required to approve any re-construction of the user's key. The protocol can further be designed to make it as hard as possible to re-construct any keys without simultaneously announcing publicly that a key has been re-constructed (e.g. via a block-chain based protocol).
Is this a huge pain to implement? Yes, yes it is. But, is there any viable alternative for a globally trusted internet/cloud in the era of internet militarization?
> Now, each of those parties is a fully independent company, with its own CEO, own board, own employees and own counter-espionage division. [...]
Do you remember that US judges didn't even give a fuck about other _countries_ having different privacy laws? I can't imagine that they will respect that "this company which actually isn't one, but five"-move.
As for US judges not caring about the five companies thing. Well, so what? They can, assuming their local laws and political climate lets them get away with it, jail everyone working for their local company. This should not compel the other four companies, in four other countries, to give them the extra four components of the key. Note that I selected USA/EU/China/Russia/India for a reason, and not, say... USA/Mexico/Colombia/Afghanistan/Iraq. If this sort of system were the accepted global standard, any nation that tries to "brute force" their own local company, instead of using whatever legitimate procedure becomes available for internationally agreed law enforcement, would just be basically marginalizing itself out of the internet.
I'll be the first to admit that what I am describing is not very likely. It would probably require a significant number of governments to be basically OK with not having access to certain data about people, so long as other governments don't have access either, which is not what most political leaders are clamoring for right now. But the problem is, the alternative is not business as usual either, the alternative is every country basically building their own silo-ed internet over time (China is there, Russia is heading there, the EU is strongly considering it, etc). Reasonably powerful non-U.S. countries will eventually see using U.S.-company run cloud services as equivalent to what Americans would think of say, having their energy grid directly connected to power plants in Russia over Alaska and running no plants within their own territory.
1) http://www.dailymail.co.uk/news/article-2868322/Disney-Micro... "Disney and Microsoft dragged into Luxembourg tax avoidance scandal engulfing EU chief Jean-Claude Juncker"
But in US, the law says companies must provide the data unecrypted ONLY IF THEY CAN DO THAT. So if they're using strong end-to-end encryption, the law should be on their side, since they can't decrypt the data themselves. Only the users can.
That's why the FBI was making such a big deal about Apple encryting the data with the user's key in the press. Because they knew they can't do anything about it, and the best they could hope for is to make it a big enough scandal that Congress will pass a law against such encryption.
And the reason I said this is how it should work in all countries is because it's common sense. If companies can't do something, then they can't be forced to do it. But as I said, in UK you could go to prison even if you forgot your password, and they ask your for your drive's password. That's an illogical law, but I guess that's what UK citizens get for not having a Constitution: illogical and abusive laws from the government that trample people's rights.
I wont debate specifics of the letter of the law because I don't know them, but im not convinced you do either.
Yeah great, show your proprietary code to a third party company and everyone is just going to immediately trust you.
Plenty of other cloud storage services offer real reasons to trust the backing store, called the code is open. I can audit it, my neighbor could audit it, and every corporate user is liable to audit it. I have no reason to ever trust an arbitrary third party I have never had reason to trust in the past who is now trying to guarantee your cloud is secure, when competitive options are letting me do my own auditing, if I wish.
Is there anything else this is comparable too - where a company has the gall to say "another company looked at our black box and said it was good, so trust us alright guys?". When cars or houses or roads or food get certified for something you always have the capacity to reproduce the certification process yourself as a verification measure. You cannot do that to proprietary software, especially when its on some foreign server somewhere running who knows what version of it.
Uh, isn't that how third party trust works?
Like how SSL cert verification goes to a trusted root CA for validation.
It's true, ultimately cloud security relies on trust, but I don't think Microsoft has done enough to deserve my trust, even if this is a good step forward.
The credibility of ISO is at stake.
http://magazine.redhat.com/2008/03/24/iso-approval-a-good-pr...
Either way, the ISO's current state is likely to be seen as a quagmire when viewed through history's lens.
Microsoft did not respond to several calls requesting comment.
http://archive.wired.com/software/coolapps/news/2007/08/ooxm...
We begin therefore where they are determined not to end, with the question whether any form of democratic self-government, anywhere, is consistent with the kind of massive, pervasive, surveillance into which the Unites States government has led not only us but the world.
This should not actually be a complicated inquiry.
Microsoft's former chief privacy adviser said he did not have faith in the security of the software company's technology
http://www.theguardian.com/world/2013/sep/30/microsoft-priva...
Additionally, is the ISO 27018 not worth implementing because Microsoft seems to have implemented it (allegedly)?
FSFE Sticker: https://blogs.fsfe.org/mk/files/2014/11/there-is-no-cloud-pa...
And I say that as someone who has settled on OneDrive for my casual cloud storage, with more important or private files (taxes, finances) stored on a personal server running OwnCloud from my home office. I have all of my files, important and casual, backed up to an external drive that lives in a fire safe. Not as secure as, say, a bank deposit box, but better than nothing.
[1]https://blog.spideroak.com/20150212080057-increasing-transpa...
An example for you: Microsoft used to have an identity service called 'Passport'. They wanted to make it into a universal login, along the lines of Google ID or Facebook logins today. They created a whole suite of related services, codenamed 'Hailstorm', which they tried to bring to market under the terrible name of ".NET MyServices". And they failed because the universal reaction of the world was that they were not prepared to trust Microsoft with their privacy. (see, e.g. http://www.theregister.co.uk/2002/12/17/net_my_services_gone...)
If any of these are not met then you are trusting someone else with your privacy.
https://upload.wikimedia.org/wikipedia/commons/c/c7/Prism_sl...
(Tedious disclaimer: my opinion, not my employers. Not representing anybody other than myself. I work at Google, not on cloud, although I routinely fire my nerf gun at people who do)
Microsoft corrupted many members of ISO in order to win approval for its phony 'open' document format, OOXML. This was so governments that keep their documents in a Microsoft-only format can pretend that they are using 'open standards.' The government of South Africa has filed an appeal against the decision, citing the irregularities in the process.
http://en.wikipedia.org/wiki/Standardization_of_Office_Open_...