HNHacker News
TopNewBestAskShowJobs

declan

8,041 karma · joined July 10, 2012

submissionscomments
declan··on HealthCare.gov Sends Personal Data to Dozens of Tracking Websites
I didn't say "someone needs to be fired" -- that's a paraphrase of what I typed, not a quote.

My point is a broader one: When you have committees and subcommittees and working groups and HHS IT people and CMS IT people and task forces and contractors and subcontractors and new replacement contractors (Accenture) and undersecretaries and sub-sub contractors and assistant secretaries and White House aides and political consultants and PR firms and deputy chiefs of staff and deputy undersecretaries all participating to some extent in the $1B+ process that is the supremely functional Healthcare.gov site we all know and love, the buck can be passed endlessly.

But in all that morass of a process, someone was or should have been responsible for ensuring that standard privacy practices were followed. To her credit, Kathleen Sebelius resigned last year (though not immediately) as a result of what the NYT called the "disastrous rollout" of Helathcare.gov. It is worth looking at whether there is any accountability in the form of dismissals or resignations with this privacy snafu.

If there is not, we should draw our own conclusions.

declan··on HealthCare.gov Sends Personal Data to Dozens of Tracking Websites
I love the idea of a real-world map/reduce job. :) But before spending any time on this, please make sure it's the right PDF. It does mention Healthcare.gov, but only a few times, and I'm no expert on HHS organizational structure. Here's the full directory of PIAs: http://www.hhs.gov/pia/
declan··on HealthCare.gov Sends Personal Data to Dozens of Tracking Websites
An additional problem, as I see it, is that the Obama administration made unambiguous assurances that no PII was being collected as part of Healthcare.gov's use of web measurement tools. Here's the excerpt from the privacy policy:

HealthCare.gov uses a variety of Web measurement software tools. We use them to collect the information listed in the “Types of information collected” section above. The tools collect information automatically and continuously. No personally identifiable information is collected by these tools. https://www.healthcare.gov/privacy/

Note the last sentence is in bold on the actual web page.

A Department of Health and Human Services organ called the Centers for Medicare & Medicaid Services is responsible for the site. An enterprising HN reader might want to skim through the CMS (very long) privacy impact assessment to see if there are any other incorrect claims about Healthcare.gov: http://www.hhs.gov/pia/cms-pia-summary-fy12q4.pdf

It will be interesting to see if anyone gets fired as a result of this particular privacy screwup. The buck should stop somewhere, right?

declan··on HealthCare.gov Sends Personal Data to Dozens of Tracking Websites
> rush of getting the site out and stabilized.

I agree that there's no evidence, at least not yet, of malicious intent. But remember that the "rush of getting the site out" took place back in 2012-2013, with a launch in 2013. It's 2015 now.

declan··on U.S. judges propose updating warrants for Tor, remote searches: p338 (2014)
This might work:

"U.S. judges propose updating warrants for Tor, remote searches: p338 (2014)"

It captures that the source of these recommendations is a judicial conference of federal judges, not the FBI, and that it's dated August 2014. And it mentions the more interesting section (to me) on page 340, which is the fact that warrants could authorize "remote access to search electronic storage and seize or copy electronically stored information" via the Internet.

Not perfect, but it seems workable...

declan··on U.S. judges propose updating warrants for Tor, remote searches: p338 (2014)
Yep, as <slapshot> says, the HN headline is in error and should be changed.

At the very least the word "automatic" should be deleted. It incorrectly implies lack of discretion on the part of the magistrate judge.

Now, perhaps many magistrate judges may be too willing to issue warrants, but that's a different discussion. And there have been plenty of examples where they've raised important issues dealing with electronic surveillance; I highlighted Magistrate Judge Orenstein's opinion re: warrantless cell tracking in this 2005 article: http://news.cnet.com/Police-blotter-Cell-phone-tracking-reje...

declan··on What the Web Said Yesterday
It's a print-world legacy style. It is, to a first approximation, when that issue of the New Yorker will be replaced on the newsstands by the next one.
declan··on Biden: Encryption should “permit the government to obtain the plain text” (1991)
There's a reason I linked to the general page of the bill (in addition to making it clear Biden introduced it in the Senate). That's because Thomas generates temporary URLs; yours no longer works.
declan··on Biden: Encryption should “permit the government to obtain the plain text” (1991)
To see the full quote, click on the loc.gov linked URL to Biden's bill, then "text of legislation," then "printer friendly."

You'll see this text: "It is the sense of Congress that providers of electronic communications services and manufacturers of electronic communications service equipment shall ensure that communications systems permit the government to obtain the plain text contents of voice, data, and other communications when appropriately authorized by law."

Vice President (then Senator) Biden's bill was what led Phil Zimmermann to publish PGP, as he wrote here in the original 1991 PGP User's Guide:

*"It was this bill that led me to publish PGP electronically for free that year, shortly before the measure was defeated after vigorous protest by civil libertarians and industry groups." http://www.philzimmermann.com/EN/essays/WhyIWrotePGP.html

The more things change...

declan··on “It shall be unlawful for any person to manufacture..encryption products” (1997)
Briefly: There has been plenty of misreporting about PRISM. I tried to correct some of that in 2013 here: http://www.cnet.com/news/no-evidence-of-nsas-direct-access-t... (Note the Washington Post backed away from their initial claims and rewrote its original PRISM story.)
declan··on “It shall be unlawful for any person to manufacture..encryption products” (1997)
<ipsin>: Thanks for your kind words! I've felt the urge to restart/resume the Politech mailing list a few times in the last few years but haven't been able to dedicate the time such an effort deserves. Also it works better if moderated by a practicing journalist, I think.

The short answer is I don't think there is such a source. EFF has good action alerts and blog posts (even if I may occasionally disagree with some of their legislative endorsements). EPIC and the ACLU are often more DC-centric, and Marc (who runs EPIC) is essentially an anti-cypherpunk in his views about the private sector.

Among advocacy groups, TechFreedom.org is a relatively new entrant with free-market, liberalize-crypto views. But Berin, who runs it, is a lawyer, not a technologist, and is spending a lot of time on topics like Net neutrality and telecom regulation nowadays.

If anyone is thinking of starting such a source of information with a cypherpunk-ish/politech-like focus on DC policy, I'd be happy to offer some advice, tips, and introductions.

declan··on “It shall be unlawful for any person to manufacture..encryption products” (1997)
There are too many questions here crossing too many areas of the law to answer in an HN comment; some of the language you're using includes legal terms of art where the meaning is not necessarily intuitive. A blog post would be more suitable and I can't take that much time away from my work on http://recent.io/

But briefly: You should assume, as I've written in many places in the past, that your records in the hands of the AT&T/VZ/etc. phone companies can easily be accessed by TLAs. The NSA itself brags of a surveillance "partnership" with those companies, as I wrote in this CNET piece: http://www.cnet.com/news/surveillance-partnership-between-ns... In those cases, crypto has little to do with it.

In this HN comment yesterday, I wrote here about some of the privacy differences between our favorite Silicon Valley companies and AT&T/VZ/etc.: https://news.ycombinator.com/item?id=8902638

declan··on “It shall be unlawful for any person to manufacture..encryption products” (1997)
This is the big one.

The late Peter Junger, who brought this case, was a principled civil libertarian and law professor who deserves to be remembered for dealing the final blow to the federal government's anti-encryption regime. He was the first person to secure a precedential court decision that said this:

"Because computer source code is an expressive means for the exchange of information and ideas about computer programming, we hold that it is protected by the First Amendment." http://caselaw.findlaw.com/us-6th-circuit/1074126.html (The 9th Circuit in _Bernstein_ didn't go that far, despite valiant efforts by EFF, as I recall it.)

Peter was a computer tinkerer as well as a lawyer. He once did me the favor of speaking to a class I taught at Case Western, and, in addition to discussing his own encryption case, talked about setting up a mail server --I recall the school let him place a colo'd box in one of their server rooms because he was an emeritus. He also wrote an article called "You Can't Patent Software: Patenting Software Is Wrong": http://samsara-blog.blogspot.com/

TLDR: One big reason why we haven't seen a proposed US law restricting mobile device encryption today is because of what Peter Junger did in the 1990s.

declan··on “It shall be unlawful for any person to manufacture..encryption products” (1997)
Nope. I think the opposite, in fact. But it's late in the SF area, and it's time for me to go to sleep. Happy to resume this in the morning.
declan··on “It shall be unlawful for any person to manufacture..encryption products” (1997)
Well, there is no U.S. law requiring key escrow. There are a very few laws that impose escrow-like requirements on some sectors. If you're a financial services firm you may be required to monitor employees' email, which makes some forms of encryption tricky. And even the CALEA excerpt you quoted above authorizes telecom carriers to provide secure end-to-end crypto (they wouldn't have "the information necessary to decrypt the communication"). CALEA doesn't apply to the tech firms HN knows and loves; they're not telecom carriers, a term of art.

But putting all that aside for the moment, banning crypto without backdoors would, at a minimum, create real difficulties for U.S. companies and require many open source/free software projects to move overseas. It would also make felons of many HN readers. That's no exaggeration; an ex-Mozilla fellow now building the crypton.io framework wrote to me this evening saying: "That bill would have made my work criminal." https://twitter.com/deezthugs/status/556678844120576000

To be clear, I don't believe the FBI|NSA|DOJ|DEA|DHS|CIA|etc. cadre of TLAs are pushing for a ban on domestic crypto now. But they tend to take the long view. Look very carefully at what is eventually proposed. Is it a ban on whole-disk encryption without backdoors? Would it extend to PCs? What about open source projects and AOSP? Would mere possession of non-backdoored crypto be a crime, or distribution, or commercial sale? Etc.

I view a lot of this as the Feds trying to pressure Apple and Google into adopting an escrowed solution for encrypted devices -- without actually enacting a law. Laws are public, subject to legal challenge (a federal appeals court in the Junger case held there are 1A issues involved in a crypto ban), and tend not to make it through Congress very quickly. But extralegal pressure can be applied in secret, is not subject to legal challenge, and can happen much sooner.

HN threads in the past have discussed some of these extralegal pressures that can be brought to bear. Multi-billion dollar .gov contracts are a big one too.

declan··on “It shall be unlawful for any person to manufacture..encryption products” (1997)
The history here is non-intuitive; I'll try to explain it. I was living in DC during the Crypto Wars of the late 1990s and covering them as a reporter (I've since shifted to working on http://recent.io/, of course).

The SAFE Act as originally introduced in the House of Representatives was designed to be generally pro-crypto by relaxing export controls. But as it made its way through the various committees, the anti-crypto forces got their hands on it and turned it on its head. It became a ban-non-backdoored-crypto bill instead.

More precisely, in 1997, a House committee approved a ban on domestic encryption without backdoors for .gov access. Here's an excerpt from the amended anti-crypto version of the SAFE Act:

"After January 31, 2000, it shall be unlawful for any person to manufacture for distribution, distribute, or import encryption products intended for sale or use in the United States, unless that product [...] permits immediate decryption of the encrypted data..."

Here's how one of the anti-crypto politicos, Rep. Bill McCollum, who went on to be Florida's attorney general, justified it while debating the House Judiciary version of that bill:

"Because this bill will promote greater use of stronger encryption, law enforcement may not be able to gather evidence that it can use to investigate and prosecute cases. Imagine a situation where the police with a search warrant seize the computer of a terrorist but cannot decrypt the list of people and places that he intends to strike next. Or the situation where the police seize the computer of a purveyor of child pornography but cannot decrypt the files to download the images to prosecute him." http://www.techlawjournal.com/cong106/encrypt/19990324mcc.ht...

So yes, you're right that sec. 2804 in one version of SAFE eliminates mandated key escrow. But other versions, including the one approved by that House committee in 1997, went exactly in the opposite direction.

declan··on “It shall be unlawful for any person to manufacture..encryption products” (1997)
The first statute you're quoting, 47 USC 1002, was part of the 1994 CALEA legislation. A basic principle of legal interpretation is that newer laws trump old ones if that is clearly the legislative intent.

So if the 1997 ban-strong-crypto bill had been enacted, it would have overriden that portion of CALEA -- effectively repealing it -- to the extent it was in conflict.

Put another way, if Congress has the power to say X one year, they typically have the power to say not(X) the next year.

declan··on New Revelations U.S. Tracked Americans’ Calls for Over a Decade
So DEA has a secret database of some significant subset of American's phone records compiled with zero court oversight. Lovely. But the first question that springs to mind is: Wy would DEA not try to vacuum up email and other metadata records too?

The law the DEA used to vacuum up Americans’ phone records is 21 USC 876, which authorizes it to demand any info the “Attorney General finds relevant or material to the investigation.” (No room for misuse there, right?)

But if 21 USC 876 lets DEA nab one metadata database, why not others? Cell phone tower records? SMS records? Email To:/From: lines?

One answer is that Silicon Valley companies tend to push back against legally dubious surveillance requests. (Yes, it's true that if they lose they have to comply or go to jail, but at least they tend to fight.)

Examples I can think of offhand: Microsoft, Google, Yahoo, Facebook began requiring warrants for email content in 2010 even though the law remains unsettled nationally. There was Google vs. DOJ in 2006, Yahoo vs NSA in 2007-2008, Amazon vs DOJ in 2007, Facebook vs. Virginia in 2009, and Twitter vs DOJ in 2010 (though I recall that was notification, not litigation). My CNET article in early 2013 disclosed Google was fighting the FBI over NSLs in two different courts: http://www.cnet.com/news/justice-department-tries-to-force-g...

On the other hand, AT&T/VZ/etc. -- which also provide email hosting! -- have long-standing surveillance “partnerships” with the Feds, as I wrote about here: http://www.cnet.com/news/surveillance-partnership-between-ns...

Sigh.

PS: A NYT article covering much the same ground, for those of you who don't subscribe to the WSJ: http://www.nytimes.com/2015/01/17/us/dea-kept-telephone-reco...

declan··on Google Glass sales halted
Whether auto-face recognition is a good idea or not, it's going to happen as the trends we all know and love continue. Even if major tech companies don't build this in to their camera-enabled products, open source projects will using distributed datasets. Or perhaps not-so-distributed datasets: face recognition systems use only something like 70-80 nodal points that give you internodal distances like eye spacing, mouth width, etc. (I may be wrong on that number; if I am I'm sure someone who works in this area will correct me.)

If this happens, I suspect it will change human interaction significantly and make it more different to be casually anonymous. I'm not so worried about people I casually interact learning my identity; I'd be more concerned about cradle-to-grave government collection and permanent storage of these records, coupled with license plate scanners, etc.

declan··on Hi, It’s Google Corporate Development
Well put. Also as <abalone> suggested nearby, the author of the linked article, Max Christian, fumbled the exchange and instead of a million-dollar exit ended up with... what?

Instead of the claim of "I can easily get to twice £X million" -- in revenue? profit? valuation? -- it looks like the author's RoomScan app is near-moribund. RoomScan Pro, which sells for $4.99, hasn't been updated in over half a year and is listed as "optimized for iPhone 5." It's been mentioned in only two articles indexed by Google News in the last eight months. The Roomscan Twitter account hasn't been updated since November. The free version of the app has been updated more recently, but free in this context isn't exactly going to pay the bills.

These are not the signs of an app that is getting to "twice £X million" anytime soon.

I do think it's an innovative idea and a good implementation, but as we see on HN all too frequently, not all innovative ideas and good implementations amount to a "twice £X million" valuation. Any company (or product) is only worth what the market will pay.

As for Google, I don't know how their corpdev team works, but my rule of thumb after working at some very large companies is: don't attribute to malice what can be explained by bureaucracy. It's not unusual for different teams not to know what the other is doing, even when they should. I don't see anything that justifies speculating about nonexistent employees named Maxine, and that kind of bizarre speculation likely poisoned the discussion.

Whoops.

declan··on Spam sites in Google News
When I worked at CNET, we were (and still are) indexed by Google News despite not having three-digit numbers in URLs.

That's because your excerpt from Google News' guidelines left off a very important addendum: "Please note that this rule is waived with News sitemaps."

declan··on Chilling Effects removes itself from search engines
There's been a long-running effort by the copyright lobby to muzzle Chilling Effects. Participants in that effort include Sony, Disney, NBCUniversal, Viacom, BSA, Universal Music, the Entertainment Software Association, and two of my previous employers (before I left to found http://recent.io/), CBS and TimeWarner. They're all members of the Copyright Alliance, which has previously had this to say about Chilling Effects:

The activities of chillingeffects.org are repugnant to the purposes of Section 512. Data collected by high-volume recipients of DMCA notices such as Google, and senders of DMCA notices such as trade associations representing the film and music industries demonstrate that the overwhelming majority of DMCA notices sent are legitimate, yet the site unfairly maligns artists and creators using the legal process created by Section 512 as proponents of censorship. Moreover, by publishing the personal contact information of the creators sending notices (a practice which Chilling Effects only recently discontinued), it subjects creators to harassment and personal attacks for seeking to exercise their legal rights. Finally, because the site does not redact information about the infringing URLs identified in the notices, it has effectively become the largest repository of URLs hosting infringing content on the internet. (https://www.techdirt.com/articles/20140317/11355726599/copyr...)

It would be interesting to know how much influence the copyright lobby has had on Chilling Effects' decision to self-censor.

For now, though, if Chilling Effects has chosen to remove itself from search engines, then presumably some enterprising soul might want to mirror the takedown notices posted on that site. That would continue to shed light on abuses of copyright, such as the demands recently made to get Github pages yanked from search engines.

Note it's often copyright lobby lawyers sending these takedown nastygrams, and those lawyers could claim their letters are copyrighted (and, I suppose, even try to get search engines to de-index the mirror site). While they have been unwilling to sue Harvard, Berkeley, and Stanford law schools, they may be more likely to sue an individual running a mirror site, even if that lawsuit were spurious.

So if such a mirror site were to be created, it might make sense for it to be hosted overseas where the local law permits and operated by someone living overseas. The domain chilledeffects.org is available...

declan··on A Career in Science Will Cost You Your Firstborn
>What's the source for your 20% figure and have you read any of Paul Campos

It's NALP data; they post it on their site.

I like what Paul Campos has written, at least what I've read of it, and agree with many of his points, which is why I referred to the "lawyer/law school bubble." I wouldn't go as far as to call it a "scam," but he knows more about the topic than I do, and it is a more memorable name for a blog.

By way of disclosure, I've taught law school classes as an adjunct and enjoyed it. But if I were giving a 22-year old advice, I'd tell them to think strongly about alternate careers barring acceptance to a short list including Stanford/Harvard/Yale, precisely because of the oversupply of lawyers (last month I suggested to my cousin that she not go to law school, for instance). Also as a practical matter look at the GCs of everyone's favorite tech companies and estimate whether you're likely to get to that level if you go to a lower-ranked school: Facebook (Harvard), Yahoo (UChicago), Google (Stanford), Twitter (NYU), etc. Whether you like it or not, biographies matter more in law.

But nowadays I'm working on http://recent.io/ and not paying close attention to Paul's or other legal blogs except for indexing and semantic analysis purposes...

declan··on A Career in Science Will Cost You Your Firstborn
I think I largely agree with you; one major difference is the opportunity cost of science postdocs vs. other careers. Philip Greenspun's linked article elsewhere in the discussion is probably the best treatment I've ever read.

But I would disagree with your concept of being "secure in your position." I'm not sure that happens nowadays outside of tenured academia, government bureaucracies, and union jobs.

Perhaps you're "secure in your position" at a law firm if you're at the top of your game in terms of expertise, if the firm overall is well-managed, if you're responsible for a multi-million dollar book of business that's some multiple of your take as a partner, and if you're assured that your clients won't go elsewhere (or hire your associates to work as staff attorneys at a fraction of what you're charging). Meeting all those boolean AND requirements strikes me as a rather rare situation relative to the overall population of attorneys out there.

declan··on Whitehouse response to Aaron Swartz petition
<crucini>, thanks for your kind words. I may not have been as clear as I should have been, so let me try again.

Let's look at what JSTOR itself said: "The case is one that we ourselves had regretted being drawn into from the outset... JSTOR settled any civil claims we might have had against him in June 2011..." http://about.jstor.org/statement-swartz

You're right that if victims can be intimidated into asking for non-prosecution, that would be a problem! But what JSTOR said above is precisely not the language of an organization that's been intimidated.

More broadly, the problem lies with the over-criminalization of everyday activities, especially in federal law, as Harvey Silverglate has documented in "Three Felonies a Day." And, if you want to go back further in history, the modern police-prosecutor, victim-has-no-say approach to criminal charges is a relatively modern phenomenon. There are other ways to approach criminal law; I'd refer you to Bruce Benson's "Enterprise of Law" for more on that.

declan··on A Career in Science Will Cost You Your Firstborn
>Replace science with medicine, or law, and the same still applies.

I don't think that's true with law. The linked essay talks about "the 20 years of your adult life that a scientist typically spends proving they deserve a career."

You can be a newly minted, bar-passed, practicing lawyer after spending 7 years of your adult life, and 6 years if you diligently optimize your course selections (typically 4 years undergrad, 3 years law school, plus a few months studying for the bar exam). That's a heck of lot less than 20 years, and matters a lot in terms of female fertility, the topic of the essay.

And about 20% of new law school graduates will be making six figures in their new job. There's a sharp peak in the distribution of full-time salaries for new lawyers centered around $185K because of big law, with a larger, flatter peak centered around $60K thanks to small firms, nonprofits, and work that doesn't actually require a law degree. Those figures come from NALP data, and reflect the situation even during the lawyer/law school bubble the U.S. is in today.

Note I'm not saying law is a necessarily a wiser choice; I know one big law associate who slept overnight on a partner's couch so much I helped her with the transport of a small refrigerator so she could keep meals at work. That's even though she lived within about four blocks of the office. She eventually quit to write novels.

declan··on Whitehouse response to Aaron Swartz petition
The White House's non-response on the two-year anniversary of Aaron Swartz's death shows why these petitions are not only flawed, but should be avoided by people who actually care about political or policy change.

Look at the nearby discussion: Instead of asking why Carmen Ortiz, who's been in her current job for nearly six years, is still there, we're debating the terms of use of the petition site. Instead of wondering why a law originally designed to protect NORAD was used to drive Aaron Swartz to suicide -- despite his JSTOR "victim" never asking for a criminal prosecution -- we're reminiscing about other, equally useless, petitions in the past.

I admit it's a brilliant move by this administration (to be sure, Rs would do the same thing). Instead of having people sign up to be members of EFF or ACLU or TechFreedom.org, which will send email alerts when legal fixes like "Aaron's Law" are pending in Congress, people slap their names on a petition that results in a committee-managed non-response on the two year anniversary of his death.

Imagine if even 5% or 10% of the 61,179 people who signed that petition instead organized rallies in their cities, or a kind of Leave The Internet Alone rally in DC. That might or may not accomplish something; it surely would accomplish more than signing the petition did. (You could wrap in a bunch of related topics: DMCA/copyright reform, NSA reform, CFAA reform and more.)

I'm sorry if I sound frustrated. I spent hundreds of hours interviewing folks involved in the case and reading court documents about the Aaron Swartz prosecution while I was at CNET before leaving to build http://recent.io/. What happened to him was a tragedy, but Carmen Ortiz will leave for a seven-figure law firm job at a time that's convenient for her, and an effort in Congress to fix things actually coughed up a bill to make current law worse: http://www.cnet.com/news/aarons-law-rewrite-backfires-reform...

If you're interested, here's a detailed piece I wrote about the federal anti-hacking law Carmen Ortiz wielded against Aaron Swartz, and how it was never originally intended to cover what he was accused of doing: http://www.cnet.com/news/from-wargames-to-aaron-swartz-how-u...

declan··on Apple’s Dev Agreement Means No EFF Mobile App for iOS
Isn't one big difference that Google doesn't attempt to prohibit you from installing apps from other sources, which EFF also pointed out?

I just took a quick look at the Google Play Developer Distribution Agreement, the Google Play Developer Program Policies, and the Android SDK license -- but it looks like some other differences are:

* Unlike Apple, Google doesn't seem to limit developers' ability to make certain "public statements."

* Unlike Apple, Google doesn't seem to restrict jailbreaking or "enabling others to do so." The "Security Features" language in section 6 seems to come closest but isn't, IMHO, equivalent.

* Unlike Apple, Google doesn't insist on being able to "revoke the digital certificate of any of Your Applications at any time." (Section 7.2 of the Google Play Developer Distribution Agreement does say your app can be removed from the store, but the list of reasons is rather short and includes copyright, porn, malware, viruses...)

That was just a quick look, so I may have missed some things and would welcome correction. I should add that I'm developing http://recent.io/ for both Android and iOS, so to the extent Apple is more restrictive, it's not a deal-killer for my purposes.

PS: EFF's Android app is on the Play Store here: https://play.google.com/store/apps/details?id=org.eff.action...

declan··on Google’s Cloud Loses Following Among CIOs, Survey Finds
As <pm> points out nearby, the GAE pricing issue was in 2011. It's now 2015.

I use GAE for http://recent.io/ (which I left CBS last year to found), and have found that prices have been gradually falling for the last few years. I can't speak to what happened in 2011, but I think it's fair to say that GAE was a much less mature product then.

My own sense is that Google would like to diversify away from being 90%+ reliant on advertising, and is highly unlikely to discontinue a paid service that serves that goal, that is profitable, that is under active development, that allows it to compete with Amazon, and that is used for its own products internally. You might as well speculate they'd discontinue search or email.

I use AWS for some smaller components of http://recent.io/, and have found both to be equally reliable. Google also has assigned me a rep who I can call or email when there's a billing issue, sign up for beta trials of new features I'd like to test, address technical problems, etc., and I've never heard from a human at Amazon.

declan··on New York Prosecutor Calls for Law to Fight Apple Data Encryption
>Probably the same way as the old USA cryptography export restrictions.

Actually it would be much worse. Even in the 1990s, you could release any crypto code (or ship any crypto product) you wanted as long as you took some fig-leaf steps to limit it to domestic use. The SAFE Act would have outlawed that.

Put another way, the Feds wanted to but were unable to prosecute Phil Zimmermann for releasing PGP. But if the SAFE Act had been enacted at the time, they would have -- because it outlaws the domestic "distribution" of non-escrowed crypto.

If you wanted to work on crypto, you'd have to move overseas. And you'd also have to hope that you wouldn't be prosecuted upon your return. The SAFE Act probably wouldn't be interpreted as an extraterritorial criminal law, but "probably" is a weak hook to hang your future and your freedom on.

← PreviousPage 7 of 30Next →