Live data from Hacker News

U.S. Cloud Act is raising concern about extraterritoriality

bloomberg.com

11–20 of 148 posts

Re: U.S. Cloud Act is raising concern about extraterritoriality

#13

Earlier quoted context omitted.

> We can now finally announce that, together with Dell EMC, and as one of the first companies in the world, successfully deployed a customer-ready, production version of Azure Stack. If they're working with Dell EMC, an American company, then it's still the exact same issue.

One step at a time. Having physical control over data definitely is an improvement. Not everyone believes conspiracy theories about spy microchips in mainboards.

Microsoft Euro branch is still subject to US law. The US can still seize your data.

Re: U.S. Cloud Act is raising concern about extraterritoriality

#14
post #5

Is there a good European cloud provider?

If you’re asking for a cloud provider that is compliant with data protection laws, Azure is at the moment your best bet. I believe they have some deal with T-Mobile so that the legal entity that does the exploitation of the data centers is a European company, and the data is out of reach from any US subpoena or similar.

If you’re looking for something more simple, as others mentioned, OVH and Hetzner are OK, although competing on price mostly. If you’re looking for a bit more quality, I can recommend Leaseweb.

Re: U.S. Cloud Act is raising concern about extraterritoriality

#15
post #10
post #2

As of today we have cloud offerings of for instance azure completely separate from the US companies due to this. Here in Norway we can get the complete azure offering from a company called Evry using azure stack [1] and there is a data centre like this in Germany too at least that I know of, probably many more. And sectors like government and banking are required to use them and not the parent companies offerings, es…

Outside of the government sector it seems like these laws are to make sure that the data is within legal jurisdiction, and has nothing to do with privacy.

Banking data is at least considered to be "important" enough to keep within the borders too, but privacy is important too in regards to GDPR. How do you prevent unauthorized access to the data (i.e. the US government) with the cloud act. Do you report those requests as a breech? There is really no difference between that and having the servers hacked in other ways.

Re: U.S. Cloud Act is raising concern about extraterritoriality

#16

Earlier quoted context omitted.

One step at a time. Having physical control over data definitely is an improvement. Not everyone believes conspiracy theories about spy microchips in mainboards.

Microsoft Euro branch is still subject to US law. The US can still seize your data.

Yes, that is why you use azure stack and not azure. It's a licensed version of the software that you can run completely independent of Microsoft.

Re: U.S. Cloud Act is raising concern about extraterritoriality

#17
post #5

Is there a good European cloud provider?

If you’re asking for a cloud provider that is compliant with data protection laws, Azure is at the moment your best bet. I believe they have some deal with T-Mobile so that the legal entity that does the exploitation of the data centers is a European company, and the data is out of reach from any US subpoena or similar. If you’re looking for something more simple, as others mentioned, OVH and Hetzner are OK, although…

Microsoft has already scrapped the trustee model in Germany again: https://mspoweruser.com/microsoft-is-discontinuing-the-germa...

Re: U.S. Cloud Act is raising concern about extraterritoriality

#18
post #6
post #2

As of today we have cloud offerings of for instance azure completely separate from the US companies due to this. Here in Norway we can get the complete azure offering from a company called Evry using azure stack [1] and there is a data centre like this in Germany too at least that I know of, probably many more. And sectors like government and banking are required to use them and not the parent companies offerings, es…

That cloud thing is overhyped. The "Cloud" will never swallow the budget and mid-tier hosting industry for purely economic reasons. Uncle Liu hosting Co. and AWS are the same things underneath, running mainstream x86 hardware, and both buying from mid-tier OEM server assemblers. The days of people buying $10k Dell servers are gone, and ones ability to capitalise on undercutting major hosters by buying directly from O…

Cloud is not purely hosting, it's the services on top, the benefits of the company behind it. I don't know the statistics but probably bigger companies will pay a premium knowing that it's Amazon doing the hosting and not 10 different Uncle Lius.

Re: U.S. Cloud Act is raising concern about extraterritoriality

#19
post #2

As of today we have cloud offerings of for instance azure completely separate from the US companies due to this. Here in Norway we can get the complete azure offering from a company called Evry using azure stack [1] and there is a data centre like this in Germany too at least that I know of, probably many more. And sectors like government and banking are required to use them and not the parent companies offerings, es…

The German one at least was cancelled recently [0] (source in German).

[0] https://www.heise.de/newsticker/meldung/Auslaufmodell-Micros...

Re: U.S. Cloud Act is raising concern about extraterritoriality

#20
post #15
post #10

Earlier quoted context omitted.

Outside of the government sector it seems like these laws are to make sure that the data is within legal jurisdiction, and has nothing to do with privacy.

Banking data is at least considered to be "important" enough to keep within the borders too, but privacy is important too in regards to GDPR. How do you prevent unauthorized access to the data (i.e. the US government) with the cloud act. Do you report those requests as a breech? There is really no difference between that and having the servers hacked in other ways.

Banking data is important because the police and tax authority wants to make sure they have access, privacy doesn't really come into play here. It's a nice side effect, though. It's the same with accounting data.

When it comes to GDPR it only talks about where and by who data is processed, it doens't really put any restriction on storage, except for some pretty vague (on purpose) requirements about data protection (read: encryption).

Post reply on HN