Live data from Hacker News

U.S. Cloud Act is raising concern about extraterritoriality

bloomberg.com

31–40 of 148 posts

Re: U.S. Cloud Act is raising concern about extraterritoriality

#31
post #26

I think this CLOUD Act will basically force internationally operating US companies to split up into a US part and an EU part. This law makes it impossible for any company with access to personal data of EU citizens, to obey both US and EU law. The only solution seems to be to ensure that they are two different companies. The other option is to abandon the EU market. What still surprises me is that nearly all of the m…

Of course it will, they were already bordering on it before that (see specifically Microsoft USA arguing it could not access Microsoft Ireland data when the US court told them to, which directly leads to the new situation)

Re: U.S. Cloud Act is raising concern about extraterritoriality

#32
post #2

As of today we have cloud offerings of for instance azure completely separate from the US companies due to this. Here in Norway we can get the complete azure offering from a company called Evry using azure stack [1] and there is a data centre like this in Germany too at least that I know of, probably many more. And sectors like government and banking are required to use them and not the parent companies offerings, es…

[deleted]

Re: U.S. Cloud Act is raising concern about extraterritoriality

#33
post #27
post #24

Earlier quoted context omitted.

But if the US government access PII without authorization via the cloud act wouldn't it count as a data breech when it comes to GDPR?

Then they should be getting encrypted or pseudoanonymised data, if you are following the regulations. For services like AWS you can argue that they should be able to get ahold of these encryption keys, but most data protection authorities seems to think this is good enough.

Encryption is useless when you store the keys on the same infrastucture. U.S may ask for keys as well.

Even if you would store the keys on a local service at some point your data will lie/transition decrypted on the remote hardware.

It's not a good idea at all to use hardware controlled by a hostile government regardless of what kind of encryption you plan to use.

Re: U.S. Cloud Act is raising concern about extraterritoriality

#34
post #9

Earlier quoted context omitted.

Hetzner and OVH do cloud offerings, though they are more experienced in real hardware and shared hosting than actual cloud. The prices are competitive with AWS IMO.

For Hetzner: https://www.hetzner.com/cloud What I like most about their service is the intuitive user interface and API. However, the downside is probably that they offer little more than virtual machines and storage. But for my projects, those things are completely sufficient and I am very happy with their service. I worked with AWS too but always hated it, because it takes so long to learn how they are doing things…

Personally, I prefer to build my stuff on top of baremetal. It costs more in personal/sysadmin time but you own the end result and it's less easily shut down by an overzealous AI at AWS HQ deciding you're a risk or competitor.

That plus OVH and Hetzner aren't US corporations, my money and trust stay in Europe where they belong.

Re: U.S. Cloud Act is raising concern about extraterritoriality

#35
post #27

Earlier quoted context omitted.

Then they should be getting encrypted or pseudoanonymised data, if you are following the regulations. For services like AWS you can argue that they should be able to get ahold of these encryption keys, but most data protection authorities seems to think this is good enough.

Encryption is useless when you store the keys on the same infrastucture. U.S may ask for keys as well. Even if you would store the keys on a local service at some point your data will lie/transition decrypted on the remote hardware. It's not a good idea at all to use hardware controlled by a hostile government regardless of what kind of encryption you plan to use.

>Encryption is useless when you store the keys on the same infrastucture. U.S may ask for keys as well.

Are you claiming HSM are unsafe?

>Even if you would store the keys on a local service at some point your data will lie/transition decrypted on the remote hardware.

Well no. You have TPM and HMS which should solve this problem sufficiently. Even hardware tokens for crypto e.g Nitrokey and/or yubikey should be sufficiently safe for most use cases.

>It's not a good idea at all to use hardware controlled by a hostile government regardless of what kind of encryption you plan to use.

It depends. You shouldn't host anything at any "hostile government", but who is the hostile government? Is this a hostile nation based on a threat model for your company? Or is this your personal opinion?

Re: U.S. Cloud Act is raising concern about extraterritoriality

#36
If complying with CLOUD act would infringe on EU citizens rights, is there any legal reason why EU regulator should not fine a company that is infringing EU laws?

We, Europeans, should follow our laws to their full extend and fine infringing companies with full power. No matter on whose request they break our laws. Be it Russians, Chinese, Australian or Americans.

Re: U.S. Cloud Act is raising concern about extraterritoriality

#37
post #36

If complying with CLOUD act would infringe on EU citizens rights, is there any legal reason why EU regulator should not fine a company that is infringing EU laws? We, Europeans, should follow our laws to their full extend and fine infringing companies with full power. No matter on whose request they break our laws. Be it Russians, Chinese, Australian or Americans.

I agree. Companies need to find a way to operate within the law, or not operate. Throwing your hands up and saying it’s too hard is not an acceptable answer.

Re: U.S. Cloud Act is raising concern about extraterritoriality

#38

Earlier quoted context omitted.

> We can now finally announce that, together with Dell EMC, and as one of the first companies in the world, successfully deployed a customer-ready, production version of Azure Stack. If they're working with Dell EMC, an American company, then it's still the exact same issue.

One step at a time. Having physical control over data definitely is an improvement. Not everyone believes conspiracy theories about spy microchips in mainboards.

> believes conspiracy theories about spy microchips in mainboards.

You mean not everyone believes the cold, hard truth?

That's unfortunate, because most of us here saw the evidence of this taking place.

Re: U.S. Cloud Act is raising concern about extraterritoriality

#39
post #15
post #10

Earlier quoted context omitted.

Outside of the government sector it seems like these laws are to make sure that the data is within legal jurisdiction, and has nothing to do with privacy.

Banking data is at least considered to be "important" enough to keep within the borders too, but privacy is important too in regards to GDPR. How do you prevent unauthorized access to the data (i.e. the US government) with the cloud act. Do you report those requests as a breech? There is really no difference between that and having the servers hacked in other ways.

It’s the other way around, the Europeans want to be able to snoop in the data. They don’t care if your data leaks to the US, as long as they have access themselves.
Post reply on HN