I think this CLOUD Act will basically force internationally operating US companies to split up into a US part and an EU part. This law makes it impossible for any company with access to personal data of EU citizens, to obey both US and EU law. The only solution seems to be to ensure that they are two different companies. The other option is to abandon the EU market. What still surprises me is that nearly all of the m…
U.S. Cloud Act is raising concern about extraterritoriality
31–40 of 148 posts
Re: U.S. Cloud Act is raising concern about extraterritoriality
#32As of today we have cloud offerings of for instance azure completely separate from the US companies due to this. Here in Norway we can get the complete azure offering from a company called Evry using azure stack [1] and there is a data centre like this in Germany too at least that I know of, probably many more. And sectors like government and banking are required to use them and not the parent companies offerings, es…
Re: U.S. Cloud Act is raising concern about extraterritoriality
#33Earlier quoted context omitted.
But if the US government access PII without authorization via the cloud act wouldn't it count as a data breech when it comes to GDPR?
Then they should be getting encrypted or pseudoanonymised data, if you are following the regulations. For services like AWS you can argue that they should be able to get ahold of these encryption keys, but most data protection authorities seems to think this is good enough.
Even if you would store the keys on a local service at some point your data will lie/transition decrypted on the remote hardware.
It's not a good idea at all to use hardware controlled by a hostile government regardless of what kind of encryption you plan to use.
Re: U.S. Cloud Act is raising concern about extraterritoriality
#34Earlier quoted context omitted.
Hetzner and OVH do cloud offerings, though they are more experienced in real hardware and shared hosting than actual cloud. The prices are competitive with AWS IMO.
For Hetzner: https://www.hetzner.com/cloud What I like most about their service is the intuitive user interface and API. However, the downside is probably that they offer little more than virtual machines and storage. But for my projects, those things are completely sufficient and I am very happy with their service. I worked with AWS too but always hated it, because it takes so long to learn how they are doing things…
That plus OVH and Hetzner aren't US corporations, my money and trust stay in Europe where they belong.
Re: U.S. Cloud Act is raising concern about extraterritoriality
#35Earlier quoted context omitted.
Then they should be getting encrypted or pseudoanonymised data, if you are following the regulations. For services like AWS you can argue that they should be able to get ahold of these encryption keys, but most data protection authorities seems to think this is good enough.
Encryption is useless when you store the keys on the same infrastucture. U.S may ask for keys as well. Even if you would store the keys on a local service at some point your data will lie/transition decrypted on the remote hardware. It's not a good idea at all to use hardware controlled by a hostile government regardless of what kind of encryption you plan to use.
Are you claiming HSM are unsafe?
>Even if you would store the keys on a local service at some point your data will lie/transition decrypted on the remote hardware.
Well no. You have TPM and HMS which should solve this problem sufficiently. Even hardware tokens for crypto e.g Nitrokey and/or yubikey should be sufficiently safe for most use cases.
>It's not a good idea at all to use hardware controlled by a hostile government regardless of what kind of encryption you plan to use.
It depends. You shouldn't host anything at any "hostile government", but who is the hostile government? Is this a hostile nation based on a threat model for your company? Or is this your personal opinion?
Re: U.S. Cloud Act is raising concern about extraterritoriality
#36We, Europeans, should follow our laws to their full extend and fine infringing companies with full power. No matter on whose request they break our laws. Be it Russians, Chinese, Australian or Americans.
Re: U.S. Cloud Act is raising concern about extraterritoriality
#37If complying with CLOUD act would infringe on EU citizens rights, is there any legal reason why EU regulator should not fine a company that is infringing EU laws? We, Europeans, should follow our laws to their full extend and fine infringing companies with full power. No matter on whose request they break our laws. Be it Russians, Chinese, Australian or Americans.
Re: U.S. Cloud Act is raising concern about extraterritoriality
#38Earlier quoted context omitted.
> We can now finally announce that, together with Dell EMC, and as one of the first companies in the world, successfully deployed a customer-ready, production version of Azure Stack. If they're working with Dell EMC, an American company, then it's still the exact same issue.
One step at a time. Having physical control over data definitely is an improvement. Not everyone believes conspiracy theories about spy microchips in mainboards.
You mean not everyone believes the cold, hard truth?
That's unfortunate, because most of us here saw the evidence of this taking place.
Re: U.S. Cloud Act is raising concern about extraterritoriality
#39Earlier quoted context omitted.
Outside of the government sector it seems like these laws are to make sure that the data is within legal jurisdiction, and has nothing to do with privacy.
Banking data is at least considered to be "important" enough to keep within the borders too, but privacy is important too in regards to GDPR. How do you prevent unauthorized access to the data (i.e. the US government) with the cloud act. Do you report those requests as a breech? There is really no difference between that and having the servers hacked in other ways.
Re: U.S. Cloud Act is raising concern about extraterritoriality
#40Is there a good European cloud provider?
Might be cost effective if the pound takes another beating though.