Live data from Hacker News

U.S. Cloud Act is raising concern about extraterritoriality

bloomberg.com

81–90 of 148 posts

Re: U.S. Cloud Act is raising concern about extraterritoriality

#81
post #65

Earlier quoted context omitted.

If you're talking about Intel ME, just use AMD or ARM.

Both have their own ME equivalent with ARM TrustZone. https://en.wikipedia.org/wiki/AMD_Platform_Security_Processo... https://en.wikipedia.org/wiki/ARM_TrustZone#TrustZone_(for_C...

I thought there is a great level of control over these and none of these run Minix and connect to the network. The actual functionality that ME is supposed to provide is purposeful.

Re: U.S. Cloud Act is raising concern about extraterritoriality

#82
post #51
post #10

Earlier quoted context omitted.

Outside of the government sector it seems like these laws are to make sure that the data is within legal jurisdiction, and has nothing to do with privacy.

Didn’t Russia require something like this back in 2016 or so? All data pertaining to Russians had to stay in Russia?

Yes, it was ostensibly about privacy but the actual compliance requirements align with jurisdiction and access rather than privacy.

Re: U.S. Cloud Act is raising concern about extraterritoriality

#83

Just look at the new HoloLens: It uses the cloud in order to analyze the objects in front of you at your office, your house or whatever on real time. Combine that with this with companies like Apple tracking your pulse in your clock(that gives them knowledge about your deep emotions an activities on real time). Add companies like Google that track your phone, your car(with the maps abilities) on real time. Add to thi…

[deleted]

Re: U.S. Cloud Act is raising concern about extraterritoriality

#84
post #45

Earlier quoted context omitted.

Interesting. Can you provide a source?

https://en.wikipedia.org/wiki/Intel_Management_Engine#Claims...

With respect, what you linked to is a conspiracy theory that the ME is used in ways other than explicitly stated by Intel and unsupported by any evidence other than allegation.

Re: U.S. Cloud Act is raising concern about extraterritoriality

#85
post #37
post #36

If complying with CLOUD act would infringe on EU citizens rights, is there any legal reason why EU regulator should not fine a company that is infringing EU laws? We, Europeans, should follow our laws to their full extend and fine infringing companies with full power. No matter on whose request they break our laws. Be it Russians, Chinese, Australian or Americans.

I agree. Companies need to find a way to operate within the law, or not operate. Throwing your hands up and saying it’s too hard is not an acceptable answer.

[deleted]

Re: U.S. Cloud Act is raising concern about extraterritoriality

#86
post #79
post #26

I think this CLOUD Act will basically force internationally operating US companies to split up into a US part and an EU part. This law makes it impossible for any company with access to personal data of EU citizens, to obey both US and EU law. The only solution seems to be to ensure that they are two different companies. The other option is to abandon the EU market. What still surprises me is that nearly all of the m…

I talked to a lawyer specializing in data protection a couple of years ago, and according to her, the problem is already there - you cannot satisfy both the GDPR and US law that requires that the US government can snoop whenever they want to. Currently, the companies are getting away with it, but with people like Max Schrems, they might not be able to in the long run.

The European Commission's own view on this is here https://www.supremecourt.gov/DocketPDF/17/17-2/23655/2017121...

Re: U.S. Cloud Act is raising concern about extraterritoriality

#87

Earlier quoted context omitted.

Encryption is useless when you store the keys on the same infrastucture. U.S may ask for keys as well. Even if you would store the keys on a local service at some point your data will lie/transition decrypted on the remote hardware. It's not a good idea at all to use hardware controlled by a hostile government regardless of what kind of encryption you plan to use.

>Encryption is useless when you store the keys on the same infrastucture. U.S may ask for keys as well. Are you claiming HSM are unsafe? >Even if you would store the keys on a local service at some point your data will lie/transition decrypted on the remote hardware. Well no. You have TPM and HMS which should solve this problem sufficiently. Even hardware tokens for crypto e.g Nitrokey and/or yubikey should be suffic…

The cloud providers provide the access controls for the HSM. Why break the encryption when you can just come through the front door?

Re: U.S. Cloud Act is raising concern about extraterritoriality

#88

Earlier quoted context omitted.

> The only solution seems to be to ensure that they are two different companies. If the EU comany is a subsiduary of the US company, then it will have to follow its orders and won't really be separate. Furthermore if people based in the USA have physical access to the servers located in the EU, then if the US government wants that data, it will probably be exfiltrated to the USA, regardless of what EU governments wan…

Here lies humanity, they tried to do the same things 15 different ways and squandered their resources doing so. (Not saying you’re advocating for this, just that it is the current plan it seems)

Here stands humanity, they tried to do the same things 15 different ways as a way of figuring out what was best for various situations.
Post reply on HN