Earlier quoted context omitted.
Yes, that is why you use azure stack and not azure. It's a licensed version of the software that you can run completely independent of Microsoft.
licenses usually include provisions for being disabled if the parent country requires it. see what happened to iran when US levied sanctions
U.S. Cloud Act is raising concern about extraterritoriality
101–110 of 148 posts
Re: U.S. Cloud Act is raising concern about extraterritoriality
#102I think this CLOUD Act will basically force internationally operating US companies to split up into a US part and an EU part. This law makes it impossible for any company with access to personal data of EU citizens, to obey both US and EU law. The only solution seems to be to ensure that they are two different companies. The other option is to abandon the EU market. What still surprises me is that nearly all of the m…
> The only solution seems to be to ensure that they are two different companies. If the EU comany is a subsiduary of the US company, then it will have to follow its orders and won't really be separate. Furthermore if people based in the USA have physical access to the servers located in the EU, then if the US government wants that data, it will probably be exfiltrated to the USA, regardless of what EU governments wan…
Maybe the US company could be a holding which would "only" own 100% of its independent EU subsidiary (which would be its own legal entity, reporting in EU)?
Re: U.S. Cloud Act is raising concern about extraterritoriality
#103Earlier quoted context omitted.
>Encryption is useless when you store the keys on the same infrastucture. U.S may ask for keys as well. Are you claiming HSM are unsafe? >Even if you would store the keys on a local service at some point your data will lie/transition decrypted on the remote hardware. Well no. You have TPM and HMS which should solve this problem sufficiently. Even hardware tokens for crypto e.g Nitrokey and/or yubikey should be suffic…
Once the attacker gets physical access to your device/computer all bets are off. Not to mention if "your device" is actually provided by a hostile party(i.e amazon/microsoft in collaboration with various US agencies). A government/state is hostile if it breaks the laws designed to protect the citizens and their freedoms(i.e privacy). I believe it's obvious by now that the U.S government seeks not only to apply its ju…
A government/state acting under they own laws is still acting under a law so they would never have physical access to something like an HSM located in a DC on another continent. Or even your laptop that's sitting in another country.
A government/state acting around the law makes any discussion about laws superfluous. They will go around them anyway, as per the premise.
Re: U.S. Cloud Act is raising concern about extraterritoriality
#104Earlier quoted context omitted.
Once the attacker gets physical access to your device/computer all bets are off. Not to mention if "your device" is actually provided by a hostile party(i.e amazon/microsoft in collaboration with various US agencies). A government/state is hostile if it breaks the laws designed to protect the citizens and their freedoms(i.e privacy). I believe it's obvious by now that the U.S government seeks not only to apply its ju…
What's your threat model here? Who's the actor you're protecting yourself from? A government/state acting under they own laws is still acting under a law so they would never have physical access to something like an HSM located in a DC on another continent. Or even your laptop that's sitting in another country. A government/state acting around the law makes any discussion about laws superfluous. They will go around t…
A government’s own laws may restrict what it can do outside of its own territory, but those restrictions, if they exist, don't always include following local law, and so it's entirely unjustified to conclude that a government acting under its own laws would not have the described access.
Re: U.S. Cloud Act is raising concern about extraterritoriality
#105Re: U.S. Cloud Act is raising concern about extraterritoriality
#106Earlier quoted context omitted.
>Encryption is useless when you store the keys on the same infrastucture. U.S may ask for keys as well. Are you claiming HSM are unsafe? >Even if you would store the keys on a local service at some point your data will lie/transition decrypted on the remote hardware. Well no. You have TPM and HMS which should solve this problem sufficiently. Even hardware tokens for crypto e.g Nitrokey and/or yubikey should be suffic…
The cloud providers provide the access controls for the HSM. Why break the encryption when you can just come through the front door?
Short of a hidden vulnerability or a manufacturing defect there's no "official" way to physically access data from the device without destroying it. And accessing the data the normal way still requires access the cloud provider doesn't have (a certificate password for example).
If we're talking hackers that could successfully hack an HSM, they don't really care about laws. And if we're talking about acting under some law, that law has to compel the owner of the password to give it up. Not the cloud provider.
Re: U.S. Cloud Act is raising concern about extraterritoriality
#107Earlier quoted context omitted.
>Encryption is useless when you store the keys on the same infrastucture. U.S may ask for keys as well. Are you claiming HSM are unsafe? >Even if you would store the keys on a local service at some point your data will lie/transition decrypted on the remote hardware. Well no. You have TPM and HMS which should solve this problem sufficiently. Even hardware tokens for crypto e.g Nitrokey and/or yubikey should be suffic…
The cloud providers provide the access controls for the HSM. Why break the encryption when you can just come through the front door?
Re: U.S. Cloud Act is raising concern about extraterritoriality
#108Earlier quoted context omitted.
What's your threat model here? Who's the actor you're protecting yourself from? A government/state acting under they own laws is still acting under a law so they would never have physical access to something like an HSM located in a DC on another continent. Or even your laptop that's sitting in another country. A government/state acting around the law makes any discussion about laws superfluous. They will go around t…
> A government/state acting under they own laws is still acting under a law so they would never have physical access to something like an HSM located in a DC on another continent. A government’s own laws may restrict what it can do outside of its own territory, but those restrictions, if they exist, don't always include following local law, and so it's entirely unjustified to conclude that a government acting under i…
Re: U.S. Cloud Act is raising concern about extraterritoriality
#109Earlier quoted context omitted.
> The only solution seems to be to ensure that they are two different companies. If the EU comany is a subsiduary of the US company, then it will have to follow its orders and won't really be separate. Furthermore if people based in the USA have physical access to the servers located in the EU, then if the US government wants that data, it will probably be exfiltrated to the USA, regardless of what EU governments wan…
>>If the EU comany is a subsiduary of the US company, then it will have to follow its orders and won't really be separate. Maybe the US company could be a holding which would "only" own 100% of its independent EU subsidiary (which would be its own legal entity, reporting in EU)?
This is why the EU should hedge its bets and keep the door open for Chinese companies.
Re: U.S. Cloud Act is raising concern about extraterritoriality
#110Earlier quoted context omitted.
>>If the EU comany is a subsiduary of the US company, then it will have to follow its orders and won't really be separate. Maybe the US company could be a holding which would "only" own 100% of its independent EU subsidiary (which would be its own legal entity, reporting in EU)?
The question is: does America care about international law and treaties or will they just do whatever they want? Ten years ago I knew the answer to this question. Today not so much. This is why the EU should hedge its bets and keep the door open for Chinese companies.
10 years ago, the NSA existed., Now the NSA exists.
The USA, like other big powers, is going to want to try to get access to information and computer systems.
> This is why the EU should hedge its bets and keep the door open for Chinese companies.
You appear to be saying that because the USA gets its hands on Europe's data, Europe should let China do so as well. That doesn't make sense to me, so I wonder what it is you are saying.