Live data from Hacker News

AWS European Sovereign Cloud to be operated by EU citizens

aboutamazon.eu

51–60 of 88 posts

Re: AWS European Sovereign Cloud to be operated by EU citizens

#51
post #43

Earlier quoted context omitted.

That is a rather laughable actual protection isn’t it? People do stuff because their bosses tell them too.

I know people (even members of my own family) who have resigned jobs because they felt the personal legal risk to themselves was excessive. In my experience, it is a much more common event at the C-suite level, where that risk is most acute, than at the level of individual contributors. If the company goes bankrupt, the ICs in accounting are unlikely to be personally found liable for the company’s debts - but if the…

Sure, then they replace them with someone with no such insight/scruples. They quit because the company wasn’t going to change ‘the orders’, yes?

Eventually they found someone who would do what they were told without quitting, that is how this works.

Re: AWS European Sovereign Cloud to be operated by EU citizens

#52
post #34

Earlier quoted context omitted.

> It will operate as a subsidiary company based in Europe. That means it's 100% subject to European law, not American law. As a subsidiary company, does Amazon retain operational control over that branch? If so, it's subject to the CLOUD act, and therefore, not compatible with EU rules. > Amazon remains the owner and controls the technology, yes. So, basically, the answer is that the EU subsidiary is not independent.…

> If so, it's subject to the CLOUD act, and therefore, not compatible with EU rules. I'm assuming the CLOUD act is the entire reason why they're explicitly going with European-only staff. That way Amazon can honestly say it has no operational control to violate EU law because there's no American employee they can command. Operational control isn't all-or-nothing. European employees will do whatever Amazon tells them…

> Operational control isn't all-or-nothing.

When the US government has no issue asking a company to hand over its tls keys, it really is.

Re: AWS European Sovereign Cloud to be operated by EU citizens

#53
post #29

Earlier quoted context omitted.

Being "100% subject to European law" doesn't override the parent company's obligations under US law. At best, it creates a legal conflict where AWS must violate either US or EU law. Which one will the US parent company prioritize if/when faced with enforcement actions? The only way this would work is if the European operation were truly independent & separately owned, no corporate control from the US. But I don't thi…

> At best, it creates a legal conflict where AWS must violate either US or EU law. No, that's the whole point of this setup. Amazon will not be violating US law when its European subsidiary says no, we won't respond to your subpoena. It would be if Amazon USA owned the European data centers directly and employed American workers. But it will do neither. The US courts can't compel companies to do things they have no l…

Case in point: China. China forces foreign companies to run this setup all the time, and its one of the chief issues with outsourcing and IP property theft/transfer (depending how you look at it).

This is an arrangement which enormously benefits Europe because it's quite similar.

Re: AWS European Sovereign Cloud to be operated by EU citizens

#55

This sounds so weird. Is there a legal requirement for this? Does this offer any type of real protection? Or is there a code of conduct that that intelligence agencies never hire people with foreign nationalities?

The article does not explicitly say it, but it's clearly a defense against the CLOUD Act (https://en.wikipedia.org/wiki/CLOUD_Act); it all makes sense once you add that missing puzzle piece.

The CLOUD Act conflicts with EU laws like the GDPR (AFAIK, this has been confirmed more than once in EU courts already), which means that EU organizations (which have to follow the GDPR) might not be allowed to use USA-owned cloud services, even when the data is completely hosted within the EU, because the cloud service sysadmins might be forced through the CLOUD Act to break the GDPR. Requiring that all employees with a high level of access have EU citizenship and residency makes it much harder for a USA court to pressure them into breaking these EU laws.

Re: AWS European Sovereign Cloud to be operated by EU citizens

#56
post #51

Earlier quoted context omitted.

I know people (even members of my own family) who have resigned jobs because they felt the personal legal risk to themselves was excessive. In my experience, it is a much more common event at the C-suite level, where that risk is most acute, than at the level of individual contributors. If the company goes bankrupt, the ICs in accounting are unlikely to be personally found liable for the company’s debts - but if the…

Sure, then they replace them with someone with no such insight/scruples. They quit because the company wasn’t going to change ‘the orders’, yes? Eventually they found someone who would do what they were told without quitting, that is how this works.

Right, and then if the US parent company orders EU managers to violate EU law, and when the managers refuse, replaces them with EU managers stupid enough to obey an illegal order - then what happens? The new EU managers get arrested and possibly end up in prison. Worse case scenario for the US parent, is the US parent company is (civilly or criminally) prosecuted under EU (or member state) law for giving the illegal order, convicted, and then as punishment, they are deprived of their local assets, including ownership of the subsidiary in question.

The parent company is ultimately at greater risk than the subsidiary-the parent can be deprived of ownership of its subsidiary, there is no equivalent consequence for the subsidiary.

Re: AWS European Sovereign Cloud to be operated by EU citizens

#57
post #29

Earlier quoted context omitted.

Being "100% subject to European law" doesn't override the parent company's obligations under US law. At best, it creates a legal conflict where AWS must violate either US or EU law. Which one will the US parent company prioritize if/when faced with enforcement actions? The only way this would work is if the European operation were truly independent & separately owned, no corporate control from the US. But I don't thi…

> Being "100% subject to European law" doesn't override the parent company's obligations under US law. At best, it creates a legal conflict where AWS must violate either US or EU law. Which one will the US parent company prioritize if/when faced with enforcement actions? IANAL/etc, but the subsidiary and the parent are different people (legal personhood). The US parent is only responsible for the EU subsidiary’s acti…

> nobody with an appropriate background is going to apply

You don't need any “appropriate background” if you are going to be a one time tool to enforce an action.

And given the previous managers know that they have no power to stop the move anyway (because their replacement will comply) I doubt many would be willing to sacrifice their position just to keep the moral high ground.

Re: AWS European Sovereign Cloud to be operated by EU citizens

#58
post #46

Earlier quoted context omitted.

They generally don't when the boss is safely protected in another country, but you'll go to jail in your own country.

They do all the time . See every mining company, ever.

Or every restaurant, or construction company.

Re: AWS European Sovereign Cloud to be operated by EU citizens

#59
post #51

Earlier quoted context omitted.

Sure, then they replace them with someone with no such insight/scruples. They quit because the company wasn’t going to change ‘the orders’, yes? Eventually they found someone who would do what they were told without quitting, that is how this works.

Right, and then if the US parent company orders EU managers to violate EU law, and when the managers refuse, replaces them with EU managers stupid enough to obey an illegal order - then what happens? The new EU managers get arrested and possibly end up in prison. Worse case scenario for the US parent, is the US parent company is (civilly or criminally) prosecuted under EU (or member state) law for giving the illegal…

Assuming it ever gets detected, which certainly isn’t going to be common eh?

I’m not really sure the point of your comment, actually. Are you asserting that no one would ever tell someone to do anything illegal because someone else might get in trouble for it?

Because if so, you might want to read the news?

Re: AWS European Sovereign Cloud to be operated by EU citizens

#60
It's weird how people here react to the CLOUD Act. The CLOUD Act contains two provisions.

One provision relates to MLATs (mutual legal assistance treaties). An MLAT is an agreement between countries to cooperate on gathering and exchanging information to enforce laws. For example an MLAT might provide a way for police from one country to go to another country to interrogate a suspect who resides in that other country.

The CLOUD Act provided a way for the executive branch to enter into bi-lateral MLATs for data exchange as long as the Attorney General and the Secretary of State agreed that the foreign country had sufficient data access protections for data it received related to US citizens.

Before this entering into an MLAT was done the same way as any other treaty. The executive would negotiate the terms, then the President would sign, then the Senate would vote, and if 2/3s of the Senators voted to ratify the President could then ratify the treaty and exchange instruments of ratification with the other country. Only at that point did the MLAT actually go into effect.

This provision makes it much easier to enter into MLATs for data sharing and it can be done entirely by the executive branch. That's a massively lower barrier than requiring a 2/3 Senate vote.

It was this expansion of MLATs that drew most of the opposition to the CLOUD Act from several major civil rights groups.

Yet I almost never see this aspect of the CLOUD Act come up here. Nearly every time it comes up it is over the other provision.

The other provision said that if a warrant or subpoena asks a US company for data that it possesses or controls it had to provide that data regardless of where it actually is storing the data.

That's how it works for physical documents. For example if I'm in Los Angeles and own two physical documents, one of which is in my vacation house in Florida and the other in my vacation house in France, and a US court orders me to turn over those documents (or copies of them), I have to.

I won't be able to successfully resist by saying the one in France is outside the jurisdiction of the court. That's because the court is not asking France for the document, or trying to order anyone outside the US to do anything. It is ordering me to produce the document, which I can do simply by calling my French housekeeper and asking them to get the document and mail it to me.

Asking my French housekeeper to mail me a document I own from my French vacation house is something legal for me to do. I probably even routinely ship documents to and from France.

If you think about it, it pretty much has to work this other. Otherwise any company that wanted to hide anything from regulators could simply ship any possibly incriminating documents they have but cannot legally destroy to a document storage service in another country once they are no longer actively using them.

As far as I know this has never been controversial.

All the CLOUD Act provision on warrants and subpoenas does is say that digital documents work the same way physical documents do.

It is probably actually more important that digital documents work this way than it is for physical documents. With physical documents if I store them in another country they then it is a hassle if I ever need to work with them.

With digital documents it is easy to store everything in another country and instantly make a local copy when I need to work with a document, and when I'm done working save any changes back to the foreign storage and delete local copies.

I'm reasonably sure most other countries either have something equivalent to this part or they have laws that prevent companies in the country from storing documents outside the country. Otherwise it would be standard procedure for companies in the country to store all their digital data outside the country, ideally somewhere that does not have an MLAT with their home country. That way as long as they did nothing that drew the attention of regulators or law enforcement in that other country their documents would be out of reach of their home country regulators.

Post reply on HN