Live data from Hacker News

Microsoft Can't Keep EU Data Safe from US Authorities

forbes.com

11–20 of 136 posts

Re: Microsoft Can't Keep EU Data Safe from US Authorities

#11

Time to pull away all EU data from the Trump USA.

I think many already started, the only reason it's starting to appear in the news is because people are making progress with the moves, and US companies are noticing it, but it's been planned and organized for a lot longer than just the last year.

Re: Microsoft Can't Keep EU Data Safe from US Authorities

#14
post #9

Earlier quoted context omitted.

If the data center is operated by a "trusted subsidiary" as the article mentions and everyone in key roles is a French citizen with no connection to the US then there is no one to give a gag order. In practice the US HQ could mandate a security update that secretly uploads all data to the US but that's a whole other can of worms that I don't think anyone is ready to open.

the data center which runs software written and controlled by the US companies and likely has a 24/7 software related support team which is distributed across the world.... in a modern cloud dater center you don't need someone physically plugging a USB stick in a server, you just need a back door in a cloud software stack many times the size then any modern operating system which often even involves custom firmware f…

... a backdoor that is a necessity anyway, because it is constantly used to upgrade the cluster software.

Re: Microsoft Can't Keep EU Data Safe from US Authorities

#15
post #7

Earlier quoted context omitted.

Specifically here, he is under oath in France so an American gag order wouldn't protect him from the French justice system. This make it less likely he's lying. It could be possible Microsoft France has a "rogue" employee system where a key person only obeys to Microsoft US orders rather than his French boss and French law. Then the boss can swear to the Senate that they're complying. This is exactly the system the U…

Until this happened MS was still going around trying to convince lawyers to use their Cloud and telling them that there is no issue. Including certain contractual "standard"(1) agreements which would make some of their higher management _personally_ liable for undue data access even under Cloud act from the US!!! (1) As in standard agreements for providers which store lawyer data, including highly sensitive details a…

The max penalty for things like this is actually life inprisonment though. If you, to aid a foreign power without authorization gather certain types of information, it's espionage.

There wouldn't be any lawsuit. If you do this kind of things you get arrested, get a trial and then you are in prison forever.

Re: Microsoft Can't Keep EU Data Safe from US Authorities

#16
An inevitable consequence of this administration destroying US foreign influence and power at an unprecedented rate is that (IMHO) it is inevitable that the EU builds their own cloud and mandates its use for EU data. It is becoming a matter of national security.

The interesting thing is that the US is acting in the exact way that they accuse China of acting. Companies like Huawei are forbidden from installing telecom infrastructure for "national security" reasons [1]. One of justifications for first banning then forcing a sale of Tiktok was because of possible Chinese government interference. It's only a matter of time before the EU and China start making the same determination against US tech giants (eg Meta executive brags about silencing dissent [2]).

This administration really is killing the golden goose.

[1]: https://www.reuters.com/business/media-telecom/us-fcc-bans-e...

[2]: https://www.youtube.com/watch?v=7eO8byuv6PE

Re: Microsoft Can't Keep EU Data Safe from US Authorities

#17

I wouldn't think "sovereign" EU data would be protected from US snooping either, unless the Five Eyes Plus alliance is going to be dissolved. Even then...

Well, not relying on US cloud would already be a giant step in the right direction, by making it significantly harder to snoop on the data.

Re: Microsoft Can't Keep EU Data Safe from US Authorities

#18
I can't imagine the Cloud Act being effective without Microsoft (and French gov) complicity.

If they can make successful tax shelters they can architect the entities and the architecture to remove this option.

There's some 9-eyes thing where this is a feature not a bug

Re: Microsoft Can't Keep EU Data Safe from US Authorities

#19
post #17

I wouldn't think "sovereign" EU data would be protected from US snooping either, unless the Five Eyes Plus alliance is going to be dissolved. Even then...

Well, not relying on US cloud would already be a giant step in the right direction, by making it significantly harder to snoop on the data.

I don't believe that's the case because the intelligence pooling is meant to remove cross-border friction. A general breakdown of western alliances would probably be required (and maybe that's where we're headed.)
Post reply on HN