Live data from Hacker News

Netherlands blocks US takeover of vital digital supplier

politico.eu

181–190 of 246 posts

Re: Netherlands blocks US takeover of vital digital supplier

#181
post #5

Solvinity is a pretty terrible company name.

We're terrible at company and brand naming here in Europe. Just look at the "Wero" payment solution (formerly/currently iDeal). Like, who the hell came up with that stupid name? The list of stupid European company names and product names are endless.

It sounds a bit like "giro" which was a physical mail-based way of transferring money. Not a bad name at all.

Re: Netherlands blocks US takeover of vital digital supplier

#182
post #9

Good for them, but I doubt this will be the last we hear about this especially with the current US government. ASML was only permitted to acquire US company Cymer (the actually valuable EUV light source technology) back in 2013 under a strict technology sharing and export control agreement. The Netherlands blocking a US acquisition due to technology control concerns is sure to ruffle some feathers in Washington.

This is a huge detail that further complicates the picture, ASML's lithography technology heavily benefitted from United States DOE research:

> In 1997, ASML began studying a shift to using extreme ultraviolet. Two years later, it joined a consortium, which included Intel and two other U.S. chipmakers, in order to exploit fundamental research conducted by the US Department of Energy. Because the Cooperative Research and Development Agreement (CRADA) it operates under is funded by the US government, licensing must be approved by Congress.

Re: Netherlands blocks US takeover of vital digital supplier

#183
post #46
post #26

Earlier quoted context omitted.

It is a bit more complex tham that. Logius is the company that actually owns and manages the DigiD stack, it's just that they hired Solvinity for their expertise. AFAIK Solvinity can't access the data. I can't find it right now, but on Tweakers there was a long comment by someone on the inside that explained Logius basically had almost no know-how of how the current stack works, and there's lots of bespoke stuff. Bas…

How can you be sure that Solvinity can't access the data if Logius doesn't know how the current stack works? 5+ years to migrate sounds really bad.

Honestly they have good separation of concerns in the Dutch government. And running the stack doesn't automatically mean hosting the services, there's enough local expertise in the Netherlands to run that.

A few years ago I had the mispleasure of working for the island government of Bonaire, and they kinda run the same systems as they do in the mainland, being a sort of municipality.

Since all gemeentes in the Netherlands are basically independently run but have to communicate with each other for DigiD but also the GBA (ID system) and loads of other stuff, they invented a standard. It's a SOAP based monstrosity called StUF, and you better spell it like that.

I can't find much about StUF in English, but there is this about the succesor where they lament on how engrained StUF still is.

https://www.conduction.nl/commonground/

It wouldn't surprise me that migration to common ground is what they are refering too. StUF knowledge is not widespread due to the level of vendor lock in. There's not many vendors and outside GovIT nobody cares about StUF.

Re: Netherlands blocks US takeover of vital digital supplier

#184
post #116

The concerning thing for the EU should be that this valuable firm had no European capital trying to buy it. The Dutch have protected their sovereignty today while decreasing the incentive for the next entrepreneur to make something on European shores. Probably the best choice but doesn't change the structural problem.

> Probably the best choice but doesn't change the structural problem.

The structural problem is that we are destroying trading relationships built with Europe over generations.

Re: Netherlands blocks US takeover of vital digital supplier

#187
post #116

The concerning thing for the EU should be that this valuable firm had no European capital trying to buy it. The Dutch have protected their sovereignty today while decreasing the incentive for the next entrepreneur to make something on European shores. Probably the best choice but doesn't change the structural problem.

There was a Dutch bid apparently, but a few million less than Kyndryl. And even the Dutch govt was asked to bid or something IIRC but said no at the time, before there was a shitstorm in the Netherlands over this.

Re: Netherlands blocks US takeover of vital digital supplier

#188
post #3

Finally! The entire country has been clamouring for this for weeks, and the government has been completely silent about it. A couple of weeks ago, the entire parliament (with only a single party dissenting) voted for a motion to end the contract with Solvinity, but the government extended it anyway, leaving blocking the takeover as the only option, and there wasn't a lot of confidence that the government would do tha…

> With the US law that the US government should be able to get access to any data held by a US company Er, what law is this, exactly?

it is not easy with a quick search to ascertain the subtleties of the CLOUD Act.

the example case on wikipedia entails a US citizen storing data with Microsoft, a US company, data that Microsoft offshored from the US. So in that case, the US Courts and politicians seem on pretty firm ground to consider that data to be "obtainable" by court order; it wouldn't make sense for American vendors to to create a privacy "double Dutch sandwich" as is done with corporate income tax loopholes. Letting the law go that far would not be a threat to "Europe".

Now if Europeans were committing crimes in the US without being in the US themselves (let's say organized crime trafficking to the US or operating phone scams) that raises more interesting questions about jurisdictions, but that discussion is only productive with good knowledge of what US-European cooperation is already in place or considered "within the pale" due to shared mutual concerns

According to wikpedia, "the CLOUD Act asserts that U.S. data and communication companies must provide stored data for a customer or subscriber on any server they own and operate when requested by warrant, but provides mechanisms for the companies or the courts to reject or challenge these if they believe the request violates the privacy rights of the foreign country the data is stored in."

It could "scare" Europeans to read that, but an important keyword is "requested by a warrant": to be scared by it, you'd need to know that US Courts are issuing warrants for Europeans who are not committing crimes in the US, which I doubt. Europeans committing crimes I already touched on.

wikipedia continues, It also provides an alternative and expedited route to MLATs through "executive agreements"; the executive branch is given the ability to enter into bi-lateral agreements with foreign countries to provide requested data related to its citizens in a streamlined manner, as long as the Attorney General, with concurrence of the Secretary of State, agree that the foreign country has sufficient protections in place to restrict access to data related to United States citizens.[8][9] The first such agreement was with the United Kingdom.[10] There is a FAQ appended to the white paper published by the U.S. Department of Justice.

This aspect of the CLOUD act should not specifically scare Europeans, they should rather be scared of their own governments cooperating in such schemes. For Europeans to want the US not to have the CLOUD act to protect them from their own governments is rational, but not something that can be discussed, it would melt European brains to say anything positive about the US.

wikipedia goes into more interesting areas for US/Euro conflict (for example, who would be covered by the GDPR for the information that the CLOUD act covers) which is interesting but I'm less equipped to discuss that than the preceding. here is the link you can chase down if you want https://en.wikipedia.org/wiki/CLOUD_Act#International_reacti... https://en.wikipedia.org/wiki/CLOUD_Act#International_reacti...

Re: Netherlands blocks US takeover of vital digital supplier

#189
post #175
post #170

Earlier quoted context omitted.

> The only real solution is cryptographic sovereignty systems where even the vendor mathematically cannot access user data, regardless of what US law says. ...OR, we host our data in our own countries with companies incorporated in our countries. (Sovereign cloud)

This misses the point that parent was making. The conversation shouldn’t be “move your data to countries you can trust”. It should be “use protocols that don’t require trust in the first place”.

I think both ideas should be the norm: privacy by architecture and sovereignty and/or decentralization where it makes sense.

Re: Netherlands blocks US takeover of vital digital supplier

#190

Earlier quoted context omitted.

As per the Dutch language saying: "Trust comes on foot, but leaves on horseback." Trust breakdowns are costly, except to the vultures "winning" the negative-sum game. Might want to read about the fall of the Warsaw pact.

> As per the Dutch language saying: "Trust comes on foot, but leaves on horseback." So it took your horse? Better stop trust from ever coming then.

It means trust builds slowly but can be lost rapidly. It's not about horse theft.
Post reply on HN