Live data from Hacker News

Did Obama Just Destroy the U.S. Internet Industry?

linkedin.com

101–110 of 291 posts

Re: Did Obama Just Destroy the U.S. Internet Industry?

#101
post #40

This is a huge deal. I live in Australia and I have been running businesses on the cloud for the last 3 years or so. I have rarely heard the issue of the PATRIOT Act raised and in spite of there being laws banning the transfer of personal data outside Australia, most people are quite lax about the issue and take the view that the risks are too small to be counted. Those days are most certainly over. This stuff will a…

My latest startup is Efficito (a Limited Company, registered in the UK). The web site is http://www.efficito.com and our servers are all in Europe. We have built the service up with a very careful eye for security (why we are going hosted cloud first, and multi-tenant is still in the works).

You have just given me what I think is a very good possibility regarding a marketing message, namely that we are not subject to NSA orders, and that we take security extraordinarily seriously. We are still looking into whole disk encryption for virtual instances, but key management is a non-trivial problem there to get right. For those who want it I can be pretty sure we'd be happy to work with you to find a way of making the system meet your needs. (Of course given a few customers, we could work with a server in Australia too.)

But I also think it goes beyond shipping the data overseas. Suppose you do business with an American company that has servers in Australia (for the record we are registered in the UK, not the US), and they get a FISA warrant? Of course they will send the info over. So you can't only look at where the business's servers are but also where what legal authorities they are obviously subject to.

Re: Did Obama Just Destroy the U.S. Internet Industry?

#102

It's odd, I hear people saying, "no big deal, nothing will change." But then I wonder, if you're saying it's no big deal, are you an American or not? The point of this pst is that foreign business will be affected, AFAICT, Europeans have always held the Internet to a stricter standard than Americans and have passed stricter laws around everything from what data can be retained to the behaviour of tracking cookies. If…

The point of this pst is that foreign business will be affected, AFAICT, Europeans have always held the Internet to a stricter standard than Americans and have passed stricter laws around everything from what data can be retained to the behaviour of tracking cookies.

I run businesses in the UK that deal with personal data and sometimes use US companies to do so.

There is a specific provision intended to fix the problem of exporting personal data outside the EEA to be processed in the US, which would otherwise be prohibited because US laws are inadequate in this area: the US Department of Commerce operates a Safe Harbor scheme, recognised by the European authorities, which US businesses can participate in to demonstrate that they handle data with sufficient care to satisfy European standards.

The problem is that if the US government is going to permit itself to access data contrary to the claimed protections anyway, then the Safe Harbor scheme is demonstrably unfit for purpose, and any legal shield it provides to European businesses that want to use US-based services to process personal data is in doubt.

This problem is hardly a new discovery, but until recently, the issue was being dealt with quietly, with European officials making occasional mutterings about being in contact with the US government to resolve the conflict here. As of the past week, I'm not sure that's going to carry much weight any more.

This leaves a paradoxical position for any business wanting to operate legally in both the US and Europe. It's not clear whether the huge players like Google or Facebook could avoid the problem by changing their corporate structures, if doing so means that a parent organisation in the US would not be required to disclose personal data held and processed only in Europe by a separate European legal entity under European data protection law. In practice, this might be worse news for US businesses that aren't yet big enough to play the corporate structures lottery, and for those European companies who benefit from services provided by such companies and might have to make other plans. Obviously quite a few smaller Internet services well known on HN would fall into that category.

If you'd asked me a year ago how the paradox would be resolved, I would probably have cynically suggested that the EU authorities would ask how high when the US authorities told them to jump, as they have done previously with things like travel and banking data. But now that this has become a major public issue that people are actually talking about, any attempt to do that seems likely to turn out very badly for European authorities whose popularity is already at an all-time low. I suspect far more Europeans resent the constant privacy intrusions and security theatre of modern life than many across the Atlantic may realise, probably because the consequences of excessive state surveillance are still within living memory in many European countries, and because all around the Med we've been watching timely reminders playing out over the past 2-3 years.

Re: Did Obama Just Destroy the U.S. Internet Industry?

#103

One biggie that the author left out of the piece: The US Gov continues to insist that they are not monitoring the data of US citizens because that would be unconstitutional without warrants. But that's a tacit admission that they are openly monitoring the data of non-US citizens. I think this is one of the most important revelations of this leak, the US Gov has made it clear that if you are a non US citizen using a w…

They'll be doing something like the old Echelon trick. US spy agencies can't spy on Americans, so they spy on Australians, Canadians and Britons. In return, Australians spy on Americans, Britons on Canadians etc etc. Then they swap intelligence and get to claim that "we didn't spy, it was given to us by our allies who are under no such regulations".

There's still a major limit there. The issue of the Verizon and PRISM systems is that they probably involve the possibility at least of legal authority over the vendors. Court orders or possibilities of court orders....

If the NSA is spying on Australians clandestinely, then they don't have that authority and they are limited to what they can scavange. It would be far better if we were to a point where no courts would coerce cooperation of this sort, and the system you are describing is better than what we have. The problem is when the NSA gets a court to forcibly deputize an American business to spy on Australians, and that's a very, very different problem.

Re: Did Obama Just Destroy the U.S. Internet Industry?

#104
One of the rather interesting side issues in this whole debate has been how casually the rights of foreigners are tossed aside as secondary to those of american citizens. There is intense debate about whether US citizens rights are being violated, but almost nobody questions whether there's any moral or ethical issue with completely unrestrained spying on everybody else.

While I understand that this is largely because the legality of the spying hinges on whether US citizens are subject to it, I still find it a rather fascinating aspect.

Re: Did Obama Just Destroy the U.S. Internet Industry?

#105
post #40

This is a huge deal. I live in Australia and I have been running businesses on the cloud for the last 3 years or so. I have rarely heard the issue of the PATRIOT Act raised and in spite of there being laws banning the transfer of personal data outside Australia, most people are quite lax about the issue and take the view that the risks are too small to be counted. Those days are most certainly over. This stuff will a…

My latest startup is Efficito (a Limited Company, registered in the UK). The web site is http://www.efficito.com and our servers are all in Europe. We have built the service up with a very careful eye for security (why we are going hosted cloud first, and multi-tenant is still in the works). You have just given me what I think is a very good possibility regarding a marketing message, namely that we are not subject to…

You have just given me what I think is a very good possibility regarding a marketing message, namely that we are not subject to NSA orders, and that we take security extraordinarily seriously.

You certainly won't be the first with that idea. I've now lost count of how many blog posts, tweets, forum posts and so on I've seen in the past week that essentially say, "Is the next big selling point for European service companies that we're not subject to US laws?"

Re: Did Obama Just Destroy the U.S. Internet Industry?

#106
While I actually hope that the predictions in this article come true, as people should not put their data at risk by allowing it to pass through the US at this point, I am pessimistic that anything will change. I was sure that seizure of overseas internet poker domains, on the basis that .com domains are controlled by an American organization, would have been enough to drastically reduce .com registrations. That didn't happen. People have a tendency not to care about things until it directly smacks them in the face, and then it's too late.

Re: Did Obama Just Destroy the U.S. Internet Industry?

#107

Earlier quoted context omitted.

In the same way that Americans are in a stronger position vs NSA snooping Australians are in a stronger position vs our own snooping.

As I noted elsewhere in the thread, Echelon taught us that the agencies can circumvent these protections by agreeing to spy on each other's citizens and then forward the intelligence.

The idea that would be just as subject to surveillance using Australian hosted servers is pure speculation and not supported by the so far leaked information on PRISM.

Re: Did Obama Just Destroy the U.S. Internet Industry?

#108
post #40

This is a huge deal. I live in Australia and I have been running businesses on the cloud for the last 3 years or so. I have rarely heard the issue of the PATRIOT Act raised and in spite of there being laws banning the transfer of personal data outside Australia, most people are quite lax about the issue and take the view that the risks are too small to be counted. Those days are most certainly over. This stuff will a…

My latest startup is Efficito (a Limited Company, registered in the UK). The web site is http://www.efficito.com and our servers are all in Europe. We have built the service up with a very careful eye for security (why we are going hosted cloud first, and multi-tenant is still in the works). You have just given me what I think is a very good possibility regarding a marketing message, namely that we are not subject to…

The UK has quite a strong military sector with their own secret agencies and a strong relationship with America.

Could that make them capable of similar monitoring? Does the UK have stronger information privacy laws that the US doesn't?

Re: Did Obama Just Destroy the U.S. Internet Industry?

#109
post #108

Earlier quoted context omitted.

My latest startup is Efficito (a Limited Company, registered in the UK). The web site is http://www.efficito.com and our servers are all in Europe. We have built the service up with a very careful eye for security (why we are going hosted cloud first, and multi-tenant is still in the works). You have just given me what I think is a very good possibility regarding a marketing message, namely that we are not subject to…

The UK has quite a strong military sector with their own secret agencies and a strong relationship with America. Could that make them capable of similar monitoring? Does the UK have stronger information privacy laws that the US doesn't?

The laws are build on different principles making them somewhat different. However, one of the things that we pay a lot of attention to is security resilience. The question is, "what has to be compromised before your data is compromised? and is there a way to detect it?" The storage is still something we are working on but you can believe it is a design goal.

The EU has very different approaches again to privacy law. I don't know you can compare them. They tend to be more lax with collection and stronger with use.

However, we can also help you install the software (open source, reviewed by developers all over the world) on your premises if you would prefer. So our best shot is only for those who really want to cloud host.

Re: Did Obama Just Destroy the U.S. Internet Industry?

#110
post #87
post #75

Earlier quoted context omitted.

Good luck. I don't see other countries innovating at even half the rate of the U.S. with tech stuff. Leaving the umbrella will be like turning out the lights. It gets boring and cold in the dark after a while.

That's possibly because of a few advantages that US companies had due to quicker exposure to leading edge technology. However, when privacy becomes a unique selling point that US corporations can no longer provide - suddenly the competition will see a reason to appear. I'm on the lookout for reasonably good Google apps alternatives, if they don't exist right now - this is a time that a solid market just got created.…

Agreed. I see this as being a catalyst for the creation of greater competition to the US internet incumbents. There will likely not be an immediate impact for Google et al. but there will be much longer term consequences I think.
Post reply on HN