Live data from Hacker News

European Parliament Up In Arms Over PRISM

slate.com

21–30 of 41 posts

Re: European Parliament Up In Arms Over PRISM

#21
post #4

It'll be interesting to see what happens to those global (US-based) cloud providers whose business strategy of poor profit margins in exchange for reduced costs of sale fair after this PR catastrophe. When it comes to the economics of this, the US is going to lose a huge amount of business due to this and potentially could in theory cause several businesses to go bankrupt. Since, government's are naturally fiscally m…

..it already is. E.g. german companies with a data protection comissioners/officers usually don't store data outside EU coutries, since the data protection level is considered to be to low. §4b Abs.2 S.2 Bundesdatenschutzgesetz prohibits conveyance of personal data outside EU borders if the interest of persons concerned outweighs it (mostly it does). This PRISM-surveillance substantiates those concerns.

My startup has faced this issue -- but it's easily solved using American cloud providers (for example: AWS Ireland).

But, frankly, I don't know how Amazon would respond if they received a national security letter asking for data hosted by Amazon in Ireland.

It'd be nice to see a country take a very strong stand on data privacy. They could be to hosting servers what Switzerland is to hosting money.

Re: European Parliament Up In Arms Over PRISM

#22
post #15

Earlier quoted context omitted.

It seems the EU has better privacy laws, but it would be foolish to think that there isn't any surveillance and spying being done here.

They don't in the slightest. Check out Sweden's FRA laws. They're even more invasive than PRISM.

In school I've been taught that companies (and government entities?) are not allowed to keep your private information stored unless they have a valid reason for keeping it, and if they do, then you're allowed to know what they're storing and have the right to ask them to delete the data.

I remember reading an article that was posted here on HN about someone demanding Facebook to reveal the personal information they were storing of him, because IIRC, one of Facebook's servers is located in Europe, so they had to abide by EU's privacy laws. He eventually got a CD containing his personal info. It contained very limited data and not as much as I believe that they would have collected, but it shows that companies in Europe have to follow these laws.

Re: European Parliament Up In Arms Over PRISM

#23
post #6
post #3

As a someone from Europe (Germany), I can say that this whole affair is definitely a public relations disaster for the US over here. In the beginning, I was really unsure if regular people who are not members of the tech community would become aware of this or if it was perceived as to much of a niche topic. Well, I guess that question has been answered: Yesterday tagesschau[1], the biggest and most trusted evening t…

It will be interesting to see the real effects though. How long will people remember about this? How much will it affect their actual choices? The US "brand" overcame so many scandals, I'm not sure this one will be different.

You bring up an interesting point. I would describe the effect of revelations of this kind on people in Germany as a noticeable jump in one direction on a sentiment continuum, if that makes any sense.

The generation of currently 25 to 40 year olds here have grown up in an extremely US-influenced cultural environment. Imagine that there is this magically interesting and quite progressive place on earth and they broadcast from there on all TV channels all the time. That's what it was like to grow up in the 90s in Germany.

Having grown up with a generally positive view of the US, the Iraq war was a decisive turning point for many people of that (i.e., my) generation. By the time Colin Powell presented his case before the UN, many Germans started to feel betrayed, because it seemed so obvious that an invasion was not the right thing to do (the GOOD GUY became a mere mortal). Older people that were familiar with the political games of the cold war might not have been surprised, but the young people definitely were. Since then for many Germans, the attitude towards the US is quite ambivalent. It is possible that this in some situations leads to unfair highlighting of wrongdoing on part of the US, but I'd say that by and large the effect is primarily that there is now interest in good news and bad news about the US.

Add to that, that many Germans feel extremely uneasy about intelligence gathering in general (think STASI), and you have a reason to assume that, at least in Germany, this thing will linger in the hearts and minds for a while.

It has to be noted, however, that this also means that the reaction in Germany cannot be generalized to the rest of Europe.

Re: European Parliament Up In Arms Over PRISM

#24
post #4

It'll be interesting to see what happens to those global (US-based) cloud providers whose business strategy of poor profit margins in exchange for reduced costs of sale fair after this PR catastrophe. When it comes to the economics of this, the US is going to lose a huge amount of business due to this and potentially could in theory cause several businesses to go bankrupt. Since, government's are naturally fiscally m…

I used to work for AWS and currently work for another large cloud computing company, and the words NSA and PRISM haven't been mentioned once in any of our companywide meetings this week. I think the HN echo chamber is hyping this up more than the rest of the real corporate world. Large companies who want to move to the cloud already know the risks/rewards of hosting their data via offsite 3rd party companies. They ar…

Well, I work at a company that leverages cloud technology, and it's been the topic on more than a few occasions.

Re: European Parliament Up In Arms Over PRISM

#26

Earlier quoted context omitted.

..it already is. E.g. german companies with a data protection comissioners/officers usually don't store data outside EU coutries, since the data protection level is considered to be to low. §4b Abs.2 S.2 Bundesdatenschutzgesetz prohibits conveyance of personal data outside EU borders if the interest of persons concerned outweighs it (mostly it does). This PRISM-surveillance substantiates those concerns.

My startup has faced this issue -- but it's easily solved using American cloud providers (for example: AWS Ireland). But, frankly, I don't know how Amazon would respond if they received a national security letter asking for data hosted by Amazon in Ireland. It'd be nice to see a country take a very strong stand on data privacy. They could be to hosting servers what Switzerland is to hosting money.

There are MLA, mutual legal assistance, which needs certain proof, and aim usually for foreign companies with data of interest to the US.

Servers from companies with a US-based headquarter belong to our new overlord, the US gov. and can be owned with a FISA-warrant (Foreign Intelligence Surveillance Act – FISA 1978/2008) garnished with a National Security Letter (NSL).

We know that procedures from Microsoft U.K. head: http://www.zdnet.com/blog/igeneration/microsoft-admits-patri...

Re: European Parliament Up In Arms Over PRISM

#27

Earlier quoted context omitted.

I used to work for AWS and currently work for another large cloud computing company, and the words NSA and PRISM haven't been mentioned once in any of our companywide meetings this week. I think the HN echo chamber is hyping this up more than the rest of the real corporate world. Large companies who want to move to the cloud already know the risks/rewards of hosting their data via offsite 3rd party companies. They ar…

I work in information security for a large international corporation, and I can add another anecdote to back up yours. We've discussed the news informally as a curiosity, but there's no business drive to really do anything about it. We're not trying to hide our business operations from the government, we're trying to hide them from our competitors. You're absolutely correct that businesses care about security from ci…

Well, if you were a large enough non-US company, and you had large US competitors - especially defense contractors - you would think differently. You would think about Echelon and industrial espionage. But I expect those kinds of companies not using foreign IT services already.

Re: European Parliament Up In Arms Over PRISM

#28

Earlier quoted context omitted.

..it already is. E.g. german companies with a data protection comissioners/officers usually don't store data outside EU coutries, since the data protection level is considered to be to low. §4b Abs.2 S.2 Bundesdatenschutzgesetz prohibits conveyance of personal data outside EU borders if the interest of persons concerned outweighs it (mostly it does). This PRISM-surveillance substantiates those concerns.

My startup has faced this issue -- but it's easily solved using American cloud providers (for example: AWS Ireland). But, frankly, I don't know how Amazon would respond if they received a national security letter asking for data hosted by Amazon in Ireland. It'd be nice to see a country take a very strong stand on data privacy. They could be to hosting servers what Switzerland is to hosting money.

If Amazon does their accounting the same way as Google/Facebook, then Amazon Ireland is likely their international HQ, and technically a different company than Amazon US. (For tax reasons; Ireland has a much lower corporate tax rate than the US)

And so I would really expect them to follow Irish, not US, law.

Re: European Parliament Up In Arms Over PRISM

#29
post #15

Earlier quoted context omitted.

They don't in the slightest. Check out Sweden's FRA laws. They're even more invasive than PRISM.

In school I've been taught that companies (and government entities?) are not allowed to keep your private information stored unless they have a valid reason for keeping it, and if they do, then you're allowed to know what they're storing and have the right to ask them to delete the data. I remember reading an article that was posted here on HN about someone demanding Facebook to reveal the personal information they w…

I guess I suppose that by privacy laws you meant something different than simply the ability to be given the information collected about you. I was also coming at it from a governmental aspect versus private as well.

Re: European Parliament Up In Arms Over PRISM

#30
post #6

Earlier quoted context omitted.

It will be interesting to see the real effects though. How long will people remember about this? How much will it affect their actual choices? The US "brand" overcame so many scandals, I'm not sure this one will be different.

You bring up an interesting point. I would describe the effect of revelations of this kind on people in Germany as a noticeable jump in one direction on a sentiment continuum, if that makes any sense. The generation of currently 25 to 40 year olds here have grown up in an extremely US-influenced cultural environment. Imagine that there is this magically interesting and quite progressive place on earth and they broadc…

What you said could mostly be said about Italy too. Except for the STASI, of course :)
Post reply on HN