Live data from Hacker News

Norwegian backup provider promises NSA-free data storage using Norwegian laws

jottacloud.com

41–50 of 125 posts

Re: Norwegian backup provider promises NSA-free data storage using Norwegian laws

#41
As a Norwegian, let me just say:

Yeah, right.

1. The Norwegian security services have a long history of violating Norwegian law (and when, for example, extensive illegal politically motivated surveillance of mostly left wing politicians was uncovered in the 90's they then had the gall to place an MP and member of the committee investigating them under surveillance while he was working on the report about their illegal surveillance), and have always been extremely cosy with the US.

2. Most bandwidth to Norway goes via Sweden. Sweden is not a safe country to pass data through if you want to avoid surveillance. See the FRA law: http://en.wikipedia.org/wiki/FRA_law ; unless they guarantee that they get their bandwidth via alternative means, this is a risk. Sure, you can encrypt the data, but if you trust that this is sufficient, then hosting your backups in the US should not a problem either. If you think Sweden's neutrality means a shit in this case, consider that Sweden has admitted to having been complicit with renditions of political asylum seekers to the CIA in direct violation of Swedish laws, so clearly they do not worry about cooperating with US intelligence agencies. To hand your data over to the NSA would not even require them to break any laws, and they've already demonstrated they don't have the moral backbone to stand up to far worse requests.

3. Norway is subject to the EU data retention regulations, and otherwise likes to bend over backwards to comply with EU directives despite not being an EU member (we're a member of the EEA, which means we get all the directives, but don't have a say - how anyone thought that was a better alternative is beyond me). In fact, Norway is "best in class" when it comes to implement EU directives - ahead of most EU countries... This doesn't impact this to a great extent, except it means all your communications with this company will be subject to retention laws, and if you consider it important enough to avoid the reach of the NSA for your hopefully encrypted backup data, this is worth keeping in mind too.

In other words: If you encrypt your communications and backup files well enough that you believe it is safe from the NSA in Norway, they'll likely be just as safe from the NSA in the US.

Re: Norwegian backup provider promises NSA-free data storage using Norwegian laws

#42
post #26

Earlier quoted context omitted.

The law that might force you to reveal the key depends on where you are, not where your hoster is.

Good luck, I have terabytes of random data. I can always provide you OTP key, and create what ever content I want you to see. (Malleable encryption)

Stay away from the UK - here a judge can throw you in jail for failure to provide keys, even if there's no evidence you still have the keys, and said judge would pretty much be guaranteed to believe that you did not hand over the correct keys if the result is garbage.

Re: Norwegian backup provider promises NSA-free data storage using Norwegian laws

#43
post #38
post #19

Earlier quoted context omitted.

(the now deleted parent wrote that the Data Retention Directive is an EU directive and that Norway is not part of the EU) That doesn't seem to stop them. 2nd paragraph of the translated WP article: In Norway DLD was adopted by the Parliament on 4 April 2011 . It was scheduled to take effect on 1 April 2012, but has been postponed several times. Ministry of Transport are now looking for that storage requirement comes…

Norway gets to implement many EU directives, thanks to being part of the European Economic Area.

In fact we usually implement them quicker than most EU countries.

Re: Norwegian backup provider promises NSA-free data storage using Norwegian laws

#44
post #41

As a Norwegian, let me just say: Yeah, right. 1. The Norwegian security services have a long history of violating Norwegian law (and when, for example, extensive illegal politically motivated surveillance of mostly left wing politicians was uncovered in the 90's they then had the gall to place an MP and member of the committee investigating them under surveillance while he was working on the report about their illega…

Well, what you say is not correct. First of all the Data Retention Directive have to be valid for you. I work for the Norwegian email provider Runbox and the EU Data Retention Directive is not applicable for us. It is only valid for carriers that own their own infrastructure down to the data center, called "communication providers". We even have it confirmed by both Kripos (FBI-ish) and Post- og Teletilsynet (Norwegian Post and Telecommunication Authority). We have tried to explain a bit why here: http://www.runbox.com/why-runbox/email-privacy-offshore-emai...

Re: Norwegian backup provider promises NSA-free data storage using Norwegian laws

#45
post #2

I'm moving away from Dropbox today. Thanks for this jensen2k.

If you crypt, Dropbox is fine. People need to use encryption. Every popular computer language has encryption routines, scroll through the source code until you find something accessible, twiddle something to personalize it while keeping it functional, perhaps convince yourself it will remain secure, etc, of course be cautious about that. Or simply, there's double encryption, fold it again. Know big 100 meg, gigabyte file size encryption, becomes vulnerable. Wikipedia is the best general crypto introduction I've see.

Re: Norwegian backup provider promises NSA-free data storage using Norwegian laws

#46
post #41

As a Norwegian, let me just say: Yeah, right. 1. The Norwegian security services have a long history of violating Norwegian law (and when, for example, extensive illegal politically motivated surveillance of mostly left wing politicians was uncovered in the 90's they then had the gall to place an MP and member of the committee investigating them under surveillance while he was working on the report about their illega…

Is there a jurisdiction on the planet where data is safe from domestic wiretapping [1] (i.e. international espionage not withstanding)?

Serious question.

1. Clarification: I mean warrantless wiretapping.

Re: Norwegian backup provider promises NSA-free data storage using Norwegian laws

#47
post #44
post #41

As a Norwegian, let me just say: Yeah, right. 1. The Norwegian security services have a long history of violating Norwegian law (and when, for example, extensive illegal politically motivated surveillance of mostly left wing politicians was uncovered in the 90's they then had the gall to place an MP and member of the committee investigating them under surveillance while he was working on the report about their illega…

Well, what you say is not correct. First of all the Data Retention Directive have to be valid for you. I work for the Norwegian email provider Runbox and the EU Data Retention Directive is not applicable for us. It is only valid for carriers that own their own infrastructure down to the data center, called "communication providers". We even have it confirmed by both Kripos (FBI-ish) and Post- og Teletilsynet (Norwegi…

And you don't believe your data passes through a "communications provider"?

By the argumentation on your page, almost none of the electronic data targeted by the data retention directive would in fact be retained if the directive is not also applied to data that merely transit a providers network, given that the vast majority of e-mail addresses in use today are not hosted by "communications providers". If that is indeed an actual loophole, it will be closed quickly if/when everyone realizes that they're not getting the data they expect.

This is in any case a minor point, as in terms of dealing with backup data, it's the two first points of my message that are by far the most serious. And I don't think they're that serious, in that I don't really believe there are any suitable alternatives that are safe enough that you can prevent surveillance based on location, so you'll depend on the crypto, and the combination of the two makes the location of the data rather moot.

Re: Norwegian backup provider promises NSA-free data storage using Norwegian laws

#48
post #33
post #2

I'm moving away from Dropbox today. Thanks for this jensen2k.

For me though, no linux support :(

I run linux into Dropbox. It's tedious having to manually select/enter files without the dragging the others get. There's language Dropbox API modules that automate this too.

Re: Norwegian backup provider promises NSA-free data storage using Norwegian laws

#49
post #40

"In Norway, privacy stands firm like the mighty mountains of Jotunheimen.". Let's not flatter ourselves too much: http://no.wikipedia.org/wiki/Datalagringsdirektivet (in Norwegian, http://translate.google.com/translate?sl=auto&tl=en&js=n&pre... ), or the less detailed http://en.wikipedia.org/wiki/Data_Retention_Directive

I don't think DLD/DRD is conflicting with the statements given in the post, as DLD only concerns itself with metadata (and yes, that can be harmful), and the article talks about the actual data. Both are important, but different, topics.

I was more objecting the very marketing-y-and-not-very-truthy quote.

That said, digging a bit more into Jottacloud does not make me any more likely to use the service, for anything I would be concerned to store at, say, Dropbox:

Their FAQ is (intentionally?) vague. How do they encrypt stuff?

"all datatraffic between your computer and Jottacloud is encrypted with 256 bits AES high grade encryption, which makes it virtually impossible for unauthorized persons to use the information being sent.".

And then:

"If you log into www.jottacloud.com it’s possible to download, view pictures and share files with friends and colleagues"

Right, so they would have the keys anyway.

Re: Norwegian backup provider promises NSA-free data storage using Norwegian laws

#50
post #19
post #17

Earlier quoted context omitted.

[deleted]

(the now deleted parent wrote that the Data Retention Directive is an EU directive and that Norway is not part of the EU) That doesn't seem to stop them. 2nd paragraph of the translated WP article: In Norway DLD was adopted by the Parliament on 4 April 2011 . It was scheduled to take effect on 1 April 2012, but has been postponed several times. Ministry of Transport are now looking for that storage requirement comes…

Datalagringsdirektivet is not applicable for most providers in Norway, only the big carriers like Telenor, Telia-Sonera/Netcom and Tele2. The practical rule is that if you have a ASN-number (Data Center) and you provide the relevant services, then you need to follow it. The email service I work for, Runbox, is not. Probably not Jotta either.
Post reply on HN