Live data from Hacker News

Norwegian backup provider promises NSA-free data storage using Norwegian laws

jottacloud.com

81–90 of 125 posts

Re: Norwegian backup provider promises NSA-free data storage using Norwegian laws

#81
post #45
post #2

I'm moving away from Dropbox today. Thanks for this jensen2k.

If you crypt, Dropbox is fine. People need to use encryption. Every popular computer language has encryption routines, scroll through the source code until you find something accessible, twiddle something to personalize it while keeping it functional, perhaps convince yourself it will remain secure, etc, of course be cautious about that. Or simply, there's double encryption, fold it again. Know big 100 meg, gigabyte…

'Twiddle something'?

Don't mess with publicly-vetted crypto code - you're far more likely to introduce a weakness. Instead, just follow the documentation and use it correctly.

Re: Norwegian backup provider promises NSA-free data storage using Norwegian laws

#82
post #68

If you want to have data storage that's secure from the NSA then you are going to need to do client side encryption. Moving your data to a company/country that promises not to access it isn't going to cut it.

According to the FAQ they are encrypted client side http://www.jottacloud.com/faq/ "Yes, all datatraffic between your computer and Jottacloud is encrypted with 256 bits AES high grade encryption, which makes it virtually impossible for unauthorized persons to use the information being sent."

I believe this refers to HTTPS.

Re: Norwegian backup provider promises NSA-free data storage using Norwegian laws

#83
post #68

If you want to have data storage that's secure from the NSA then you are going to need to do client side encryption. Moving your data to a company/country that promises not to access it isn't going to cut it.

According to the FAQ they are encrypted client side http://www.jottacloud.com/faq/ "Yes, all datatraffic between your computer and Jottacloud is encrypted with 256 bits AES high grade encryption, which makes it virtually impossible for unauthorized persons to use the information being sent."

That is just referring to SSL.

Re: Norwegian backup provider promises NSA-free data storage using Norwegian laws

#84
post #46

Earlier quoted context omitted.

Is there a jurisdiction on the planet where data is safe from domestic wiretapping [1] (i.e. international espionage not withstanding)? Serious question. 1. Clarification: I mean warrantless wiretapping.

No. Job #1 for a national government is national security, and governments inherently have the power to intrude upon privately operated companies. I think that in the long run, the U.S. is still a good place to keep data. U.S. citizens have an instinctual distrust of government that Europeans often mock, but in this case I think is an advantage. In addition the U.S. has some of the strongest protections for freedom o…

Yes, that's what I too think right now in June 2013, although I am an European. But... How about in the future, considernig the progress towards a surveillance state which began around after 9/11 and Patriot Act? (And some say it began even earlier, but was greatly accelerated by Patriot Act)

The progress seems to be to give up individual liberties and freedoms in the name of War on Terror. Because the changes are incremental, people don't quite realize the progress until it is too late. By then, they consider it a status quo and youngsters don't even know what they are missing. It's the so-called boiling frog analogy.

Re: Norwegian backup provider promises NSA-free data storage using Norwegian laws

#85
post #69

Encrypt all you like. It boils down to this: Will a government make you prove a negative, and if you don't, will it lock you up? If you have encrypted files, there must have been or still be a key to decrypt it. You will be asked for the key. You will either given them the key, say no, or say you don't have it. The first two are no good, so all you have is the denial that you have the key. If government cant find the…

*he

fixed that for you

Re: Norwegian backup provider promises NSA-free data storage using Norwegian laws

#86
post #46
post #41

As a Norwegian, let me just say: Yeah, right. 1. The Norwegian security services have a long history of violating Norwegian law (and when, for example, extensive illegal politically motivated surveillance of mostly left wing politicians was uncovered in the 90's they then had the gall to place an MP and member of the committee investigating them under surveillance while he was working on the report about their illega…

Is there a jurisdiction on the planet where data is safe from domestic wiretapping [1] (i.e. international espionage not withstanding)? Serious question. 1. Clarification: I mean warrantless wiretapping.

Not a jurisdiction, but your data is pretty safe from warrantless wiretapping in a Tor .onion server.

Re: Norwegian backup provider promises NSA-free data storage using Norwegian laws

#87
United States Government:

-We are serious about creating jobs and supporting great American companies. -Makes the most lucrative young companies in the US unusable in the name of spying on their own citizens.

What in the actual fuck?

Re: Norwegian backup provider promises NSA-free data storage using Norwegian laws

#88
post #41

As a Norwegian, let me just say: Yeah, right. 1. The Norwegian security services have a long history of violating Norwegian law (and when, for example, extensive illegal politically motivated surveillance of mostly left wing politicians was uncovered in the 90's they then had the gall to place an MP and member of the committee investigating them under surveillance while he was working on the report about their illega…

Thank you for taking the time to describe this. I'd been, naively, hoping -- yet to research -- that Norway might be somewhat better than Sweden.

I'm coming to the impression that none of the Scandinavian countries may be particularly friendly to data privacy advocates.

Re: Norwegian backup provider promises NSA-free data storage using Norwegian laws

#89
post #53
post #47

Earlier quoted context omitted.

And you don't believe your data passes through a "communications provider"? By the argumentation on your page, almost none of the electronic data targeted by the data retention directive would in fact be retained if the directive is not also applied to data that merely transit a providers network, given that the vast majority of e-mail addresses in use today are not hosted by "communications providers". If that is in…

It does, but they dont offer email or phone services. So they are also exempt. We use Blix: https://www.blix.com/ What you call a loophole, was no secret in the hearings about the new law. The government wanted this implemented mainly for the phone providers. They understood that foreign email providers like Gmail and Hotmail that most use in Norway, could not be under the law in any practical way, so they restricted…

I read your website and tried your service for a few days this past April. I cancelled immediately after you emailed both my web hosting and support account credentials. In plain text. That is egregious.

I mention this only to point out that without proper security procedures your data privacy policy is irrelevant. Not one-way hashing and salting passwords negates everything else you do.

I'm happy to try again some day but you really have to have airtight security at a minimum to appeal to privacy-conscious users. Password reset is one of the first things we test for any new service.

Re: Norwegian backup provider promises NSA-free data storage using Norwegian laws

#90

If you want to have data storage that's secure from the NSA then you are going to need to do client side encryption. Moving your data to a company/country that promises not to access it isn't going to cut it.

Encryption won't help you, since a judge will simply throw you in jail for contempt until you cough up the key or give them a copy of the decrypted data. Honestly, in this hostile government environment, if you have something worth protecting you need to have a "dead man switch" on your data. Unless you take an action every few days (which you can't if in jail) then your data gets deleted.

I may be misreading this, but I think there's a big difference between "being readily accessible to the NSA" and "taking a judge to make it available."
Post reply on HN