Live data from Hacker News

Norwegian backup provider promises NSA-free data storage using Norwegian laws

jottacloud.com

101–110 of 125 posts

Re: Norwegian backup provider promises NSA-free data storage using Norwegian laws

#101
post #86
post #46

Earlier quoted context omitted.

Is there a jurisdiction on the planet where data is safe from domestic wiretapping [1] (i.e. international espionage not withstanding)? Serious question. 1. Clarification: I mean warrantless wiretapping.

Not a jurisdiction, but your data is pretty safe from warrantless wiretapping in a Tor .onion server.

Why the downvote?

Re: Norwegian backup provider promises NSA-free data storage using Norwegian laws

#102
post #18

Earlier quoted context omitted.

I have to agree. The user needs control over their encryption. Taking advantage of Norway's laws is fine, until the day that those laws go sour on you.

The slippery slope in all of this is the application of the law. Sure, if the government was going after someone like Steve Muller ( http://www.wired.com/threatlevel/2008/04/gsm-researcher/ ) you'd want him to be able to keep his stuff from prying eyes. What about a Suadi National accused of plotting terror attacks in NYC? Would you want the same laws applied to him? Or would you want to able to force someone like th…

>I really don't know what the right answer is, but sometimes laws intended to keep us safe, also give shelter to bad guys.

Americans inherently know this. We were brought up with the idea that freedom isn't free and that the price of liberty is eternal vigilance. Just because it is more convenient to violate the civil liberties of all to catch a few bad actors doesn't mean it is what our country is all about.

Europeans often find that sentiment ridiculous. But that is just the cost of privacy and liberty - one that our forefathers were welcome to pay.

Re: Norwegian backup provider promises NSA-free data storage using Norwegian laws

#103
post #44
post #41

As a Norwegian, let me just say: Yeah, right. 1. The Norwegian security services have a long history of violating Norwegian law (and when, for example, extensive illegal politically motivated surveillance of mostly left wing politicians was uncovered in the 90's they then had the gall to place an MP and member of the committee investigating them under surveillance while he was working on the report about their illega…

Well, what you say is not correct. First of all the Data Retention Directive have to be valid for you. I work for the Norwegian email provider Runbox and the EU Data Retention Directive is not applicable for us. It is only valid for carriers that own their own infrastructure down to the data center, called "communication providers". We even have it confirmed by both Kripos (FBI-ish) and Post- og Teletilsynet (Norwegi…

This sounds strange, as far as I understand it:

http://www.lovdata.no/ltavd1/filer/sf-20130514-0484.html#1-2 http://www.lovdata.no/ltavd1/filer/sf-20130514-0484.html#2-6

together states that if you provide email services, you are required to store metadata (which is what the Data Retention Directive is all about).

On a side note, if the secret services cooperate to do massive ingress/egress storage of data on the network level (say for 6 months) -- having easily passable meta-data would help turn that massive data dump into useful information (assuming index and organization around ip/date or something similar).

As for being safe from NSA outside of the US (even with an ally) -- that makes no sense. While it is against Norwegian law to hack into Norwegian businesses - the NSA isn't subject to Norwegian laws, their subject to US law. The secret services are explicitly set up to preform illegal actions in foreign territories (which is why the NSA story is about spying on Americans, rather than on spying in general).

Re: Norwegian backup provider promises NSA-free data storage using Norwegian laws

#104

Earlier quoted context omitted.

I may be misreading this, but I think there's a big difference between "being readily accessible to the NSA" and "taking a judge to make it available."

If, through whatever means, they become interested enough in your data, they can just go judge shopping until they find one that decides that NSA suspicion is enough to issue a search warrant.

True enough, but that scales very poorly, while their current approach demonstrably scales rather well.

In a game of picking one's battles, that seems like an easy win; I'll worry about contempt charges and rubber hoses some other day.

Re: Norwegian backup provider promises NSA-free data storage using Norwegian laws

#105
post #40

"In Norway, privacy stands firm like the mighty mountains of Jotunheimen.". Let's not flatter ourselves too much: http://no.wikipedia.org/wiki/Datalagringsdirektivet (in Norwegian, http://translate.google.com/translate?sl=auto&tl=en&js=n&pre... ), or the less detailed http://en.wikipedia.org/wiki/Data_Retention_Directive

I don't think DLD/DRD is conflicting with the statements given in the post, as DLD only concerns itself with metadata (and yes, that can be harmful), and the article talks about the actual data. Both are important, but different, topics.

Well, after reading Snowden's comments about what is available (everything) - it would seem that DLD goes hand in hand with storing all traffic for a limited time -- you would need help searching that to actually recover something.

Re: Norwegian backup provider promises NSA-free data storage using Norwegian laws

#106
post #103
post #44

Earlier quoted context omitted.

Well, what you say is not correct. First of all the Data Retention Directive have to be valid for you. I work for the Norwegian email provider Runbox and the EU Data Retention Directive is not applicable for us. It is only valid for carriers that own their own infrastructure down to the data center, called "communication providers". We even have it confirmed by both Kripos (FBI-ish) and Post- og Teletilsynet (Norwegi…

This sounds strange, as far as I understand it: http://www.lovdata.no/ltavd1/filer/sf-20130514-0484.html#1-2 http://www.lovdata.no/ltavd1/filer/sf-20130514-0484.html#2-6 together states that if you provide email services, you are required to store metadata (which is what the Data Retention Directive is all about). On a side note, if the secret services cooperate to do massive ingress/egress storage of data on the net…

[deleted]

Re: Norwegian backup provider promises NSA-free data storage using Norwegian laws

#107
post #46

Earlier quoted context omitted.

Is there a jurisdiction on the planet where data is safe from domestic wiretapping [1] (i.e. international espionage not withstanding)? Serious question. 1. Clarification: I mean warrantless wiretapping.

No. Job #1 for a national government is national security, and governments inherently have the power to intrude upon privately operated companies. I think that in the long run, the U.S. is still a good place to keep data. U.S. citizens have an instinctual distrust of government that Europeans often mock, but in this case I think is an advantage. In addition the U.S. has some of the strongest protections for freedom o…

> Job #1 for a national government is national security, and governments inherently have the power to intrude upon privately operated companies.

I would say that job #1 of a government is establishing and enforcing domestic property rights (to allow an economy to function); and job #2 is building public-good infrastructure like roads.

"National security" is job #1 of an organism interested in its own survival--but there's no reason a government needs to be such a thing; the only reason I can see for it is the precedent set by monarchies, where each current king wants the government to persist in its current form so that they themselves will stay in control of it. A government could run a country perfectly capably while leaving itself undefended from being "eaten" by a foreign government (or populist coup) at any time.

Re: Norwegian backup provider promises NSA-free data storage using Norwegian laws

#108
post #107

Earlier quoted context omitted.

No. Job #1 for a national government is national security, and governments inherently have the power to intrude upon privately operated companies. I think that in the long run, the U.S. is still a good place to keep data. U.S. citizens have an instinctual distrust of government that Europeans often mock, but in this case I think is an advantage. In addition the U.S. has some of the strongest protections for freedom o…

> Job #1 for a national government is national security, and governments inherently have the power to intrude upon privately operated companies. I would say that job #1 of a government is establishing and enforcing domestic property rights (to allow an economy to function); and job #2 is building public-good infrastructure like roads. "National security" is job #1 of an organism interested in its own survival --but t…

National Security is intrinsically about enforcing domestic property rights. It covers issues like terrorism but also foreign hostilities. Don't be a doof and pretend that National Security doesn't at least start with the interests of the citizens in mind. Seems like it gets awfully lost in the woods, but you can't pretend that if people just had the right ideals things would be fine.

Re: Norwegian backup provider promises NSA-free data storage using Norwegian laws

#109
post #83
post #68

Earlier quoted context omitted.

According to the FAQ they are encrypted client side http://www.jottacloud.com/faq/ "Yes, all datatraffic between your computer and Jottacloud is encrypted with 256 bits AES high grade encryption, which makes it virtually impossible for unauthorized persons to use the information being sent."

That is just referring to SSL.

SSL keeps your data (relatively) safe from Sweden, though.

And Denmark, too, as my traceroutes seem to show.

Re: Norwegian backup provider promises NSA-free data storage using Norwegian laws

#110
post #80

Earlier quoted context omitted.

My reading of that is that you aren't allowed to redistribute any modifications or use it for anything other than accessing the tarsnap service. So not really open source software in any sense that I understand. [NB My comments is not intended as a criticism of tarsnap or Colin's licensing policy - he wrote it so, in my book, he can license it any way he wants.]

> Redistribution and use... without modification , is permitted for the sole purpose of using the "tarsnap" service. (emphasis mine) This sounds like there are no restrictions on distributing modified source / binaries.

Quite the opposite: No permission is given to distribute modified versions, so you're not allowed to do it.
Post reply on HN