Live data from Hacker News

Norwegian backup provider promises NSA-free data storage using Norwegian laws

jottacloud.com

111–120 of 125 posts

Re: Norwegian backup provider promises NSA-free data storage using Norwegian laws

#111
post #105
post #40

Earlier quoted context omitted.

I don't think DLD/DRD is conflicting with the statements given in the post, as DLD only concerns itself with metadata (and yes, that can be harmful), and the article talks about the actual data. Both are important, but different, topics.

Well, after reading Snowden's comments about what is available (everything) - it would seem that DLD goes hand in hand with storing all traffic for a limited time -- you would need help searching that to actually recover something.

> DLD goes hand in hand with storing all traffic for a limited time

Nope? From the linked translated wikipedia page:

> Data that reveals the content of the communication must not be stored

Re: Norwegian backup provider promises NSA-free data storage using Norwegian laws

#112
post #41

As a Norwegian, let me just say: Yeah, right. 1. The Norwegian security services have a long history of violating Norwegian law (and when, for example, extensive illegal politically motivated surveillance of mostly left wing politicians was uncovered in the 90's they then had the gall to place an MP and member of the committee investigating them under surveillance while he was working on the report about their illega…

+1

Re: Norwegian backup provider promises NSA-free data storage using Norwegian laws

#113
post #69

Encrypt all you like. It boils down to this: Will a government make you prove a negative, and if you don't, will it lock you up? If you have encrypted files, there must have been or still be a key to decrypt it. You will be asked for the key. You will either given them the key, say no, or say you don't have it. The first two are no good, so all you have is the denial that you have the key. If government cant find the…

I think the thing this is supposed to be analogous to is carrying around an encrypted drive with your stuff on it. As in just trying to deal with the problems of not physically holding onto the drive (that is if there is client side encryption).

Basically what this would prevent would be data collection if you were caught in a web of general surveillance. I agree that if you're in a situation where a government is making a case against you you're fucked. But that requires specific targeting of you.

Re: Norwegian backup provider promises NSA-free data storage using Norwegian laws

#114
post #111
post #105

Earlier quoted context omitted.

Well, after reading Snowden's comments about what is available (everything) - it would seem that DLD goes hand in hand with storing all traffic for a limited time -- you would need help searching that to actually recover something.

> DLD goes hand in hand with storing all traffic for a limited time Nope? From the linked translated wikipedia page: > Data that reveals the content of the communication must not be stored

I meant - if you already, illegally store everything - that everything is problematic to search, and to store permanently. If you also, legally, through DLD store metadata, then that makes your illegally collected data more useful.

Re: Norwegian backup provider promises NSA-free data storage using Norwegian laws

#115
post #84

Earlier quoted context omitted.

No. Job #1 for a national government is national security, and governments inherently have the power to intrude upon privately operated companies. I think that in the long run, the U.S. is still a good place to keep data. U.S. citizens have an instinctual distrust of government that Europeans often mock, but in this case I think is an advantage. In addition the U.S. has some of the strongest protections for freedom o…

Yes, that's what I too think right now in June 2013, although I am an European. But... How about in the future, considernig the progress towards a surveillance state which began around after 9/11 and Patriot Act? (And some say it began even earlier, but was greatly accelerated by Patriot Act) The progress seems to be to give up individual liberties and freedoms in the name of War on Terror. Because the changes are in…

Except that even in the U.S. it has literally been much worse, even before computers. We have always had an ebb-and-flow with civil liberties.

First we enslaved the blacks, then we started making them free. Then we made a slave control law to forcibly rendition captured slaves back to their masters in the slave states. Then we fought and died and FREED THE SLAVES!.... except that we didn't, as it turns out. Reconstruction was a high-water mark, then Jim Crow and the KKK came.

Hell, we didn't even start off from a great place. Go read about the Alien and Sedition Acts when you get a chance.

And likewise with privacy rights. We didn't start off with those either. As long as the government didn't have to search you or your property to find something, it was fair game. But then we added controls for postal mail. Then telephones, and eventually cell phones, beepers, and more. We also had the Supreme Court essentially create "reasonable expectation of privacy" out of whole cloth (which I don't blame them for, but goes to show how we didn't start off with Jefferson's dream government just to beat back all the attackers over time).

Of course in between there were COINTELPRO, FBI watchlists, HUAC & McCarthy's red scare, J. Edgar Hoover (which even MULTICS referenced, IIRC), ECPA, CALEA, attempts at the Clipper chip, munitions controls on crypto, etc. etc.

So it hasn't all been consistent progress but it also hasn't all been consistent withdrawal. So while I respect and greatly admire those who fight for increased privacy because they think it's the right thing to do, I can only assume those who characterize civil liberties in the U.S. as something that has simply been slowly eroded over time have not studied as much U.S. history as they should have.

Re: Norwegian backup provider promises NSA-free data storage using Norwegian laws

#116
post #53

Earlier quoted context omitted.

It does, but they dont offer email or phone services. So they are also exempt. We use Blix: https://www.blix.com/ What you call a loophole, was no secret in the hearings about the new law. The government wanted this implemented mainly for the phone providers. They understood that foreign email providers like Gmail and Hotmail that most use in Norway, could not be under the law in any practical way, so they restricted…

I read your website and tried your service for a few days this past April. I cancelled immediately after you emailed both my web hosting and support account credentials. In plain text. That is egregious. I mention this only to point out that without proper security procedures your data privacy policy is irrelevant. Not one-way hashing and salting passwords negates everything else you do. I'm happy to try again some d…

If you're worried about the NSA or other nation-states then I wouldn't stop with hashing+salting. You need to be using something like scrypt/bcrypt/PBKDF2. cperciva has a paper about scrypt, bcrypt is at least widely known for this use case, and PBKDF2 is even a "certified" way to do that.

Re: Norwegian backup provider promises NSA-free data storage using Norwegian laws

#117
post #67
post #45

Earlier quoted context omitted.

If you crypt, Dropbox is fine. People need to use encryption. Every popular computer language has encryption routines, scroll through the source code until you find something accessible, twiddle something to personalize it while keeping it functional, perhaps convince yourself it will remain secure, etc, of course be cautious about that. Or simply, there's double encryption, fold it again. Know big 100 meg, gigabyte…

The main selling point of Dropbox is cross-platform support for umpteen platforms, so you'd need to find an encryption tool that will work on all platforms; say bye to iOS...

Check out boxcryptor, works in the OS's that you probably care about.

Re: Norwegian backup provider promises NSA-free data storage using Norwegian laws

#118
post #42

Earlier quoted context omitted.

Good luck, I have terabytes of random data. I can always provide you OTP key, and create what ever content I want you to see. (Malleable encryption)

Stay away from the UK - here a judge can throw you in jail for failure to provide keys, even if there's no evidence you still have the keys, and said judge would pretty much be guaranteed to believe that you did not hand over the correct keys if the result is garbage.

If you claim the encryption was done using a One Time Pad, you can pick any result you want, generate the corresponding key, and hand that over.

https://en.wikipedia.org/wiki/One-time_pad

Re: Norwegian backup provider promises NSA-free data storage using Norwegian laws

#119
post #24

If you want to have data storage that's secure from the NSA then you are going to need to do client side encryption. Moving your data to a company/country that promises not to access it isn't going to cut it.

Good suggestion, I've been using Amazon Glacier with the CloudBerry backup software which supports client-side AES encryption ( http://www.cloudberrylab.com/amazon-glacier-backup-software.... ) and couldn't ask for more. Of course you will have to trust CloudBerry not to put a backdoor in their Software, but it seems there are no OSS alternatives right now that work as easily.

Duplicity (http://duplicity.nongnu.org/) and its nice frontend Déjà Dup (https://launchpad.net/deja-dup). Client-side encryption, multiple backends.

Re: Norwegian backup provider promises NSA-free data storage using Norwegian laws

#120
post #46
post #41

As a Norwegian, let me just say: Yeah, right. 1. The Norwegian security services have a long history of violating Norwegian law (and when, for example, extensive illegal politically motivated surveillance of mostly left wing politicians was uncovered in the 90's they then had the gall to place an MP and member of the committee investigating them under surveillance while he was working on the report about their illega…

Is there a jurisdiction on the planet where data is safe from domestic wiretapping [1] (i.e. international espionage not withstanding)? Serious question. 1. Clarification: I mean warrantless wiretapping.

The US and Canada are actually some of the better places for a privacy-protecting provider, as long as you want to use strong cryptography. CALEA in the US is the main impediment to making a system where the operator intentionally can't disclose information, and that can be solved (for now) by not being a CALEA-covered provider (essentially, PSTN or VOIP interconnected with PSTN, or some kind of broadband physical access layer).
Post reply on HN