Live data from Hacker News

An Apology to my European IT Team

fredlybrand.com

81–90 of 97 posts

Re: An Apology to my European IT Team

#81
post #2

Seems odd that someone wouldn't have understood that even 10-15 years ago. Outsourced means being exposed to risk from your supplier -- by the company itself, by its employees, or by governments. Gmail has somewhat better technical security to protect from outside non-state hackers than your average self-hosted exchange server, and from insiders (the IT guy, like Snowden, may not have the same goals as the organizati…

For those interested in google apps retention:

http://support.google.com/a/bin/answer.py?hl=en&answer=15112...

Spoiler Alert: Apps for Business/Education only

Re: An Apology to my European IT Team

#82
post #34

Earlier quoted context omitted.

Snowden directly answers this -- he claims NSA analysts can get away with it: http://www.guardian.co.uk/world/2013/jun/17/edward-snowden-n... and http://www.guardian.co.uk/world/2013/jun/17/edward-snowden-n... This is getting overlooked, but a 2009 NYT article claimed an NSA analyst looked through Bill Clinton's email out of curiosity (he was caught). I think this is very revealing. http://www.nytimes.com/2009/06/17/…

Many government and private sector systems share these types of problems. Think Facebook and the DMV. As controls mature around the process, trolling through the data becomes relatively easy to enforce. My understanding is that in most state DMVs, looking up the driving record of a public figure or similarly flagged individual by some clerk is immediately detected, and "curiosity" lookups on friends and family eventu…

There is no problem. This spying is being done for economic advantage, not to "protect us."

This information is being passed on to American corporations. This is very old news.

http://www.commondreams.org/headlines/070200-02.htm

Re: An Apology to my European IT Team

#83
post #78

Sadly the NSA programs are strongly anti-business as it is based on 'trust in me'. American businesses could and should lobby Congress to fight this and to find ways to protect US stored data, I know I wouldn't trust a Chinese cloud company not to snoop or steal business/corporate ideas and trade secrets. But if there were assurances for US cloud businesses that this doesn't affect their business ideas accidentally o…

I love how business-friendliness is your top concern here. How about this: only businesses (like Facebook, Google et al.) should be able to say 'trust in me' - to their customers. Privacy regulation is only for the government, this will ensure that the surveillance state is built by corporations, as God intended. It's obviously a huge risk and embarrassment if the US government looks at data from Europeans. But if Am…

Well I mentioned business aspects since that was the topic/article focus, lack of trust in US business/cloud data due to unsure protections and secrets of business.

Also I mention that frequently because the people that say 'I have nothing to hide' and don't mind, might think differently if they are business focused and do worry about people stealing ideas, plans, or reacting based on those business secrets.

It is bad all around when individual privacy is at risk unknowingly, but it also affects business privacy and that impacts everyone and harms perception of US cloud services for one which the article mentions.

If you make something public on a website like Facebook you should expect that will be used. But noone expected private emails, phone calls, logs of files in the cloud to be so easily accessible. It creates huge problems in business trustworthiness and protections. That aside from the more important lack of individual privacy that is expected in the same and the root of the problem.

Re: An Apology to my European IT Team

#84
post #65

The author is overlooking one major flaw in his discussion: security (and possibly also reliability). His implication is that they can run internal servers more securely than Google and Salesforce. While government collection of encrypted emails is problematic, securing your own server and making it reliable is an entirely different issue. Unless they have an absolutely top notch security team they'd be better off on…

When your provider is forced by their government to just hand over your data, security is pretty much irrelevant. Anything is more secure than that.

The problem this, and many articles are missing: it isn't that the gov is taking the data from the cloud providers' servers. It's that the gov is mirroring all internet traffic and backing it all up.Thus they don't have to gain access to a cloud provider... let alone to a closet server, to get your traffic/emails.

Re: An Apology to my European IT Team

#85
post #39

While OP's apology is appreciable, there was more than enough information available in 2008 to understand that his Czech colleagues were right. The Prism scandal may have come as a surprise to US citizens, but the US has been spying foreign nationals and companies for years, and we've long known about it - haven't you heard of Echelon? It was also well known that these systems were used for industrial espionage.

Agreed - that was the exact reason that I was apologizing to the guys in CZ. I simply had no idea. Once we talked through the issue, I trusted their judgment (just like they've trusted ours on the areas we know better).

It was simply an area I'd never done any work in - that's the benefit of a global, diverse (and still very small) organization.

Re: An Apology to my European IT Team

#86
post #49

Earlier quoted context omitted.

That would be trivially defeated by sending everyone a slightly different spam email. (And if your encryption doesn't produce totally different files for slight changes in plaintext, it doesn't deserve that name.)

I think you're replying to the wrong comment tree. Spammers already do this today, by including your name and other data in the message, and varying the wording, but that is not enough to fool the spam blockers, and there are diminishing rewards as your addresses/IPs begin to get marked as source of spam regardless of the content.

No, it was the right one. I was thinking about the grand-grand-fathers suggestion in relation to encryption.

Re: An Apology to my European IT Team

#87
post #69

It doesn't take much reading of the literature to understand industrial espionage or any of the other substantive risks of outsourcing. Prism or not, when you put your intellectual property on someone else's networks you are taking a risk. Yet most of the managers I see who make this decision just don't care. They ignore the advice of their systems admins and follow the old adage "you can't get fired for buying IBM"…

We'd brought up a wafer fab in the Hsinchu Scientific Park in Taiwan before - so we weren't strangers to the concerns about industrial espionage. Several of us have done a lot of work with the government and we'd manufactured some very sensitive products (as does the current business).

My apology is really around the fact that at the time we were trusting that such programs would not exist here (this was before explained Echelon to us), and that the US didn't work that way. I was naive and I was wrong.

Re: An Apology to my European IT Team

#88

The author is overlooking one major flaw in his discussion: security (and possibly also reliability). His implication is that they can run internal servers more securely than Google and Salesforce. While government collection of encrypted emails is problematic, securing your own server and making it reliable is an entirely different issue. Unless they have an absolutely top notch security team they'd be better off on…

Our IT team, though small, is very good at what they do and extremely focused on security. We install machines on customer floors that run 24.7.365, which themselves are remotely monitored and serviced. Security is important to us from a manufacturing standpoint as well as from an operational standpoint.

Re: An Apology to my European IT Team

#89
post #78

Sadly the NSA programs are strongly anti-business as it is based on 'trust in me'. American businesses could and should lobby Congress to fight this and to find ways to protect US stored data, I know I wouldn't trust a Chinese cloud company not to snoop or steal business/corporate ideas and trade secrets. But if there were assurances for US cloud businesses that this doesn't affect their business ideas accidentally o…

I love how business-friendliness is your top concern here. How about this: only businesses (like Facebook, Google et al.) should be able to say 'trust in me' - to their customers. Privacy regulation is only for the government, this will ensure that the surveillance state is built by corporations, as God intended. It's obviously a huge risk and embarrassment if the US government looks at data from Europeans. But if Am…

> How about this: only businesses (like Facebook, Google et al.) should be able to say 'trust in me' - to their customers.

As a user of Facebook, you aren't a customer, but the product that is sold to the advertising customers.

Re: An Apology to my European IT Team

#90
post #65

The author is overlooking one major flaw in his discussion: security (and possibly also reliability). His implication is that they can run internal servers more securely than Google and Salesforce. While government collection of encrypted emails is problematic, securing your own server and making it reliable is an entirely different issue. Unless they have an absolutely top notch security team they'd be better off on…

When your provider is forced by their government to just hand over your data, security is pretty much irrelevant. Anything is more secure than that.

No, not true. There are government and non-government attacks. Even if we assume cloud services are more vulnerable to government snooping, we need to also consider that many more companies and individuals suffer more damage from regular criminal hackers than from the NSA. Avoiding a small risk by increasing your exposure to a large risk is not rational.
Post reply on HN