Almost everybody here talks to move email elsewhere, etc. There are no positive comments.
Does this mean that the US government has won and can do anything they want?
341–350 of 671 posts
Almost everybody here talks to move email elsewhere, etc. There are no positive comments.
Does this mean that the US government has won and can do anything they want?
Earlier quoted context omitted.
It'll be interesting to see whether companies start to shift to using encrypted email over the next few decades - it's not that hard to set up if you know the counterparty will be using encryption of the same kind, and if it's not a service bought in from an external company you can fairly sure it is secure. Companies could at least insist that intra-company email is encrypted, which would be a huge amount of their n…
Exchange/Outlook already does intra- and extra-company encryption.
The US government is destroying one of the few bright spots in the American economy with its out of control military. It is unconscionable. And the sad thing is it has been enabled by the betrayal by many of the web 2.0 giants, Facebook, Google etc. Google especially is sad to see since they were willing to forgo the Chinese market on principle, but then decided that taking on the authoritarian US government was too…
I wrote an article a year or two ago entitled "Don't Be Evil, or comply with the PATRIOT Act?" The companies with the ability to move all operations out of US jurisdiction/coercion who don't do so are complicit in all of this.
I can imagine what would happen to Google if, through some dark miracle, their leadership decided to do this.
Most of their top engineers live in America. So do the leaders, but ignore them, we've already decided they want this. The employees don't, though: There are eleven thousand people, there, who'll need to be relocated to - where? Europe, probably Ireland, where many of them have never been.
Certainly not where they have roots, or where their family is.
Google has deep pockets. They can afford to pay massive relocation bonuses, and they'll have to do so. Still, this is eleven thousand people; we're probably talking about a billion plus, just to get a reasonable number of them to follow. After all, most of these engineers would be perfectly capable of finding work at a different company.
Okay, so they've done that. They lost a lot of good people; probably a lot of their best people, the ones that care least about money. Still, they're now in Europe.
Now what?
Most of their infrastructure is still in the US. Compute clusters, god only knows how many. Storage clusters. User data, placed in the US under safe harbor provisions because an attempt at keeping it in Europe is unfeasible given the rather diverse tapestry of privacy laws here.
They'll need to move it all to Europe. They'll need to figure out a place to put it, and they'll need to pay billions - quite a few - to rebuild and expand their infrastructure here.
By the time this is all done, they'll have new problems. Realistically, they'll go bankrupt somewhere in the middle. And that's not mentioning possible reactions from the US government.
It would be great if leaving the US was an option, but it really.. just isn't.
Earlier quoted context omitted.
I don't blame the companies; they're about as much a victim of USgov as we are IMHO. That being said, if all the online-storage/cloud-server/email-providers/social-whatever companies in US start going out of business because nobody trusts them I strongly suspect something will have to change. It's just too bad we have to do a "scorched earth"[1] to bring about change. 1. http://en.wikipedia.org/wiki/Scorched_earth
This is where I disagree. I do blame companies like Google for not fighting this more. At the very least they make users aware that these laws exist, even if they cannot detail specifics related to their surveillance involvement.
Earlier quoted context omitted.
Because the Central American governments so wonderfully respect human rights.
Not to put words in the OP's mouth, but I think it's not so much about the USA's not respecting human rights as about that _and_ its having too much power for everybody's good. By not having to pay taxes to USGov, they probably hope to make that power diminish. EDIT: Good God, I've always been the guy arguing with your average America hater that we should count ourselves lucky that in the monopolar world we live in,…
Earlier quoted context omitted.
Do what I do! I have my own domain name, currently hosting with Google Apps. If I get the motivation to move to another host like myself, I can do it without changing contact information.
Oh good, because Google will never be subject to an NSL.
I'm in the process of moving any Saas offerings I use off USA-affiliated companies, but it's actually more difficult than I first thought. I believe there might even be a very profitable market in simply duplicating the functionality of Saas offerings at a higher price with security/privacy guarantees in Germany/HK/etc. Might be the next hot business to be in? You'd be surprised as to the number of people seeking alt…
Moving services off USA-based companies is like using two bicycle locks instead of one. A determined government is still going to get your data, they just need to spend a bit more time. Focus instead on encryption.
If enough people leave US based companies for foreign companies it will put pressure on the government. I have a feeling this pressure is already underway.
Earlier quoted context omitted.
Yes, there is a strong parallel between pre-Nazi Germany and current USA. Of course, Americans will not literally follow Nazi ideology. What we see in America is an increasing merger between industry and government. Finance is the most regulated sector; hence "too big to fail" and all the exploits pulled by big banks. Telecom is almost completely government controlled (through the graning of regulatory monopolies). T…
> we're taking anti-corrective action instead of corrective action at every step That's not true. The Congress almost defunded the NSA recently. It was a far closer thing than anyone in the establishment suspects. In the end, we are a country that values it's privacy, values small government, and we'll assert that sooner or later. It may be later. But hey, it took a long time for us to figure out slavery, women's rig…
But yes, the USA is the only nation founded on the principles of individual freedom, and many people remember that, so there is a chance.
Where's the "I wish you hadn't done that, lavabit, I'm a customer and I feel very screwed over by this action" comments? Or is this appropriate for any SaaS vendor? You're OK with this? Should all customers, even those who really don't care if the NSA could be watching, be put out because some feel that this cause trumps actually doing business and having customer-vendor relationships? I could see someone suing an Sa…
So? A SaaS vendor that shuts down operations in to avoid complying with a mandate of a court is taking a major risk of losing all its assets to legal action by the government. On top of that, the risk of legal action by dissatisfied customer is a pretty small marginal cost.
> "You cost me $XX in actual costs and $YYY in lost business. Your TOS says nothing about your shutting down because the government asked you to do something you didn't agree with."
You'll probably find that, unless you have specific contract terms relating to expected costs of failure to provide service, expectation damages of the type you describe are barred by the foreseeability prong of the test for expectation damages.
For the unfamiliar: Lavabit was a webmail service, that (claimed to) encrypt emails in such a way that they literally did not have access to the content stored on their own servers. The linked email would lend some credence to those claims. It was originally designed in contrast to gmail scanning your email for targeted advertising, but my imperfect memory says that their system should also have been resilient to "we…
Takeaway for fellow hackers: If you are building a system that stores user-generated data, prepare for the eventuality that someone other than the user will demand to see it.
In general, the prevailing theory is that all companies are required to release private keys or passwords needed to unlock evidence. As a consequence of Lavabit fighting, they likely got slapped with some pretty harsh contempt of court rulings, including a demand to record all private keys needed for decryption going forward. The worst case (that I can talk about) I saw involved requiring a specific employee be demoted due to improper care of a company's systems.
What's sad is that because Lavabit was such a small service provider, they never had the previous rounds of government threats and must have been caught off guard. As I've said in past posts (before Snowden), it is common knowledge among large-scale service providers that the local government can always come in to take a look. Doesn't matter if you are in the US, EU, or China, you have to comply. I've seen the US DOJ threaten pretty harshly a customer who simply asked about 'options' of how to comply.
Past post with explanation: https://news.ycombinator.com/item?id=5754641
P.S. Right or wrong is a separate conversation...