Live data from Hacker News

Dear USA, my data has left your building

cpbotha.net

81–90 of 158 posts

Re: Dear USA, my data has left your building

#81
post #7

Nitpickers aside (yes, what they had they may still have or at least in digest form) this is a single instance of a tidal wave of people doing this. EU datacenters are doing quite well because of the NSA revelations. The economic impact of this could very well counteract any net plus the US had while they were able to spy at will. Likely it's not going to be the same parties that will end up footing the bill. The pra…

European chest-beating in the wake of the NSA revelations is fairly hypocritical. The difference between the US and the EU is that in the US, the snooping was icky, secret and very possibly illegal. In the EU, it's done out in the open, required by law:

According to the directive, member states will have to store citizens' telecommunications data for six to 24 months stipulating a maximum time period. Under the directive the police and security agencies will be able to request access to details such as IP address and time of use of every email, phone call and text message sent or received. A permission to access the information will be granted only by a court.

http://en.wikipedia.org/wiki/Data_Retention_Directive

Concerns about spying on foreigners vs. nationals? Does not apply in the EU. All the chatter about mission creep in the PRISM data, how it's used by the DEA, IRS etc., rather than use national security? That's routine, by the book usage of the very same data in the EU.

Re: Dear USA, my data has left your building

#82
post #72
post #7

Nitpickers aside (yes, what they had they may still have or at least in digest form) this is a single instance of a tidal wave of people doing this. EU datacenters are doing quite well because of the NSA revelations. The economic impact of this could very well counteract any net plus the US had while they were able to spy at will. Likely it's not going to be the same parties that will end up footing the bill. The pra…

Much as I'd like to see some kind of "tidal wave of people doing this", purely in the interests of sending a message to somebody somewhere that data sniffing = not cool, I don't personally know anyone who's taken the time or energy to move all his data off of bugged U.S. servers onto bugged European or Asian ones or attempted to host it himself in less-efficient email clients, etc., nor plans to, nor do I hear very m…

Large companies have a pretty strong set of rules to guide them in the EU DPD en privacy laws of individual countries, that means that they need to subcontract with others in such a way that they can fulfill this.

From a few months ago if you were serious about trying to comply with the law in Europe then by now you are either migrating to EU hosting, you've already migrated or you are planning your migration. If not you run the risk of being found non-compliant at some point in the future or to get very pointed questions when a new investor decides to step on board or when you're in a position to sell your company to a larger entity.

This is not going to be advertised, it isn't going to be in the headlines, it is just happening underwater and out of sight. But it definitely is happening. Individuals making those same choices are doing so for different reasons than corporations.

Re: Dear USA, my data has left your building

#83
post #7

Nitpickers aside (yes, what they had they may still have or at least in digest form) this is a single instance of a tidal wave of people doing this. EU datacenters are doing quite well because of the NSA revelations. The economic impact of this could very well counteract any net plus the US had while they were able to spy at will. Likely it's not going to be the same parties that will end up footing the bill. The pra…

European chest-beating in the wake of the NSA revelations is fairly hypocritical. The difference between the US and the EU is that in the US, the snooping was icky, secret and very possibly illegal. In the EU, it's done out in the open, required by law: According to the directive, member states will have to store citizens' telecommunications data for six to 24 months stipulating a maximum time period. Under the direc…

DRD is in many ways incompatible with DPD, this is well known and a source of much industry confusion.

Note that the DRD applies to specific requests and that the data is kept by the corporations (typically telcos and ISPs) rather than turned over wholesale to government institutions, in other words, you need a warrant to get specific data.

As such, there is a huge difference here.

Where the hypocrisy comes in is where the EU nation states were actively aiding the NSA in exchange for access and tricks regarding nationality to side-step local limitations ('I spy on your citizens if you spy on mine').

Re: Dear USA, my data has left your building

#84
post #22

Can anyone recommend a linux VPS host outside the US as an alternative to Linode or Digitalocean?

http://www.hetzner.de/en/hosting/produktmatrix_vserver/vserv.... German company, servers in Germany. Cheaper than Linode, AWS, etc.

European companies will be pleasantly surprised that the prices listed include VAT - which means that if you provide your company's VAT number on sign-up, you won't have to pay VAT. So a €7.90 VPS will cost a European company €6.64 (roughly equivalent to $8.86).

Re: Dear USA, my data has left your building

#85
post #59
post #5

Over the last month I have cancelled all our servers in US, setting up a new one this morning in Amsterdam One thing I am worried about is potential liability of having someone sueing us under data protection laws here in Ireland, claiming their data was inspected by US and we couldnt protect their privacy Here in Europe we get to have data protection commisioners and strong laws on the subject unlike across the pond…

One thing I don't entirely understand is whether having an EU-based server provided by an US company (Rackspace, AWS, Digital Ocean, you name it) makes any difference at all.

No one can say - although at the moment you can be sure they are subject to US intercept orders.

The companies are incorporated in the US, so subject to US law. But the physical servers are located in other jurisdictions, and sometimes US law conflicts with that law.

In practice, so far I suspect that the US law has won out, because other jurisdictions haven't known to fight it. In the future that might change, but... secret orders supported by secret laws enforced by secret courts can be pretty hard for other jurisdictions to fight.

Re: Dear USA, my data has left your building

#86
post #68

"My webhoster (WebFaction) receives mail for all my domains. My Synology retrieves mail every 5 minutes via POP (you can set this up via Roundcube on the Synology) and deletes it from WebFaction." but even if you can delete your mail from your mailhost after downloading it to your private machine, isn't the point that the NSA probably collected the email before it even hit your mailhost?

That probably depends on whether your ISP's mailserver uses opportunistic encryption. Any email I send to Google from my mailserver is always sent over a TLS-encrypted connection for instance, because Google's mailservers agree to encrypt where possible.

In this scenario, the NSA wiretaps will get direct access to any email sent over unencrypted connections to the ISP mailserver, but they'll have to work harder to get at the encrypted data.

Of course, as we know they've suborned the encryption used by many, many organisations so this is no guarantee of protection against an NSA fishing expedition, but it's a lot better than nothing.

Re: Dear USA, my data has left your building

#87
post #72
post #7

Nitpickers aside (yes, what they had they may still have or at least in digest form) this is a single instance of a tidal wave of people doing this. EU datacenters are doing quite well because of the NSA revelations. The economic impact of this could very well counteract any net plus the US had while they were able to spy at will. Likely it's not going to be the same parties that will end up footing the bill. The pra…

Much as I'd like to see some kind of "tidal wave of people doing this", purely in the interests of sending a message to somebody somewhere that data sniffing = not cool, I don't personally know anyone who's taken the time or energy to move all his data off of bugged U.S. servers onto bugged European or Asian ones or attempted to host it himself in less-efficient email clients, etc., nor plans to, nor do I hear very m…

U.S. policy is greatly influenced by corporations. Let's assume that an alternative non-american gmail shows up with most of the key functionality in place but with extensive user privacy being a selling point. I for one would switch in a heartbeat. I think a lot of other technically minded people would as well. Many of which are probably influential when it comes to technology decisions among their peers. It doesn't have to be a mass exodus. A trickle of influential can turn into a tide. We've see it before, especially with internet companies.

Google's a data company. They're definitely going to see this and if it's non-trivial then they're going to react. Lawyers and lobbying ensues. Policy may be affected.

Re: Dear USA, my data has left your building

#88
post #22

Can anyone recommend a linux VPS host outside the US as an alternative to Linode or Digitalocean?

I've been trying out http://www.exoscale.ch , and while slightly more pricy than similar offers, they seem to offer a pretty good service, with high focus on privacy and security. Also, they're hosted in Switzerland.

Just checked out the pricing - really expensive, if you compare with the Germans at Hetzner http://www.hetzner.de/hosting/produktmatrix/rootserver-produ...

I think the Swiss market has ample room for more competition.

Re: Dear USA, my data has left your building

#89
post #5

Over the last month I have cancelled all our servers in US, setting up a new one this morning in Amsterdam One thing I am worried about is potential liability of having someone sueing us under data protection laws here in Ireland, claiming their data was inspected by US and we couldnt protect their privacy Here in Europe we get to have data protection commisioners and strong laws on the subject unlike across the pond…

As I understand it the Dutch government are pretty much in bed with the Americans on a lot of things (we have some of their nukes dotted around the country for a start). I would be very surprised if the government aren't playing nicely with the NSA as well.
Post reply on HN