Live data from Hacker News

Dear USA, my data has left your building

cpbotha.net

101–110 of 158 posts

Re: Dear USA, my data has left your building

#101

> On my Android telephone (whoops…) I am using the Kaiten IMAP client. Check out: http://www.ubuntu.com/phone Devices supported: https://wiki.ubuntu.com/Touch/Devices Currently, the Galaxy Nexus seems to be the best option; see its hardware support progress here: https://docs.google.com/spreadsheet/ccc?key=0ArLs7UPtu-hJdDZ... (column "Maguro")

Even better: Firefox OS

The only thing I'd miss there is the lack of support for "native apps" (meaning everything runs in the browser). But it's still great to have another open-source mobile OS alternative.

Re: Dear USA, my data has left your building

#102
> The loss of GMail conversation view was initially really REALLY painful

Considering all the shit going down lately... we've seen a recent surge in use of things like DuckDuckGo and OwnCloud, but no good replacement for the Gmail UI. I'm surprised no one's seen that opportunity and created something similar, but installable on your own personal server so that you can have access to a good web UI from anywhere.

If I can make the time, I'd love to do something like this.

Re: Dear USA, my data has left your building

#103
post #13

Obviously we[1] sympathize with this, since we've been running a swiss location since 2006 - one that has become increasingly busy in the last 3-4 months. However, I personally don't store my data there - even though I am deeply disturbed by the recent revelations and invoke all manner of security precautions in my own digital life. First of all, it appears that intra-US Internet traffic is subject to less scrutiny a…

I have a Synology device (exact same model as the article author actually, and likewise I love it). However I'm having trouble finding a way to back it up securely. The built-in backup methods don't seem to account for encrypting the backups (even if the volume is encrypted). Any suggestions?

However I'm having trouble finding a way to back it up securely. The built-in backup methods don't seem to account for encrypting the backups (even if the volume is encrypted). Any suggestions?

Two suggestions:

A) Download the source [1], and see if it is complete and then you can port in cryptsetup and the LUKS stuff from Linux.

B) Run Linux. If you're at the point where you're worried about encrypted backups, then you should probably be running some form of Linux instead. You can get a small form factor PC that includes the motherboard and processor for not much more than the Synology box. That'll give you a lot more options for software and services too.

We're using this for all the offsite backup drives, and it wasn't too hard to get going. If you (or anyone reading this) can't figure out cryptsetup, just PM me and I'll help you out.

[1] http://sourceforge.net/projects/dsgpl/files/?source=navbar

Re: Dear USA, my data has left your building

#104
post #25

It's the bottom line that's important. As long as the current surveillance regime is in place, there's nowhere you can be online that isn't watchable by them. The NSA is the largest practitioner and consumer of surveillance among its allies and other targets, and likely drives and influences most surveillance activity among its allies and other targets. The NSA gets its funding from US tax collections, and those taxe…

Actually, there's a potential error in what I said. If corporate America benefits from economic espionage (e.g. spying on PetroBras), then it will never stop.

Re: Dear USA, my data has left your building

#105
post #72
post #7

Nitpickers aside (yes, what they had they may still have or at least in digest form) this is a single instance of a tidal wave of people doing this. EU datacenters are doing quite well because of the NSA revelations. The economic impact of this could very well counteract any net plus the US had while they were able to spy at will. Likely it's not going to be the same parties that will end up footing the bill. The pra…

Much as I'd like to see some kind of "tidal wave of people doing this", purely in the interests of sending a message to somebody somewhere that data sniffing = not cool, I don't personally know anyone who's taken the time or energy to move all his data off of bugged U.S. servers onto bugged European or Asian ones or attempted to host it himself in less-efficient email clients, etc., nor plans to, nor do I hear very m…

I completely agree that the technologies used for self-hosting have been neglected during this era's obsession with what I call the "plain cloud." As you point out, convenience is paramount. The plain cloud has seen the lion's share of R&D and has been sold to consumers as the pinnacle of convenience.

However, I contend that had an equal amount of R&D been invested in a distributed cloud (what we used to refer to as "the Internet," not to be snarky)--especially one that provided federated encrypted data backup among trusted friends and family, a model that would embrace high-bandwidth symmetric connections to consumers' homes and the notion of self-serving--we'd be better off now.

In other threads at HN, I believe this has been covered sufficiently, so I'll cut that short.

I think your first paragraph may be correct insofar as there are many of us who were already doing self-hosting of our data. Those concerned with privacy were already assuming the situation was fairly bad, although I think even we were surprised at how bad it is.

My data is no more interesting than the OP's. Boring e-mail, boring family photos, boring unpopular music, boring documents. Yet out of principal, I self-host it. Self hosting is not that remarkable, but it is a rapidly disappearing practice. As recently as five to ten years ago nearly everyone in the world self-hosted their personal data.

Since my first DSL line in 1998, I've always splurged a bit for a symmetric connection. Since then I've found it disheartening that symmetric connections were and remain marginalized. Today, I can connect to my home VPN relatively easily from any of my devices to access my data. It could certainly be a lot better (I've ranted elsewhere that VPNs suck; they've not seen genuine R&D in ages).

Running a personal mail server is pretty simple too. With so much *-as-a-service out there, I admit that some people are losing the will to install a service of their own, but assuming you do a little bit of research, some modern options are more or less install-and-play, with decent anti-spam.

Again, had a distributed cloud continued to see bountiful R&D as the plain cloud has, the self-managed options would be 5-10 years more mature today. Had Thunderbird not been effectively neglected for the past ~4 years, it would probably be a (slightly) nicer e-mail client.

Re: Dear USA, my data has left your building

#106
The author is an ignorant puppy. [\ad hominem] What's the use of all those spendings if his email is not encrypted and hosted on his own hardened server behind a firewall he knows how to configure himself? And even then, if his counterparts are not doing the same, we're back to the original problem.

Re: Dear USA, my data has left your building

#109
post #98

Earlier quoted context omitted.

If there really is months more worth of information I wonder if the public, US or otherwise (as we find more countries with intelligence agencies working as accessories), will experience outrage fatigue. I guess it will depend on how bad each revelation is but I could easily imagine a lot people picking the one revelation that really bothered them and then framing all others relative to that: "they're doing Y too? Wh…

"I wonder if the public, US or otherwise (as we find more countries with intelligence agencies working as accessories), will experience outrage fatigue." Unfortunately, I fear the mainstream mindset towards this issue will hinge on how the major political candidates in the 2016 election choose to frame the issue. If there's widespread consensus from the leading Presidential candidates in both parties that this is not…

This is a very insightful way to look at things and it highlights the role of the leadership. In current world not much of the stuff matters, actually, as it is very high on the Maslow's pyramid. So it has to be thought leaders who define the course of action for the "careless masses" (TM).

Re: Dear USA, my data has left your building

#110
post #59
post #5

Over the last month I have cancelled all our servers in US, setting up a new one this morning in Amsterdam One thing I am worried about is potential liability of having someone sueing us under data protection laws here in Ireland, claiming their data was inspected by US and we couldnt protect their privacy Here in Europe we get to have data protection commisioners and strong laws on the subject unlike across the pond…

One thing I don't entirely understand is whether having an EU-based server provided by an US company (Rackspace, AWS, Digital Ocean, you name it) makes any difference at all.

A server that is located in the EU is almost certainly owned and operated by a EU-based legal entity that is a wholly owned subsidiary of the US parent. So strictly speaking you would be getting your services from a EU company that is owned and controlled from the US but that is subject to all the relevant local laws.
Post reply on HN