Live data from Hacker News

Microsoft Can't Keep EU Data Safe from US Authorities

forbes.com

111–120 of 136 posts

Re: Microsoft Can't Keep EU Data Safe from US Authorities

#111

Earlier quoted context omitted.

The max penalty for things like this is actually life inprisonment though. If you, to aid a foreign power without authorization gather certain types of information, it's espionage. There wouldn't be any lawsuit. If you do this kind of things you get arrested, get a trial and then you are in prison forever.

except we are speaking about lying under oath, not espionage, you don't get a trail for espionage because you lie under oath and leading management also technically doesn't need to know that is happens for it to be doable. Or in other words they have a lot of reason to "accidentally" not know about it/have it overlooked this means even if it happens they are very unlikely to be charged for anything more then negligen…

He wouldn't even be charged for lying under oath if he lied and it became apparent, because there'd be not considering the much more serious espionage charges. They'd only prosecute the espionage part.

Participating in a plot to supply french state information to the US is espionage. France also apparently has a broad definition of espionage, relative to some other EU countries.

States have a tendency of coming down rather harshly on this kind of thing, so this idea about negligence is I think unlikely. If you know about it the charges will be espionage charges. If it happened it would be the biggest thing ever. They'd arrest most Microsoft employees in relevant teams as well the leadership, probably many others too. Just interrogation would probably take half a year due to lack of interrogators.

Re: Microsoft Can't Keep EU Data Safe from US Authorities

#112

Another take: Microsoft admitted under oath in France that the US government doesn't care enough about French data to ever have requested any. I'm sure if you asked the current administration what they think of France, they'd reply, "all they do is wine!"

The current administration will have difficulties pointing to France on a map.

Re: Microsoft Can't Keep EU Data Safe from US Authorities

#113

Earlier quoted context omitted.

Signal used to never collect data on users, but they've changed that a while ago and now they keep user's name, photo, phone number, and a list of their contacts permanently in the cloud protected from the government by nothing except by a leaky enclave and a pin ( https://web.archive.org/web/20250117232443/https://www.vice.... ) More recently they've started collected the contents of messages into the cloud too, yet…

You're able to disable the pin feature to prevent that data from being saved though, so it definitely isn't a requirement. I'm also not sure where you've read that they collect the contents of messages, because as far as I'm aware they still aren't doing that and I can't find any info online that indicates that they are (other than their secure backup feature that's opt-in only I suppose)

Actually you can't. If you choose not to set a pin, Signal just chooses one for you and uses that to upload all your data, only you won't be able to access it. There is no way to prevent your data from being sent to the cloud. For more info see here: https://old.reddit.com/r/signal/comments/htmzrr/psa_disablin... and https://community.signalusers.org/t/what-contact-info-does-t...

The fact that Signal users are still unaware of where their data is going and when should tell you all you need to know about how trustworthy the service is. Not being 100% clear about the risks people take when using software which is promoted for use by people whose freedom and/or lives depend on it being secure is a very bad look for Signal.

As for message backups they are at least opt-in (for now anyway) and you can learn more about them here: https://signal.org/blog/introducing-secure-backups/

Re: Microsoft Can't Keep EU Data Safe from US Authorities

#114

Earlier quoted context omitted.

The US by and large can (and does) assert authority outside of its jurisdiction, from which another country can choose to capitulate. Most of the time countries do, because they are all swapping data on their citizens between themselves to skirt various laws. In the case where the US really wants something, and the country won't yield, they'll fund contras or destabilize the government (if small enough to be bullied)…

The unfortunate truth, 300,000 years later and humans still operate on "might makes right" whether militarily, or economically.

If the violent, untrustworthy, Americans choose to go to war with their former allies over some data then that's their choice. Better than just giving these warmongers everything they want.

Re: Microsoft Can't Keep EU Data Safe from US Authorities

#115

Earlier quoted context omitted.

That's just not possible. It's why detractors never got on board with the Cloud. Until FHE is feasible, the decryption keys and plaintext have to exists in RAM eventually at some point in order even if only took be re-encrypted, if any complex work is to be done on it. Because eg, Amazon, has access to your hardware, there's simply no way to prevent them from reading your secrets out of your VM that's using their RAM…

Ok I thought that was the whole point of things like Intel TDX , AMD SEV and various enclave mechanisms which provide full ram encryption and attestation ? The only issue left would be managed services though, which then I wouldn’t use, but I’d be able to run my own postgre safely on infra I’m renting.

Supposedly, yes, but in a world that was caught flat footed with RowHammer, Spectre, and Meltdown; if I wouldn't trust those with a lot of other people's lives within a shared Cloud environment.

Intel's SGX has been broken a number of times and that should be harder to break than TDX. Like I said in my original comment though, do all the things. But if you find yourself relying on TDX to protect live(s), please pay a computer security professional to audit your security and do a threat assessment.

Re: Microsoft Can't Keep EU Data Safe from US Authorities

#116

Earlier quoted context omitted.

Might have Something to do with the current US administration tweeting pictures of confidential material in the past, exposing their capabilities to the world. Intelligence community members tend to hold their cards close to their chests.

I mean, do you see any actual moves they’ve made to move away from the US? I don’t. They always make a lot of noise about how this time they’re not going to take the depredations of the US before doing just that.

I'm flattered that you think that the intelligence agencies of the four other "eyes", Australia, Canada, New Zealand; would tell me their moves, or that I'd hear about it, but honestly, I'm not that important.

Seriously though, what are you expecting to hear? For the CSIS to post to Twitter what they're hiding from the CIA, as if the CIA hasn't heard of Twitter or something? Or for the GCSB to broadcast which billionaires are making bunkers in Hammer Springs to /r/secretbillionairebunkers like someone is wrong on WarThunder?

What I'm saying is the spooks of their respective countries are just gonna keep a bit more to themselves and not tell the US because the think someone in the current US administration is going to leak it, putting their assets at risk. The respective secret agencies haven't put out coordinated press releases saying they're doing this or gone on the talk show tour to talk about it, so I have no proof, but it seems quite possible to me that they are.

Re: Microsoft Can't Keep EU Data Safe from US Authorities

#117
post #87
post #66

Earlier quoted context omitted.

Apparently someone buys it, otherwise AWS would not invest 8+ billions in Germany: https://www.aboutamazon.eu/news/aws/aws-plans-to-invest-7-8-... "If it's certified, it must be good".

They buy it because it's enough to tick the corporate compliance box. Decisions made by people that don't actually give a F

It's all because of something that started years ago: the move to the cloud.

Companies started to move to cloud like there was no tomorrow.

Their on-prem products became maintenance or zombies.

Now you want the self hosted? Good luck.

What's the alternative for a SaaS provider? Support all the possible cloud alternatives? That's nearly impossible, so some companies (mainly big organizations) provide their software/SaaS in AWS gov regions and so be it.

(Or... be smart, see the trend and start selling your software again in self-hosted solutions!)

For a consumer (gov, for example) this means: you don't have that feature, you give in, or you build it/let it build (open source).

This is the only reason why we saw the recent announcement of the Austrian govt that was able to migrate from MS to Nextcloud. Without an alternative, ... they couldn't have done anything.

Re: Microsoft Can't Keep EU Data Safe from US Authorities

#118
I wonder why people are surprised, as this is an open secret nobody is willing to admit. And it's basically the reason we had Schrim I and Schrim II.

At the same time a massive migration from US cloud in EU to EU cloud would be a massive pain for a lot of companies in the EU.

Re: Microsoft Can't Keep EU Data Safe from US Authorities

#119
post #60

This applies to any company, doesn't it? Your home country can tell you "Give us your data" and you have to comply. "I will never give up customer data" is a very tough promise to keep, if the government threatens you with your business license being revoked, your servers and domains being forcibly seized by the police, and you personally going to jail. (Under the current US administration, we can add "A close examin…

Your home country can tell you "Give us your data" and you have to comply

Not according to both Amazon's and Microsoft's historic marketing materials. They have always claimed that data stored in your local jurisdiction is not accessible to law enforcement abroad. And the US judiciary initially agreed with that: https://petri.com/microsoft-wins-appeal-data-stored-abroad-s...

...which then led to the US CLOUD act and here we are, once again, proving that the past is alterable; just like Oceania has always been at war with Eurasia.

Re: Microsoft Can't Keep EU Data Safe from US Authorities

#120
post #106

Earlier quoted context omitted.

What would stop them from doing that?

Capital flight

The alleged existence of this mechanism requires kind of a long feedback loop, and might not be reliable enough for some potential customers' taste.
Post reply on HN