Earlier quoted context omitted.
Ok I thought that was the whole point of things like Intel TDX , AMD SEV and various enclave mechanisms which provide full ram encryption and attestation ? The only issue left would be managed services though, which then I wouldn’t use, but I’d be able to run my own postgre safely on infra I’m renting.
Supposedly, yes, but in a world that was caught flat footed with RowHammer, Spectre, and Meltdown; if I wouldn't trust those with a lot of other people's lives within a shared Cloud environment. Intel's SGX has been broken a number of times and that should be harder to break than TDX. Like I said in my original comment though, do all the things. But if you find yourself relying on TDX to protect live(s), please pay a…
Microsoft Can't Keep EU Data Safe from US Authorities
121–130 of 136 posts
Re: Microsoft Can't Keep EU Data Safe from US Authorities
#122Earlier quoted context omitted.
This is why I still prefer Signal; this practice seems to be their modus operandi even though they, too, were affected by AWS us-east-1 catastrophe
Signal used to never collect data on users, but they've changed that a while ago and now they keep user's name, photo, phone number, and a list of their contacts permanently in the cloud protected from the government by nothing except by a leaky enclave and a pin ( https://web.archive.org/web/20250117232443/https://www.vice.... ) More recently they've started collected the contents of messages into the cloud too, yet…
Alternatives?
Was hard enough getting my circle on signal.
Re: Microsoft Can't Keep EU Data Safe from US Authorities
#123Earlier quoted context omitted.
Specifically here, he is under oath in France so an American gag order wouldn't protect him from the French justice system. This make it less likely he's lying. It could be possible Microsoft France has a "rogue" employee system where a key person only obeys to Microsoft US orders rather than his French boss and French law. Then the boss can swear to the Senate that they're complying. This is exactly the system the U…
> This is exactly the system the US Congress accused TikTok of having set up. "Every accusation is a confession" remains undefeated
--
As a side rant:
"Specious accusations are often confessions."
I understand the psychology and casual use of absolutely worded reactions, and that their extreme expression is not taken literally, but as emphasis. But I still prefer balanced wording.
A surprisingly large number of people tragically clash and talk past each other over charged non-issues, that normal undramatic language would render moot.
I.e. "We must believe all X", vs. "We should listen to all X", ... and many more.
"Black Lives Matter Too", isn't as pithy. Nor should the last word be necessary for anyone to understand the three word version. But the fourth word, nodding to the wider context, pre-counters a lot of ridiculous responses to the original line. Not actually suggesting a sea change in a well recognized movement banner line. But it is a widely observed example of how any lack of pedantic clarity is seized upon by motivated reactionaries, to achieve politically significant impact via obtuse reinterpretation.
A little verbal pedantry is an effective speed bump against the siren song of motivated or inadvertent polarization.
Re: Microsoft Can't Keep EU Data Safe from US Authorities
#124Earlier quoted context omitted.
Supposedly, yes, but in a world that was caught flat footed with RowHammer, Spectre, and Meltdown; if I wouldn't trust those with a lot of other people's lives within a shared Cloud environment. Intel's SGX has been broken a number of times and that should be harder to break than TDX. Like I said in my original comment though, do all the things. But if you find yourself relying on TDX to protect live(s), please pay a…
eg, https://news.ycombinator.com/item?id=45746753
I’ll do all the things if ever needed, but I get that if a cloud act request happens , your cloud provider will be able to get your stuff.
I’m specialized enough in another field to know that I’m not a security person in spite of my interest in it ( I used to enjoy reverse engineering back in the days ) - I wouldn’t make that kind of decision without consulting a professional first.
Re: Microsoft Can't Keep EU Data Safe from US Authorities
#125Earlier quoted context omitted.
> This is exactly the system the US Congress accused TikTok of having set up. "Every accusation is a confession" remains undefeated
Agreed. -- As a side rant: "Specious accusations are often confessions." I understand the psychology and casual use of absolutely worded reactions, and that their extreme expression is not taken literally, but as emphasis. But I still prefer balanced wording. A surprisingly large number of people tragically clash and talk past each other over charged non-issues, that normal undramatic language would render moot. I.e.…
People who are not operating in good faith won't operate in good faith. There were thousands of words written on the phenomenon protested by BLM, but those are easily ignored. Three words are twisted and co-opted by propagandists. Consider a function that describes "comprehension by bigots" as a function of word count. We know that 0 words yields 0 comprehension. Evidence suggests that 10k words also yields 0 comprehension. There is no evidence that this Laffer curve will ever achieve anything other than zero.
It's possible to reach and change bigots' minds, but it requires human connections. Not sloganeering, prose, or reels.
Re: Microsoft Can't Keep EU Data Safe from US Authorities
#126Earlier quoted context omitted.
Signal used to never collect data on users, but they've changed that a while ago and now they keep user's name, photo, phone number, and a list of their contacts permanently in the cloud protected from the government by nothing except by a leaky enclave and a pin ( https://web.archive.org/web/20250117232443/https://www.vice.... ) More recently they've started collected the contents of messages into the cloud too, yet…
Well shit. Alternatives? Was hard enough getting my circle on signal.
Re: Microsoft Can't Keep EU Data Safe from US Authorities
#127Earlier quoted context omitted.
Agreed. -- As a side rant: "Specious accusations are often confessions." I understand the psychology and casual use of absolutely worded reactions, and that their extreme expression is not taken literally, but as emphasis. But I still prefer balanced wording. A surprisingly large number of people tragically clash and talk past each other over charged non-issues, that normal undramatic language would render moot. I.e.…
It's naive or foolish to think that the problem with "Black Lives Matter" was insufficient specificity. People who are not operating in good faith won't operate in good faith. There were thousands of words written on the phenomenon protested by BLM, but those are easily ignored. Three words are twisted and co-opted by propagandists. Consider a function that describes "comprehension by bigots" as a function of word co…
I wasn’t making a hard argument.
Words are not everything. Still, they matter.
To the degree that pushback against anti-minority mistreatment can be framed as pro-universal (reciprocal) respect, I think it helps. Given the latter is in fact the real, most general, and most relevant principle.
That avoids the framing created and imposed by biases. I.e. that somehow, race or other category is the question, instead of (logically and morally) irrelevant to the value of reciprocal respect. Not forgetting the point of it all, avoids actual or perceived reverse biasing. Minority rights and equality being interpreted by either side as anti-majority, or being at the expense of anyone.
Some shrill minority defenders do manage to imply that, as well the people having trouble respecting some group.
This are just thoughts based on what I find works better in personal encounters with people I know or ran into, who had/have difficulty seeing the world without in-group, out-group filters of various kinds.
Keep the simple, general, most important thing clear and center.
Avoid letting the conversation be artificially narrowed by exactly the destructive framing we want to push back on. The narrower the framing the more people forget, ignore, and successfully distract from the main principle. The more people get bogged down in narrower and narrower arguments, the less people understand each other.
Re: Microsoft Can't Keep EU Data Safe from US Authorities
#128Earlier quoted context omitted.
If the data center is operated by a "trusted subsidiary" as the article mentions and everyone in key roles is a French citizen with no connection to the US then there is no one to give a gag order. In practice the US HQ could mandate a security update that secretly uploads all data to the US but that's a whole other can of worms that I don't think anyone is ready to open.
> In practice the US HQ could mandate a security update that secretly uploads all data to the US but that's a whole other can of worms that I don't think anyone is ready to open. incredibly ambiguous/unsatisfying sentence. if this french hearing is concerned about french data security, then asking a question about your "in practice" is exactly a can of worms the french would like to open.
Re: Microsoft Can't Keep EU Data Safe from US Authorities
#129This applies to any company, doesn't it? Your home country can tell you "Give us your data" and you have to comply. "I will never give up customer data" is a very tough promise to keep, if the government threatens you with your business license being revoked, your servers and domains being forcibly seized by the police, and you personally going to jail. (Under the current US administration, we can add "A close examin…
> This applies to any company, doesn't it? Your home country can tell you "Give us your data" and you have to comply. Not all countries have an equivalent to the USA CLOUD Act.
Not yet, anyway. Unfortunately, pretty much every country seems to be getting less and less open and free over time. Some are better than others, but it does feel like everyone is regrettably rowing in same direction.
Re: Microsoft Can't Keep EU Data Safe from US Authorities
#130This applies to any company, doesn't it? Your home country can tell you "Give us your data" and you have to comply. "I will never give up customer data" is a very tough promise to keep, if the government threatens you with your business license being revoked, your servers and domains being forcibly seized by the police, and you personally going to jail. (Under the current US administration, we can add "A close examin…
> "I will never give up customer data" is a very tough promise to keep If you don't have a spine, sure That's what US companies are seen as from a European perspective: Spineless and untrustable It's a great sales argument for locally grown software though, so I'm not complaining :)
I've never understood this take. A lot of people were saying this sort of thing when Proton Mail turned over some user data to authorities in Europe a while back.
If you're running a tech company and run afoul of the law in some or another jurisdiction, it doesn't matter how much spine you think you have. When a group of men with guns, i.e. the police, shows up at your door and gives you the option of turning over some customer data or spending the next 10 years of your life in a steel cage, I'm betting that practically no one is going to choose the cage, spine or not.
The only way to keep user data safe is to not collect it in the first place.