Live data from Hacker News

Norwegian backup provider promises NSA-free data storage using Norwegian laws

jottacloud.com

121–125 of 125 posts

Re: Norwegian backup provider promises NSA-free data storage using Norwegian laws

#121
post #103
post #44

Earlier quoted context omitted.

Well, what you say is not correct. First of all the Data Retention Directive have to be valid for you. I work for the Norwegian email provider Runbox and the EU Data Retention Directive is not applicable for us. It is only valid for carriers that own their own infrastructure down to the data center, called "communication providers". We even have it confirmed by both Kripos (FBI-ish) and Post- og Teletilsynet (Norwegi…

This sounds strange, as far as I understand it: http://www.lovdata.no/ltavd1/filer/sf-20130514-0484.html#1-2 http://www.lovdata.no/ltavd1/filer/sf-20130514-0484.html#2-6 together states that if you provide email services, you are required to store metadata (which is what the Data Retention Directive is all about). On a side note, if the secret services cooperate to do massive ingress/egress storage of data on the net…

If you are a layman, it does. But this quote is very restrictive in the interpretation by Post og Teletilsynet: "Tilbyder av elektronisk kommunikasjonsnett som anvendes til offentlig elektronisk kommunikasjonstjeneste og tilbyder av offentlig elektronisk kommunikasjonstjeneste er lagringspliktig."

What we dont do is offer "Tilbyder av elektronisk kommunikasjonsnett". That means we are outside. Then the rest is not relevant.

We have been in the courts about this and both Kripos (they wanted information) and the judge found that we are outside the scope of this.

Re: Norwegian backup provider promises NSA-free data storage using Norwegian laws

#122
post #41

As a Norwegian, let me just say: Yeah, right. 1. The Norwegian security services have a long history of violating Norwegian law (and when, for example, extensive illegal politically motivated surveillance of mostly left wing politicians was uncovered in the 90's they then had the gall to place an MP and member of the committee investigating them under surveillance while he was working on the report about their illega…

Thank you for taking the time to describe this. I'd been, naively, hoping -- yet to research -- that Norway might be somewhat better than Sweden. I'm coming to the impression that none of the Scandinavian countries may be particularly friendly to data privacy advocates.

How did you come to that conclusion?

Re: Norwegian backup provider promises NSA-free data storage using Norwegian laws

#123
post #53

Earlier quoted context omitted.

It does, but they dont offer email or phone services. So they are also exempt. We use Blix: https://www.blix.com/ What you call a loophole, was no secret in the hearings about the new law. The government wanted this implemented mainly for the phone providers. They understood that foreign email providers like Gmail and Hotmail that most use in Norway, could not be under the law in any practical way, so they restricted…

I read your website and tried your service for a few days this past April. I cancelled immediately after you emailed both my web hosting and support account credentials. In plain text. That is egregious. I mention this only to point out that without proper security procedures your data privacy policy is irrelevant. Not one-way hashing and salting passwords negates everything else you do. I'm happy to try again some d…

Both your web hosting and support account credentials are encrypted. I see you point not sending them to you when you setup the services, but you have to understand that we do offer services for a wide range of people. Some really want a copy of their login in their email that they have locally.

But I take your point about this and we will try to make that optional. It is optional when you setup email sub-accounts for the administrator.

Re: Norwegian backup provider promises NSA-free data storage using Norwegian laws

#124
post #103

Earlier quoted context omitted.

This sounds strange, as far as I understand it: http://www.lovdata.no/ltavd1/filer/sf-20130514-0484.html#1-2 http://www.lovdata.no/ltavd1/filer/sf-20130514-0484.html#2-6 together states that if you provide email services, you are required to store metadata (which is what the Data Retention Directive is all about). On a side note, if the secret services cooperate to do massive ingress/egress storage of data on the net…

If you are a layman, it does. But this quote is very restrictive in the interpretation by Post og Teletilsynet: "Tilbyder av elektronisk kommunikasjonsnett som anvendes til offentlig elektronisk kommunikasjonstjeneste og tilbyder av offentlig elektronisk kommunikasjonstjeneste er lagringspliktig." What we dont do is offer "Tilbyder av elektronisk kommunikasjonsnett". That means we are outside. Then the rest is not re…

Ok, it wasn't entirely clear to me that you'd been in court over this after the law was enacted. That certainly is good news.

Does indeed sound like the directive is tailor made to make ingress/egress snooping on data useful. The kind of snooping we saw with NSA's "secret rooms". Such illegal wire tapping would fit very well with meta data stored at the ISP level -- and could also explain why anyone not at that level are not required to store meta data (it would be redundant).

Re: Norwegian backup provider promises NSA-free data storage using Norwegian laws

#125
post #118
post #42

Earlier quoted context omitted.

Stay away from the UK - here a judge can throw you in jail for failure to provide keys, even if there's no evidence you still have the keys, and said judge would pretty much be guaranteed to believe that you did not hand over the correct keys if the result is garbage.

If you claim the encryption was done using a One Time Pad, you can pick any result you want, generate the corresponding key, and hand that over. https://en.wikipedia.org/wiki/One-time_pad

Unfortunately, the OTP is always as large as the encrypted data. So strictly speaking, this is not really "encrypted data + password" but more of a "split data into two random-looking parts". In particular, this is nothing you can keep in your head or print on paper.

You'd have to keep it on a separate storage medium. And if you have to hand out the done medium, what's preventing them to get your second medium? And if you are able to keep that second medium secret and safe, why don't you store the whole unencrypted data on it in the first place?

Either way: OTPs are really cool, but I don't think they have any relevance here.

Post reply on HN