Live data from Hacker News

Dear USA, my data has left your building

cpbotha.net

131–140 of 158 posts

Re: Dear USA, my data has left your building

#131
post #26

I suspected there was going to be a mass exodus. NSA basically killed cloud-computing. I don't think it will come back soon. And while on the subject, consider selling your Microsoft stock. How many enterprise customers will choose Microsoft products again after 2013?

> NSA basically killed cloud-computing. I don't think the current disgust will last too long. A lot of people will move, at some point they'll realize the grass isn't all that much greener on the other side. There is a definite activation energy required for such a move and I'm sure that the NSA debacle provided just that for a fairly large number of parties but in the very long term the difference will be small. (In…

No, current disgust won't last too long, but it is currently being transformed into future policy at almost ever shop that uses cloud services, from governments, major corporations to small companies that outsource their IT needs.

And those policies, which can be summarized as "we won't store our shit with US companies" will last for decades.

It may take many years before they are fully implement because nobody wants to throw money at migrating legacy with no immediate financial upside. Besides, in many cases there aren't yet sufficient competing non-US services that meet all requirements.

It will be a slow exodus, but it will also be a massive and irreversible exodus.

Re: Dear USA, my data has left your building

#132
post #126

Earlier quoted context omitted.

It's scary that they don't care but not surprising. We live in a world where the majority of people with privilege are comfortable with the fact that racial profiling still pervades the criminal justice system. In fact, such a statement will be viewed as controversial and debate will be diluted by meaningless argument about whether racial profiling exists or whether the use of the term, "privilege," is even fair. Pri…

Please explain what "the reality" is in regards for what they use it for that is more frightening.

From: http://www.nsa.gov/public_info/_files/speeches_testimonies/2...

     When conducting 702 FISA surveillance, the only information NSA obtains results from the use of specific identifiers (for example email addresses and telephone numbers) used by non-U.S. persons overseas who are believed to possess or receive foreign intelligence information.
     
     Foreign terrorists sometimes communicate with persons in the U.S. or Americans overseas. In targeting a terrorist overseas who is not a U.S. person, NSA may get both sides of a communication. If that communication involves a U.S. person, NSA must follow Attorney General protects the privacy of U.S. persons.

     The collection under FISA section 702 is the most significant tool in the NSA collection arsenal for the detection, identification, and disruption of terrorist threats to the U.S. and around the world.
It's probably all true. I'd wager the majority of information gathered from surveillance activities under the FISA is to spoil terrorist threats against the U.S. However denials like this have a way of avoiding the definition of, "terrorist threat," or explaining the scope and restrictions the information so gathered must be used.

I suspect they might use the aforementioned section of the FISA to enable the extradition and persecution of whistle-blowers as terrorists. This would allow them to black-van these people and remove them from the world. However one can only speculate that this is true. And therein, in my opinion, lies the danger.

Edit formatting issues...

Re: Dear USA, my data has left your building

#133

I recently deleted my Google+ profile. I have to say that Google is among the nice ones out there. They have a no-nonsense process with tools in place to export the data and delete accounts. Facebook/Quora make it really difficult to delete your data. It's ironic that it's easier to leave the good corporations than the bad ones.

Was your data actually deleted, or does Google still have it?

They said that they will delete the data "over a few days". I only deleted my Google+ profile, not the entire Google account and I had manually emptied the profile anyway.

Re: Dear USA, my data has left your building

#134
post #38

Earlier quoted context omitted.

Maybe it's time EU, Latin America, and most of the Asian countries start banning US hardware, too - you know, just like US started banning Huawei, for the same reasons.

So, would we use Chinese hardware? It probably has backdoors too.. And at least here in Latin America I believe there aren't enough hardware providers to build anything resembling a modern computer.

> So, would we use Chinese hardware? It probably has backdoors too..

Indeed, but at least the backdoors aren't used to feed an establishment that has a track record of rendition, UAV assassination and technology-based lethal sabotage.

Re: Dear USA, my data has left your building

#135
post #68

"My webhoster (WebFaction) receives mail for all my domains. My Synology retrieves mail every 5 minutes via POP (you can set this up via Roundcube on the Synology) and deletes it from WebFaction." but even if you can delete your mail from your mailhost after downloading it to your private machine, isn't the point that the NSA probably collected the email before it even hit your mailhost?

I haven't looked at the revelations in detail, but I don't think they're recording copies of every e-mail they intercept to anyone. If your account is already of interest to them, they're probably watching your e-mails, but if they take an interest in it 10 years in the future, that's when they go to GMail and grab all your past e-mails. So storing your e-mails on a computer you control probably still has some effect for most of us.

Re: Dear USA, my data has left your building

#136

GCHQ is not exactly any rosier than the NSA. I don't know why OP imagines that WebFaction (UK company) is immune to spying in a way that Google isn't. I'm afraid this will be characteristic of the anticipated mass exodus. People will move away from US services because it makes them feel good, but their destinations are going to be either Five Eyes territory or countries that don't even feel a need to hide their surve…

At least for e-mail, I think the idea is to ensure that a cloud provider doesn't have a long backlog of his e-mails. Of course, if the NSA take an interest in him, they'll still find a way to monitor his current e-mails, but this makes it harder for them to pull all his past e-mails. I doubt WebFaction is secretly storing all the e-mail he has deleted, because that costs money, and they can't show advertising next to it.

Re: Dear USA, my data has left your building

#137
post #53
post #52

"The loss of GMail conversation view was initially really REALLY painful." I recently experienced the same pain with Thunderbird after moving away from the new Gmail compose interface however I've since moved on to Airmail [1] which deals with conversations (and other Gmail behaviours (shortcuts etc) in a very similar way to Gmail and am extremely happy with the move. [1] http://airmailapp.com

Thanks for the tip! I use Linux on all my laptops and workstation, so unfortunately I can't use airmail or postbox (windows + osx) for this.

Geary is a mail client for Linux with a similar interface to conversation view. It's still fairly young, so not entirely polished, but it is usable.

Edit: usable, but seemingly with no support for encryption/signing, among various other things. Maybe it needs a bit more time to be ready.

Re: Dear USA, my data has left your building

#138
post #7

Nitpickers aside (yes, what they had they may still have or at least in digest form) this is a single instance of a tidal wave of people doing this. EU datacenters are doing quite well because of the NSA revelations. The economic impact of this could very well counteract any net plus the US had while they were able to spy at will. Likely it's not going to be the same parties that will end up footing the bill. The pra…

Perhaps the only language that the US will understand is a loss of business?

Re: Dear USA, my data has left your building

#139

Earlier quoted context omitted.

I think you're right. Even moving your mail or web server to another country won't help deter the actual collection with prism. However, I think responses like this create tension between the companies agreeing to give their information, and the government. If google, yahoo, and facebook start to lose money they might potentially fight legislation like this going forward and may advocate in reverting these policies.

This is probably the biggest thing we need to work towards. Sure, leaving gmail might be painful and it might not really help us out in the end (regarding preventing spying) but hurting the big players enough for them to move into offense mode is a great scenario.

Reading this comment made me feel uneasy, and I couldn't tell why. After giving it some thought, I found the reason.

There is nothing wrong with the argument, it is sound logic, and reasonable. In fact, I agree with it. No, this comment made me recoil because for a second, it made me envision a reality where our political influence, as people, can only be exercised through corporations.

And, (maybe, I confess, because I am so deep into the lecture of cloud atlas) I can't help but sense that it is a dangerous road to be embarked on. But these are just my two cents...

Re: Dear USA, my data has left your building

#140
post #13

Obviously we[1] sympathize with this, since we've been running a swiss location since 2006 - one that has become increasingly busy in the last 3-4 months. However, I personally don't store my data there - even though I am deeply disturbed by the recent revelations and invoke all manner of security precautions in my own digital life. First of all, it appears that intra-US Internet traffic is subject to less scrutiny a…

I don't know much about rsync.net or if you guys provide a quick client-side encrypted storage method (though a quick glance at your FAQ seems to suggest otherwise). But the reason Gmail is not being trusted is that there is some possibility the NSA has backend access to their servers via various kinds of legal arm-twisting they are not allowed to talk about. I don't encrypt the mails I send via Gmail before they hit…

Duplicity is a quick, client-side method that works over plain old SSH. There are some fancier ways to do it with git that we have recipes for.

The answer to your question, though, is no - we don't have anything. We just have raw disk that you access over SSH.

So you can do whatever you want. That's the point. If any party had backend access to our servers, it wouldn't matter if you used a reasonable (and simple) toolchain.

Post reply on HN