Live data from Hacker News

Dear USA, my data has left your building

cpbotha.net

151–158 of 158 posts

Re: Dear USA, my data has left your building

#151

It's a bit naive to believe that after Google may have deleted your emails (no good reason to trust them, I'm afraid), the NSA also no longer has access to them. They picked them up as they arrived at or left your Gmail account and will keep them forever.

I hate responses (and attitudes) such as this. It's as if you've concluded that anything you do going forward is pointless and a waste of time.

I am not yet ready to come to that conclusion and have recently stepped up my efforts to better protect my data -- both at rest and in transit -- and encourage everyone else to do the same.

Re: Dear USA, my data has left your building

#152

GCHQ is not exactly any rosier than the NSA. I don't know why OP imagines that WebFaction (UK company) is immune to spying in a way that Google isn't. I'm afraid this will be characteristic of the anticipated mass exodus. People will move away from US services because it makes them feel good, but their destinations are going to be either Five Eyes territory or countries that don't even feel a need to hide their surve…

At least for e-mail, I think the idea is to ensure that a cloud provider doesn't have a long backlog of his e-mails. Of course, if the NSA take an interest in him, they'll still find a way to monitor his current e-mails, but this makes it harder for them to pull all his past e-mails. I doubt WebFaction is secretly storing all the e-mail he has deleted, because that costs money, and they can't show advertising next to…

We know that the Five Eyes have ISP-level taps. Why do we think they aren't reading SMTP as it flows across WebFaction's datacenter?

Re: Dear USA, my data has left your building

#153

I recently deleted my Google+ profile. I have to say that Google is among the nice ones out there. They have a no-nonsense process with tools in place to export the data and delete accounts. Facebook/Quora make it really difficult to delete your data. It's ironic that it's easier to leave the good corporations than the bad ones.

Since when Quora too make the cut to the baddies?

Re: Dear USA, my data has left your building

#154
post #146

Earlier quoted context omitted.

The data retention directive is undoubtedly problematic, but if it is implemented according to law, it means that telcos will hand over metadata on individual accounts at the request of a court. There are no secret courts, no gag orders and no dragnet mining of content as opposed to metadata. But of course that says nothing about what European police organizations are up to ... secretly. I'm thinking of things like t…

How un-secret are they? Is there a room I can go sit and watch search warrants being requested and issued? If not, why do you believe it's better than the US situation?

The existence of such a room is not the only way in which the situation could possibly be better than in the US. In fact, such a room would itself be a gross violation of privacy.

I think I explained in which ways I think it is better as far as the data retention directive is concerned. Whether or not it is really better in practice considering what police in any particular country might do, that I don't know. Maybe we need our own Snowden to tell us that.

Re: Dear USA, my data has left your building

#155
post #146

Earlier quoted context omitted.

How un-secret are they? Is there a room I can go sit and watch search warrants being requested and issued? If not, why do you believe it's better than the US situation?

The existence of such a room is not the only way in which the situation could possibly be better than in the US. In fact, such a room would itself be a gross violation of privacy. I think I explained in which ways I think it is better as far as the data retention directive is concerned. Whether or not it is really better in practice considering what police in any particular country might do, that I don't know. Maybe…

I was asking a question, not saying you're wrong. I'm genuinely curious what forms of transparency exists in the EU, and how it curbs abuses.

Re: Dear USA, my data has left your building

#156
post #43
post #7

Nitpickers aside (yes, what they had they may still have or at least in digest form) this is a single instance of a tidal wave of people doing this. EU datacenters are doing quite well because of the NSA revelations. The economic impact of this could very well counteract any net plus the US had while they were able to spy at will. Likely it's not going to be the same parties that will end up footing the bill. The pra…

It will however have an economic impact on US, if you do that. Think of it as "voting with your wallet". You're voting with your wallet against US. It's also a political stand. As a foreigner who can't vote against the current US government, or even as a US citizen, your action can have a political impact.

Our political system sucks. I'm deeply affected by the US or Russian government's actions - because the Internet is mostly American and Russian, yet I don't have rights to influence decisions in either of those countries. Our country's minimum monthly wage is $211 and our average - $500, so there isn't even a lot of voting with our wallets that we can do. The only choice I had is to donate to Fight for the Future and plan moving everything to a home server, essentially reverting to my setup from 5 years ago.

Re: Dear USA, my data has left your building

#157

Earlier quoted context omitted.

At least for e-mail, I think the idea is to ensure that a cloud provider doesn't have a long backlog of his e-mails. Of course, if the NSA take an interest in him, they'll still find a way to monitor his current e-mails, but this makes it harder for them to pull all his past e-mails. I doubt WebFaction is secretly storing all the e-mail he has deleted, because that costs money, and they can't show advertising next to…

We know that the Five Eyes have ISP-level taps. Why do we think they aren't reading SMTP as it flows across WebFaction's datacenter?

They are quite probably reading it, and I think I read something about a buffer of a few days that they kept things for. But they're probably not keeping all of everyone's communications in case they want to refer to them in five years time. Whereas on GMail they can dig back through years of old e-mails as well.

At the very least, it adds a small per-person cost to their surveillance, because they have to store copies of e-mails themselves rather than getting Google to do it.

Re: Dear USA, my data has left your building

#158

Earlier quoted context omitted.

I have a Synology device (exact same model as the article author actually, and likewise I love it). However I'm having trouble finding a way to back it up securely. The built-in backup methods don't seem to account for encrypting the backups (even if the volume is encrypted). Any suggestions?

However I'm having trouble finding a way to back it up securely. The built-in backup methods don't seem to account for encrypting the backups (even if the volume is encrypted). Any suggestions? Two suggestions: A) Download the source [1], and see if it is complete and then you can port in cryptsetup and the LUKS stuff from Linux. B) Run Linux. If you're at the point where you're worried about encrypted backups, then…

Actually the Diskstation runs Linux already, and I have full SSH access to it. It uses ecryptfs already, and I love the thing. I am glad I chose it over building my own (and that's not something I expected to be saying before I bought it).

My question was purely about backing it up securely. I'm guessing rsync'ing the encrypted volume is the answer, just need time to look into it.

Post reply on HN