Live data from Hacker News

Cock.li server seized again by German prosecutor, service moves to Romania

arstechnica.com

21–30 of 30 posts

Re: Cock.li server seized again by German prosecutor, service moves to Romania

#21

Ignoring the childish domain name, hopefully the discussion won't go down that route again - that guy seems quite sincere and explains the situation quite well. My take away: Don't (blindly) trust Germany, and certainly don't use Hetzner. If he's correct ("Hetzner didn't provide a copy of the confiscation order to me or my lawyer") I'm glad to be the first in this community that runs around, arms flailing, shouting "…

Hetzner actually has the reputation that they take things down that they think are critical and that they happily coorperate with each official request.

It seems this things are not known outside of the german internet tho. Its a nice hoster, and cheap, but they dont care to fuck around for a few dollars and rather delete/close/remove.

Re: Cock.li server seized again by German prosecutor, service moves to Romania

#22
post #11

Earlier quoted context omitted.

Yeah, Hetzner also has this strange habit of spitting out SQL errors when you put apostrophes into forms on their website. I'd avoid them.

As someone who just applied for (and failed to get) a job at a DB company: Not sanitizing your inputs is unacceptable, even for a newbie . These guys must be really stupid.

They are to big to fail at this point. And based on their price the servers are amazing. (If you dont care about a perfect uptime.)

Re: Cock.li server seized again by German prosecutor, service moves to Romania

#23
post #9

since people seem surprised, let me reiterate on those laughable german data protection laws: http://glasz.org/sheeplog/2015/02/data-privacy-regulations-i... DO NOT trust any government or company. everything is full of submissive sheep. particularly so in germany.

Same goes for the U.S. and other five eye countries, even if of other reasons partially.

But to be safe make sure to never use any company to do anything privacy related which is in: U.S., Germany, England, Australia and the one i am missing.

If a gov of any of these decides your privacy is worth nothing anymore, they will just proceed to do so.

Re: Cock.li server seized again by German prosecutor, service moves to Romania

#24
post #12
post #9

since people seem surprised, let me reiterate on those laughable german data protection laws: http://glasz.org/sheeplog/2015/02/data-privacy-regulations-i... DO NOT trust any government or company. everything is full of submissive sheep. particularly so in germany.

One of the remarkable things about the U.S. constitution is that it theoretically allows no escape rope from protection of rights; by contrast the constitutions of many European democracies as well as Canada contain "notwithstanding clauses" that allow free rein to the government when they deem it necessary for any reason to trample on your rights. Not saying the USA is particularly good about upholding those rights.…

There have been more legit services destroyed trough uncompetent lawyers in the U.S. than anywhere else. (afaik)

Re: Cock.li server seized again by German prosecutor, service moves to Romania

#25
post #15

Running a server containing users’ data (especially an e-mail server) in 2016 without full-disk encryption is like running a web server without HTTPS . Just don’t . It’s a privacy disaster waiting to happen. This can happen in any country, even to a silly cock joke site like this, and your users will be hurt by it, possibly for many years to come. There is no longer any excuse not to do it.

Excuse my ignorance, but how does full-disk encryption work if you don't have console access to it?

How do you enter the password after, say, a hard reset/power outage?

Re: Cock.li server seized again by German prosecutor, service moves to Romania

#26
post #25
post #15

Running a server containing users’ data (especially an e-mail server) in 2016 without full-disk encryption is like running a web server without HTTPS . Just don’t . It’s a privacy disaster waiting to happen. This can happen in any country, even to a silly cock joke site like this, and your users will be hurt by it, possibly for many years to come. There is no longer any excuse not to do it.

Excuse my ignorance, but how does full-disk encryption work if you don't have console access to it? How do you enter the password after, say, a hard reset/power outage?

SSH?

Re: Cock.li server seized again by German prosecutor, service moves to Romania

#27
post #14
post #3

Mr. Canfield's thoughts on the matter: >> Of course, though the facts of the case are yet to be seen since no one in Germany is talking to us, I will definitely never host anything in Germany ever again He was trusting of authorities and purposely did not use TLS (beyond STARTTLS) or encrypt his hard drives. And this is what happens. They take his hard drives immediately and seize his entire service. How are we suppo…

I wish that Debian installer (and other distributions) would have encryption on as default, especially if the installer ask you if you intend to install it as a mail server. Users are entrusting their communication to the server which means that the sane defaults should address their need for privacy and control. Law enforcement always operate on what is easiest and cheapest. A common practice seem to have been estab…

IMO, "sane defaults" are missing from pretty much every operating system out there -- both in their installers and the resulting installed system.

It all comes down to that "convenience versus security" trade-off and, for better or worse, those implementing these systems tend to lean more towards the "convenience" side. It's going to take some major changes before we start seeing systems that are "(mostly) secure by default".

Re: Cock.li server seized again by German prosecutor, service moves to Romania

#28
post #23
post #9

since people seem surprised, let me reiterate on those laughable german data protection laws: http://glasz.org/sheeplog/2015/02/data-privacy-regulations-i... DO NOT trust any government or company. everything is full of submissive sheep. particularly so in germany.

Same goes for the U.S. and other five eye countries, even if of other reasons partially. But to be safe make sure to never use any company to do anything privacy related which is in: U.S., Germany, England, Australia and the one i am missing. If a gov of any of these decides your privacy is worth nothing anymore, they will just proceed to do so.

> "... and the one i am missing."

New Zealand.

Re: Cock.li server seized again by German prosecutor, service moves to Romania

#29
post #25
post #15

Running a server containing users’ data (especially an e-mail server) in 2016 without full-disk encryption is like running a web server without HTTPS . Just don’t . It’s a privacy disaster waiting to happen. This can happen in any country, even to a silly cock joke site like this, and your users will be hurt by it, possibly for many years to come. There is no longer any excuse not to do it.

Excuse my ignorance, but how does full-disk encryption work if you don't have console access to it? How do you enter the password after, say, a hard reset/power outage?

For Debian and Ubuntu servers: Mandos (http://www.recompile.se/mandos)

Introduction here: http://www.recompile.se/mandos/man/intro.8mandos

Disclosure: I am a co-author. (Yeah, yeah, we will switch our certificate from CACert to LetsEncrypt. Soon. Ish.)

Re: Cock.li server seized again by German prosecutor, service moves to Romania

#30
post #23

Earlier quoted context omitted.

Same goes for the U.S. and other five eye countries, even if of other reasons partially. But to be safe make sure to never use any company to do anything privacy related which is in: U.S., Germany, England, Australia and the one i am missing. If a gov of any of these decides your privacy is worth nothing anymore, they will just proceed to do so.

> "... and the one i am missing." New Zealand.

thank you
Post reply on HN