We will see this trend of blocking US ownership more often. Any government cannot and should not give access to their own government, citizen data to foreign buyers no matter how good the relationship is. Beside the point, this is drawing clearer picture of US control: losing. Us is seen as a threat and coercion making practices start with owning data using that as control.
Netherlands blocks US takeover of vital digital supplier
201–210 of 246 posts
Re: Netherlands blocks US takeover of vital digital supplier
#202This is exactly why privacy by architecture matters more than privacy by policy. The Netherlands trusted a policy ("Solvinity can't access the data") but the architecture allowed it anyway. The only real solution is cryptographic sovereignty systems where even the vendor mathematically cannot access user data, regardless of what US law says. Not we promise we won't look but we literally cannot look. Building somethin…
So we are back to a single “something you know” factor as identity?
There’s a reason your idea doesn’t exist.
Re: Netherlands blocks US takeover of vital digital supplier
#203As a Dutch citizen, I don't understand why we can't self-host an open source identity solution for 20M users with 30K requests an hour. How hard can it be?
How hard can it be to hire a competent engineer when you hire for a bank or a government.
Governments need it to be solved by a team (either within the government or a vendor company) because it is the non-tech things that are missing from the open source solution: high availability / redundancy, hosting, backups, business continuity, audits, someone to grill when there is a leak.
The people who work in government and banks aren’t incompetent. They are just like you and I but they work within a highly rigid system because if their system isn’t rigid, societies fall. People don’t think rationally during bank runs or when nobody in a country can access public services for weeks at a time. This is the core hazard of Mr. Robot.
Re: Netherlands blocks US takeover of vital digital supplier
#204Earlier quoted context omitted.
No
Except for the military. I once interviewed for a job at what I think was a civil service branch that developed software for the military. But they were out of budget for this, while the military did have budget, so if I was hired, I'd have to wear a military uniform to the office. A very stylish one, they claimed.
Re: Netherlands blocks US takeover of vital digital supplier
#205Earlier quoted context omitted.
Germany as well
What are the penalties for not doing so? I'm always amazed at the willingness of Europeans to follow rules like these, regardless of their impact on personal sovereignty. People in Finland were the most extreme example of this behavior that I've ever encountered. People would look like you murdered a child for jaywalking in Helsinki.
Re: Netherlands blocks US takeover of vital digital supplier
#206Earlier quoted context omitted.
Maybe better, but less useful. I don't carry my Identity Card at all, unless I cross the border within EU where it is used. All other functions I have in our country app. To which I can log in using physical card, but I have other options that are online.
In the Netherlands it is mandatory to carry your ID card or passport at all times.
Police may require identification only in specific situations connected to their duties, not arbitrarily. If you cannot show valid ID when requested, you can still be fined or taken to a police station to establish your identity, so in practice most people do carry ID anyway.
The distinction is historically sensitive in the Netherlands because compulsory identification documents were heavily associated with Nazi occupation policies during World War II.
Re: Netherlands blocks US takeover of vital digital supplier
#207Finally! The entire country has been clamouring for this for weeks, and the government has been completely silent about it. A couple of weeks ago, the entire parliament (with only a single party dissenting) voted for a motion to end the contract with Solvinity, but the government extended it anyway, leaving blocking the takeover as the only option, and there wasn't a lot of confidence that the government would do tha…
It is a bit more complex tham that. Logius is the company that actually owns and manages the DigiD stack, it's just that they hired Solvinity for their expertise. AFAIK Solvinity can't access the data. I can't find it right now, but on Tweakers there was a long comment by someone on the inside that explained Logius basically had almost no know-how of how the current stack works, and there's lots of bespoke stuff. Bas…
Re: Netherlands blocks US takeover of vital digital supplier
#208Earlier quoted context omitted.
Germany as well
What are the penalties for not doing so? I'm always amazed at the willingness of Europeans to follow rules like these, regardless of their impact on personal sovereignty. People in Finland were the most extreme example of this behavior that I've ever encountered. People would look like you murdered a child for jaywalking in Helsinki.
Re: Netherlands blocks US takeover of vital digital supplier
#209We will see this trend of blocking US ownership more often. Any government cannot and should not give access to their own government, citizen data to foreign buyers no matter how good the relationship is. Beside the point, this is drawing clearer picture of US control: losing. Us is seen as a threat and coercion making practices start with owning data using that as control.
You seem to be assuming citizen data was being transferred. Do you have evidence of that?
Some American companies have tried to establish convoluted workarounds in Europe to get around this, but as far as I’m aware it hasn’t been tested in court yet.
Re: Netherlands blocks US takeover of vital digital supplier
#210This is exactly why privacy by architecture matters more than privacy by policy. The Netherlands trusted a policy ("Solvinity can't access the data") but the architecture allowed it anyway. The only real solution is cryptographic sovereignty systems where even the vendor mathematically cannot access user data, regardless of what US law says. Not we promise we won't look but we literally cannot look. Building somethin…