Live data from Hacker News

Getting out of the cloud…

blog.koehntopp.info

31–40 of 95 posts

Re: Getting out of the cloud…

#32
post #4

Can any one please explain in layman terms what this means a bit more clearly? I think I understood the part where the US no longer a good place to store data, and that there are no proper privacy laws protecting foreign citizens' data that is stored on US soil. So basically, if you still want to have a proper privacy policy, GTFO your data to non-US servers ASAP. Anything else? Something I've gotten wrong?

EU law requires certain protections for data classed as "personal data" and "sensitive personal data". It especially requires that "Personal data shall not be transferred to a country or territory outside the European Economic Area unless that country or territory ensures an adequate level of protection for the rights and freedoms of data subjects in relation to the processing of personal data".

There was an agreement, "safe harbour", with the US, but Trump has issued an EO that contradicts it: https://www.lawfareblog.com/us-eu-privacy-shield-maybe-yes-m...

If that agreement is terminated, then it's no longer legal to transfer personal data from the EU to the US. This affects rather a lot of companies.

https://en.wikipedia.org/wiki/Data_Protection_Act_1998#Defin...

Re: Getting out of the cloud…

#33
post #31

Can anyone recommend a European alternative for Amazon AWS?

Aren't the data centers technically owned by Amazon Ireland for compliance (cough tax) reasons? Amazon clearly state that data never moves out of the region.

As long as Amazon has a US presence, it, and the data is hosts, is within legal reach of US judges and government.

Re: Getting out of the cloud…

#35

Earlier quoted context omitted.

The inverted index could simply be built/live on client side. The cloud is then just a backup data storage. Encrypted email is downloaded, unencrypted and indexed on your laptop/phone etc.

To be clear, you're proposing that users download their entire email storage to their phones and browsers before they can search or spam filter their email? And you think that this would be a compelling product for the average email user? I'm having a hard time figuring out if you're trolling.

Isn't this how pretty much any mail client does it? Thunderbird does a decent job at spam filtering my mail. You know, I can even search folders in Outlook! Saying that scanning your 1M mails with 1kb each requires the use of a cloud service seems a bit over the top.

Re: Getting out of the cloud…

#36
post #4

Can any one please explain in layman terms what this means a bit more clearly? I think I understood the part where the US no longer a good place to store data, and that there are no proper privacy laws protecting foreign citizens' data that is stored on US soil. So basically, if you still want to have a proper privacy policy, GTFO your data to non-US servers ASAP. Anything else? Something I've gotten wrong?

I know of more than one company that has essentially duplicated all of their infrastructure from the US to the EU so they can store EU data in the EU.

Re: Getting out of the cloud…

#37

Earlier quoted context omitted.

The inverted index could simply be built/live on client side. The cloud is then just a backup data storage. Encrypted email is downloaded, unencrypted and indexed on your laptop/phone etc.

To be clear, you're proposing that users download their entire email storage to their phones and browsers before they can search or spam filter their email? And you think that this would be a compelling product for the average email user? I'm having a hard time figuring out if you're trolling.

Yes, people are proposing that people download their email. How is that controversial? That's how email works. It's not like emails are large.

Re: Getting out of the cloud…

#38
Starting to think the Trump presidency will be great for Europe, by making it politically unfeasible for European politicians to continue pretending the US is a good ally, leader of the free world, champion of liberal values, etc...

The US fifth column voluntarily leaving the EU will surely expedite the process.

Re: Getting out of the cloud…

#39

Earlier quoted context omitted.

To be clear, you're proposing that users download their entire email storage to their phones and browsers before they can search or spam filter their email? And you think that this would be a compelling product for the average email user? I'm having a hard time figuring out if you're trolling.

Sure - might not be easy for email. It does work for imessages (no server storage, typical size 1-5GB, stored + indexed on client side). So once phones start having 50GB+ storage(wait my iphone already does :p), its not so far fetched to think of having a 20GB inbox stored+indexed on the phone - of course you don't need to store the attachments etc. Anyways, my point was not to suggest a full solution but to say that…

> its not so far fetched to think of having a 20GB inbox stored+indexed on the phone

Yes it is. Besides just syncing the data there are a huge number of other performance hits.

> of course you don't need to store the attachments etc.

Why not? Do you want to a) drop support for searching through attachments (like pdfs) or b) not encrypt those?

> companies are not incentivized to solve this problem.

There has been huge improvements in the last few years in this space (take Signal as an example). But major email providers are not incentivized because most users don't care, UX and performance suffer, email is inherently an unsafe (even if you put PGP on top [1]) and because they would not be able to make as much ad revenue (worse targeting).

[1]: https://blog.filippo.io/giving-up-on-long-term-pgp/

Re: Getting out of the cloud…

#40

Earlier quoted context omitted.

FISA Content requests: July to December 2015 21000–21499. Note - FISA requests includes all personal information, NSL does not. And sure - this particular order is about foreigners' data, but they might require citizens' data in future. Also is data privacy only a US citizen's right? Googlers claimed to have strong views when non-citizen googlers were being treated unfairly on immigration. But no statement when non-c…

FISA is for non-Americans' data, and you were talking about Americans previously. You can't write an executive order that says you can get access to something you previously needed a warrant for without a warrant.

> You can't write an executive order that says you can get access to something you previously needed a warrant for without a warrant.

Well, you can. If the US AG thinks it's illegal, you can fire her. If it's argued in court, you've got a floating SCOTUS appointment ready to make.

(The distinction between "can they do that?" and "can they legally do that?" is normally pedantic but at a time when CBP are reported to be ignoring court orders ( http://nypost.com/2017/01/29/customs-agents-ignore-judge-enf... ), this is becoming increasingly important)

Post reply on HN