Live data from Hacker News

Silent Circle raises $30M, moves to Switzerland

telecompaper.com

31–40 of 46 posts

Re: Silent Circle raises $30M, moves to Switzerland

#31
post #15
post #11

Earlier quoted context omitted.

I think the point is that silent circle is secured by policy, not by technology. The validity of their security assertions only extend as far as you trust their word.

It's hard for anything but policy to protect against denial of service (legal attacks against the company). Even if you have technical security which prevents compromise of data, they can shut the business down. CALEA means you are actually prevented from building/operating some kinds of privacy tech within the US (PSTN voice without wiretaps for sure, and PSTN-interconnected VOIP is a gray area; a mobile-focused VPN…

As a service provider you have to provide access to a fairly low percentage of data on your network under CALEA. But CALEA does not make end-to-end data protection illegal. You are not obligated to steal your customers' keys or access their endpoint equipment.

In practice, many operators do offer up access to 100% of their traffic, and to their endpoint devices to law enforcement and security agencies, but it's not a CALEA legal requirement.

Re: Silent Circle raises $30M, moves to Switzerland

#32
post #22

Interesting choice. This week another "secure" email service https://protonmail.ch/ launched and their sales pitch is all about Swiss privacy protection laws. Might be a new trend.

Thank you, that looks really good. I have had a consulting business for 15 years and several customers have insisted on all email being encrypted, sometimes using Apple's email app with encryption enabled and sometimes just manually using PGP.

For just those customers who cared about protecting their IP, protonmail looks like it would be easier to use, as long as all parties used it.

Re: Silent Circle raises $30M, moves to Switzerland

#33

I wonder how much longer Switzerland can cash in on their national brand for security and privacy. Their largest banks can't even keep their customers' accounts safe from foreign tax investigators. Why would I trust the integrity of my data there?

These days we seem to live by degrees rather than absolutes - I trust the Swiss more than I do the Americans.

Re: Silent Circle raises $30M, moves to Switzerland

#34
post #9
post #3

Earlier quoted context omitted.

I think you are confusing substantiated, well supported, warrants/subpoenas/etc and tax collaboration agreements, with arbitrary user requests, gag orders, mass surveillance, etc. The two are at opposite spectrums.

I'm not sure we have such a clean historical record in that area. There was a huge scandal in the 80s about massive surveillance of people on the left of the political spectrum : http://en.wikipedia.org/wiki/Secret_files_scandal

The big difference there was: It ended quite a few political careers when it came out, including federal minister Kopp's (since we have no real president that's actually the highest political chair). Switzerland has checks and balances in place that make it very risky for politicians to act contra the people's interests. In the US I can see no such outfall even after all the dirty business has come out - it all seems to be legal.

Re: Silent Circle raises $30M, moves to Switzerland

#35
There is a good write up here about Swiss privacy laws and how they have their own, which do not comply with the EU, etc.

https://www.bestvpn.com/blog/6803/5-best-vpns-for-switzerlan...

Not an promotional link, it just happens to be a decent article with linked source material.

Re: Silent Circle raises $30M, moves to Switzerland

#36
post #15

Earlier quoted context omitted.

It's hard for anything but policy to protect against denial of service (legal attacks against the company). Even if you have technical security which prevents compromise of data, they can shut the business down. CALEA means you are actually prevented from building/operating some kinds of privacy tech within the US (PSTN voice without wiretaps for sure, and PSTN-interconnected VOIP is a gray area; a mobile-focused VPN…

I didn't know Tor, Bittorrent and Bitcoin use laws to protect themselves from DoS.

Those are protocols, not companies or even services... That's like saying ZRTP or SCIMP are using laws to protect themselves...

There are certainly examples of companies using the protocols you listed that have chosen where they operate with great care...

Re: Silent Circle raises $30M, moves to Switzerland

#38
post #22

Interesting choice. This week another "secure" email service https://protonmail.ch/ launched and their sales pitch is all about Swiss privacy protection laws. Might be a new trend.

Thank you, that looks really good. I have had a consulting business for 15 years and several customers have insisted on all email being encrypted, sometimes using Apple's email app with encryption enabled and sometimes just manually using PGP. For just those customers who cared about protecting their IP, protonmail looks like it would be easier to use, as long as all parties used it.

Your clients have the right idea, by using only encrypted email to discuss sensitive information. Anything less would be a step backwards.

Re: Silent Circle raises $30M, moves to Switzerland

#40

Earlier quoted context omitted.

When implementing technology intended to provide user privacy, both fall under "attack on user privacy", and should be treated as such. Either the service has access to user data, in which case it can be arbitrarily compromised for reasons of varying "legitimacy", or the service does not have access to user data, in which case the legitimacy of the request is irrelevant.

Unless the courts ask you to modify your software to access the user data next time they login (iirc, this was the case with bit mail).

That's a strong argument against creating services where JavaScript code served by the server has access to user data.
Post reply on HN