I worked on a team deploying a service to European Sovereign Cloud (ESC). Disclaimer - I am a low level SDE and all opinions are my own. AWS has set up proper boundaries between ESC and global AWS. Since I'm based out of the US I can't see anything going on in ECS even in the service we develop. To fix an issue there we have to play telephone with an engineer in ESC where they give us a summary of the issue or debug…
AWS European Sovereign Cloud
41–50 of 76 posts
Re: AWS European Sovereign Cloud
#42Earlier quoted context omitted.
Yes, 100%. They are fully compromised and an extension of US dominance. They can and will be weaponized against us. Same with Apple iCloud - one day Europeans will wake up and see that all their pictures have been deleted.
> one day Europeans will wake up and see that all their pictures have been deleted Possible this happens due to bugs in iCloud's GDPR implementation.
Re: AWS European Sovereign Cloud
#43Sovereign-by-design but still runs a software stack that is largely written and maintained by a US staff... All of these isolation sovereignty iniatives are window dressing to the bigger problem that the EU and other countries are massively dependent on proprietaey US-centric software stacks.
Sovereign-by-design but still runs a software stack that is largely written and maintained by a US staff... Not as much as you might think. The most important component -- Nitro -- basically runs out of Germany.
Or the Germany that bought Crypto AG along with the CIA to backdoor encryption hardware?
Re: AWS European Sovereign Cloud
#44Earlier quoted context omitted.
It would seem like the problem is one of the business layout and technical layout. Organize your business and your tech correctly and you can have an owned foreign subsidiary that can comply with local laws. But things would have to be quite separate.
> Organize your business and your tech correctly and you can have an owned foreign subsidiary that can comply with local laws. I doubt it, a majority owned subsidiary is usually passed through for many legal purposes.
Or, just buy bits of control interest outright (CryptoAG?)
Re: AWS European Sovereign Cloud
#45I would love to see a US specific version of this as well. Something similar to GovCloud with the same security controls and employee vetting but accessible to commercial customers.
Re: AWS European Sovereign Cloud
#46Microsoft admitted that it 'cannot guarantee' data sovereignty [0] "on June 18 before a [French] Senate inquiry into public procurement and the role it plays in European digital sovereignty" as the CLOUD Act "gives the US government authority to obtain digital data held by US-based tech corporations irrespective of whether that data is stored on servers at home or on foreign soil." It'd be great if they could clarify…
AWS maintains a similar stance, too [0]?
The CLOUD Act clarified that if a service provider is compelled to produce data under one of the limited exceptions, such as a search warrant for content data, the data to be produced can include data stored in the U.S. or outside the U.S.
> Microsoft admitted that it 'cannot guarantee' data sovereigntyHm. As for AWS, they say that if the customer sets up proper security boundaries [0], they'll ensure will keep their end of the bargain [2][3]:
As part of the technical design, access to the AWS European Sovereign Cloud physical infrastructure and logical system is managed by Qualified AWS European Sovereign Cloud Staff and can only be granted to Qualified AWS European Sovereign Cloud Staff located in the EU. AWS European Sovereign Cloud-restricted data will not be accessible, including to AWS employees, from outside the EU.
All computing on Amazon Elastic Compute Cloud (Amazon EC2) in the AWS European Sovereign Cloud will run on the Nitro System, which eliminates any mechanisms for AWS employees to access customer data on EC2. An independent third party (the UK-based NCC Group) completed a design review confirming the security controls of the Nitro System (“As a matter of design, NCC Group found no gaps in the Nitro System that would compromise these security claims”), and AWS updated its service terms to assure customers “there are no technical means or APIs available to AWS personnel to read, copy, extract, modify, or otherwise access” customer content on the EC2 Nitro System.
Customers also have additional mechanisms to prevent access to their data using cryptography. AWS provides advanced encryption, key management services, and hardware security modules that customers can use to protect their content further. Customers have a range of options to encrypt data in transit and at rest, including options to bring their own keys and use external key stores. Encrypted content is rendered useless without the applicable decryption keys.
The AWS European Sovereign Cloud will also benefit from AWS transparency protections over data movement. We commit in the AWS Service Terms that access to the EC2 Nitro System APIs is "always logged, and always requires authentication and authorization." The AWS European Sovereign Cloud also offers immutable, validated logs that make it impossible to modify, delete, or forge AWS CloudTrail log files without detection.
[0] https://aws.amazon.com/compliance/cloud-act/[1] https://aws.amazon.com/compliance/shared-responsibility-mode...
[2] https://d1.awsstatic.com/onedam/marketing-channels/website/a...
Re: AWS European Sovereign Cloud
#47Microsoft admitted that it 'cannot guarantee' data sovereignty [0] "on June 18 before a [French] Senate inquiry into public procurement and the role it plays in European digital sovereignty" as the CLOUD Act "gives the US government authority to obtain digital data held by US-based tech corporations irrespective of whether that data is stored on servers at home or on foreign soil." It'd be great if they could clarify…
By setting it up with a European governance structure, Amazon can tell the US government "hey we told them give us the data, but they refused because that would send them to jail under EU law, and they're a legally separate entity so there's nothing we can do."
This is very intentionally not just a regular foreign subsidiary owned by the parent company.
Re: AWS European Sovereign Cloud
#48If push comes to shove, these services can and will be weaponized against EU interests. They are bugged and backdoored to the brim. If we see a risk in chinese-made electrical buses which can potentially be remotely shut down by an integrated sim card, then using AWS should be a no go in the current political climate - no matter how much lipstick they put on that pig. Last week, after receiving a fine in Italy, the C…
There will be gnashing of the teeth, doomsaying galore, a few actual minor catastrophes... but we will be okay.
Not just okay, but we will be better off for it. The Internet will be better off for it, because the inescapable side effect will be at least a bit of re-decentralization.
Any European equivalent replacing what is lost will be better. Not because we have better coders or are even better people, mind you - far from it. It will be better because we will have the gift of hindsight; any replacement for web-based productivity services, search engines or social media springing up will be the product of a society and legislative system which has caught up at least in some sense to technological progress and which has been there, done that. The actual web two point oh.
So let's pull out as many plugs as we can. It'll hurt for a bit, but not only is it without alternative - it'll be fresh, it'll be fun and it'll be good in the end.
Let's get to work.
Re: AWS European Sovereign Cloud
#49Earlier quoted context omitted.
If the EU employees can look around the code, it would then get quite interesting if they were to point out a backdoor. which they would of course raise with an EU based CERT. In a way that protects US customers as well having a set that can't be stopped from doing that.
Assuming EU employees get to see the sources, let alone own their building process.
Re: AWS European Sovereign Cloud
#50Earlier quoted context omitted.
Sovereign-by-design but still runs a software stack that is largely written and maintained by a US staff... Not as much as you might think. The most important component -- Nitro -- basically runs out of Germany.
The AWS EC2 virtualization team invented and maintains the Nitro system. And that team is overwhelmingly based in Seattle, WA USA.