Live data from Hacker News

Norwegian backup provider promises NSA-free data storage using Norwegian laws

jottacloud.com

51–60 of 125 posts

Re: Norwegian backup provider promises NSA-free data storage using Norwegian laws

#51
post #6
post #4

From the article "U.S. law enforcement could use the USA PATRIOT Act on a U.S.-based organisation, like Microsoft, Google, Dropbox or Amazon, for example, to force its local subsidiary companies across the world into handing over user data to U.S. authorities." Exactly how? By my understanding a company in EU operates under EU law and US parent company is only stock owner. Stock owner can not by my understanding forc…

Your understanding is false. A sole stockholder (for example, the parent of an independent subsidiary), always has control, even if not by specific direction. They can, after all, fire the entire board, and elect a new one that will direct the company to do what they want. Not to mention in most cases, parent companies do in fact, maintain control over subsidiaries (IE they are not independent subsidiaries), and thus…

The way company law is set up in Norway, you cant as a board member do anything else than what is best for the company you are board member in. Doing something different would mean you could be held responsible. They could fire the board, but the next board have the same rules to go by.

Re: Norwegian backup provider promises NSA-free data storage using Norwegian laws

#52
post #42

Earlier quoted context omitted.

Good luck, I have terabytes of random data. I can always provide you OTP key, and create what ever content I want you to see. (Malleable encryption)

Stay away from the UK - here a judge can throw you in jail for failure to provide keys, even if there's no evidence you still have the keys, and said judge would pretty much be guaranteed to believe that you did not hand over the correct keys if the result is garbage.

I think this might be slight hyperbole but can you link to some cases/incidents for support?

Cheers.

Re: Norwegian backup provider promises NSA-free data storage using Norwegian laws

#53
post #47
post #44

Earlier quoted context omitted.

Well, what you say is not correct. First of all the Data Retention Directive have to be valid for you. I work for the Norwegian email provider Runbox and the EU Data Retention Directive is not applicable for us. It is only valid for carriers that own their own infrastructure down to the data center, called "communication providers". We even have it confirmed by both Kripos (FBI-ish) and Post- og Teletilsynet (Norwegi…

And you don't believe your data passes through a "communications provider"? By the argumentation on your page, almost none of the electronic data targeted by the data retention directive would in fact be retained if the directive is not also applied to data that merely transit a providers network, given that the vast majority of e-mail addresses in use today are not hosted by "communications providers". If that is in…

It does, but they dont offer email or phone services. So they are also exempt. We use Blix: https://www.blix.com/

What you call a loophole, was no secret in the hearings about the new law. The government wanted this implemented mainly for the phone providers. They understood that foreign email providers like Gmail and Hotmail that most use in Norway, could not be under the law in any practical way, so they restricted who this is applicable to.

Re: Norwegian backup provider promises NSA-free data storage using Norwegian laws

#54
post #46
post #41

As a Norwegian, let me just say: Yeah, right. 1. The Norwegian security services have a long history of violating Norwegian law (and when, for example, extensive illegal politically motivated surveillance of mostly left wing politicians was uncovered in the 90's they then had the gall to place an MP and member of the committee investigating them under surveillance while he was working on the report about their illega…

Is there a jurisdiction on the planet where data is safe from domestic wiretapping [1] (i.e. international espionage not withstanding)? Serious question. 1. Clarification: I mean warrantless wiretapping.

It seems like we need an independent project Loon but with servers attached to the balloons!

Re: Norwegian backup provider promises NSA-free data storage using Norwegian laws

#55
post #52
post #42

Earlier quoted context omitted.

Stay away from the UK - here a judge can throw you in jail for failure to provide keys, even if there's no evidence you still have the keys, and said judge would pretty much be guaranteed to believe that you did not hand over the correct keys if the result is garbage.

I think this might be slight hyperbole but can you link to some cases/incidents for support? Cheers.

It's not actually that common, but there have been at least 3 people prosecuted:

http://www.bbc.co.uk/news/uk-england-11479831

http://www.theregister.co.uk/2009/08/11/ripa_iii_figures/

Re: Norwegian backup provider promises NSA-free data storage using Norwegian laws

#56
post #42

Earlier quoted context omitted.

Good luck, I have terabytes of random data. I can always provide you OTP key, and create what ever content I want you to see. (Malleable encryption)

Stay away from the UK - here a judge can throw you in jail for failure to provide keys, even if there's no evidence you still have the keys, and said judge would pretty much be guaranteed to believe that you did not hand over the correct keys if the result is garbage.

http://www.theregister.co.uk/2008/10/14/ripa_self_incriminat...

A couple of people have been convicted of refusing to hand over their encryption key.

It's worth noting that this is a separate offence, so there's a determinate prison sentence. You can't be held in contempt of court for refusing to hand it over.

Re: Norwegian backup provider promises NSA-free data storage using Norwegian laws

#58

Earlier quoted context omitted.

From their website, it seems that tarsnap can't be counted as OSS: "The Tarsnap client code is built around the open source libarchive archive handling library. While the Tarsnap code is not distributed under an open source license..."

Here's the source code: https://www.tarsnap.com/download.html This is the license: Unless specified otherwise in individual files, the contents of this package is covered by the following copyright, license, and disclaimer: Copyright 2006, 2007, 2008, 2009, 2010, 2011 Colin Percival All rights reserved. Redistribution and use in source and binary forms, without modification, is permitted for the sole purpose of using…

My reading of that is that you aren't allowed to redistribute any modifications or use it for anything other than accessing the tarsnap service.

So not really open source software in any sense that I understand.

[NB My comments is not intended as a criticism of tarsnap or Colin's licensing policy - he wrote it so, in my book, he can license it any way he wants.]

Re: Norwegian backup provider promises NSA-free data storage using Norwegian laws

#60
post #45
post #2

I'm moving away from Dropbox today. Thanks for this jensen2k.

If you crypt, Dropbox is fine. People need to use encryption. Every popular computer language has encryption routines, scroll through the source code until you find something accessible, twiddle something to personalize it while keeping it functional, perhaps convince yourself it will remain secure, etc, of course be cautious about that. Or simply, there's double encryption, fold it again. Know big 100 meg, gigabyte…

Any recommendations and best practices to encrypt data ?
Post reply on HN