Live data from Hacker News

AWS European Sovereign Cloud

aws.eu

61–70 of 76 posts

Re: AWS European Sovereign Cloud

#61
This move had a chance to work a couple of years ago, when European companies were seeking CYA compliance in regards to GDPR. The tone has now clearly shifted to a decoupling from American tech. My prediction is that American cloud providers will lag behind truly European alternatives this year.

Re: AWS European Sovereign Cloud

#62

Microsoft admitted that it 'cannot guarantee' data sovereignty [0] "on June 18 before a [French] Senate inquiry into public procurement and the role it plays in European digital sovereignty" as the CLOUD Act "gives the US government authority to obtain digital data held by US-based tech corporations irrespective of whether that data is stored on servers at home or on foreign soil." It'd be great if they could clarify…

It seems like the entire point is precisely to get around the CLOUD Act. By setting it up with a European governance structure, Amazon can tell the US government "hey we told them give us the data, but they refused because that would send them to jail under EU law, and they're a legally separate entity so there's nothing we can do." This is very intentionally not just a regular foreign subsidiary owned by the parent…

> so there's nothing we can do

And US law will just let it go?

There are several options for AWS. They can simply just obfuscate command to local employees. Or fly US employees there just for this one task. "EU law" will find out after they are back in US - if ever. There is no way to escape CLOUD Act if it is US owned.

Re: AWS European Sovereign Cloud

#63
post #62

Earlier quoted context omitted.

It seems like the entire point is precisely to get around the CLOUD Act. By setting it up with a European governance structure, Amazon can tell the US government "hey we told them give us the data, but they refused because that would send them to jail under EU law, and they're a legally separate entity so there's nothing we can do." This is very intentionally not just a regular foreign subsidiary owned by the parent…

> so there's nothing we can do And US law will just let it go? There are several options for AWS. They can simply just obfuscate command to local employees. Or fly US employees there just for this one task. "EU law" will find out after they are back in US - if ever. There is no way to escape CLOUD Act if it is US owned.

There must already be protocols in place that prevent any random Amazon employee from getting access to sensitive data (like, the folks in the warehouses can’t just walk in to the AWS datacenters, I assume).

That’s who those US employees would be, from the point of view of the EU branch… no reason to assume they’d let them in. Flying people over to do crimes seems like a risky idea.

Re: AWS European Sovereign Cloud

#64
post #62

Earlier quoted context omitted.

It seems like the entire point is precisely to get around the CLOUD Act. By setting it up with a European governance structure, Amazon can tell the US government "hey we told them give us the data, but they refused because that would send them to jail under EU law, and they're a legally separate entity so there's nothing we can do." This is very intentionally not just a regular foreign subsidiary owned by the parent…

> so there's nothing we can do And US law will just let it go? There are several options for AWS. They can simply just obfuscate command to local employees. Or fly US employees there just for this one task. "EU law" will find out after they are back in US - if ever. There is no way to escape CLOUD Act if it is US owned.

"Obfuscating commands" isn't a thing. EU employees know if they are retrieving data or not. And they don't blindly run commands like they're dummies or something.

And if they fly American employees over, what makes you think they'd be let in the building, or under what credentials do you think they'd be accessing the system? Legally speaking, those Americans are simply from a partner company. Just because you're doing business with a partner company doesn't mean you let them into your building.

The point is that AWS is intentionally making it so they don't have options.

So yes, US law lets it go. The law is limited in terms of what it can affect outside US borders. If the EU doesn't want to cooperate, and the US isn't willing to engage in sanctions or war against the EU, then yeah the US is out of options.

Re: AWS European Sovereign Cloud

#65
post #15

Earlier quoted context omitted.

> how realistic it is that the US is forcing Amazon to secretly backdoor its own software for US spying abroad? probably 100%?

Over 100%, in that I'm sure multiple independent groups are working on it all the time. The spooks regularly place actual agents in foreign governments (the Germans found a big nest of them and nothing much happened in the end). There's no way it would be challenging for them to find an employee willing to cash a giant cheque in exchange for quietly granting their own government access.

[deleted]

Re: AWS European Sovereign Cloud

#66
post #13

If push comes to shove, these services can and will be weaponized against EU interests. They are bugged and backdoored to the brim. If we see a risk in chinese-made electrical buses which can potentially be remotely shut down by an integrated sim card, then using AWS should be a no go in the current political climate - no matter how much lipstick they put on that pig. Last week, after receiving a fine in Italy, the C…

Italy’s demand was completely unreasonable and CloudFlare threatened to end business in Italy, including informing impacted partners. People talking about EU sovereignty and US hegemony then crying Italy isn’t allowed to dictate terms globally are showing they’re not people with principles — they’re just losers who would be every bit as hegemonic as the US, they just lack the power to be and are publicly crying about…

I heard they are hiring in Cloudflare PR department

Re: AWS European Sovereign Cloud

#69
post #66

Earlier quoted context omitted.

Italy’s demand was completely unreasonable and CloudFlare threatened to end business in Italy, including informing impacted partners. People talking about EU sovereignty and US hegemony then crying Italy isn’t allowed to dictate terms globally are showing they’re not people with principles — they’re just losers who would be every bit as hegemonic as the US, they just lack the power to be and are publicly crying about…

I heard they are hiring in Cloudflare PR department

The best PR that Cloudflare could possibly have here is just the demand letter from AGCOM (aka the Italian comms agency).

Just reading what they are demanding from Cloudflare and their reasoning for it is enough to turn pretty much anyone to Cloudflare’s side. And that’s before even digging into the details of the context preceding that whole conflict

Re: AWS European Sovereign Cloud

#70
post #22

Earlier quoted context omitted.

I don't think there are any protections against that. On the other hand, you'd have to ask yourself how realistic it is that the US is forcing Amazon to secretly backdoor its own software for US spying abroad? I can't give an answer on that one, you'll have to form your own opinion. I imagine that if a back door were ever discovered, AWS's reputation would tank so hard that a lot of companies would probably never do…

Maybe you missed when Microsoft blocked the email account of the chief prosecutor of the international court of justice: https://www.heise.de/en/news/Criminal-Court-Microsoft-s-emai... Of course these services are backdoored.

How is that a “backdoor”? It was just an (outrageous) administrative decision.
Post reply on HN